diff --git a/.gitignore b/.gitignore index a366580..c51238e 100644 --- a/.gitignore +++ b/.gitignore @@ -184,6 +184,12 @@ docs/za-download-3/ *.docx *.xlsx *.pptx +*.numbers + +# ============================================ +# MkDocs Build Output +# ============================================ +docs-site/ # ============================================ # Entfernte Projekte (nicht mehr aktiv) diff --git a/ai-compliance-sdk/docs/DEVELOPER.md b/ai-compliance-sdk/docs/DEVELOPER.md deleted file mode 100644 index f894d8e..0000000 --- a/ai-compliance-sdk/docs/DEVELOPER.md +++ /dev/null @@ -1,1011 +0,0 @@ -# AI Compliance SDK - Entwickler-Dokumentation - -## Inhaltsverzeichnis - -1. [Schnellstart](#1-schnellstart) -2. [Architektur-Übersicht](#2-architektur-übersicht) -3. [Policy Engine](#3-policy-engine) -4. [License Policy Engine](#4-license-policy-engine) -5. [Legal RAG Integration](#5-legal-rag-integration) -6. [Wizard & Legal Assistant](#6-wizard--legal-assistant) -7. [Eskalations-System](#7-eskalations-system) -8. [API-Endpoints](#8-api-endpoints) -9. [Policy-Dateien](#9-policy-dateien) -10. [Tests ausführen](#10-tests-ausführen) -11. [Generic Obligations Framework](#11-generic-obligations-framework) -12. [Tests für Obligations Framework](#12-tests-für-obligations-framework) -13. [DSFA (Datenschutz-Folgenabschätzung)](#13-dsfa-datenschutz-folgenabschätzung-nach-art-35-dsgvo) - ---- - -## 1. Schnellstart - -### Voraussetzungen - -- Go 1.21+ -- PostgreSQL (für Eskalations-Store) -- Qdrant (für Legal RAG) -- Ollama oder Anthropic API Key (für LLM) - -### Build & Run - -```bash -# Build -cd ai-compliance-sdk -go build -o server ./cmd/server - -# Run -./server --config config.yaml - -# Alternativ: mit Docker -docker compose up -d -``` - -### Erste Anfrage - -```bash -# UCCA Assessment erstellen -curl -X POST http://localhost:8080/sdk/v1/ucca/assess \ - -H "Content-Type: application/json" \ - -d '{ - "use_case_text": "Chatbot für Kundenservice mit FAQ-Suche", - "domain": "utilities", - "data_types": { - "personal_data": false, - "public_data": true - }, - "automation": "assistive", - "model_usage": { - "rag": true - }, - "hosting": { - "region": "eu" - } - }' -``` - ---- - -## 2. Architektur-Übersicht - -``` -┌─────────────────────────────────────────────────────────────────┐ -│ API Layer (Gin) │ -│ internal/api/handlers/ │ -├─────────────────────────────────────────────────────────────────┤ -│ │ -│ ┌─────────────┐ ┌─────────────┐ ┌─────────────────────────┐ │ -│ │ UCCA │ │ License │ │ Eskalation │ │ -│ │ Handler │ │ Handler │ │ Handler │ │ -│ └──────┬──────┘ └──────┬──────┘ └───────────┬─────────────┘ │ -│ │ │ │ │ -├─────────┼────────────────┼──────────────────────┼────────────────┤ -│ ▼ ▼ ▼ │ -│ ┌─────────────┐ ┌─────────────┐ ┌─────────────────────────┐ │ -│ │ Policy │ │ License │ │ Escalation │ │ -│ │ Engine │ │ Policy │ │ Store │ │ -│ │ │ │ Engine │ │ │ │ -│ └──────┬──────┘ └──────┬──────┘ └───────────┬─────────────┘ │ -│ │ │ │ │ -│ └────────┬───────┴──────────────────────┘ │ -│ ▼ │ -│ ┌─────────────────────────────────────────────────┐ │ -│ │ Legal RAG System │ │ -│ │ (Qdrant + LLM Integration) │ │ -│ └─────────────────────────────────────────────────┘ │ -│ │ -└─────────────────────────────────────────────────────────────────┘ -``` - -### Kernprinzip - -**LLM ist NICHT die Quelle der Wahrheit!** - -| Komponente | Entscheidet | LLM-Nutzung | -|------------|-------------|-------------| -| Policy Engine | Feasibility, Risk Level | Nein | -| License Engine | Operation Mode, Stop-Lines | Nein | -| Gap Mapping | Facts → Gaps → Controls | Nein | -| Legal RAG | Erklärung generieren | Ja (nur Output) | - ---- - -## 3. Policy Engine - -### Übersicht - -Die Policy Engine (`internal/ucca/policy_engine.go`) evaluiert Use Cases gegen deterministische Regeln. - -### Verwendung - -```go -import "ai-compliance-sdk/internal/ucca" - -// Engine erstellen -engine, err := ucca.NewPolicyEngineFromPath("policies/ucca_policy_v1.yaml") -if err != nil { - log.Fatal(err) -} - -// Intake erstellen -intake := &ucca.UseCaseIntake{ - UseCaseText: "Chatbot für Kundenservice", - Domain: ucca.DomainUtilities, - DataTypes: ucca.DataTypes{ - PersonalData: false, - PublicData: true, - }, - Automation: ucca.AutomationAssistive, - ModelUsage: ucca.ModelUsage{ - RAG: true, - }, - Hosting: ucca.Hosting{ - Region: "eu", - }, -} - -// Evaluieren -result := engine.Evaluate(intake) - -// Ergebnis auswerten -fmt.Println("Feasibility:", result.Feasibility) // YES, NO, CONDITIONAL -fmt.Println("Risk Level:", result.RiskLevel) // MINIMAL, LOW, MEDIUM, HIGH -fmt.Println("Risk Score:", result.RiskScore) // 0-100 -``` - -### Ergebnis-Struktur - -```go -type EvaluationResult struct { - Feasibility Feasibility // YES, NO, CONDITIONAL - RiskLevel RiskLevel // MINIMAL, LOW, MEDIUM, HIGH - RiskScore int // 0-100 - TriggeredRules []TriggeredRule // Ausgelöste Regeln - RequiredControls []Control // Erforderliche Maßnahmen - RecommendedArchitecture []Pattern // Empfohlene Patterns - DSFARecommended bool // DSFA erforderlich? - Art22Risk bool // Art. 22 Risiko? - TrainingAllowed TrainingAllowed // YES, NO, CONDITIONAL - PolicyVersion string // Version der Policy -} -``` - -### Regeln hinzufügen - -Neue Regeln werden in `policies/ucca_policy_v1.yaml` definiert: - -```yaml -rules: - - id: R-CUSTOM-001 - code: R-CUSTOM-001 - category: custom - title: Custom Rule - title_de: Benutzerdefinierte Regel - description: Custom rule description - severity: WARN # INFO, WARN, BLOCK - gdpr_ref: "Art. 6 DSGVO" - condition: - all_of: - - field: domain - equals: custom_domain - - field: data_types.personal_data - equals: true - controls: - - C_CUSTOM_CONTROL -``` - ---- - -## 4. License Policy Engine - -### Übersicht - -Die License Policy Engine (`internal/ucca/license_policy.go`) prüft die Lizenz-Compliance für Standards und Normen. - -### Operationsmodi - -| Modus | Beschreibung | Lizenzanforderung | -|-------|--------------|-------------------| -| `LINK_ONLY` | Nur Verweise | Keine | -| `NOTES_ONLY` | Eigene Notizen | Keine | -| `EXCERPT_ONLY` | Kurzzitate (<150 Zeichen) | Standard-Lizenz | -| `FULLTEXT_RAG` | Volltext-Embedding | Explizite KI-Lizenz | -| `TRAINING` | Modell-Training | Enterprise + Vertrag | - -### Verwendung - -```go -import "ai-compliance-sdk/internal/ucca" - -engine := ucca.NewLicensePolicyEngine() - -facts := &ucca.LicensedContentFacts{ - Present: true, - Publisher: "DIN_MEDIA", - LicenseType: "SINGLE_WORKSTATION", - AIUsePermitted: "NO", - ProofUploaded: false, - OperationMode: "FULLTEXT_RAG", -} - -result := engine.Evaluate(facts) - -if !result.Allowed { - fmt.Println("Blockiert:", result.StopLine.Message) - fmt.Println("Effektiver Modus:", result.EffectiveMode) -} -``` - -### Ingest-Entscheidung - -```go -// Prüfen ob Volltext-Ingest erlaubt ist -canIngest := engine.CanIngestFulltext(facts) - -// Oder detaillierte Entscheidung -decision := engine.DecideIngest(facts) -fmt.Println("Fulltext:", decision.AllowFulltext) -fmt.Println("Notes:", decision.AllowNotes) -fmt.Println("Metadata:", decision.AllowMetadata) -``` - -### Audit-Logging - -```go -// Audit-Entry erstellen -entry := engine.FormatAuditEntry("tenant-123", "doc-456", facts, result) - -// Human-readable Summary -summary := engine.FormatHumanReadableSummary(result) -fmt.Println(summary) -``` - -### Publisher-spezifische Regeln - -DIN Media hat explizite Restriktionen: - -```go -// DIN Media blockiert FULLTEXT_RAG ohne AI-Lizenz -if facts.Publisher == "DIN_MEDIA" && facts.AIUsePermitted != "YES" { - // → STOP_DIN_FULLTEXT_AI_NOT_ALLOWED - // → Downgrade auf LINK_ONLY -} -``` - ---- - -## 5. Legal RAG Integration - -### Übersicht - -Das Legal RAG System (`internal/ucca/legal_rag.go`) generiert Erklärungen mit rechtlichem Kontext. - -### Verwendung - -```go -import "ai-compliance-sdk/internal/ucca" - -rag := ucca.NewLegalRAGService(qdrantClient, llmClient, "bp_legal_corpus") - -// Erklärung generieren -explanation, err := rag.Explain(ctx, result, intake) -if err != nil { - log.Error(err) -} - -fmt.Println("Erklärung:", explanation.Text) -fmt.Println("Rechtsquellen:", explanation.Sources) -``` - -### Rechtsquellen im RAG - -| Quelle | Chunks | Beschreibung | -|--------|--------|--------------| -| DSGVO | 128 | EU Datenschutz-Grundverordnung | -| AI Act | 96 | EU AI-Verordnung | -| NIS2 | 128 | Netzwerk-Informationssicherheit | -| SCC | 32 | Standardvertragsklauseln | -| DPF | 714 | Data Privacy Framework | - ---- - -## 6. Wizard & Legal Assistant - -### Wizard-Schema - -Das Wizard-Schema (`policies/wizard_schema_v1.yaml`) definiert die Fragen für das Frontend. - -### Legal Assistant verwenden - -```go -// Wizard-Frage an Legal Assistant stellen -type WizardAskRequest struct { - Question string `json:"question"` - StepNumber int `json:"step_number"` - FieldID string `json:"field_id,omitempty"` - CurrentData map[string]interface{} `json:"current_data,omitempty"` -} - -// POST /sdk/v1/ucca/wizard/ask -``` - -### Beispiel API-Call - -```bash -curl -X POST http://localhost:8080/sdk/v1/ucca/wizard/ask \ - -H "Content-Type: application/json" \ - -d '{ - "question": "Was sind personenbezogene Daten?", - "step_number": 2, - "field_id": "data_types.personal_data" - }' -``` - ---- - -## 7. Eskalations-System - -### Eskalationsstufen - -| Level | Auslöser | Prüfer | SLA | -|-------|----------|--------|-----| -| E0 | Nur INFO | Automatisch | - | -| E1 | WARN, geringes Risiko | Team-Lead | 24h | -| E2 | Art. 9, DSFA empfohlen | DSB | 8h | -| E3 | BLOCK, hohes Risiko | DSB + Legal | 4h | - -### Eskalation erstellen - -```go -import "ai-compliance-sdk/internal/ucca" - -store := ucca.NewEscalationStore(db) - -escalation := &ucca.Escalation{ - AssessmentID: "assess-123", - Level: ucca.EscalationE2, - TriggerReason: "Art. 9 Daten betroffen", - RequiredReviews: 1, -} - -err := store.CreateEscalation(ctx, escalation) -``` - -### SLA-Monitor - -```go -monitor := ucca.NewSLAMonitor(store, notificationService) - -// Im Hintergrund starten -go monitor.Start(ctx) -``` - ---- - -## 8. API-Endpoints - -### UCCA Endpoints - -| Method | Endpoint | Beschreibung | -|--------|----------|--------------| -| POST | `/sdk/v1/ucca/assess` | Assessment erstellen | -| GET | `/sdk/v1/ucca/assess/:id` | Assessment abrufen | -| POST | `/sdk/v1/ucca/explain` | Erklärung generieren | -| GET | `/sdk/v1/ucca/wizard/schema` | Wizard-Schema abrufen | -| POST | `/sdk/v1/ucca/wizard/ask` | Legal Assistant fragen | - -### License Endpoints - -| Method | Endpoint | Beschreibung | -|--------|----------|--------------| -| POST | `/sdk/v1/license/evaluate` | Lizenz-Prüfung | -| POST | `/sdk/v1/license/decide-ingest` | Ingest-Entscheidung | - -### Eskalations-Endpoints - -| Method | Endpoint | Beschreibung | -|--------|----------|--------------| -| GET | `/sdk/v1/escalations` | Offene Eskalationen | -| GET | `/sdk/v1/escalations/:id` | Eskalation abrufen | -| POST | `/sdk/v1/escalations/:id/decide` | Entscheidung treffen | - ---- - -## 9. Policy-Dateien - -### Dateistruktur - -``` -policies/ -├── ucca_policy_v1.yaml # Haupt-Policy (Regeln, Controls, Patterns) -├── wizard_schema_v1.yaml # Wizard-Fragen und Legal Assistant -├── controls_catalog.yaml # Detaillierte Control-Beschreibungen -├── gap_mapping.yaml # Facts → Gaps → Controls -├── licensed_content_policy.yaml # Standards/Normen Compliance -└── scc_legal_corpus.yaml # SCC Rechtsquellen -``` - -### Policy-Version - -Jede Policy hat eine Version: - -```yaml -metadata: - version: "1.0.0" - effective_date: "2025-01-01" - author: "Compliance Team" -``` - ---- - -## 10. Tests ausführen - -### Alle Tests - -```bash -cd ai-compliance-sdk -go test -v ./... -``` - -### Spezifische Tests - -```bash -# Policy Engine Tests -go test -v ./internal/ucca/policy_engine_test.go - -# License Policy Tests -go test -v ./internal/ucca/license_policy_test.go - -# Eskalation Tests -go test -v ./internal/ucca/escalation_test.go -``` - -### Test-Coverage - -```bash -go test -cover ./... - -# HTML-Report -go test -coverprofile=coverage.out ./... -go tool cover -html=coverage.out -``` - -### Beispiel: Neuen Test hinzufügen - -```go -func TestMyNewFeature(t *testing.T) { - engine := NewLicensePolicyEngine() - - facts := &LicensedContentFacts{ - Present: true, - Publisher: "DIN_MEDIA", - OperationMode: "FULLTEXT_RAG", - } - - result := engine.Evaluate(facts) - - if result.Allowed { - t.Error("Expected blocked for DIN_MEDIA FULLTEXT_RAG") - } -} -``` - ---- - -## Anhang: Wichtige Dateien - -| Datei | Beschreibung | -|-------|--------------| -| `internal/ucca/policy_engine.go` | Haupt-Policy-Engine | -| `internal/ucca/license_policy.go` | License Policy Engine | -| `internal/ucca/legal_rag.go` | Legal RAG Integration | -| `internal/ucca/escalation_store.go` | Eskalations-Verwaltung | -| `internal/ucca/sla_monitor.go` | SLA-Überwachung | -| `internal/api/handlers/ucca_handlers.go` | API-Handler | -| `cmd/server/main.go` | Server-Einstiegspunkt | - ---- - ---- - -## 11. Generic Obligations Framework - -### Übersicht - -Das Obligations Framework ermöglicht die automatische Ableitung regulatorischer Pflichten aus NIS2, DSGVO und AI Act. - -### Verwendung - -```go -import "ai-compliance-sdk/internal/ucca" - -// Registry erstellen (lädt alle Module) -registry := ucca.NewObligationsRegistry() - -// UnifiedFacts aufbauen -facts := &ucca.UnifiedFacts{ - Organization: ucca.OrganizationFacts{ - EmployeeCount: 150, - AnnualRevenue: 30000000, - Country: "DE", - EUMember: true, - }, - Sector: ucca.SectorFacts{ - PrimarySector: "digital_infrastructure", - SpecialServices: []string{"cloud", "msp"}, - IsKRITIS: false, - }, - DataProtection: ucca.DataProtectionFacts{ - ProcessesPersonalData: true, - }, - AIUsage: ucca.AIUsageFacts{ - UsesAI: true, - HighRiskCategories: []string{"employment"}, - IsGPAIProvider: false, - }, -} - -// Alle anwendbaren Pflichten evaluieren -overview := registry.EvaluateAll(facts, "Muster GmbH") - -// Ergebnis auswerten -fmt.Println("Anwendbare Regulierungen:", len(overview.ApplicableRegulations)) -fmt.Println("Gesamtzahl Pflichten:", len(overview.Obligations)) -fmt.Println("Kritische Pflichten:", overview.ExecutiveSummary.CriticalObligations) -``` - -### Neues Regulierungsmodul erstellen - -```go -// 1. Module-Interface implementieren -type MyRegulationModule struct { - obligations []ucca.Obligation - controls []ucca.ObligationControl - incidentDeadlines []ucca.IncidentDeadline -} - -func (m *MyRegulationModule) ID() string { return "my_regulation" } -func (m *MyRegulationModule) Name() string { return "My Regulation" } - -func (m *MyRegulationModule) IsApplicable(facts *ucca.UnifiedFacts) bool { - // Prüflogik implementieren - return facts.Organization.Country == "DE" -} - -func (m *MyRegulationModule) DeriveObligations(facts *ucca.UnifiedFacts) []ucca.Obligation { - // Pflichten basierend auf Facts ableiten - return m.obligations -} - -// 2. In Registry registrieren -func NewMyRegulationModule() (*MyRegulationModule, error) { - m := &MyRegulationModule{} - // YAML laden oder hardcoded Pflichten definieren - return m, nil -} - -// In obligations_registry.go: -// r.Register(NewMyRegulationModule()) -``` - -### YAML-basierte Pflichten - -```yaml -# policies/obligations/my_regulation_obligations.yaml -regulation: my_regulation -name: "My Regulation" - -obligations: - - id: "MYREG-OBL-001" - title: "Compliance-Pflicht" - description: "Beschreibung der Pflicht" - applies_when: "classification != 'nicht_betroffen'" - legal_basis: - - norm: "§ 1 MyReg" - category: "Governance" - responsible: "Geschäftsführung" - deadline: - type: "relative" - duration: "12 Monate" - sanctions: - max_fine: "1 Mio. EUR" - priority: "high" - -controls: - - id: "MYREG-CTRL-001" - name: "Kontrollmaßnahme" - category: "Technical" - when_applicable: "immer" - what_to_do: "Maßnahme implementieren" - evidence_needed: - - "Dokumentation" -``` - -### PDF Export - -```go -import "ai-compliance-sdk/internal/ucca" - -// Exporter erstellen -exporter := ucca.NewPDFExporter("de") - -// PDF generieren -response, err := exporter.ExportManagementMemo(overview) -if err != nil { - log.Fatal(err) -} - -// base64-kodierter PDF-Inhalt -fmt.Println("Content-Type:", response.ContentType) // application/pdf -fmt.Println("Filename:", response.Filename) - -// PDF speichern -decoded, _ := base64.StdEncoding.DecodeString(response.Content) -os.WriteFile("memo.pdf", decoded, 0644) - -// Alternativ: Markdown -mdResponse, err := exporter.ExportMarkdown(overview) -fmt.Println(mdResponse.Content) // Markdown-Text -``` - -### API-Endpoints - -```bash -# Assessment erstellen -curl -X POST http://localhost:8090/sdk/v1/ucca/obligations/assess \ - -H "Content-Type: application/json" \ - -d '{ - "facts": { - "organization": {"employee_count": 150, "country": "DE"}, - "sector": {"primary_sector": "healthcare"}, - "data_protection": {"processes_personal_data": true}, - "ai_usage": {"uses_ai": false} - }, - "organization_name": "Test GmbH" - }' - -# PDF Export (direkt) -curl -X POST http://localhost:8090/sdk/v1/ucca/obligations/export/direct \ - -H "Content-Type: application/json" \ - -d '{ - "overview": { ... }, - "format": "pdf", - "language": "de" - }' -``` - ---- - -## 12. Tests für Obligations Framework - -```bash -# Alle Obligations-Tests -go test -v ./internal/ucca/..._module_test.go - -# NIS2 Module Tests -go test -v ./internal/ucca/nis2_module_test.go - -# DSGVO Module Tests -go test -v ./internal/ucca/dsgvo_module_test.go - -# AI Act Module Tests -go test -v ./internal/ucca/ai_act_module_test.go - -# PDF Export Tests -go test -v ./internal/ucca/pdf_export_test.go -``` - -### Beispiel-Tests - -```go -func TestNIS2Module_LargeCompanyInAnnexISector(t *testing.T) { - module, _ := ucca.NewNIS2Module() - - facts := &ucca.UnifiedFacts{ - Organization: ucca.OrganizationFacts{ - EmployeeCount: 500, - AnnualRevenue: 100000000, - Country: "DE", - }, - Sector: ucca.SectorFacts{ - PrimarySector: "energy", - }, - } - - if !module.IsApplicable(facts) { - t.Error("Expected NIS2 to apply to large energy company") - } - - classification := module.Classify(facts) - if classification != "besonders_wichtige_einrichtung" { - t.Errorf("Expected 'besonders_wichtige_einrichtung', got '%s'", classification) - } -} - -func TestAIActModule_HighRiskEmploymentAI(t *testing.T) { - module, _ := ucca.NewAIActModule() - - facts := &ucca.UnifiedFacts{ - AIUsage: ucca.AIUsageFacts{ - UsesAI: true, - HighRiskCategories: []string{"employment"}, - }, - } - - if !module.IsApplicable(facts) { - t.Error("Expected AI Act to apply") - } - - riskLevel := module.ClassifyRisk(facts) - if riskLevel != ucca.AIActHighRisk { - t.Errorf("Expected 'high_risk', got '%s'", riskLevel) - } -} -``` - ---- - -## Anhang: Wichtige Dateien (erweitert) - -| Datei | Beschreibung | -|-------|--------------| -| `internal/ucca/policy_engine.go` | Haupt-Policy-Engine | -| `internal/ucca/license_policy.go` | License Policy Engine | -| `internal/ucca/obligations_framework.go` | Obligations Interfaces & Typen | -| `internal/ucca/obligations_registry.go` | Modul-Registry | -| `internal/ucca/nis2_module.go` | NIS2 Decision Tree | -| `internal/ucca/dsgvo_module.go` | DSGVO Pflichten | -| `internal/ucca/ai_act_module.go` | AI Act Risk Classification | -| `internal/ucca/pdf_export.go` | PDF/Markdown Export | -| `internal/api/handlers/obligations_handlers.go` | Obligations API | -| `policies/obligations/*.yaml` | Pflichten-Kataloge | - ---- - ---- - -## 13. DSFA (Datenschutz-Folgenabschätzung nach Art. 35 DSGVO) - -### Übersicht - -Das DSFA-Modul implementiert die Datenschutz-Folgenabschätzung gemäß Art. 35 DSGVO als generisches Compliance-Tool für jeden KI-Anwendungsfall. - -### Architektur - -``` -┌─────────────────────────────────────────────────────────────────┐ -│ Frontend (admin-v2) │ -│ app/(sdk)/sdk/dsfa/ │ -│ ├── page.tsx (Dashboard) │ -│ └── [id]/page.tsx (5-Abschnitt-Editor) │ -├─────────────────────────────────────────────────────────────────┤ -│ Components │ -│ components/sdk/dsfa/ │ -│ ├── DSFACard.tsx (Listenansicht) │ -│ ├── RiskMatrix.tsx (Interaktive Risiko-Matrix) │ -│ └── ApprovalPanel.tsx (Genehmigungs-Workflow) │ -├─────────────────────────────────────────────────────────────────┤ -│ API Client │ -│ lib/sdk/dsfa/ │ -│ ├── types.ts (TypeScript-Typen) │ -│ └── api.ts (API-Funktionen) │ -├─────────────────────────────────────────────────────────────────┤ -│ Backend (Go) │ -│ internal/dsgvo/ │ -│ ├── models.go (DSFA-Datenmodell) │ -│ ├── store.go (PostgreSQL-Persistierung) │ -│ └── handlers.go (API-Endpoints) │ -└─────────────────────────────────────────────────────────────────┘ -``` - -### Zwei Einstiegswege - -| Weg | Beschreibung | Vorausgefüllt | -|-----|--------------|---------------| -| **UCCA-getriggert** | Automatisch bei Trigger-Regeln (R-A002, R-A003, etc.) | Ja | -| **Standalone** | Manuell für Verarbeitungen ohne UCCA | Nein | - -### Die 5 Abschnitte nach Art. 35 DSGVO - -| # | Abschnitt | Art. 35 Ref | Inhalt | -|---|-----------|-------------|--------| -| 1 | Systematische Beschreibung | Abs. 7 lit. a | Zweck, Datenkategorien, Betroffene, Empfänger, Rechtsgrundlage | -| 2 | Notwendigkeit & Verhältnismäßigkeit | Abs. 7 lit. b | Warum notwendig? Alternativen? Datenminimierung? | -| 3 | Risikobewertung | Abs. 7 lit. c | Risiko-Matrix (Eintrittswahrscheinlichkeit × Schwere) | -| 4 | Abhilfemaßnahmen | Abs. 7 lit. d | Technische + Organisatorische Maßnahmen | -| 5 | Stellungnahme DSB | Abs. 2 + Art. 36 | DSB-Konsultation, ggf. Behörden-Konsultation | - -### Datenmodell - -```go -type DSFA struct { - ID uuid.UUID `json:"id"` - TenantID uuid.UUID `json:"tenant_id"` - AssessmentID *uuid.UUID `json:"assessment_id,omitempty"` // UCCA-Verknüpfung - Name string `json:"name"` - Description string `json:"description"` - - // Abschnitt 1: Systematische Beschreibung - ProcessingDescription string `json:"processing_description"` - ProcessingPurpose string `json:"processing_purpose"` - DataCategories []string `json:"data_categories"` - DataSubjects []string `json:"data_subjects"` - Recipients []string `json:"recipients"` - LegalBasis string `json:"legal_basis"` - - // Abschnitt 2: Notwendigkeit - NecessityAssessment string `json:"necessity_assessment"` - ProportionalityAssessment string `json:"proportionality_assessment"` - DataMinimization string `json:"data_minimization"` - AlternativesConsidered string `json:"alternatives_considered"` - - // Abschnitt 3: Risikobewertung - Risks []DSFARisk `json:"risks"` - OverallRiskLevel string `json:"overall_risk_level"` - RiskScore int `json:"risk_score"` - AffectedRights []string `json:"affected_rights"` - TriggeredRuleCodes []string `json:"triggered_rule_codes"` - - // Abschnitt 4: Maßnahmen - Mitigations []DSFAMitigation `json:"mitigations"` - TOMReferences []string `json:"tom_references"` - - // Abschnitt 5: DSB-Stellungnahme - DPOConsulted bool `json:"dpo_consulted"` - DPOName string `json:"dpo_name"` - DPOOpinion string `json:"dpo_opinion"` - AuthorityConsulted bool `json:"authority_consulted"` - AuthorityReference string `json:"authority_reference"` - - // Workflow - Status string `json:"status"` // draft, in_review, approved, rejected - SectionProgress DSFASectionProgress `json:"section_progress"` - ReviewComments []DSFAReviewComment `json:"review_comments"` -} - -type DSFARisk struct { - ID string `json:"id"` - Category string `json:"category"` // confidentiality, integrity, availability, rights_freedoms - Description string `json:"description"` - Likelihood string `json:"likelihood"` // low, medium, high - Impact string `json:"impact"` // low, medium, high - RiskLevel string `json:"risk_level"` // low, medium, high, very_high -} - -type DSFAMitigation struct { - ID string `json:"id"` - RiskID string `json:"risk_id"` - Description string `json:"description"` - Type string `json:"type"` // technical, organizational, legal - Status string `json:"status"` // planned, in_progress, implemented, verified - ResponsibleParty string `json:"responsible_party"` - TOMReference string `json:"tom_reference,omitempty"` -} -``` - -### API-Endpoints - -| Method | Endpoint | Beschreibung | -|--------|----------|--------------| -| GET | `/sdk/v1/dsgvo/dsfas` | Alle DSFAs auflisten | -| POST | `/sdk/v1/dsgvo/dsfas` | Neue DSFA erstellen | -| GET | `/sdk/v1/dsgvo/dsfas/:id` | DSFA abrufen | -| PUT | `/sdk/v1/dsgvo/dsfas/:id` | DSFA aktualisieren | -| DELETE | `/sdk/v1/dsgvo/dsfas/:id` | DSFA löschen | -| PUT | `/sdk/v1/dsgvo/dsfas/:id/sections/:num` | Abschnitt aktualisieren | -| POST | `/sdk/v1/dsgvo/dsfas/:id/submit-for-review` | Zur Prüfung einreichen | -| POST | `/sdk/v1/dsgvo/dsfas/:id/approve` | Genehmigen/Ablehnen | -| GET | `/sdk/v1/dsgvo/dsfas/stats` | Statistiken abrufen | -| POST | `/sdk/v1/dsgvo/dsfas/from-assessment/:id` | DSFA aus UCCA erstellen | -| GET | `/sdk/v1/dsgvo/dsfas/by-assessment/:id` | DSFA zu Assessment finden | - -### Verwendung (Backend) - -```go -import "ai-compliance-sdk/internal/dsgvo" - -// Store erstellen -store := dsgvo.NewStore(db) - -// DSFA erstellen -dsfa := &dsgvo.DSFA{ - Name: "KI-Chatbot Kundenservice", - ProcessingPurpose: "Automatisierte Kundenanfragen-Bearbeitung", - DataCategories: []string{"Kontaktdaten", "Anfrageinhalte"}, - DataSubjects: []string{"Kunden"}, - LegalBasis: "legitimate_interest", - Status: "draft", -} - -id, err := store.CreateDSFA(ctx, tenantID, dsfa) - -// Abschnitt aktualisieren -err = store.UpdateDSFASection(ctx, id, 1, map[string]interface{}{ - "processing_description": "Detaillierte Beschreibung...", -}) - -// Zur Prüfung einreichen -err = store.SubmitDSFAForReview(ctx, id, userID) - -// Genehmigen -err = store.ApproveDSFA(ctx, id, approverID, true, "Genehmigt nach Prüfung") -``` - -### Verwendung (Frontend) - -```typescript -import { listDSFAs, getDSFA, updateDSFASection, submitDSFAForReview } from '@/lib/sdk/dsfa/api' - -// DSFAs laden -const dsfas = await listDSFAs() - -// Einzelne DSFA laden -const dsfa = await getDSFA(id) - -// Abschnitt aktualisieren -await updateDSFASection(id, 1, { - processing_purpose: 'Neuer Zweck', - data_categories: ['Kontaktdaten', 'Nutzungsdaten'], -}) - -// Zur Prüfung einreichen -await submitDSFAForReview(id) -``` - -### Risiko-Matrix - -Die Risiko-Matrix berechnet die Risikostufe aus Eintrittswahrscheinlichkeit und Auswirkung: - -```typescript -import { calculateRiskLevel } from '@/lib/sdk/dsfa/types' - -const { level, score } = calculateRiskLevel('high', 'high') -// level: 'very_high', score: 90 -``` - -| Eintritt \ Auswirkung | Niedrig | Mittel | Hoch | -|-----------------------|---------|--------|------| -| **Hoch** | Mittel (40) | Hoch (70) | Sehr Hoch (90) | -| **Mittel** | Niedrig (20) | Mittel (50) | Hoch (70) | -| **Niedrig** | Niedrig (10) | Niedrig (20) | Mittel (40) | - -### UCCA-Integration (Trigger-Regeln) - -Folgende UCCA-Regeln lösen eine DSFA-Empfehlung aus: - -| Code | Beschreibung | -|------|--------------| -| R-A002 | Art. 9 Daten (besondere Kategorien) | -| R-A003 | Daten von Minderjährigen | -| R-A005 | Biometrische Daten | -| R-B002 | Scoring (systematische Bewertung) | -| R-B003 | Profiling | -| R-B004 | Marketing mit personenbezogenen Daten | -| R-D003 | Training mit Gesundheitsdaten | -| R-G002 | Risiko-Score ≥ 60 | - -### Tests - -```bash -# Backend-Tests -go test -v ./internal/dsgvo/... - -# Frontend-Tests -cd admin-v2 && npm test -- --testPathPattern=dsfa -``` - -### Wichtige Dateien - -| Datei | Beschreibung | -|-------|--------------| -| `internal/dsgvo/models.go` | DSFA-Datenmodell | -| `internal/dsgvo/store.go` | PostgreSQL-Store | -| `internal/api/handlers/dsgvo_handlers.go` | API-Handler | -| `admin-v2/lib/sdk/dsfa/types.ts` | TypeScript-Typen | -| `admin-v2/lib/sdk/dsfa/api.ts` | API-Client | -| `admin-v2/components/sdk/dsfa/` | UI-Komponenten | -| `admin-v2/app/(sdk)/sdk/dsfa/` | Dashboard & Editor | - ---- - -*Dokumentationsstand: 2026-02-09* diff --git a/billing-service/Dockerfile b/billing-service/Dockerfile new file mode 100644 index 0000000..fdc0a49 --- /dev/null +++ b/billing-service/Dockerfile @@ -0,0 +1,40 @@ +# Build stage +FROM golang:1.23-alpine AS builder + +WORKDIR /app + +# Install git for go mod download +RUN apk add --no-cache git + +# Copy go mod files +COPY go.mod go.sum* ./ + +# Download dependencies +RUN go mod download + +# Copy source code +COPY . . + +# Build the application +RUN CGO_ENABLED=0 GOOS=linux go build -a -installsuffix cgo -o billing-service ./cmd/server + +# Final stage +FROM alpine:3.19 + +WORKDIR /app + +# Install ca-certificates for HTTPS requests (Stripe API) +RUN apk --no-cache add ca-certificates tzdata + +# Copy binary from builder +COPY --from=builder /app/billing-service . + +# Expose port +EXPOSE 8083 + +# Health check +HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ + CMD wget --no-verbose --tries=1 --spider http://localhost:8083/health || exit 1 + +# Run the application +CMD ["./billing-service"] diff --git a/billing-service/README.md b/billing-service/README.md new file mode 100644 index 0000000..becc5da --- /dev/null +++ b/billing-service/README.md @@ -0,0 +1,296 @@ +# Billing Service + +Go-Microservice fuer Stripe-basiertes Subscription Management mit Task-basierter Abrechnung. + +## Uebersicht + +Der Billing Service verwaltet: +- Subscription Lifecycle (Trial, Active, Canceled) +- Task-basierte Kontingentierung (1 Task = 1 Einheit) +- Carryover-Logik (Tasks sammeln sich bis zu 5 Monate an) +- Stripe Integration (Checkout, Webhooks, Portal) +- Feature Gating und Entitlements + +## Quick Start + +### Voraussetzungen + +- Go 1.21+ +- PostgreSQL 14+ +- Docker (optional) + +### Lokale Entwicklung + +```bash +# 1. Dependencies installieren +go mod download + +# 2. Umgebungsvariablen setzen +export DATABASE_URL="postgres://user:pass@localhost:5432/breakpilot?sslmode=disable" +export JWT_SECRET="your-jwt-secret" +export STRIPE_SECRET_KEY="sk_test_..." +export STRIPE_WEBHOOK_SECRET="whsec_..." +export BILLING_SUCCESS_URL="http://localhost:3000/billing/success" +export BILLING_CANCEL_URL="http://localhost:3000/billing/cancel" +export INTERNAL_API_KEY="internal-api-key" +export TRIAL_PERIOD_DAYS="7" +export PORT="8083" + +# 3. Service starten +go run cmd/server/main.go + +# 4. Tests ausfuehren +go test -v ./... +``` + +### Mit Docker + +```bash +# Service bauen und starten +docker compose up billing-service + +# Nur bauen +docker build -t billing-service . +``` + +## Architektur + +``` +billing-service/ +├── cmd/server/main.go # Entry Point +├── internal/ +│ ├── config/config.go # Konfiguration +│ ├── database/database.go # DB Connection + Migrations +│ ├── models/models.go # Datenmodelle +│ ├── middleware/middleware.go # JWT Auth, CORS, Rate Limiting +│ ├── services/ +│ │ ├── subscription_service.go # Subscription Management +│ │ ├── task_service.go # Task Consumption +│ │ ├── entitlement_service.go # Feature Gating +│ │ ├── usage_service.go # Usage Tracking (Legacy) +│ │ └── stripe_service.go # Stripe API +│ └── handlers/ +│ ├── billing_handlers.go # API Endpoints +│ └── webhook_handlers.go # Stripe Webhooks +├── Dockerfile +└── go.mod +``` + +## Task-basiertes Billing + +### Konzept + +- **1 Task = 1 Kontingentverbrauch** (unabhaengig von Seitenanzahl, Tokens, etc.) +- **Monatliches Kontingent**: Plan-abhaengig (Basic: 30, Standard: 100, Premium: Fair Use) +- **Carryover**: Ungenutzte Tasks sammeln sich bis zu 5 Monate an +- **Max Balance**: `monthly_allowance * 5` (z.B. Basic: max 150 Tasks) + +### Task Types + +```go +TaskTypeCorrection = "correction" // Korrekturaufgabe +TaskTypeLetter = "letter" // Brief erstellen +TaskTypeMeeting = "meeting" // Meeting-Protokoll +TaskTypeBatch = "batch" // Batch-Verarbeitung +TaskTypeOther = "other" // Sonstige +``` + +### Monatswechsel-Logik + +Bei jedem API-Aufruf wird geprueft, ob ein Monat vergangen ist: +1. `last_renewal_at` pruefen +2. Falls >= 1 Monat: `task_balance += monthly_allowance` +3. Cap bei `max_task_balance` +4. `last_renewal_at` aktualisieren + +## API Endpoints + +### User Endpoints (JWT Auth) + +| Methode | Endpoint | Beschreibung | +|---------|----------|--------------| +| GET | `/api/v1/billing/status` | Aktueller Billing Status | +| GET | `/api/v1/billing/plans` | Verfuegbare Plaene | +| POST | `/api/v1/billing/trial/start` | Trial starten | +| POST | `/api/v1/billing/change-plan` | Plan wechseln | +| POST | `/api/v1/billing/cancel` | Abo kuendigen | +| GET | `/api/v1/billing/portal` | Stripe Portal URL | + +### Internal Endpoints (API Key) + +| Methode | Endpoint | Beschreibung | +|---------|----------|--------------| +| GET | `/api/v1/billing/entitlements/:userId` | Entitlements abrufen | +| GET | `/api/v1/billing/entitlements/check/:userId/:feature` | Feature pruefen | +| GET | `/api/v1/billing/tasks/check/:userId` | Task erlaubt? | +| POST | `/api/v1/billing/tasks/consume` | Task konsumieren | +| GET | `/api/v1/billing/tasks/usage/:userId` | Task Usage Info | + +### Webhook + +| Methode | Endpoint | Beschreibung | +|---------|----------|--------------| +| POST | `/api/v1/billing/webhook` | Stripe Webhooks | + +## Plaene und Preise + +| Plan | Preis | Tasks/Monat | Max Balance | Features | +|------|-------|-------------|-------------|----------| +| Basic | 9.90 EUR | 30 | 150 | Basis-Features | +| Standard | 19.90 EUR | 100 | 500 | + Templates, Batch | +| Premium | 39.90 EUR | Fair Use | 5000 | + Team, Admin, API | + +### Fair Use Mode (Premium) + +Im Premium-Plan: +- Keine praktische Begrenzung +- Tasks werden trotzdem getrackt (fuer Monitoring) +- Balance wird nicht dekrementiert +- `CheckTaskAllowed` gibt immer `true` zurueck + +## Datenbank + +### Wichtige Tabellen + +```sql +-- Task-basierte Nutzung pro Account +CREATE TABLE account_usage ( + account_id UUID UNIQUE, + plan VARCHAR(50), + monthly_task_allowance INT, + max_task_balance INT, + task_balance INT, + last_renewal_at TIMESTAMPTZ +); + +-- Einzelne Task-Records +CREATE TABLE tasks ( + id UUID PRIMARY KEY, + account_id UUID, + task_type VARCHAR(50), + consumed BOOLEAN, + created_at TIMESTAMPTZ +); +``` + +## Tests + +```bash +# Alle Tests +go test -v ./... + +# Mit Coverage +go test -cover ./... + +# Nur Models +go test -v ./internal/models/... + +# Nur Services +go test -v ./internal/services/... + +# Nur Handlers +go test -v ./internal/handlers/... +``` + +## Stripe Integration + +### Webhooks + +Konfiguriere im Stripe Dashboard: +``` +URL: https://your-domain.com/api/v1/billing/webhook +Events: + - checkout.session.completed + - customer.subscription.created + - customer.subscription.updated + - customer.subscription.deleted + - invoice.paid + - invoice.payment_failed +``` + +### Lokales Testing + +```bash +# Stripe CLI installieren +brew install stripe/stripe-cli/stripe + +# Webhook forwarding +stripe listen --forward-to localhost:8083/api/v1/billing/webhook + +# Test Events triggern +stripe trigger checkout.session.completed +stripe trigger invoice.paid +``` + +## Umgebungsvariablen + +| Variable | Beschreibung | Beispiel | +|----------|--------------|----------| +| `DATABASE_URL` | PostgreSQL Connection String | `postgres://...` | +| `JWT_SECRET` | JWT Signing Secret | `your-secret` | +| `STRIPE_SECRET_KEY` | Stripe Secret Key | `sk_test_...` | +| `STRIPE_WEBHOOK_SECRET` | Webhook Signing Secret | `whsec_...` | +| `BILLING_SUCCESS_URL` | Checkout Success Redirect | `http://...` | +| `BILLING_CANCEL_URL` | Checkout Cancel Redirect | `http://...` | +| `INTERNAL_API_KEY` | Service-to-Service Auth | `internal-key` | +| `TRIAL_PERIOD_DAYS` | Trial Dauer in Tagen | `7` | +| `PORT` | Server Port | `8083` | + +## Error Handling + +### Task Limit Reached + +```json +{ + "error": "TASK_LIMIT_REACHED", + "message": "Dein Aufgaben-Kontingent ist aufgebraucht.", + "current_balance": 0, + "plan": "basic" +} +``` + +HTTP Status: `402 Payment Required` + +### No Subscription + +```json +{ + "error": "NO_SUBSCRIPTION", + "message": "Kein aktives Abonnement gefunden." +} +``` + +HTTP Status: `403 Forbidden` + +## Frontend Integration + +### Task Usage anzeigen + +```typescript +// Response von GET /api/v1/billing/status +interface TaskUsageInfo { + tasks_available: number; // z.B. 45 + max_tasks: number; // z.B. 150 + info_text: string; // "Aufgaben verfuegbar: 45 von max. 150" + tooltip_text: string; // "Aufgaben koennen sich bis zu 5 Monate ansammeln." +} +``` + +### Task konsumieren + +```typescript +// Vor jeder KI-Aktion +const response = await fetch('/api/v1/billing/tasks/check/' + userId); +const { allowed, message } = await response.json(); + +if (!allowed) { + showUpgradeDialog(message); + return; +} + +// Nach erfolgreicher KI-Aktion +await fetch('/api/v1/billing/tasks/consume', { + method: 'POST', + body: JSON.stringify({ user_id: userId, task_type: 'correction' }) +}); +``` diff --git a/billing-service/cmd/server/main.go b/billing-service/cmd/server/main.go new file mode 100644 index 0000000..4ca2fe3 --- /dev/null +++ b/billing-service/cmd/server/main.go @@ -0,0 +1,143 @@ +package main + +import ( + "log" + + "github.com/breakpilot/billing-service/internal/config" + "github.com/breakpilot/billing-service/internal/database" + "github.com/breakpilot/billing-service/internal/handlers" + "github.com/breakpilot/billing-service/internal/middleware" + "github.com/breakpilot/billing-service/internal/services" + "github.com/gin-gonic/gin" +) + +func main() { + // Load configuration + cfg, err := config.Load() + if err != nil { + log.Fatalf("Failed to load config: %v", err) + } + + // Initialize database + db, err := database.Connect(cfg.DatabaseURL) + if err != nil { + log.Fatalf("Failed to connect to database: %v", err) + } + defer db.Close() + + // Run migrations + if err := database.Migrate(db); err != nil { + log.Fatalf("Failed to run migrations: %v", err) + } + + // Setup Gin router + if cfg.Environment == "production" { + gin.SetMode(gin.ReleaseMode) + } + + router := gin.Default() + + // Global middleware + router.Use(middleware.CORS()) + router.Use(middleware.RequestLogger()) + router.Use(middleware.RateLimiter()) + + // Health check (no auth required) + router.GET("/health", func(c *gin.Context) { + c.JSON(200, gin.H{ + "status": "healthy", + "service": "billing-service", + "version": "1.0.0", + }) + }) + + // Initialize services + subscriptionService := services.NewSubscriptionService(db) + + // Create Stripe service (mock or real depending on config) + var stripeService *services.StripeService + if cfg.IsMockMode() { + log.Println("Starting in MOCK MODE - Stripe API calls will be simulated") + stripeService = services.NewMockStripeService( + cfg.BillingSuccessURL, + cfg.BillingCancelURL, + cfg.TrialPeriodDays, + subscriptionService, + ) + } else { + stripeService = services.NewStripeService( + cfg.StripeSecretKey, + cfg.StripeWebhookSecret, + cfg.BillingSuccessURL, + cfg.BillingCancelURL, + cfg.TrialPeriodDays, + subscriptionService, + ) + } + + entitlementService := services.NewEntitlementService(db, subscriptionService) + usageService := services.NewUsageService(db, entitlementService) + + // Initialize handlers + billingHandler := handlers.NewBillingHandler( + db, + subscriptionService, + stripeService, + entitlementService, + usageService, + ) + webhookHandler := handlers.NewWebhookHandler( + db, + cfg.StripeWebhookSecret, + subscriptionService, + entitlementService, + ) + + // API v1 routes + v1 := router.Group("/api/v1/billing") + { + // Stripe webhook (no auth - uses Stripe signature) + v1.POST("/webhook", webhookHandler.HandleStripeWebhook) + + // ============================================= + // User Endpoints (require JWT auth) + // ============================================= + user := v1.Group("") + user.Use(middleware.AuthMiddleware(cfg.JWTSecret)) + { + // Subscription status and management + user.GET("/status", billingHandler.GetBillingStatus) + user.GET("/plans", billingHandler.GetPlans) + user.POST("/trial/start", billingHandler.StartTrial) + user.POST("/change-plan", billingHandler.ChangePlan) + user.POST("/cancel", billingHandler.CancelSubscription) + user.GET("/portal", billingHandler.GetCustomerPortal) + } + + // ============================================= + // Internal Endpoints (service-to-service) + // ============================================= + internal := v1.Group("") + internal.Use(middleware.InternalAPIKeyMiddleware(cfg.InternalAPIKey)) + { + // Entitlements + internal.GET("/entitlements/:userId", billingHandler.GetEntitlements) + internal.GET("/entitlements/check/:userId/:feature", billingHandler.CheckEntitlement) + + // Usage tracking + internal.POST("/usage/track", billingHandler.TrackUsage) + internal.GET("/usage/check/:userId/:type", billingHandler.CheckUsage) + } + } + + // Start server + port := cfg.Port + if port == "" { + port = "8083" + } + + log.Printf("Starting Billing Service on port %s", port) + if err := router.Run(":" + port); err != nil { + log.Fatalf("Failed to start server: %v", err) + } +} diff --git a/billing-service/go.mod b/billing-service/go.mod new file mode 100644 index 0000000..bc65f87 --- /dev/null +++ b/billing-service/go.mod @@ -0,0 +1,49 @@ +module github.com/breakpilot/billing-service + +go 1.23.0 + +require ( + github.com/gin-gonic/gin v1.11.0 + github.com/golang-jwt/jwt/v5 v5.3.0 + github.com/google/uuid v1.6.0 + github.com/jackc/pgx/v5 v5.7.6 + github.com/joho/godotenv v1.5.1 + github.com/stripe/stripe-go/v76 v76.25.0 +) + +require ( + github.com/bytedance/sonic v1.14.0 // indirect + github.com/bytedance/sonic/loader v0.3.0 // indirect + github.com/cloudwego/base64x v0.1.6 // indirect + github.com/gabriel-vasile/mimetype v1.4.8 // indirect + github.com/gin-contrib/sse v1.1.0 // indirect + github.com/go-playground/locales v0.14.1 // indirect + github.com/go-playground/universal-translator v0.18.1 // indirect + github.com/go-playground/validator/v10 v10.27.0 // indirect + github.com/goccy/go-json v0.10.2 // indirect + github.com/goccy/go-yaml v1.18.0 // indirect + github.com/jackc/pgpassfile v1.0.0 // indirect + github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect + github.com/jackc/puddle/v2 v2.2.2 // indirect + github.com/json-iterator/go v1.1.12 // indirect + github.com/klauspost/cpuid/v2 v2.3.0 // indirect + github.com/leodido/go-urn v1.4.0 // indirect + github.com/mattn/go-isatty v0.0.20 // indirect + github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421 // indirect + github.com/modern-go/reflect2 v1.0.2 // indirect + github.com/pelletier/go-toml/v2 v2.2.4 // indirect + github.com/quic-go/qpack v0.5.1 // indirect + github.com/quic-go/quic-go v0.54.0 // indirect + github.com/twitchyliquid64/golang-asm v0.15.1 // indirect + github.com/ugorji/go/codec v1.3.0 // indirect + go.uber.org/mock v0.5.0 // indirect + golang.org/x/arch v0.20.0 // indirect + golang.org/x/crypto v0.40.0 // indirect + golang.org/x/mod v0.25.0 // indirect + golang.org/x/net v0.42.0 // indirect + golang.org/x/sync v0.16.0 // indirect + golang.org/x/sys v0.35.0 // indirect + golang.org/x/text v0.27.0 // indirect + golang.org/x/tools v0.34.0 // indirect + google.golang.org/protobuf v1.36.9 // indirect +) diff --git a/billing-service/go.sum b/billing-service/go.sum new file mode 100644 index 0000000..1429c48 --- /dev/null +++ b/billing-service/go.sum @@ -0,0 +1,111 @@ +github.com/bytedance/sonic v1.14.0 h1:/OfKt8HFw0kh2rj8N0F6C/qPGRESq0BbaNZgcNXXzQQ= +github.com/bytedance/sonic v1.14.0/go.mod h1:WoEbx8WTcFJfzCe0hbmyTGrfjt8PzNEBdxlNUO24NhA= +github.com/bytedance/sonic/loader v0.3.0 h1:dskwH8edlzNMctoruo8FPTJDF3vLtDT0sXZwvZJyqeA= +github.com/bytedance/sonic/loader v0.3.0/go.mod h1:N8A3vUdtUebEY2/VQC0MyhYeKUFosQU6FxH2JmUe6VI= +github.com/cloudwego/base64x v0.1.6 h1:t11wG9AECkCDk5fMSoxmufanudBtJ+/HemLstXDLI2M= +github.com/cloudwego/base64x v0.1.6/go.mod h1:OFcloc187FXDaYHvrNIjxSe8ncn0OOM8gEHfghB2IPU= +github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= +github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= +github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= +github.com/gabriel-vasile/mimetype v1.4.8 h1:FfZ3gj38NjllZIeJAmMhr+qKL8Wu+nOoI3GqacKw1NM= +github.com/gabriel-vasile/mimetype v1.4.8/go.mod h1:ByKUIKGjh1ODkGM1asKUbQZOLGrPjydw3hYPU2YU9t8= +github.com/gin-contrib/sse v1.1.0 h1:n0w2GMuUpWDVp7qSpvze6fAu9iRxJY4Hmj6AmBOU05w= +github.com/gin-contrib/sse v1.1.0/go.mod h1:hxRZ5gVpWMT7Z0B0gSNYqqsSCNIJMjzvm6fqCz9vjwM= +github.com/gin-gonic/gin v1.11.0 h1:OW/6PLjyusp2PPXtyxKHU0RbX6I/l28FTdDlae5ueWk= +github.com/gin-gonic/gin v1.11.0/go.mod h1:+iq/FyxlGzII0KHiBGjuNn4UNENUlKbGlNmc+W50Dls= +github.com/go-playground/assert/v2 v2.2.0 h1:JvknZsQTYeFEAhQwI4qEt9cyV5ONwRHC+lYKSsYSR8s= +github.com/go-playground/assert/v2 v2.2.0/go.mod h1:VDjEfimB/XKnb+ZQfWdccd7VUvScMdVu0Titje2rxJ4= +github.com/go-playground/locales v0.14.1 h1:EWaQ/wswjilfKLTECiXz7Rh+3BjFhfDFKv/oXslEjJA= +github.com/go-playground/locales v0.14.1/go.mod h1:hxrqLVvrK65+Rwrd5Fc6F2O76J/NuW9t0sjnWqG1slY= +github.com/go-playground/universal-translator v0.18.1 h1:Bcnm0ZwsGyWbCzImXv+pAJnYK9S473LQFuzCbDbfSFY= +github.com/go-playground/universal-translator v0.18.1/go.mod h1:xekY+UJKNuX9WP91TpwSH2VMlDf28Uj24BCp08ZFTUY= +github.com/go-playground/validator/v10 v10.27.0 h1:w8+XrWVMhGkxOaaowyKH35gFydVHOvC0/uWoy2Fzwn4= +github.com/go-playground/validator/v10 v10.27.0/go.mod h1:I5QpIEbmr8On7W0TktmJAumgzX4CA1XNl4ZmDuVHKKo= +github.com/goccy/go-json v0.10.2 h1:CrxCmQqYDkv1z7lO7Wbh2HN93uovUHgrECaO5ZrCXAU= +github.com/goccy/go-json v0.10.2/go.mod h1:6MelG93GURQebXPDq3khkgXZkazVtN9CRI+MGFi0w8I= +github.com/goccy/go-yaml v1.18.0 h1:8W7wMFS12Pcas7KU+VVkaiCng+kG8QiFeFwzFb+rwuw= +github.com/goccy/go-yaml v1.18.0/go.mod h1:XBurs7gK8ATbW4ZPGKgcbrY1Br56PdM69F7LkFRi1kA= +github.com/golang-jwt/jwt/v5 v5.3.0 h1:pv4AsKCKKZuqlgs5sUmn4x8UlGa0kEVt/puTpKx9vvo= +github.com/golang-jwt/jwt/v5 v5.3.0/go.mod h1:fxCRLWMO43lRc8nhHWY6LGqRcf+1gQWArsqaEUEa5bE= +github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8= +github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU= +github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= +github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= +github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= +github.com/jackc/pgpassfile v1.0.0 h1:/6Hmqy13Ss2zCq62VdNG8tM1wchn8zjSGOBJ6icpsIM= +github.com/jackc/pgpassfile v1.0.0/go.mod h1:CEx0iS5ambNFdcRtxPj5JhEz+xB6uRky5eyVu/W2HEg= +github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 h1:iCEnooe7UlwOQYpKFhBabPMi4aNAfoODPEFNiAnClxo= +github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761/go.mod h1:5TJZWKEWniPve33vlWYSoGYefn3gLQRzjfDlhSJ9ZKM= +github.com/jackc/pgx/v5 v5.7.6 h1:rWQc5FwZSPX58r1OQmkuaNicxdmExaEz5A2DO2hUuTk= +github.com/jackc/pgx/v5 v5.7.6/go.mod h1:aruU7o91Tc2q2cFp5h4uP3f6ztExVpyVv88Xl/8Vl8M= +github.com/jackc/puddle/v2 v2.2.2 h1:PR8nw+E/1w0GLuRFSmiioY6UooMp6KJv0/61nB7icHo= +github.com/jackc/puddle/v2 v2.2.2/go.mod h1:vriiEXHvEE654aYKXXjOvZM39qJ0q+azkZFrfEOc3H4= +github.com/joho/godotenv v1.5.1 h1:7eLL/+HRGLY0ldzfGMeQkb7vMd0as4CfYvUVzLqw0N0= +github.com/joho/godotenv v1.5.1/go.mod h1:f4LDr5Voq0i2e/R5DDNOoa2zzDfwtkZa6DnEwAbqwq4= +github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM= +github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo= +github.com/klauspost/cpuid/v2 v2.3.0 h1:S4CRMLnYUhGeDFDqkGriYKdfoFlDnMtqTiI/sFzhA9Y= +github.com/klauspost/cpuid/v2 v2.3.0/go.mod h1:hqwkgyIinND0mEev00jJYCxPNVRVXFQeu1XKlok6oO0= +github.com/leodido/go-urn v1.4.0 h1:WT9HwE9SGECu3lg4d/dIA+jxlljEa1/ffXKmRjqdmIQ= +github.com/leodido/go-urn v1.4.0/go.mod h1:bvxc+MVxLKB4z00jd1z+Dvzr47oO32F/QSNjSBOlFxI= +github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY= +github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y= +github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421 h1:ZqeYNhU3OHLH3mGKHDcjJRFFRrJa6eAM5H+CtDdOsPc= +github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q= +github.com/modern-go/reflect2 v1.0.2 h1:xBagoLtFs94CBntxluKeaWgTMpvLxC4ur3nMaC9Gz0M= +github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjYzDa0/r8luk= +github.com/pelletier/go-toml/v2 v2.2.4 h1:mye9XuhQ6gvn5h28+VilKrrPoQVanw5PMw/TB0t5Ec4= +github.com/pelletier/go-toml/v2 v2.2.4/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY= +github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= +github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= +github.com/quic-go/qpack v0.5.1 h1:giqksBPnT/HDtZ6VhtFKgoLOWmlyo9Ei6u9PqzIMbhI= +github.com/quic-go/qpack v0.5.1/go.mod h1:+PC4XFrEskIVkcLzpEkbLqq1uCoxPhQuvK5rH1ZgaEg= +github.com/quic-go/quic-go v0.54.0 h1:6s1YB9QotYI6Ospeiguknbp2Znb/jZYjZLRXn9kMQBg= +github.com/quic-go/quic-go v0.54.0/go.mod h1:e68ZEaCdyviluZmy44P6Iey98v/Wfz6HCjQEm+l8zTY= +github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= +github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw= +github.com/stretchr/objx v0.5.0/go.mod h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo= +github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI= +github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= +github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= +github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU= +github.com/stretchr/testify v1.8.1/go.mod h1:w2LPCIKwWwSfY2zedu0+kehJoqGctiVI29o6fzry7u4= +github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U= +github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= +github.com/stripe/stripe-go/v76 v76.25.0 h1:kmDoOTvdQSTQssQzWZQQkgbAR2Q8eXdMWbN/ylNalWA= +github.com/stripe/stripe-go/v76 v76.25.0/go.mod h1:rw1MxjlAKKcZ+3FOXgTHgwiOa2ya6CPq6ykpJ0Q6Po4= +github.com/twitchyliquid64/golang-asm v0.15.1 h1:SU5vSMR7hnwNxj24w34ZyCi/FmDZTkS4MhqMhdFk5YI= +github.com/twitchyliquid64/golang-asm v0.15.1/go.mod h1:a1lVb/DtPvCB8fslRZhAngC2+aY1QWCk3Cedj/Gdt08= +github.com/ugorji/go/codec v1.3.0 h1:Qd2W2sQawAfG8XSvzwhBeoGq71zXOC/Q1E9y/wUcsUA= +github.com/ugorji/go/codec v1.3.0/go.mod h1:pRBVtBSKl77K30Bv8R2P+cLSGaTtex6fsA2Wjqmfxj4= +go.uber.org/mock v0.5.0 h1:KAMbZvZPyBPWgD14IrIQ38QCyjwpvVVV6K/bHl1IwQU= +go.uber.org/mock v0.5.0/go.mod h1:ge71pBPLYDk7QIi1LupWxdAykm7KIEFchiOqd6z7qMM= +golang.org/x/arch v0.20.0 h1:dx1zTU0MAE98U+TQ8BLl7XsJbgze2WnNKF/8tGp/Q6c= +golang.org/x/arch v0.20.0/go.mod h1:bdwinDaKcfZUGpH09BB7ZmOfhalA8lQdzl62l8gGWsk= +golang.org/x/crypto v0.40.0 h1:r4x+VvoG5Fm+eJcxMaY8CQM7Lb0l1lsmjGBQ6s8BfKM= +golang.org/x/crypto v0.40.0/go.mod h1:Qr1vMER5WyS2dfPHAlsOj01wgLbsyWtFn/aY+5+ZdxY= +golang.org/x/mod v0.25.0 h1:n7a+ZbQKQA/Ysbyb0/6IbB1H/X41mKgbhfv7AfG/44w= +golang.org/x/mod v0.25.0/go.mod h1:IXM97Txy2VM4PJ3gI61r1YEk/gAj6zAHN3AdZt6S9Ww= +golang.org/x/net v0.0.0-20210520170846-37e1c6afe023/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y= +golang.org/x/net v0.42.0 h1:jzkYrhi3YQWD6MLBJcsklgQsoAcw89EcZbJw8Z614hs= +golang.org/x/net v0.42.0/go.mod h1:FF1RA5d3u7nAYA4z2TkclSCKh68eSXtiFwcWQpPXdt8= +golang.org/x/sync v0.16.0 h1:ycBJEhp9p4vXvUZNszeOq0kGTPghopOL8q0fq3vstxw= +golang.org/x/sync v0.16.0/go.mod h1:1dzgHSNfp02xaA81J2MS99Qcpr2w7fw1gpm99rleRqA= +golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.35.0 h1:vz1N37gP5bs89s7He8XuIYXpyY0+QlsKmzipCbUtyxI= +golang.org/x/sys v0.35.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k= +golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= +golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= +golang.org/x/text v0.27.0 h1:4fGWRpyh641NLlecmyl4LOe6yDdfaYNrGb2zdfo4JV4= +golang.org/x/text v0.27.0/go.mod h1:1D28KMCvyooCX9hBiosv5Tz/+YLxj0j7XhWjpSUF7CU= +golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= +golang.org/x/tools v0.34.0 h1:qIpSLOxeCYGg9TrcJokLBG4KFA6d795g0xkBkiESGlo= +golang.org/x/tools v0.34.0/go.mod h1:pAP9OwEaY1CAW3HOmg3hLZC5Z0CCmzjAF2UQMSqNARg= +google.golang.org/protobuf v1.36.9 h1:w2gp2mA27hUeUzj9Ex9FBjsBm40zfaDtEWow293U7Iw= +google.golang.org/protobuf v1.36.9/go.mod h1:fuxRtAxBytpl4zzqUh6/eyUujkJdNiuEkXntxiD/uRU= +gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= +gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= +gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= +gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= diff --git a/billing-service/internal/config/config.go b/billing-service/internal/config/config.go new file mode 100644 index 0000000..a56c0c5 --- /dev/null +++ b/billing-service/internal/config/config.go @@ -0,0 +1,157 @@ +package config + +import ( + "fmt" + "os" + + "github.com/joho/godotenv" +) + +// Config holds all configuration for the billing service +type Config struct { + // Server + Port string + Environment string + + // Database + DatabaseURL string + + // JWT (shared with consent-service) + JWTSecret string + + // Stripe + StripeSecretKey string + StripeWebhookSecret string + StripePublishableKey string + StripeMockMode bool // If true, Stripe calls are mocked (for dev without Stripe keys) + + // URLs + BillingSuccessURL string + BillingCancelURL string + FrontendURL string + + // Trial + TrialPeriodDays int + + // CORS + AllowedOrigins []string + + // Rate Limiting + RateLimitRequests int + RateLimitWindow int // in seconds + + // Internal API Key (for service-to-service communication) + InternalAPIKey string +} + +// Load loads configuration from environment variables +func Load() (*Config, error) { + // Load .env file if exists (for development) + _ = godotenv.Load() + + cfg := &Config{ + Port: getEnv("PORT", "8083"), + Environment: getEnv("ENVIRONMENT", "development"), + DatabaseURL: getEnv("DATABASE_URL", ""), + JWTSecret: getEnv("JWT_SECRET", ""), + + // Stripe + StripeSecretKey: getEnv("STRIPE_SECRET_KEY", ""), + StripeWebhookSecret: getEnv("STRIPE_WEBHOOK_SECRET", ""), + StripePublishableKey: getEnv("STRIPE_PUBLISHABLE_KEY", ""), + StripeMockMode: getEnvBool("STRIPE_MOCK_MODE", false), + + // URLs + BillingSuccessURL: getEnv("BILLING_SUCCESS_URL", "http://localhost:8000/app/billing/success"), + BillingCancelURL: getEnv("BILLING_CANCEL_URL", "http://localhost:8000/app/billing/cancel"), + FrontendURL: getEnv("FRONTEND_URL", "http://localhost:8000"), + + // Trial + TrialPeriodDays: getEnvInt("TRIAL_PERIOD_DAYS", 7), + + // Rate Limiting + RateLimitRequests: getEnvInt("RATE_LIMIT_REQUESTS", 100), + RateLimitWindow: getEnvInt("RATE_LIMIT_WINDOW", 60), + + // Internal API + InternalAPIKey: getEnv("INTERNAL_API_KEY", ""), + } + + // Parse allowed origins + originsStr := getEnv("ALLOWED_ORIGINS", "http://localhost:3000,http://localhost:8000") + cfg.AllowedOrigins = parseCommaSeparated(originsStr) + + // Validate required fields + if cfg.DatabaseURL == "" { + return nil, fmt.Errorf("DATABASE_URL is required") + } + + if cfg.JWTSecret == "" { + return nil, fmt.Errorf("JWT_SECRET is required") + } + + // Stripe key is required unless mock mode is enabled + if cfg.StripeSecretKey == "" && !cfg.StripeMockMode { + // In development mode, auto-enable mock mode if no Stripe key + if cfg.Environment == "development" { + cfg.StripeMockMode = true + } else { + return nil, fmt.Errorf("STRIPE_SECRET_KEY is required (set STRIPE_MOCK_MODE=true to bypass in dev)") + } + } + + return cfg, nil +} + +// IsMockMode returns true if Stripe should be mocked +func (c *Config) IsMockMode() bool { + return c.StripeMockMode +} + +func getEnv(key, defaultValue string) string { + if value := os.Getenv(key); value != "" { + return value + } + return defaultValue +} + +func getEnvInt(key string, defaultValue int) int { + if value := os.Getenv(key); value != "" { + var result int + fmt.Sscanf(value, "%d", &result) + return result + } + return defaultValue +} + +func getEnvBool(key string, defaultValue bool) bool { + if value := os.Getenv(key); value != "" { + return value == "true" || value == "1" || value == "yes" + } + return defaultValue +} + +func parseCommaSeparated(s string) []string { + if s == "" { + return []string{} + } + var result []string + start := 0 + for i := 0; i <= len(s); i++ { + if i == len(s) || s[i] == ',' { + item := s[start:i] + // Trim whitespace + for len(item) > 0 && item[0] == ' ' { + item = item[1:] + } + for len(item) > 0 && item[len(item)-1] == ' ' { + item = item[:len(item)-1] + } + if item != "" { + result = append(result, item) + } + start = i + 1 + } + } + return result +} diff --git a/billing-service/internal/database/database.go b/billing-service/internal/database/database.go new file mode 100644 index 0000000..2be0beb --- /dev/null +++ b/billing-service/internal/database/database.go @@ -0,0 +1,260 @@ +package database + +import ( + "context" + "fmt" + "time" + + "github.com/jackc/pgx/v5/pgxpool" +) + +// DB wraps the pgx pool +type DB struct { + Pool *pgxpool.Pool +} + +// Connect establishes a connection to the PostgreSQL database +func Connect(databaseURL string) (*DB, error) { + config, err := pgxpool.ParseConfig(databaseURL) + if err != nil { + return nil, fmt.Errorf("failed to parse database URL: %w", err) + } + + // Configure connection pool + config.MaxConns = 15 + config.MinConns = 3 + config.MaxConnLifetime = time.Hour + config.MaxConnIdleTime = 30 * time.Minute + config.HealthCheckPeriod = time.Minute + + ctx, cancel := context.WithTimeout(context.Background(), 10*time.Second) + defer cancel() + + pool, err := pgxpool.NewWithConfig(ctx, config) + if err != nil { + return nil, fmt.Errorf("failed to create connection pool: %w", err) + } + + // Test the connection + if err := pool.Ping(ctx); err != nil { + return nil, fmt.Errorf("failed to ping database: %w", err) + } + + return &DB{Pool: pool}, nil +} + +// Close closes the database connection pool +func (db *DB) Close() { + db.Pool.Close() +} + +// Migrate runs database migrations for the billing service +func Migrate(db *DB) error { + ctx := context.Background() + + migrations := []string{ + // ============================================= + // Billing Service Tables + // ============================================= + + // Subscriptions - core subscription data + `CREATE TABLE IF NOT EXISTS subscriptions ( + id UUID PRIMARY KEY DEFAULT gen_random_uuid(), + user_id UUID NOT NULL, + stripe_customer_id VARCHAR(255), + stripe_subscription_id VARCHAR(255) UNIQUE, + plan_id VARCHAR(50) NOT NULL, + status VARCHAR(30) NOT NULL DEFAULT 'trialing', + trial_end TIMESTAMPTZ, + current_period_start TIMESTAMPTZ, + current_period_end TIMESTAMPTZ, + cancel_at_period_end BOOLEAN DEFAULT FALSE, + canceled_at TIMESTAMPTZ, + ended_at TIMESTAMPTZ, + created_at TIMESTAMPTZ DEFAULT NOW(), + updated_at TIMESTAMPTZ DEFAULT NOW(), + UNIQUE(user_id) + )`, + + // Billing Plans - cached from Stripe + `CREATE TABLE IF NOT EXISTS billing_plans ( + id VARCHAR(50) PRIMARY KEY, + stripe_price_id VARCHAR(255) UNIQUE, + stripe_product_id VARCHAR(255), + name VARCHAR(100) NOT NULL, + description TEXT, + price_cents INT NOT NULL, + currency VARCHAR(3) DEFAULT 'eur', + interval VARCHAR(10) DEFAULT 'month', + features JSONB DEFAULT '{}', + is_active BOOLEAN DEFAULT TRUE, + sort_order INT DEFAULT 0, + created_at TIMESTAMPTZ DEFAULT NOW(), + updated_at TIMESTAMPTZ DEFAULT NOW() + )`, + + // Usage Summary - aggregated usage per period + `CREATE TABLE IF NOT EXISTS usage_summary ( + id UUID PRIMARY KEY DEFAULT gen_random_uuid(), + user_id UUID NOT NULL, + usage_type VARCHAR(50) NOT NULL, + period_start TIMESTAMPTZ NOT NULL, + total_count INT DEFAULT 0, + created_at TIMESTAMPTZ DEFAULT NOW(), + updated_at TIMESTAMPTZ DEFAULT NOW(), + UNIQUE(user_id, usage_type, period_start) + )`, + + // User Entitlements - cached entitlements for fast lookups + `CREATE TABLE IF NOT EXISTS user_entitlements ( + id UUID PRIMARY KEY DEFAULT gen_random_uuid(), + user_id UUID NOT NULL UNIQUE, + plan_id VARCHAR(50) NOT NULL, + ai_requests_limit INT DEFAULT 0, + ai_requests_used INT DEFAULT 0, + documents_limit INT DEFAULT 0, + documents_used INT DEFAULT 0, + features JSONB DEFAULT '{}', + period_start TIMESTAMPTZ, + period_end TIMESTAMPTZ, + created_at TIMESTAMPTZ DEFAULT NOW(), + updated_at TIMESTAMPTZ DEFAULT NOW() + )`, + + // Stripe Webhook Events - for idempotency + `CREATE TABLE IF NOT EXISTS stripe_webhook_events ( + id UUID PRIMARY KEY DEFAULT gen_random_uuid(), + stripe_event_id VARCHAR(255) UNIQUE NOT NULL, + event_type VARCHAR(100) NOT NULL, + processed BOOLEAN DEFAULT FALSE, + processed_at TIMESTAMPTZ, + payload JSONB, + error_message TEXT, + created_at TIMESTAMPTZ DEFAULT NOW() + )`, + + // Billing Audit Log + `CREATE TABLE IF NOT EXISTS billing_audit_log ( + id UUID PRIMARY KEY DEFAULT gen_random_uuid(), + user_id UUID, + action VARCHAR(50) NOT NULL, + entity_type VARCHAR(50), + entity_id VARCHAR(255), + old_value JSONB, + new_value JSONB, + metadata JSONB, + ip_address INET, + user_agent TEXT, + created_at TIMESTAMPTZ DEFAULT NOW() + )`, + + // Invoices - cached from Stripe + `CREATE TABLE IF NOT EXISTS invoices ( + id UUID PRIMARY KEY DEFAULT gen_random_uuid(), + user_id UUID NOT NULL, + stripe_invoice_id VARCHAR(255) UNIQUE NOT NULL, + stripe_subscription_id VARCHAR(255), + status VARCHAR(30) NOT NULL, + amount_due INT NOT NULL, + amount_paid INT DEFAULT 0, + currency VARCHAR(3) DEFAULT 'eur', + hosted_invoice_url TEXT, + invoice_pdf TEXT, + period_start TIMESTAMPTZ, + period_end TIMESTAMPTZ, + due_date TIMESTAMPTZ, + paid_at TIMESTAMPTZ, + created_at TIMESTAMPTZ DEFAULT NOW() + )`, + + // ============================================= + // Task-based Billing Tables + // ============================================= + + // Account Usage - tracks task balance per account + `CREATE TABLE IF NOT EXISTS account_usage ( + id UUID PRIMARY KEY DEFAULT gen_random_uuid(), + account_id UUID NOT NULL UNIQUE, + plan VARCHAR(50) NOT NULL, + monthly_task_allowance INT NOT NULL, + carryover_months_cap INT DEFAULT 5, + max_task_balance INT NOT NULL, + task_balance INT NOT NULL, + last_renewal_at TIMESTAMPTZ NOT NULL, + created_at TIMESTAMPTZ DEFAULT NOW(), + updated_at TIMESTAMPTZ DEFAULT NOW() + )`, + + // Tasks - individual task consumption records + `CREATE TABLE IF NOT EXISTS tasks ( + id UUID PRIMARY KEY DEFAULT gen_random_uuid(), + account_id UUID NOT NULL, + task_type VARCHAR(50) NOT NULL, + consumed BOOLEAN DEFAULT TRUE, + page_count INT DEFAULT 0, + token_count INT DEFAULT 0, + process_time INT DEFAULT 0, + created_at TIMESTAMPTZ DEFAULT NOW() + )`, + + // ============================================= + // Indexes + // ============================================= + `CREATE INDEX IF NOT EXISTS idx_subscriptions_user ON subscriptions(user_id)`, + `CREATE INDEX IF NOT EXISTS idx_subscriptions_stripe_customer ON subscriptions(stripe_customer_id)`, + `CREATE INDEX IF NOT EXISTS idx_subscriptions_stripe_sub ON subscriptions(stripe_subscription_id)`, + `CREATE INDEX IF NOT EXISTS idx_subscriptions_status ON subscriptions(status)`, + `CREATE INDEX IF NOT EXISTS idx_subscriptions_trial_end ON subscriptions(trial_end)`, + + `CREATE INDEX IF NOT EXISTS idx_usage_summary_user ON usage_summary(user_id)`, + `CREATE INDEX IF NOT EXISTS idx_usage_summary_period ON usage_summary(period_start)`, + `CREATE INDEX IF NOT EXISTS idx_usage_summary_type ON usage_summary(usage_type)`, + + `CREATE INDEX IF NOT EXISTS idx_user_entitlements_user ON user_entitlements(user_id)`, + `CREATE INDEX IF NOT EXISTS idx_user_entitlements_plan ON user_entitlements(plan_id)`, + + `CREATE INDEX IF NOT EXISTS idx_stripe_webhook_events_event_id ON stripe_webhook_events(stripe_event_id)`, + `CREATE INDEX IF NOT EXISTS idx_stripe_webhook_events_type ON stripe_webhook_events(event_type)`, + `CREATE INDEX IF NOT EXISTS idx_stripe_webhook_events_processed ON stripe_webhook_events(processed)`, + + `CREATE INDEX IF NOT EXISTS idx_billing_audit_log_user ON billing_audit_log(user_id)`, + `CREATE INDEX IF NOT EXISTS idx_billing_audit_log_action ON billing_audit_log(action)`, + `CREATE INDEX IF NOT EXISTS idx_billing_audit_log_created ON billing_audit_log(created_at)`, + + `CREATE INDEX IF NOT EXISTS idx_invoices_user ON invoices(user_id)`, + `CREATE INDEX IF NOT EXISTS idx_invoices_stripe_invoice ON invoices(stripe_invoice_id)`, + `CREATE INDEX IF NOT EXISTS idx_invoices_status ON invoices(status)`, + + `CREATE INDEX IF NOT EXISTS idx_account_usage_account ON account_usage(account_id)`, + `CREATE INDEX IF NOT EXISTS idx_account_usage_plan ON account_usage(plan)`, + `CREATE INDEX IF NOT EXISTS idx_account_usage_renewal ON account_usage(last_renewal_at)`, + + `CREATE INDEX IF NOT EXISTS idx_tasks_account ON tasks(account_id)`, + `CREATE INDEX IF NOT EXISTS idx_tasks_type ON tasks(task_type)`, + `CREATE INDEX IF NOT EXISTS idx_tasks_created ON tasks(created_at)`, + + // ============================================= + // Insert default plans + // ============================================= + `INSERT INTO billing_plans (id, name, description, price_cents, currency, interval, features, sort_order) + VALUES + ('basic', 'Basic', 'Perfekt für den Einstieg', 990, 'eur', 'month', + '{"ai_requests_limit": 300, "documents_limit": 50, "feature_flags": ["basic_ai", "basic_documents"], "max_team_members": 1, "priority_support": false, "custom_branding": false}', + 1), + ('standard', 'Standard', 'Für regelmäßige Nutzer', 1990, 'eur', 'month', + '{"ai_requests_limit": 1500, "documents_limit": 200, "feature_flags": ["basic_ai", "basic_documents", "templates", "batch_processing"], "max_team_members": 3, "priority_support": false, "custom_branding": false}', + 2), + ('premium', 'Premium', 'Für Teams und Power-User', 3990, 'eur', 'month', + '{"ai_requests_limit": 5000, "documents_limit": 1000, "feature_flags": ["basic_ai", "basic_documents", "templates", "batch_processing", "team_features", "admin_panel", "audit_log", "api_access"], "max_team_members": 10, "priority_support": true, "custom_branding": true}', + 3) + ON CONFLICT (id) DO NOTHING`, + } + + for _, migration := range migrations { + if _, err := db.Pool.Exec(ctx, migration); err != nil { + return fmt.Errorf("failed to run migration: %w", err) + } + } + + return nil +} diff --git a/billing-service/internal/handlers/billing_handlers.go b/billing-service/internal/handlers/billing_handlers.go new file mode 100644 index 0000000..5bd980f --- /dev/null +++ b/billing-service/internal/handlers/billing_handlers.go @@ -0,0 +1,427 @@ +package handlers + +import ( + "net/http" + + "github.com/breakpilot/billing-service/internal/database" + "github.com/breakpilot/billing-service/internal/middleware" + "github.com/breakpilot/billing-service/internal/models" + "github.com/breakpilot/billing-service/internal/services" + "github.com/gin-gonic/gin" +) + +// BillingHandler handles billing-related HTTP requests +type BillingHandler struct { + db *database.DB + subscriptionService *services.SubscriptionService + stripeService *services.StripeService + entitlementService *services.EntitlementService + usageService *services.UsageService +} + +// NewBillingHandler creates a new BillingHandler +func NewBillingHandler( + db *database.DB, + subscriptionService *services.SubscriptionService, + stripeService *services.StripeService, + entitlementService *services.EntitlementService, + usageService *services.UsageService, +) *BillingHandler { + return &BillingHandler{ + db: db, + subscriptionService: subscriptionService, + stripeService: stripeService, + entitlementService: entitlementService, + usageService: usageService, + } +} + +// GetBillingStatus returns the current billing status for a user +// GET /api/v1/billing/status +func (h *BillingHandler) GetBillingStatus(c *gin.Context) { + userID, err := middleware.GetUserID(c) + if err != nil || userID.String() == "" { + c.JSON(http.StatusUnauthorized, gin.H{ + "error": "unauthorized", + "message": "User not authenticated", + }) + return + } + + ctx := c.Request.Context() + + // Get subscription + subscription, err := h.subscriptionService.GetByUserID(ctx, userID) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "internal_error", + "message": "Failed to get subscription", + }) + return + } + + // Get available plans + plans, err := h.subscriptionService.GetAvailablePlans(ctx) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "internal_error", + "message": "Failed to get plans", + }) + return + } + + response := models.BillingStatusResponse{ + HasSubscription: subscription != nil, + AvailablePlans: plans, + } + + if subscription != nil { + // Get plan details + plan, _ := h.subscriptionService.GetPlanByID(ctx, string(subscription.PlanID)) + + subInfo := &models.SubscriptionInfo{ + PlanID: subscription.PlanID, + Status: subscription.Status, + IsTrialing: subscription.Status == models.StatusTrialing, + CancelAtPeriodEnd: subscription.CancelAtPeriodEnd, + CurrentPeriodEnd: subscription.CurrentPeriodEnd, + } + + if plan != nil { + subInfo.PlanName = plan.Name + subInfo.PriceCents = plan.PriceCents + subInfo.Currency = plan.Currency + } + + // Calculate trial days left + if subscription.TrialEnd != nil && subscription.Status == models.StatusTrialing { + // TODO: Calculate days left + } + + response.Subscription = subInfo + + // Get task usage info (legacy usage tracking - see TaskService for new task-based usage) + // TODO: Replace with TaskService.GetTaskUsageInfo for task-based billing + _, _ = h.usageService.GetUsageSummary(ctx, userID) + + // Get entitlements + entitlements, _ := h.entitlementService.GetEntitlements(ctx, userID) + if entitlements != nil { + response.Entitlements = entitlements + } + } + + c.JSON(http.StatusOK, response) +} + +// GetPlans returns all available billing plans +// GET /api/v1/billing/plans +func (h *BillingHandler) GetPlans(c *gin.Context) { + ctx := c.Request.Context() + + plans, err := h.subscriptionService.GetAvailablePlans(ctx) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "internal_error", + "message": "Failed to get plans", + }) + return + } + + c.JSON(http.StatusOK, gin.H{ + "plans": plans, + }) +} + +// StartTrial starts a trial for the user with a specific plan +// POST /api/v1/billing/trial/start +func (h *BillingHandler) StartTrial(c *gin.Context) { + userID, err := middleware.GetUserID(c) + if err != nil || userID.String() == "" { + c.JSON(http.StatusUnauthorized, gin.H{ + "error": "unauthorized", + "message": "User not authenticated", + }) + return + } + + var req models.StartTrialRequest + if err := c.ShouldBindJSON(&req); err != nil { + c.JSON(http.StatusBadRequest, gin.H{ + "error": "invalid_request", + "message": "Invalid request body", + }) + return + } + + ctx := c.Request.Context() + + // Check if user already has a subscription + existing, _ := h.subscriptionService.GetByUserID(ctx, userID) + if existing != nil { + c.JSON(http.StatusConflict, gin.H{ + "error": "subscription_exists", + "message": "User already has a subscription", + }) + return + } + + // Get user email from context + email, _ := c.Get("email") + emailStr, _ := email.(string) + + // Create Stripe checkout session + checkoutURL, sessionID, err := h.stripeService.CreateCheckoutSession(ctx, userID, emailStr, req.PlanID) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "stripe_error", + "message": "Failed to create checkout session", + "details": err.Error(), + }) + return + } + + c.JSON(http.StatusOK, models.StartTrialResponse{ + CheckoutURL: checkoutURL, + SessionID: sessionID, + }) +} + +// ChangePlan changes the user's subscription plan +// POST /api/v1/billing/change-plan +func (h *BillingHandler) ChangePlan(c *gin.Context) { + userID, err := middleware.GetUserID(c) + if err != nil || userID.String() == "" { + c.JSON(http.StatusUnauthorized, gin.H{ + "error": "unauthorized", + "message": "User not authenticated", + }) + return + } + + var req models.ChangePlanRequest + if err := c.ShouldBindJSON(&req); err != nil { + c.JSON(http.StatusBadRequest, gin.H{ + "error": "invalid_request", + "message": "Invalid request body", + }) + return + } + + ctx := c.Request.Context() + + // Get current subscription + subscription, err := h.subscriptionService.GetByUserID(ctx, userID) + if err != nil || subscription == nil { + c.JSON(http.StatusNotFound, gin.H{ + "error": "no_subscription", + "message": "No active subscription found", + }) + return + } + + // Change plan via Stripe + err = h.stripeService.ChangePlan(ctx, subscription.StripeSubscriptionID, req.NewPlanID) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "stripe_error", + "message": "Failed to change plan", + "details": err.Error(), + }) + return + } + + c.JSON(http.StatusOK, models.ChangePlanResponse{ + Success: true, + Message: "Plan changed successfully", + }) +} + +// CancelSubscription cancels the user's subscription at period end +// POST /api/v1/billing/cancel +func (h *BillingHandler) CancelSubscription(c *gin.Context) { + userID, err := middleware.GetUserID(c) + if err != nil || userID.String() == "" { + c.JSON(http.StatusUnauthorized, gin.H{ + "error": "unauthorized", + "message": "User not authenticated", + }) + return + } + + ctx := c.Request.Context() + + // Get current subscription + subscription, err := h.subscriptionService.GetByUserID(ctx, userID) + if err != nil || subscription == nil { + c.JSON(http.StatusNotFound, gin.H{ + "error": "no_subscription", + "message": "No active subscription found", + }) + return + } + + // Cancel at period end via Stripe + err = h.stripeService.CancelSubscription(ctx, subscription.StripeSubscriptionID) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "stripe_error", + "message": "Failed to cancel subscription", + "details": err.Error(), + }) + return + } + + c.JSON(http.StatusOK, models.CancelSubscriptionResponse{ + Success: true, + Message: "Subscription will be canceled at the end of the billing period", + }) +} + +// GetCustomerPortal returns a URL to the Stripe customer portal +// GET /api/v1/billing/portal +func (h *BillingHandler) GetCustomerPortal(c *gin.Context) { + userID, err := middleware.GetUserID(c) + if err != nil || userID.String() == "" { + c.JSON(http.StatusUnauthorized, gin.H{ + "error": "unauthorized", + "message": "User not authenticated", + }) + return + } + + ctx := c.Request.Context() + + // Get current subscription + subscription, err := h.subscriptionService.GetByUserID(ctx, userID) + if err != nil || subscription == nil || subscription.StripeCustomerID == "" { + c.JSON(http.StatusNotFound, gin.H{ + "error": "no_subscription", + "message": "No active subscription found", + }) + return + } + + // Create portal session + portalURL, err := h.stripeService.CreateCustomerPortalSession(ctx, subscription.StripeCustomerID) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "stripe_error", + "message": "Failed to create portal session", + "details": err.Error(), + }) + return + } + + c.JSON(http.StatusOK, models.CustomerPortalResponse{ + PortalURL: portalURL, + }) +} + +// ============================================= +// Internal Endpoints (Service-to-Service) +// ============================================= + +// GetEntitlements returns entitlements for a user (internal) +// GET /api/v1/billing/entitlements/:userId +func (h *BillingHandler) GetEntitlements(c *gin.Context) { + userIDStr := c.Param("userId") + + ctx := c.Request.Context() + + entitlements, err := h.entitlementService.GetEntitlementsByUserIDString(ctx, userIDStr) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "internal_error", + "message": "Failed to get entitlements", + }) + return + } + + if entitlements == nil { + c.JSON(http.StatusNotFound, gin.H{ + "error": "not_found", + "message": "No entitlements found for user", + }) + return + } + + c.JSON(http.StatusOK, entitlements) +} + +// TrackUsage tracks usage for a user (internal) +// POST /api/v1/billing/usage/track +func (h *BillingHandler) TrackUsage(c *gin.Context) { + var req models.TrackUsageRequest + if err := c.ShouldBindJSON(&req); err != nil { + c.JSON(http.StatusBadRequest, gin.H{ + "error": "invalid_request", + "message": "Invalid request body", + }) + return + } + + ctx := c.Request.Context() + + quantity := req.Quantity + if quantity <= 0 { + quantity = 1 + } + + err := h.usageService.TrackUsage(ctx, req.UserID, req.UsageType, quantity) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "internal_error", + "message": "Failed to track usage", + }) + return + } + + c.JSON(http.StatusOK, gin.H{ + "success": true, + "message": "Usage tracked", + }) +} + +// CheckUsage checks if usage is allowed (internal) +// GET /api/v1/billing/usage/check/:userId/:type +func (h *BillingHandler) CheckUsage(c *gin.Context) { + userIDStr := c.Param("userId") + usageType := c.Param("type") + + ctx := c.Request.Context() + + response, err := h.usageService.CheckUsageAllowed(ctx, userIDStr, usageType) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "internal_error", + "message": "Failed to check usage", + }) + return + } + + c.JSON(http.StatusOK, response) +} + +// CheckEntitlement checks if a user has a specific entitlement (internal) +// GET /api/v1/billing/entitlements/check/:userId/:feature +func (h *BillingHandler) CheckEntitlement(c *gin.Context) { + userIDStr := c.Param("userId") + feature := c.Param("feature") + + ctx := c.Request.Context() + + hasEntitlement, planID, err := h.entitlementService.CheckEntitlement(ctx, userIDStr, feature) + if err != nil { + c.JSON(http.StatusInternalServerError, gin.H{ + "error": "internal_error", + "message": "Failed to check entitlement", + }) + return + } + + c.JSON(http.StatusOK, models.EntitlementCheckResponse{ + HasEntitlement: hasEntitlement, + PlanID: planID, + }) +} diff --git a/billing-service/internal/handlers/billing_handlers_test.go b/billing-service/internal/handlers/billing_handlers_test.go new file mode 100644 index 0000000..907245c --- /dev/null +++ b/billing-service/internal/handlers/billing_handlers_test.go @@ -0,0 +1,612 @@ +package handlers + +import ( + "bytes" + "encoding/json" + "net/http" + "net/http/httptest" + "testing" + + "github.com/breakpilot/billing-service/internal/models" + "github.com/gin-gonic/gin" +) + +func init() { + // Set Gin to test mode + gin.SetMode(gin.TestMode) +} + +func TestGetPlans_ResponseFormat(t *testing.T) { + // Test that GetPlans returns the expected response structure + // Since we don't have a real database connection in unit tests, + // we test the expected structure and format + + // Test that default plans are well-formed + plans := models.GetDefaultPlans() + + if len(plans) == 0 { + t.Error("Default plans should not be empty") + } + + for _, plan := range plans { + // Verify JSON serialization works + data, err := json.Marshal(plan) + if err != nil { + t.Errorf("Failed to marshal plan %s: %v", plan.ID, err) + } + + // Verify we can unmarshal back + var decoded models.BillingPlan + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Errorf("Failed to unmarshal plan %s: %v", plan.ID, err) + } + + // Verify key fields + if decoded.ID != plan.ID { + t.Errorf("Plan ID mismatch: got %s, expected %s", decoded.ID, plan.ID) + } + } +} + +func TestBillingStatusResponse_Structure(t *testing.T) { + // Test the response structure + response := models.BillingStatusResponse{ + HasSubscription: true, + Subscription: &models.SubscriptionInfo{ + PlanID: models.PlanStandard, + PlanName: "Standard", + Status: models.StatusActive, + IsTrialing: false, + CancelAtPeriodEnd: false, + PriceCents: 1990, + Currency: "eur", + }, + TaskUsage: &models.TaskUsageInfo{ + TasksAvailable: 85, + MaxTasks: 500, + InfoText: "Aufgaben verfuegbar: 85 von max. 500", + TooltipText: "Aufgaben koennen sich bis zu 5 Monate ansammeln.", + }, + Entitlements: &models.EntitlementInfo{ + Features: []string{"basic_ai", "basic_documents", "templates", "batch_processing"}, + MaxTeamMembers: 3, + PrioritySupport: false, + CustomBranding: false, + BatchProcessing: true, + CustomTemplates: true, + FairUseMode: false, + }, + AvailablePlans: models.GetDefaultPlans(), + } + + // Test JSON serialization + data, err := json.Marshal(response) + if err != nil { + t.Fatalf("Failed to marshal BillingStatusResponse: %v", err) + } + + // Verify it's valid JSON + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Response is not valid JSON: %v", err) + } + + // Check required fields exist + if _, ok := decoded["has_subscription"]; !ok { + t.Error("Response should have 'has_subscription' field") + } +} + +func TestStartTrialRequest_Validation(t *testing.T) { + tests := []struct { + name string + request models.StartTrialRequest + wantError bool + }{ + { + name: "Valid basic plan", + request: models.StartTrialRequest{PlanID: models.PlanBasic}, + wantError: false, + }, + { + name: "Valid standard plan", + request: models.StartTrialRequest{PlanID: models.PlanStandard}, + wantError: false, + }, + { + name: "Valid premium plan", + request: models.StartTrialRequest{PlanID: models.PlanPremium}, + wantError: false, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + // Test JSON serialization + data, err := json.Marshal(tt.request) + if err != nil { + t.Fatalf("Failed to marshal request: %v", err) + } + + var decoded models.StartTrialRequest + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Failed to unmarshal request: %v", err) + } + + if decoded.PlanID != tt.request.PlanID { + t.Errorf("PlanID mismatch: got %s, expected %s", decoded.PlanID, tt.request.PlanID) + } + }) + } +} + +func TestChangePlanRequest_Structure(t *testing.T) { + request := models.ChangePlanRequest{ + NewPlanID: models.PlanPremium, + } + + data, err := json.Marshal(request) + if err != nil { + t.Fatalf("Failed to marshal ChangePlanRequest: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Response is not valid JSON: %v", err) + } + + if _, ok := decoded["new_plan_id"]; !ok { + t.Error("Request should have 'new_plan_id' field") + } +} + +func TestStartTrialResponse_Structure(t *testing.T) { + response := models.StartTrialResponse{ + CheckoutURL: "https://checkout.stripe.com/c/pay/cs_test_123", + SessionID: "cs_test_123", + } + + data, err := json.Marshal(response) + if err != nil { + t.Fatalf("Failed to marshal StartTrialResponse: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Response is not valid JSON: %v", err) + } + + if _, ok := decoded["checkout_url"]; !ok { + t.Error("Response should have 'checkout_url' field") + } + if _, ok := decoded["session_id"]; !ok { + t.Error("Response should have 'session_id' field") + } +} + +func TestCancelSubscriptionResponse_Structure(t *testing.T) { + response := models.CancelSubscriptionResponse{ + Success: true, + Message: "Subscription will be canceled at the end of the billing period", + CancelDate: "2025-01-16", + ActiveUntil: "2025-01-16", + } + + _, err := json.Marshal(response) + if err != nil { + t.Fatalf("Failed to marshal CancelSubscriptionResponse: %v", err) + } + + if !response.Success { + t.Error("Success should be true") + } +} + +func TestCustomerPortalResponse_Structure(t *testing.T) { + response := models.CustomerPortalResponse{ + PortalURL: "https://billing.stripe.com/p/session/test_123", + } + + data, err := json.Marshal(response) + if err != nil { + t.Fatalf("Failed to marshal CustomerPortalResponse: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Response is not valid JSON: %v", err) + } + + if _, ok := decoded["portal_url"]; !ok { + t.Error("Response should have 'portal_url' field") + } +} + +func TestEntitlementCheckResponse_Structure(t *testing.T) { + tests := []struct { + name string + response models.EntitlementCheckResponse + }{ + { + name: "Has entitlement", + response: models.EntitlementCheckResponse{ + HasEntitlement: true, + PlanID: models.PlanStandard, + }, + }, + { + name: "No entitlement", + response: models.EntitlementCheckResponse{ + HasEntitlement: false, + PlanID: models.PlanBasic, + Message: "Feature not available in this plan", + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + data, err := json.Marshal(tt.response) + if err != nil { + t.Fatalf("Failed to marshal EntitlementCheckResponse: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Response is not valid JSON: %v", err) + } + + if _, ok := decoded["has_entitlement"]; !ok { + t.Error("Response should have 'has_entitlement' field") + } + }) + } +} + +func TestTrackUsageRequest_Validation(t *testing.T) { + tests := []struct { + name string + request models.TrackUsageRequest + valid bool + }{ + { + name: "Valid AI request", + request: models.TrackUsageRequest{ + UserID: "550e8400-e29b-41d4-a716-446655440000", + UsageType: "ai_request", + Quantity: 1, + }, + valid: true, + }, + { + name: "Valid document created", + request: models.TrackUsageRequest{ + UserID: "550e8400-e29b-41d4-a716-446655440000", + UsageType: "document_created", + Quantity: 1, + }, + valid: true, + }, + { + name: "Multiple quantity", + request: models.TrackUsageRequest{ + UserID: "550e8400-e29b-41d4-a716-446655440000", + UsageType: "ai_request", + Quantity: 5, + }, + valid: true, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + data, err := json.Marshal(tt.request) + if err != nil { + t.Fatalf("Failed to marshal TrackUsageRequest: %v", err) + } + + var decoded models.TrackUsageRequest + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Failed to unmarshal TrackUsageRequest: %v", err) + } + + if decoded.UserID != tt.request.UserID { + t.Errorf("UserID mismatch: got %s, expected %s", decoded.UserID, tt.request.UserID) + } + }) + } +} + +func TestCheckUsageResponse_Format(t *testing.T) { + tests := []struct { + name string + response models.CheckUsageResponse + }{ + { + name: "Allowed response", + response: models.CheckUsageResponse{ + Allowed: true, + CurrentUsage: 450, + Limit: 1500, + Remaining: 1050, + }, + }, + { + name: "Limit reached", + response: models.CheckUsageResponse{ + Allowed: false, + CurrentUsage: 1500, + Limit: 1500, + Remaining: 0, + Message: "Usage limit reached for ai_request (1500/1500)", + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + data, err := json.Marshal(tt.response) + if err != nil { + t.Fatalf("Failed to marshal CheckUsageResponse: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Response is not valid JSON: %v", err) + } + + if _, ok := decoded["allowed"]; !ok { + t.Error("Response should have 'allowed' field") + } + }) + } +} + +func TestConsumeTaskRequest_Format(t *testing.T) { + tests := []struct { + name string + request models.ConsumeTaskRequest + }{ + { + name: "Correction task", + request: models.ConsumeTaskRequest{ + UserID: "550e8400-e29b-41d4-a716-446655440000", + TaskType: models.TaskTypeCorrection, + }, + }, + { + name: "Letter task", + request: models.ConsumeTaskRequest{ + UserID: "550e8400-e29b-41d4-a716-446655440000", + TaskType: models.TaskTypeLetter, + }, + }, + { + name: "Batch task", + request: models.ConsumeTaskRequest{ + UserID: "550e8400-e29b-41d4-a716-446655440000", + TaskType: models.TaskTypeBatch, + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + data, err := json.Marshal(tt.request) + if err != nil { + t.Fatalf("Failed to marshal ConsumeTaskRequest: %v", err) + } + + var decoded models.ConsumeTaskRequest + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Failed to unmarshal ConsumeTaskRequest: %v", err) + } + + if decoded.TaskType != tt.request.TaskType { + t.Errorf("TaskType mismatch: got %s, expected %s", decoded.TaskType, tt.request.TaskType) + } + }) + } +} + +func TestConsumeTaskResponse_Format(t *testing.T) { + tests := []struct { + name string + response models.ConsumeTaskResponse + }{ + { + name: "Successful consumption", + response: models.ConsumeTaskResponse{ + Success: true, + TaskID: "task-uuid-123", + TasksRemaining: 49, + }, + }, + { + name: "Limit reached", + response: models.ConsumeTaskResponse{ + Success: false, + TasksRemaining: 0, + Message: "Dein Aufgaben-Kontingent ist aufgebraucht.", + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + data, err := json.Marshal(tt.response) + if err != nil { + t.Fatalf("Failed to marshal ConsumeTaskResponse: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Response is not valid JSON: %v", err) + } + + if _, ok := decoded["success"]; !ok { + t.Error("Response should have 'success' field") + } + if _, ok := decoded["tasks_remaining"]; !ok { + t.Error("Response should have 'tasks_remaining' field") + } + }) + } +} + +func TestCheckTaskAllowedResponse_Format(t *testing.T) { + tests := []struct { + name string + response models.CheckTaskAllowedResponse + }{ + { + name: "Task allowed", + response: models.CheckTaskAllowedResponse{ + Allowed: true, + TasksAvailable: 50, + MaxTasks: 150, + PlanID: models.PlanBasic, + }, + }, + { + name: "Task not allowed", + response: models.CheckTaskAllowedResponse{ + Allowed: false, + TasksAvailable: 0, + MaxTasks: 150, + PlanID: models.PlanBasic, + Message: "Dein Aufgaben-Kontingent ist aufgebraucht.", + }, + }, + { + name: "Premium Fair Use", + response: models.CheckTaskAllowedResponse{ + Allowed: true, + TasksAvailable: 1000, + MaxTasks: 5000, + PlanID: models.PlanPremium, + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + data, err := json.Marshal(tt.response) + if err != nil { + t.Fatalf("Failed to marshal CheckTaskAllowedResponse: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Response is not valid JSON: %v", err) + } + + if _, ok := decoded["allowed"]; !ok { + t.Error("Response should have 'allowed' field") + } + if _, ok := decoded["tasks_available"]; !ok { + t.Error("Response should have 'tasks_available' field") + } + if _, ok := decoded["plan_id"]; !ok { + t.Error("Response should have 'plan_id' field") + } + }) + } +} + +// HTTP Handler Tests (without DB) + +func TestHTTPErrorResponse_Format(t *testing.T) { + // Test standard error response format + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + // Simulate an error response + c.JSON(http.StatusUnauthorized, gin.H{ + "error": "unauthorized", + "message": "User not authenticated", + }) + + if w.Code != http.StatusUnauthorized { + t.Errorf("Expected status 401, got %d", w.Code) + } + + var response map[string]interface{} + err := json.Unmarshal(w.Body.Bytes(), &response) + if err != nil { + t.Fatalf("Failed to parse response: %v", err) + } + + if _, ok := response["error"]; !ok { + t.Error("Error response should have 'error' field") + } + if _, ok := response["message"]; !ok { + t.Error("Error response should have 'message' field") + } +} + +func TestHTTPSuccessResponse_Format(t *testing.T) { + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + // Simulate a success response + c.JSON(http.StatusOK, gin.H{ + "success": true, + "message": "Operation completed", + }) + + if w.Code != http.StatusOK { + t.Errorf("Expected status 200, got %d", w.Code) + } + + var response map[string]interface{} + err := json.Unmarshal(w.Body.Bytes(), &response) + if err != nil { + t.Fatalf("Failed to parse response: %v", err) + } + + if response["success"] != true { + t.Error("Success response should have success=true") + } +} + +func TestRequestParsing_InvalidJSON(t *testing.T) { + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + // Create request with invalid JSON + invalidJSON := []byte(`{"plan_id": }`) // Invalid JSON + c.Request = httptest.NewRequest("POST", "/test", bytes.NewReader(invalidJSON)) + c.Request.Header.Set("Content-Type", "application/json") + + var req models.StartTrialRequest + err := c.ShouldBindJSON(&req) + + if err == nil { + t.Error("Should return error for invalid JSON") + } +} + +func TestHTTPHeaders_ContentType(t *testing.T) { + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + c.JSON(http.StatusOK, gin.H{"test": "value"}) + + contentType := w.Header().Get("Content-Type") + if contentType != "application/json; charset=utf-8" { + t.Errorf("Expected JSON content type, got %s", contentType) + } +} diff --git a/billing-service/internal/handlers/webhook_handlers.go b/billing-service/internal/handlers/webhook_handlers.go new file mode 100644 index 0000000..417bc9f --- /dev/null +++ b/billing-service/internal/handlers/webhook_handlers.go @@ -0,0 +1,205 @@ +package handlers + +import ( + "io" + "log" + "net/http" + + "github.com/breakpilot/billing-service/internal/database" + "github.com/breakpilot/billing-service/internal/services" + "github.com/gin-gonic/gin" + "github.com/stripe/stripe-go/v76/webhook" +) + +// WebhookHandler handles Stripe webhook events +type WebhookHandler struct { + db *database.DB + webhookSecret string + subscriptionService *services.SubscriptionService + entitlementService *services.EntitlementService +} + +// NewWebhookHandler creates a new WebhookHandler +func NewWebhookHandler( + db *database.DB, + webhookSecret string, + subscriptionService *services.SubscriptionService, + entitlementService *services.EntitlementService, +) *WebhookHandler { + return &WebhookHandler{ + db: db, + webhookSecret: webhookSecret, + subscriptionService: subscriptionService, + entitlementService: entitlementService, + } +} + +// HandleStripeWebhook handles incoming Stripe webhook events +// POST /api/v1/billing/webhook +func (h *WebhookHandler) HandleStripeWebhook(c *gin.Context) { + // Read the request body + body, err := io.ReadAll(c.Request.Body) + if err != nil { + log.Printf("Webhook: Error reading body: %v", err) + c.JSON(http.StatusBadRequest, gin.H{"error": "cannot read body"}) + return + } + + // Get the Stripe signature header + sigHeader := c.GetHeader("Stripe-Signature") + if sigHeader == "" { + log.Printf("Webhook: Missing Stripe-Signature header") + c.JSON(http.StatusBadRequest, gin.H{"error": "missing signature"}) + return + } + + // Verify the webhook signature + event, err := webhook.ConstructEvent(body, sigHeader, h.webhookSecret) + if err != nil { + log.Printf("Webhook: Signature verification failed: %v", err) + c.JSON(http.StatusUnauthorized, gin.H{"error": "invalid signature"}) + return + } + + ctx := c.Request.Context() + + // Check if we've already processed this event (idempotency) + processed, err := h.subscriptionService.IsEventProcessed(ctx, event.ID) + if err != nil { + log.Printf("Webhook: Error checking event: %v", err) + c.JSON(http.StatusInternalServerError, gin.H{"error": "internal error"}) + return + } + if processed { + log.Printf("Webhook: Event %s already processed", event.ID) + c.JSON(http.StatusOK, gin.H{"status": "already_processed"}) + return + } + + // Mark event as being processed + if err := h.subscriptionService.MarkEventProcessing(ctx, event.ID, string(event.Type)); err != nil { + log.Printf("Webhook: Error marking event: %v", err) + } + + // Handle the event based on type + var handleErr error + switch event.Type { + case "checkout.session.completed": + handleErr = h.handleCheckoutSessionCompleted(ctx, event.Data.Raw) + + case "customer.subscription.created": + handleErr = h.handleSubscriptionCreated(ctx, event.Data.Raw) + + case "customer.subscription.updated": + handleErr = h.handleSubscriptionUpdated(ctx, event.Data.Raw) + + case "customer.subscription.deleted": + handleErr = h.handleSubscriptionDeleted(ctx, event.Data.Raw) + + case "invoice.paid": + handleErr = h.handleInvoicePaid(ctx, event.Data.Raw) + + case "invoice.payment_failed": + handleErr = h.handleInvoicePaymentFailed(ctx, event.Data.Raw) + + case "customer.created": + log.Printf("Webhook: Customer created - %s", event.ID) + + default: + log.Printf("Webhook: Unhandled event type: %s", event.Type) + } + + if handleErr != nil { + log.Printf("Webhook: Error handling %s: %v", event.Type, handleErr) + // Mark event as failed + h.subscriptionService.MarkEventFailed(ctx, event.ID, handleErr.Error()) + c.JSON(http.StatusInternalServerError, gin.H{"error": "handler error"}) + return + } + + // Mark event as processed + if err := h.subscriptionService.MarkEventProcessed(ctx, event.ID); err != nil { + log.Printf("Webhook: Error marking event processed: %v", err) + } + + c.JSON(http.StatusOK, gin.H{"status": "processed"}) +} + +// handleCheckoutSessionCompleted handles successful checkout +func (h *WebhookHandler) handleCheckoutSessionCompleted(ctx interface{}, data []byte) error { + log.Printf("Webhook: Processing checkout.session.completed") + + // Parse checkout session from data + // The actual implementation will parse the JSON and create/update subscription + + // TODO: Implementation + // 1. Parse checkout session data + // 2. Extract customer_id, subscription_id, user_id (from metadata) + // 3. Create or update subscription record + // 4. Update entitlements + + return nil +} + +// handleSubscriptionCreated handles new subscription creation +func (h *WebhookHandler) handleSubscriptionCreated(ctx interface{}, data []byte) error { + log.Printf("Webhook: Processing customer.subscription.created") + + // TODO: Implementation + // 1. Parse subscription data + // 2. Extract status, plan, trial_end, etc. + // 3. Create subscription record + // 4. Set up initial entitlements + + return nil +} + +// handleSubscriptionUpdated handles subscription updates +func (h *WebhookHandler) handleSubscriptionUpdated(ctx interface{}, data []byte) error { + log.Printf("Webhook: Processing customer.subscription.updated") + + // TODO: Implementation + // 1. Parse subscription data + // 2. Update subscription record (status, plan, cancel_at_period_end, etc.) + // 3. Update entitlements if plan changed + + return nil +} + +// handleSubscriptionDeleted handles subscription cancellation +func (h *WebhookHandler) handleSubscriptionDeleted(ctx interface{}, data []byte) error { + log.Printf("Webhook: Processing customer.subscription.deleted") + + // TODO: Implementation + // 1. Parse subscription data + // 2. Update subscription status to canceled/expired + // 3. Remove or downgrade entitlements + + return nil +} + +// handleInvoicePaid handles successful invoice payment +func (h *WebhookHandler) handleInvoicePaid(ctx interface{}, data []byte) error { + log.Printf("Webhook: Processing invoice.paid") + + // TODO: Implementation + // 1. Parse invoice data + // 2. Update subscription period + // 3. Reset usage counters for new period + // 4. Store invoice record + + return nil +} + +// handleInvoicePaymentFailed handles failed invoice payment +func (h *WebhookHandler) handleInvoicePaymentFailed(ctx interface{}, data []byte) error { + log.Printf("Webhook: Processing invoice.payment_failed") + + // TODO: Implementation + // 1. Parse invoice data + // 2. Update subscription status to past_due + // 3. Send notification to user + // 4. Possibly restrict access + + return nil +} diff --git a/billing-service/internal/handlers/webhook_handlers_test.go b/billing-service/internal/handlers/webhook_handlers_test.go new file mode 100644 index 0000000..799dcfb --- /dev/null +++ b/billing-service/internal/handlers/webhook_handlers_test.go @@ -0,0 +1,433 @@ +package handlers + +import ( + "bytes" + "encoding/json" + "net/http" + "net/http/httptest" + "testing" + + "github.com/gin-gonic/gin" +) + +// TestWebhookEventTypes tests the event types we handle +func TestWebhookEventTypes(t *testing.T) { + eventTypes := []struct { + eventType string + shouldHandle bool + }{ + {"checkout.session.completed", true}, + {"customer.subscription.created", true}, + {"customer.subscription.updated", true}, + {"customer.subscription.deleted", true}, + {"invoice.paid", true}, + {"invoice.payment_failed", true}, + {"customer.created", true}, // Handled but just logged + {"unknown.event.type", false}, + } + + for _, tt := range eventTypes { + t.Run(tt.eventType, func(t *testing.T) { + if tt.eventType == "" { + t.Error("Event type should not be empty") + } + }) + } +} + +// TestWebhookRequest_MissingSignature tests handling of missing signature +func TestWebhookRequest_MissingSignature(t *testing.T) { + gin.SetMode(gin.TestMode) + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + // Create request without Stripe-Signature header + body := []byte(`{"id": "evt_test_123", "type": "test.event"}`) + c.Request = httptest.NewRequest("POST", "/webhook", bytes.NewReader(body)) + c.Request.Header.Set("Content-Type", "application/json") + // Note: No Stripe-Signature header + + // Simulate the check we do in the handler + sigHeader := c.GetHeader("Stripe-Signature") + if sigHeader == "" { + c.JSON(http.StatusBadRequest, gin.H{"error": "missing signature"}) + } + + if w.Code != http.StatusBadRequest { + t.Errorf("Expected status 400 for missing signature, got %d", w.Code) + } + + var response map[string]interface{} + err := json.Unmarshal(w.Body.Bytes(), &response) + if err != nil { + t.Fatalf("Failed to parse response: %v", err) + } + + if response["error"] != "missing signature" { + t.Errorf("Expected 'missing signature' error, got '%v'", response["error"]) + } +} + +// TestWebhookRequest_EmptyBody tests handling of empty request body +func TestWebhookRequest_EmptyBody(t *testing.T) { + gin.SetMode(gin.TestMode) + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + // Create request with empty body + c.Request = httptest.NewRequest("POST", "/webhook", bytes.NewReader([]byte{})) + c.Request.Header.Set("Content-Type", "application/json") + c.Request.Header.Set("Stripe-Signature", "t=123,v1=signature") + + // Read the body + body := make([]byte, 0) + + // Simulate empty body handling + if len(body) == 0 { + c.JSON(http.StatusBadRequest, gin.H{"error": "empty body"}) + } + + if w.Code != http.StatusBadRequest { + t.Errorf("Expected status 400 for empty body, got %d", w.Code) + } +} + +// TestWebhookIdempotency tests idempotency behavior +func TestWebhookIdempotency(t *testing.T) { + // Test that the same event ID should not be processed twice + eventID := "evt_test_123456789" + + // Simulate event tracking + processedEvents := make(map[string]bool) + + // First time - should process + if !processedEvents[eventID] { + processedEvents[eventID] = true + } + + // Second time - should skip + alreadyProcessed := processedEvents[eventID] + if !alreadyProcessed { + t.Error("Event should be marked as processed") + } +} + +// TestWebhookResponse_Processed tests successful webhook response +func TestWebhookResponse_Processed(t *testing.T) { + gin.SetMode(gin.TestMode) + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + c.JSON(http.StatusOK, gin.H{"status": "processed"}) + + if w.Code != http.StatusOK { + t.Errorf("Expected status 200, got %d", w.Code) + } + + var response map[string]interface{} + err := json.Unmarshal(w.Body.Bytes(), &response) + if err != nil { + t.Fatalf("Failed to parse response: %v", err) + } + + if response["status"] != "processed" { + t.Errorf("Expected status 'processed', got '%v'", response["status"]) + } +} + +// TestWebhookResponse_AlreadyProcessed tests idempotent response +func TestWebhookResponse_AlreadyProcessed(t *testing.T) { + gin.SetMode(gin.TestMode) + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + c.JSON(http.StatusOK, gin.H{"status": "already_processed"}) + + if w.Code != http.StatusOK { + t.Errorf("Expected status 200, got %d", w.Code) + } + + var response map[string]interface{} + err := json.Unmarshal(w.Body.Bytes(), &response) + if err != nil { + t.Fatalf("Failed to parse response: %v", err) + } + + if response["status"] != "already_processed" { + t.Errorf("Expected status 'already_processed', got '%v'", response["status"]) + } +} + +// TestWebhookResponse_InternalError tests error response +func TestWebhookResponse_InternalError(t *testing.T) { + gin.SetMode(gin.TestMode) + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + c.JSON(http.StatusInternalServerError, gin.H{"error": "handler error"}) + + if w.Code != http.StatusInternalServerError { + t.Errorf("Expected status 500, got %d", w.Code) + } + + var response map[string]interface{} + err := json.Unmarshal(w.Body.Bytes(), &response) + if err != nil { + t.Fatalf("Failed to parse response: %v", err) + } + + if response["error"] != "handler error" { + t.Errorf("Expected 'handler error', got '%v'", response["error"]) + } +} + +// TestWebhookResponse_InvalidSignature tests signature verification failure +func TestWebhookResponse_InvalidSignature(t *testing.T) { + gin.SetMode(gin.TestMode) + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + + c.JSON(http.StatusUnauthorized, gin.H{"error": "invalid signature"}) + + if w.Code != http.StatusUnauthorized { + t.Errorf("Expected status 401, got %d", w.Code) + } + + var response map[string]interface{} + err := json.Unmarshal(w.Body.Bytes(), &response) + if err != nil { + t.Fatalf("Failed to parse response: %v", err) + } + + if response["error"] != "invalid signature" { + t.Errorf("Expected 'invalid signature', got '%v'", response["error"]) + } +} + +// TestCheckoutSessionCompleted_EventStructure tests the event data structure +func TestCheckoutSessionCompleted_EventStructure(t *testing.T) { + // Test the expected structure of a checkout.session.completed event + eventData := map[string]interface{}{ + "id": "cs_test_123", + "customer": "cus_test_456", + "subscription": "sub_test_789", + "mode": "subscription", + "payment_status": "paid", + "status": "complete", + "metadata": map[string]interface{}{ + "user_id": "550e8400-e29b-41d4-a716-446655440000", + "plan_id": "standard", + }, + } + + data, err := json.Marshal(eventData) + if err != nil { + t.Fatalf("Failed to marshal event data: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Failed to unmarshal event data: %v", err) + } + + // Verify required fields + if decoded["customer"] == nil { + t.Error("Event should have 'customer' field") + } + if decoded["subscription"] == nil { + t.Error("Event should have 'subscription' field") + } + metadata, ok := decoded["metadata"].(map[string]interface{}) + if !ok || metadata["user_id"] == nil { + t.Error("Event should have 'metadata.user_id' field") + } +} + +// TestSubscriptionCreated_EventStructure tests subscription.created event structure +func TestSubscriptionCreated_EventStructure(t *testing.T) { + eventData := map[string]interface{}{ + "id": "sub_test_123", + "customer": "cus_test_456", + "status": "trialing", + "items": map[string]interface{}{ + "data": []map[string]interface{}{ + { + "price": map[string]interface{}{ + "id": "price_test_789", + "metadata": map[string]interface{}{"plan_id": "standard"}, + }, + }, + }, + }, + "trial_end": 1735689600, + "current_period_end": 1735689600, + "metadata": map[string]interface{}{ + "user_id": "550e8400-e29b-41d4-a716-446655440000", + "plan_id": "standard", + }, + } + + data, err := json.Marshal(eventData) + if err != nil { + t.Fatalf("Failed to marshal event data: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Failed to unmarshal event data: %v", err) + } + + // Verify required fields + if decoded["status"] != "trialing" { + t.Errorf("Expected status 'trialing', got '%v'", decoded["status"]) + } +} + +// TestSubscriptionUpdated_StatusTransitions tests subscription status transitions +func TestSubscriptionUpdated_StatusTransitions(t *testing.T) { + validTransitions := []struct { + from string + to string + }{ + {"trialing", "active"}, + {"active", "past_due"}, + {"past_due", "active"}, + {"active", "canceled"}, + {"trialing", "canceled"}, + } + + for _, tt := range validTransitions { + t.Run(tt.from+"->"+tt.to, func(t *testing.T) { + if tt.from == "" || tt.to == "" { + t.Error("Status should not be empty") + } + }) + } +} + +// TestInvoicePaid_EventStructure tests invoice.paid event structure +func TestInvoicePaid_EventStructure(t *testing.T) { + eventData := map[string]interface{}{ + "id": "in_test_123", + "subscription": "sub_test_456", + "customer": "cus_test_789", + "status": "paid", + "amount_paid": 1990, + "currency": "eur", + "period_start": 1735689600, + "period_end": 1738368000, + "hosted_invoice_url": "https://invoice.stripe.com/test", + "invoice_pdf": "https://invoice.stripe.com/test.pdf", + } + + data, err := json.Marshal(eventData) + if err != nil { + t.Fatalf("Failed to marshal event data: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Failed to unmarshal event data: %v", err) + } + + // Verify required fields + if decoded["status"] != "paid" { + t.Errorf("Expected status 'paid', got '%v'", decoded["status"]) + } + if decoded["subscription"] == nil { + t.Error("Event should have 'subscription' field") + } +} + +// TestInvoicePaymentFailed_EventStructure tests invoice.payment_failed event structure +func TestInvoicePaymentFailed_EventStructure(t *testing.T) { + eventData := map[string]interface{}{ + "id": "in_test_123", + "subscription": "sub_test_456", + "customer": "cus_test_789", + "status": "open", + "attempt_count": 1, + "next_payment_attempt": 1735776000, + } + + data, err := json.Marshal(eventData) + if err != nil { + t.Fatalf("Failed to marshal event data: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Failed to unmarshal event data: %v", err) + } + + // Verify fields + if decoded["attempt_count"] == nil { + t.Error("Event should have 'attempt_count' field") + } +} + +// TestSubscriptionDeleted_EventStructure tests subscription.deleted event structure +func TestSubscriptionDeleted_EventStructure(t *testing.T) { + eventData := map[string]interface{}{ + "id": "sub_test_123", + "customer": "cus_test_456", + "status": "canceled", + "ended_at": 1735689600, + "canceled_at": 1735689600, + } + + data, err := json.Marshal(eventData) + if err != nil { + t.Fatalf("Failed to marshal event data: %v", err) + } + + var decoded map[string]interface{} + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Failed to unmarshal event data: %v", err) + } + + // Verify required fields + if decoded["status"] != "canceled" { + t.Errorf("Expected status 'canceled', got '%v'", decoded["status"]) + } +} + +// TestStripeSignatureFormat tests the Stripe signature header format +func TestStripeSignatureFormat(t *testing.T) { + // Stripe signature format: t=timestamp,v1=signature + validSignatures := []string{ + "t=1609459200,v1=abc123def456", + "t=1609459200,v1=signature_here,v0=old_signature", + } + + for _, sig := range validSignatures { + if len(sig) < 10 { + t.Errorf("Signature seems too short: %s", sig) + } + // Should start with timestamp + if sig[:2] != "t=" { + t.Errorf("Signature should start with 't=': %s", sig) + } + } +} + +// TestWebhookEventID_Format tests Stripe event ID format +func TestWebhookEventID_Format(t *testing.T) { + validEventIDs := []string{ + "evt_1234567890abcdef", + "evt_test_123456789", + "evt_live_987654321", + } + + for _, eventID := range validEventIDs { + // Event IDs should start with "evt_" + if len(eventID) < 10 || eventID[:4] != "evt_" { + t.Errorf("Invalid event ID format: %s", eventID) + } + } +} diff --git a/billing-service/internal/middleware/middleware.go b/billing-service/internal/middleware/middleware.go new file mode 100644 index 0000000..6ac16e7 --- /dev/null +++ b/billing-service/internal/middleware/middleware.go @@ -0,0 +1,288 @@ +package middleware + +import ( + "net/http" + "strings" + "sync" + "time" + + "github.com/gin-gonic/gin" + "github.com/golang-jwt/jwt/v5" + "github.com/google/uuid" +) + +// UserClaims represents the JWT claims for a user +type UserClaims struct { + UserID string `json:"user_id"` + Email string `json:"email"` + Role string `json:"role"` + jwt.RegisteredClaims +} + +// CORS returns a CORS middleware +func CORS() gin.HandlerFunc { + return func(c *gin.Context) { + origin := c.Request.Header.Get("Origin") + + // Allow localhost for development + allowedOrigins := []string{ + "http://localhost:3000", + "http://localhost:8000", + "http://localhost:8080", + "http://localhost:8083", + "https://breakpilot.app", + } + + allowed := false + for _, o := range allowedOrigins { + if origin == o { + allowed = true + break + } + } + + if allowed { + c.Header("Access-Control-Allow-Origin", origin) + } + + c.Header("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS") + c.Header("Access-Control-Allow-Headers", "Origin, Content-Type, Authorization, X-Requested-With, X-Internal-API-Key") + c.Header("Access-Control-Allow-Credentials", "true") + c.Header("Access-Control-Max-Age", "86400") + + if c.Request.Method == "OPTIONS" { + c.AbortWithStatus(http.StatusNoContent) + return + } + + c.Next() + } +} + +// RequestLogger logs each request +func RequestLogger() gin.HandlerFunc { + return func(c *gin.Context) { + start := time.Now() + path := c.Request.URL.Path + method := c.Request.Method + + c.Next() + + latency := time.Since(start) + status := c.Writer.Status() + + // Log only in development or for errors + if status >= 400 { + gin.DefaultWriter.Write([]byte( + method + " " + path + " " + + string(rune(status)) + " " + + latency.String() + "\n", + )) + } + } +} + +// RateLimiter implements a simple in-memory rate limiter +func RateLimiter() gin.HandlerFunc { + type client struct { + count int + lastSeen time.Time + } + + var ( + mu sync.Mutex + clients = make(map[string]*client) + ) + + // Clean up old entries periodically + go func() { + for { + time.Sleep(time.Minute) + mu.Lock() + for ip, c := range clients { + if time.Since(c.lastSeen) > time.Minute { + delete(clients, ip) + } + } + mu.Unlock() + } + }() + + return func(c *gin.Context) { + ip := c.ClientIP() + + mu.Lock() + defer mu.Unlock() + + if _, exists := clients[ip]; !exists { + clients[ip] = &client{} + } + + cli := clients[ip] + + // Reset count if more than a minute has passed + if time.Since(cli.lastSeen) > time.Minute { + cli.count = 0 + } + + cli.count++ + cli.lastSeen = time.Now() + + // Allow 100 requests per minute + if cli.count > 100 { + c.AbortWithStatusJSON(http.StatusTooManyRequests, gin.H{ + "error": "rate_limit_exceeded", + "message": "Too many requests. Please try again later.", + }) + return + } + + c.Next() + } +} + +// AuthMiddleware validates JWT tokens +func AuthMiddleware(jwtSecret string) gin.HandlerFunc { + return func(c *gin.Context) { + authHeader := c.GetHeader("Authorization") + if authHeader == "" { + c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{ + "error": "missing_authorization", + "message": "Authorization header is required", + }) + return + } + + // Extract token from "Bearer " + parts := strings.Split(authHeader, " ") + if len(parts) != 2 || parts[0] != "Bearer" { + c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{ + "error": "invalid_authorization", + "message": "Authorization header must be in format: Bearer ", + }) + return + } + + tokenString := parts[1] + + // Parse and validate token + token, err := jwt.ParseWithClaims(tokenString, &UserClaims{}, func(token *jwt.Token) (interface{}, error) { + return []byte(jwtSecret), nil + }) + + if err != nil { + c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{ + "error": "invalid_token", + "message": "Invalid or expired token", + }) + return + } + + if claims, ok := token.Claims.(*UserClaims); ok && token.Valid { + // Set user info in context + c.Set("user_id", claims.UserID) + c.Set("email", claims.Email) + c.Set("role", claims.Role) + c.Next() + } else { + c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{ + "error": "invalid_claims", + "message": "Invalid token claims", + }) + return + } + } +} + +// InternalAPIKeyMiddleware validates internal API key for service-to-service communication +func InternalAPIKeyMiddleware(apiKey string) gin.HandlerFunc { + return func(c *gin.Context) { + if apiKey == "" { + c.AbortWithStatusJSON(http.StatusInternalServerError, gin.H{ + "error": "config_error", + "message": "Internal API key not configured", + }) + return + } + + providedKey := c.GetHeader("X-Internal-API-Key") + if providedKey == "" { + c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{ + "error": "missing_api_key", + "message": "X-Internal-API-Key header is required", + }) + return + } + + if providedKey != apiKey { + c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{ + "error": "invalid_api_key", + "message": "Invalid API key", + }) + return + } + + c.Next() + } +} + +// AdminOnly ensures only admin users can access the route +func AdminOnly() gin.HandlerFunc { + return func(c *gin.Context) { + role, exists := c.Get("role") + if !exists { + c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{ + "error": "unauthorized", + "message": "User role not found", + }) + return + } + + roleStr, ok := role.(string) + if !ok || (roleStr != "admin" && roleStr != "super_admin" && roleStr != "data_protection_officer") { + c.AbortWithStatusJSON(http.StatusForbidden, gin.H{ + "error": "forbidden", + "message": "Admin access required", + }) + return + } + + c.Next() + } +} + +// GetUserID extracts the user ID from the context +func GetUserID(c *gin.Context) (uuid.UUID, error) { + userIDStr, exists := c.Get("user_id") + if !exists { + return uuid.Nil, nil + } + + userID, err := uuid.Parse(userIDStr.(string)) + if err != nil { + return uuid.Nil, err + } + + return userID, nil +} + +// GetClientIP returns the client's IP address +func GetClientIP(c *gin.Context) string { + // Check X-Forwarded-For header first (for proxied requests) + if xff := c.GetHeader("X-Forwarded-For"); xff != "" { + ips := strings.Split(xff, ",") + return strings.TrimSpace(ips[0]) + } + + // Check X-Real-IP header + if xri := c.GetHeader("X-Real-IP"); xri != "" { + return xri + } + + return c.ClientIP() +} + +// GetUserAgent returns the client's User-Agent +func GetUserAgent(c *gin.Context) string { + return c.GetHeader("User-Agent") +} diff --git a/billing-service/internal/models/models.go b/billing-service/internal/models/models.go new file mode 100644 index 0000000..dfe0fff --- /dev/null +++ b/billing-service/internal/models/models.go @@ -0,0 +1,372 @@ +package models + +import ( + "time" + + "github.com/google/uuid" +) + +// SubscriptionStatus represents the status of a subscription +type SubscriptionStatus string + +const ( + StatusTrialing SubscriptionStatus = "trialing" + StatusActive SubscriptionStatus = "active" + StatusPastDue SubscriptionStatus = "past_due" + StatusCanceled SubscriptionStatus = "canceled" + StatusExpired SubscriptionStatus = "expired" +) + +// PlanID represents the available plan IDs +type PlanID string + +const ( + PlanBasic PlanID = "basic" + PlanStandard PlanID = "standard" + PlanPremium PlanID = "premium" +) + +// TaskType represents the type of task +type TaskType string + +const ( + TaskTypeCorrection TaskType = "correction" + TaskTypeLetter TaskType = "letter" + TaskTypeMeeting TaskType = "meeting" + TaskTypeBatch TaskType = "batch" + TaskTypeOther TaskType = "other" +) + +// CarryoverMonthsCap is the maximum number of months tasks can accumulate +const CarryoverMonthsCap = 5 + +// Subscription represents a user's subscription +type Subscription struct { + ID uuid.UUID `json:"id"` + UserID uuid.UUID `json:"user_id"` + StripeCustomerID string `json:"stripe_customer_id"` + StripeSubscriptionID string `json:"stripe_subscription_id"` + PlanID PlanID `json:"plan_id"` + Status SubscriptionStatus `json:"status"` + TrialEnd *time.Time `json:"trial_end,omitempty"` + CurrentPeriodEnd *time.Time `json:"current_period_end,omitempty"` + CancelAtPeriodEnd bool `json:"cancel_at_period_end"` + CreatedAt time.Time `json:"created_at"` + UpdatedAt time.Time `json:"updated_at"` +} + +// BillingPlan represents a billing plan with its features and limits +type BillingPlan struct { + ID PlanID `json:"id"` + StripePriceID string `json:"stripe_price_id"` + Name string `json:"name"` + Description string `json:"description"` + PriceCents int `json:"price_cents"` // Price in cents (990 = 9.90 EUR) + Currency string `json:"currency"` + Interval string `json:"interval"` // "month" or "year" + Features PlanFeatures `json:"features"` + IsActive bool `json:"is_active"` + SortOrder int `json:"sort_order"` +} + +// PlanFeatures represents the features and limits of a plan +type PlanFeatures struct { + // Task-based limits (primary billing unit) + MonthlyTaskAllowance int `json:"monthly_task_allowance"` // Tasks per month + MaxTaskBalance int `json:"max_task_balance"` // Max accumulated tasks (allowance * CarryoverMonthsCap) + + // Legacy fields for backward compatibility (deprecated, use task-based limits) + AIRequestsLimit int `json:"ai_requests_limit,omitempty"` + DocumentsLimit int `json:"documents_limit,omitempty"` + + // Feature flags + FeatureFlags []string `json:"feature_flags"` + MaxTeamMembers int `json:"max_team_members,omitempty"` + PrioritySupport bool `json:"priority_support"` + CustomBranding bool `json:"custom_branding"` + BatchProcessing bool `json:"batch_processing"` + CustomTemplates bool `json:"custom_templates"` + + // Premium: Fair Use (no visible limit) + FairUseMode bool `json:"fair_use_mode"` +} + +// Task represents a single task that consumes 1 unit from the balance +type Task struct { + ID uuid.UUID `json:"id"` + AccountID uuid.UUID `json:"account_id"` + TaskType TaskType `json:"task_type"` + CreatedAt time.Time `json:"created_at"` + Consumed bool `json:"consumed"` // Always true when created + // Internal metrics (not shown to user) + PageCount int `json:"-"` + TokenCount int `json:"-"` + ProcessTime int `json:"-"` // in seconds +} + +// AccountUsage represents the task-based usage for an account +type AccountUsage struct { + ID uuid.UUID `json:"id"` + AccountID uuid.UUID `json:"account_id"` + PlanID PlanID `json:"plan"` + MonthlyTaskAllowance int `json:"monthly_task_allowance"` + CarryoverMonthsCap int `json:"carryover_months_cap"` // Always 5 + MaxTaskBalance int `json:"max_task_balance"` // allowance * cap + TaskBalance int `json:"task_balance"` // Current available tasks + LastRenewalAt time.Time `json:"last_renewal_at"` + CreatedAt time.Time `json:"created_at"` + UpdatedAt time.Time `json:"updated_at"` +} + +// UsageSummary tracks usage for a specific period (internal metrics) +type UsageSummary struct { + ID uuid.UUID `json:"id"` + UserID uuid.UUID `json:"user_id"` + UsageType string `json:"usage_type"` // "task", "page", "token" + PeriodStart time.Time `json:"period_start"` + TotalCount int `json:"total_count"` + CreatedAt time.Time `json:"created_at"` + UpdatedAt time.Time `json:"updated_at"` +} + +// UserEntitlements represents cached entitlements for a user +type UserEntitlements struct { + ID uuid.UUID `json:"id"` + UserID uuid.UUID `json:"user_id"` + PlanID PlanID `json:"plan_id"` + TaskBalance int `json:"task_balance"` + MaxBalance int `json:"max_balance"` + Features PlanFeatures `json:"features"` + UpdatedAt time.Time `json:"updated_at"` + // Legacy fields for backward compatibility with old entitlement service + AIRequestsLimit int `json:"ai_requests_limit"` + AIRequestsUsed int `json:"ai_requests_used"` + DocumentsLimit int `json:"documents_limit"` + DocumentsUsed int `json:"documents_used"` +} + +// StripeWebhookEvent tracks processed webhook events for idempotency +type StripeWebhookEvent struct { + StripeEventID string `json:"stripe_event_id"` + EventType string `json:"event_type"` + Processed bool `json:"processed"` + ProcessedAt time.Time `json:"processed_at"` + CreatedAt time.Time `json:"created_at"` +} + +// BillingStatusResponse is the response for the billing status endpoint +type BillingStatusResponse struct { + HasSubscription bool `json:"has_subscription"` + Subscription *SubscriptionInfo `json:"subscription,omitempty"` + TaskUsage *TaskUsageInfo `json:"task_usage,omitempty"` + Entitlements *EntitlementInfo `json:"entitlements,omitempty"` + AvailablePlans []BillingPlan `json:"available_plans,omitempty"` +} + +// SubscriptionInfo contains subscription details for the response +type SubscriptionInfo struct { + PlanID PlanID `json:"plan_id"` + PlanName string `json:"plan_name"` + Status SubscriptionStatus `json:"status"` + IsTrialing bool `json:"is_trialing"` + TrialDaysLeft int `json:"trial_days_left,omitempty"` + CurrentPeriodEnd *time.Time `json:"current_period_end,omitempty"` + CancelAtPeriodEnd bool `json:"cancel_at_period_end"` + PriceCents int `json:"price_cents"` + Currency string `json:"currency"` +} + +// TaskUsageInfo contains current task usage information +// This is the ONLY usage info shown to users +type TaskUsageInfo struct { + TasksAvailable int `json:"tasks_available"` // Current balance + MaxTasks int `json:"max_tasks"` // Max possible balance + InfoText string `json:"info_text"` // "Aufgaben verfuegbar: X von max. Y" + TooltipText string `json:"tooltip_text"` // "Aufgaben koennen sich bis zu 5 Monate ansammeln." +} + +// EntitlementInfo contains feature entitlements +type EntitlementInfo struct { + Features []string `json:"features"` + MaxTeamMembers int `json:"max_team_members,omitempty"` + PrioritySupport bool `json:"priority_support"` + CustomBranding bool `json:"custom_branding"` + BatchProcessing bool `json:"batch_processing"` + CustomTemplates bool `json:"custom_templates"` + FairUseMode bool `json:"fair_use_mode"` // Premium only +} + +// StartTrialRequest is the request to start a trial +type StartTrialRequest struct { + PlanID PlanID `json:"plan_id" binding:"required"` +} + +// StartTrialResponse is the response after starting a trial +type StartTrialResponse struct { + CheckoutURL string `json:"checkout_url"` + SessionID string `json:"session_id"` +} + +// ChangePlanRequest is the request to change plans +type ChangePlanRequest struct { + NewPlanID PlanID `json:"new_plan_id" binding:"required"` +} + +// ChangePlanResponse is the response after changing plans +type ChangePlanResponse struct { + Success bool `json:"success"` + Message string `json:"message"` + EffectiveDate string `json:"effective_date,omitempty"` +} + +// CancelSubscriptionResponse is the response after canceling +type CancelSubscriptionResponse struct { + Success bool `json:"success"` + Message string `json:"message"` + CancelDate string `json:"cancel_date"` + ActiveUntil string `json:"active_until"` +} + +// CustomerPortalResponse contains the portal URL +type CustomerPortalResponse struct { + PortalURL string `json:"portal_url"` +} + +// ConsumeTaskRequest is the request to consume a task (internal) +type ConsumeTaskRequest struct { + UserID string `json:"user_id" binding:"required"` + TaskType TaskType `json:"task_type" binding:"required"` +} + +// ConsumeTaskResponse is the response after consuming a task +type ConsumeTaskResponse struct { + Success bool `json:"success"` + TaskID string `json:"task_id,omitempty"` + TasksRemaining int `json:"tasks_remaining"` + Message string `json:"message,omitempty"` +} + +// CheckTaskAllowedResponse is the response for task limit checks +type CheckTaskAllowedResponse struct { + Allowed bool `json:"allowed"` + TasksAvailable int `json:"tasks_available"` + MaxTasks int `json:"max_tasks"` + PlanID PlanID `json:"plan_id"` + Message string `json:"message,omitempty"` +} + +// EntitlementCheckResponse is the response for entitlement checks (internal) +type EntitlementCheckResponse struct { + HasEntitlement bool `json:"has_entitlement"` + PlanID PlanID `json:"plan_id,omitempty"` + Message string `json:"message,omitempty"` +} + +// TaskLimitError represents the error when task limit is reached +type TaskLimitError struct { + Error string `json:"error"` + CurrentBalance int `json:"current_balance"` + Plan PlanID `json:"plan"` +} + +// UsageInfo represents current usage information (legacy, prefer TaskUsageInfo) +type UsageInfo struct { + AIRequestsUsed int `json:"ai_requests_used"` + AIRequestsLimit int `json:"ai_requests_limit"` + AIRequestsPercent float64 `json:"ai_requests_percent"` + DocumentsUsed int `json:"documents_used"` + DocumentsLimit int `json:"documents_limit"` + DocumentsPercent float64 `json:"documents_percent"` + PeriodStart string `json:"period_start"` + PeriodEnd string `json:"period_end"` +} + +// CheckUsageResponse is the response for legacy usage checks +type CheckUsageResponse struct { + Allowed bool `json:"allowed"` + CurrentUsage int `json:"current_usage"` + Limit int `json:"limit"` + Remaining int `json:"remaining"` + Message string `json:"message,omitempty"` +} + +// TrackUsageRequest is the request to track usage (internal) +type TrackUsageRequest struct { + UserID string `json:"user_id" binding:"required"` + UsageType string `json:"usage_type" binding:"required"` + Quantity int `json:"quantity"` +} + +// GetDefaultPlans returns the default billing plans with task-based limits +func GetDefaultPlans() []BillingPlan { + return []BillingPlan{ + { + ID: PlanBasic, + Name: "Basic", + Description: "Perfekt fuer den Einstieg - Gelegentliche Nutzung", + PriceCents: 990, // 9.90 EUR + Currency: "eur", + Interval: "month", + Features: PlanFeatures{ + MonthlyTaskAllowance: 30, // 30 tasks/month + MaxTaskBalance: 30 * CarryoverMonthsCap, // 150 max + FeatureFlags: []string{"basic_ai", "basic_documents"}, + MaxTeamMembers: 1, + PrioritySupport: false, + CustomBranding: false, + BatchProcessing: false, + CustomTemplates: false, + FairUseMode: false, + }, + IsActive: true, + SortOrder: 1, + }, + { + ID: PlanStandard, + Name: "Standard", + Description: "Fuer regelmaessige Nutzer - Mehrere Klassen und regelmaessige Korrekturen", + PriceCents: 1990, // 19.90 EUR + Currency: "eur", + Interval: "month", + Features: PlanFeatures{ + MonthlyTaskAllowance: 100, // 100 tasks/month + MaxTaskBalance: 100 * CarryoverMonthsCap, // 500 max + FeatureFlags: []string{"basic_ai", "basic_documents", "templates", "batch_processing"}, + MaxTeamMembers: 3, + PrioritySupport: false, + CustomBranding: false, + BatchProcessing: true, + CustomTemplates: true, + FairUseMode: false, + }, + IsActive: true, + SortOrder: 2, + }, + { + ID: PlanPremium, + Name: "Premium", + Description: "Sorglos-Tarif - Vielnutzer, Teams, schulischer Kontext", + PriceCents: 3990, // 39.90 EUR + Currency: "eur", + Interval: "month", + Features: PlanFeatures{ + MonthlyTaskAllowance: 1000, // Very high (Fair Use) + MaxTaskBalance: 1000 * CarryoverMonthsCap, // 5000 max (not shown to user) + FeatureFlags: []string{"basic_ai", "basic_documents", "templates", "batch_processing", "team_features", "admin_panel", "audit_log", "api_access"}, + MaxTeamMembers: 10, + PrioritySupport: true, + CustomBranding: true, + BatchProcessing: true, + CustomTemplates: true, + FairUseMode: true, // No visible limit + }, + IsActive: true, + SortOrder: 3, + }, + } +} + +// CalculateMaxTaskBalance calculates max task balance from monthly allowance +func CalculateMaxTaskBalance(monthlyAllowance int) int { + return monthlyAllowance * CarryoverMonthsCap +} diff --git a/billing-service/internal/models/models_test.go b/billing-service/internal/models/models_test.go new file mode 100644 index 0000000..3113c66 --- /dev/null +++ b/billing-service/internal/models/models_test.go @@ -0,0 +1,319 @@ +package models + +import ( + "testing" +) + +func TestCarryoverMonthsCap(t *testing.T) { + // Verify the constant is set correctly + if CarryoverMonthsCap != 5 { + t.Errorf("CarryoverMonthsCap should be 5, got %d", CarryoverMonthsCap) + } +} + +func TestCalculateMaxTaskBalance(t *testing.T) { + tests := []struct { + name string + monthlyAllowance int + expected int + }{ + {"Basic plan", 30, 150}, + {"Standard plan", 100, 500}, + {"Premium plan", 1000, 5000}, + {"Zero allowance", 0, 0}, + {"Single task", 1, 5}, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + result := CalculateMaxTaskBalance(tt.monthlyAllowance) + if result != tt.expected { + t.Errorf("CalculateMaxTaskBalance(%d) = %d, expected %d", + tt.monthlyAllowance, result, tt.expected) + } + }) + } +} + +func TestGetDefaultPlans(t *testing.T) { + plans := GetDefaultPlans() + + if len(plans) != 3 { + t.Fatalf("Expected 3 plans, got %d", len(plans)) + } + + // Test Basic plan + basic := plans[0] + if basic.ID != PlanBasic { + t.Errorf("First plan should be Basic, got %s", basic.ID) + } + if basic.PriceCents != 990 { + t.Errorf("Basic price should be 990 cents, got %d", basic.PriceCents) + } + if basic.Features.MonthlyTaskAllowance != 30 { + t.Errorf("Basic monthly allowance should be 30, got %d", basic.Features.MonthlyTaskAllowance) + } + if basic.Features.MaxTaskBalance != 150 { + t.Errorf("Basic max balance should be 150, got %d", basic.Features.MaxTaskBalance) + } + if basic.Features.FairUseMode { + t.Error("Basic should not have FairUseMode") + } + + // Test Standard plan + standard := plans[1] + if standard.ID != PlanStandard { + t.Errorf("Second plan should be Standard, got %s", standard.ID) + } + if standard.PriceCents != 1990 { + t.Errorf("Standard price should be 1990 cents, got %d", standard.PriceCents) + } + if standard.Features.MonthlyTaskAllowance != 100 { + t.Errorf("Standard monthly allowance should be 100, got %d", standard.Features.MonthlyTaskAllowance) + } + if !standard.Features.BatchProcessing { + t.Error("Standard should have BatchProcessing") + } + if !standard.Features.CustomTemplates { + t.Error("Standard should have CustomTemplates") + } + + // Test Premium plan + premium := plans[2] + if premium.ID != PlanPremium { + t.Errorf("Third plan should be Premium, got %s", premium.ID) + } + if premium.PriceCents != 3990 { + t.Errorf("Premium price should be 3990 cents, got %d", premium.PriceCents) + } + if !premium.Features.FairUseMode { + t.Error("Premium should have FairUseMode") + } + if !premium.Features.PrioritySupport { + t.Error("Premium should have PrioritySupport") + } + if !premium.Features.CustomBranding { + t.Error("Premium should have CustomBranding") + } +} + +func TestPlanIDConstants(t *testing.T) { + if PlanBasic != "basic" { + t.Errorf("PlanBasic should be 'basic', got '%s'", PlanBasic) + } + if PlanStandard != "standard" { + t.Errorf("PlanStandard should be 'standard', got '%s'", PlanStandard) + } + if PlanPremium != "premium" { + t.Errorf("PlanPremium should be 'premium', got '%s'", PlanPremium) + } +} + +func TestSubscriptionStatusConstants(t *testing.T) { + statuses := []struct { + status SubscriptionStatus + expected string + }{ + {StatusTrialing, "trialing"}, + {StatusActive, "active"}, + {StatusPastDue, "past_due"}, + {StatusCanceled, "canceled"}, + {StatusExpired, "expired"}, + } + + for _, tt := range statuses { + if string(tt.status) != tt.expected { + t.Errorf("Status %s should be '%s'", tt.status, tt.expected) + } + } +} + +func TestTaskTypeConstants(t *testing.T) { + types := []struct { + taskType TaskType + expected string + }{ + {TaskTypeCorrection, "correction"}, + {TaskTypeLetter, "letter"}, + {TaskTypeMeeting, "meeting"}, + {TaskTypeBatch, "batch"}, + {TaskTypeOther, "other"}, + } + + for _, tt := range types { + if string(tt.taskType) != tt.expected { + t.Errorf("TaskType %s should be '%s'", tt.taskType, tt.expected) + } + } +} + +func TestPlanFeatures_CarryoverCalculation(t *testing.T) { + plans := GetDefaultPlans() + + for _, plan := range plans { + expectedMax := plan.Features.MonthlyTaskAllowance * CarryoverMonthsCap + if plan.Features.MaxTaskBalance != expectedMax { + t.Errorf("Plan %s: MaxTaskBalance should be %d (allowance * 5), got %d", + plan.ID, expectedMax, plan.Features.MaxTaskBalance) + } + } +} + +func TestBillingPlan_AllPlansActive(t *testing.T) { + plans := GetDefaultPlans() + + for _, plan := range plans { + if !plan.IsActive { + t.Errorf("Plan %s should be active", plan.ID) + } + } +} + +func TestBillingPlan_CurrencyIsEuro(t *testing.T) { + plans := GetDefaultPlans() + + for _, plan := range plans { + if plan.Currency != "eur" { + t.Errorf("Plan %s currency should be 'eur', got '%s'", plan.ID, plan.Currency) + } + } +} + +func TestBillingPlan_IntervalIsMonth(t *testing.T) { + plans := GetDefaultPlans() + + for _, plan := range plans { + if plan.Interval != "month" { + t.Errorf("Plan %s interval should be 'month', got '%s'", plan.ID, plan.Interval) + } + } +} + +func TestBillingPlan_SortOrder(t *testing.T) { + plans := GetDefaultPlans() + + for i, plan := range plans { + expectedOrder := i + 1 + if plan.SortOrder != expectedOrder { + t.Errorf("Plan %s sort order should be %d, got %d", + plan.ID, expectedOrder, plan.SortOrder) + } + } +} + +func TestTaskUsageInfo_FormatStrings(t *testing.T) { + usage := TaskUsageInfo{ + TasksAvailable: 45, + MaxTasks: 150, + InfoText: "Aufgaben verfuegbar: 45 von max. 150", + TooltipText: "Aufgaben koennen sich bis zu 5 Monate ansammeln.", + } + + if usage.TasksAvailable != 45 { + t.Errorf("TasksAvailable should be 45, got %d", usage.TasksAvailable) + } + if usage.MaxTasks != 150 { + t.Errorf("MaxTasks should be 150, got %d", usage.MaxTasks) + } +} + +func TestCheckTaskAllowedResponse_Allowed(t *testing.T) { + response := CheckTaskAllowedResponse{ + Allowed: true, + TasksAvailable: 50, + MaxTasks: 150, + PlanID: PlanBasic, + } + + if !response.Allowed { + t.Error("Response should be allowed") + } + if response.Message != "" { + t.Errorf("Message should be empty for allowed response, got '%s'", response.Message) + } +} + +func TestCheckTaskAllowedResponse_NotAllowed(t *testing.T) { + response := CheckTaskAllowedResponse{ + Allowed: false, + TasksAvailable: 0, + MaxTasks: 150, + PlanID: PlanBasic, + Message: "Dein Aufgaben-Kontingent ist aufgebraucht.", + } + + if response.Allowed { + t.Error("Response should not be allowed") + } + if response.TasksAvailable != 0 { + t.Errorf("TasksAvailable should be 0, got %d", response.TasksAvailable) + } +} + +func TestTaskLimitError(t *testing.T) { + err := TaskLimitError{ + Error: "TASK_LIMIT_REACHED", + CurrentBalance: 0, + Plan: PlanBasic, + } + + if err.Error != "TASK_LIMIT_REACHED" { + t.Errorf("Error should be 'TASK_LIMIT_REACHED', got '%s'", err.Error) + } + if err.CurrentBalance != 0 { + t.Errorf("CurrentBalance should be 0, got %d", err.CurrentBalance) + } + if err.Plan != PlanBasic { + t.Errorf("Plan should be basic, got '%s'", err.Plan) + } +} + +func TestConsumeTaskRequest(t *testing.T) { + req := ConsumeTaskRequest{ + UserID: "550e8400-e29b-41d4-a716-446655440000", + TaskType: TaskTypeCorrection, + } + + if req.UserID == "" { + t.Error("UserID should not be empty") + } + if req.TaskType != TaskTypeCorrection { + t.Errorf("TaskType should be correction, got '%s'", req.TaskType) + } +} + +func TestConsumeTaskResponse_Success(t *testing.T) { + resp := ConsumeTaskResponse{ + Success: true, + TaskID: "task-123", + TasksRemaining: 49, + } + + if !resp.Success { + t.Error("Response should be successful") + } + if resp.TasksRemaining != 49 { + t.Errorf("TasksRemaining should be 49, got %d", resp.TasksRemaining) + } +} + +func TestEntitlementInfo_Premium(t *testing.T) { + premium := GetDefaultPlans()[2] + + info := EntitlementInfo{ + Features: premium.Features.FeatureFlags, + MaxTeamMembers: premium.Features.MaxTeamMembers, + PrioritySupport: premium.Features.PrioritySupport, + CustomBranding: premium.Features.CustomBranding, + BatchProcessing: premium.Features.BatchProcessing, + CustomTemplates: premium.Features.CustomTemplates, + FairUseMode: premium.Features.FairUseMode, + } + + if !info.FairUseMode { + t.Error("Premium should have FairUseMode") + } + if info.MaxTeamMembers != 10 { + t.Errorf("Premium MaxTeamMembers should be 10, got %d", info.MaxTeamMembers) + } +} diff --git a/billing-service/internal/services/entitlement_service.go b/billing-service/internal/services/entitlement_service.go new file mode 100644 index 0000000..f9152b0 --- /dev/null +++ b/billing-service/internal/services/entitlement_service.go @@ -0,0 +1,232 @@ +package services + +import ( + "context" + "encoding/json" + "time" + + "github.com/breakpilot/billing-service/internal/database" + "github.com/breakpilot/billing-service/internal/models" + "github.com/google/uuid" +) + +// EntitlementService handles entitlement-related operations +type EntitlementService struct { + db *database.DB + subService *SubscriptionService +} + +// NewEntitlementService creates a new EntitlementService +func NewEntitlementService(db *database.DB, subService *SubscriptionService) *EntitlementService { + return &EntitlementService{ + db: db, + subService: subService, + } +} + +// GetEntitlements returns the entitlement info for a user +func (s *EntitlementService) GetEntitlements(ctx context.Context, userID uuid.UUID) (*models.EntitlementInfo, error) { + entitlements, err := s.getUserEntitlements(ctx, userID) + if err != nil || entitlements == nil { + return nil, err + } + + return &models.EntitlementInfo{ + Features: entitlements.Features.FeatureFlags, + MaxTeamMembers: entitlements.Features.MaxTeamMembers, + PrioritySupport: entitlements.Features.PrioritySupport, + CustomBranding: entitlements.Features.CustomBranding, + }, nil +} + +// GetEntitlementsByUserIDString returns entitlements by user ID string (for internal API) +func (s *EntitlementService) GetEntitlementsByUserIDString(ctx context.Context, userIDStr string) (*models.UserEntitlements, error) { + userID, err := uuid.Parse(userIDStr) + if err != nil { + return nil, err + } + + return s.getUserEntitlements(ctx, userID) +} + +// getUserEntitlements retrieves or creates entitlements for a user +func (s *EntitlementService) getUserEntitlements(ctx context.Context, userID uuid.UUID) (*models.UserEntitlements, error) { + query := ` + SELECT id, user_id, plan_id, ai_requests_limit, ai_requests_used, + documents_limit, documents_used, features, period_start, period_end, + created_at, updated_at + FROM user_entitlements + WHERE user_id = $1 + ` + + var ent models.UserEntitlements + var featuresJSON []byte + var periodStart, periodEnd *time.Time + + err := s.db.Pool.QueryRow(ctx, query, userID).Scan( + &ent.ID, &ent.UserID, &ent.PlanID, &ent.AIRequestsLimit, &ent.AIRequestsUsed, + &ent.DocumentsLimit, &ent.DocumentsUsed, &featuresJSON, &periodStart, &periodEnd, + nil, &ent.UpdatedAt, + ) + + if err != nil { + if err.Error() == "no rows in result set" { + // Try to create entitlements based on subscription + return s.createEntitlementsFromSubscription(ctx, userID) + } + return nil, err + } + + if len(featuresJSON) > 0 { + json.Unmarshal(featuresJSON, &ent.Features) + } + + return &ent, nil +} + +// createEntitlementsFromSubscription creates entitlements based on user's subscription +func (s *EntitlementService) createEntitlementsFromSubscription(ctx context.Context, userID uuid.UUID) (*models.UserEntitlements, error) { + // Get user's subscription + sub, err := s.subService.GetByUserID(ctx, userID) + if err != nil || sub == nil { + return nil, err + } + + // Get plan details + plan, err := s.subService.GetPlanByID(ctx, string(sub.PlanID)) + if err != nil || plan == nil { + return nil, err + } + + // Create entitlements + return s.CreateEntitlements(ctx, userID, sub.PlanID, plan.Features, sub.CurrentPeriodEnd) +} + +// CreateEntitlements creates entitlements for a user +func (s *EntitlementService) CreateEntitlements(ctx context.Context, userID uuid.UUID, planID models.PlanID, features models.PlanFeatures, periodEnd *time.Time) (*models.UserEntitlements, error) { + featuresJSON, _ := json.Marshal(features) + + now := time.Now() + periodStart := now + + query := ` + INSERT INTO user_entitlements ( + user_id, plan_id, ai_requests_limit, ai_requests_used, + documents_limit, documents_used, features, period_start, period_end + ) VALUES ($1, $2, $3, 0, $4, 0, $5, $6, $7) + ON CONFLICT (user_id) DO UPDATE SET + plan_id = EXCLUDED.plan_id, + ai_requests_limit = EXCLUDED.ai_requests_limit, + documents_limit = EXCLUDED.documents_limit, + features = EXCLUDED.features, + period_start = EXCLUDED.period_start, + period_end = EXCLUDED.period_end, + updated_at = NOW() + RETURNING id, user_id, plan_id, ai_requests_limit, ai_requests_used, + documents_limit, documents_used, updated_at + ` + + var ent models.UserEntitlements + err := s.db.Pool.QueryRow(ctx, query, + userID, planID, features.AIRequestsLimit, features.DocumentsLimit, + featuresJSON, periodStart, periodEnd, + ).Scan( + &ent.ID, &ent.UserID, &ent.PlanID, &ent.AIRequestsLimit, &ent.AIRequestsUsed, + &ent.DocumentsLimit, &ent.DocumentsUsed, &ent.UpdatedAt, + ) + + if err != nil { + return nil, err + } + + ent.Features = features + return &ent, nil +} + +// UpdateEntitlements updates entitlements for a user (e.g., on plan change) +func (s *EntitlementService) UpdateEntitlements(ctx context.Context, userID uuid.UUID, planID models.PlanID, features models.PlanFeatures) error { + featuresJSON, _ := json.Marshal(features) + + query := ` + UPDATE user_entitlements SET + plan_id = $2, + ai_requests_limit = $3, + documents_limit = $4, + features = $5, + updated_at = NOW() + WHERE user_id = $1 + ` + + _, err := s.db.Pool.Exec(ctx, query, + userID, planID, features.AIRequestsLimit, features.DocumentsLimit, featuresJSON, + ) + return err +} + +// ResetUsageCounters resets usage counters for a new period +func (s *EntitlementService) ResetUsageCounters(ctx context.Context, userID uuid.UUID, newPeriodStart, newPeriodEnd *time.Time) error { + query := ` + UPDATE user_entitlements SET + ai_requests_used = 0, + documents_used = 0, + period_start = $2, + period_end = $3, + updated_at = NOW() + WHERE user_id = $1 + ` + + _, err := s.db.Pool.Exec(ctx, query, userID, newPeriodStart, newPeriodEnd) + return err +} + +// CheckEntitlement checks if a user has a specific feature entitlement +func (s *EntitlementService) CheckEntitlement(ctx context.Context, userIDStr, feature string) (bool, models.PlanID, error) { + userID, err := uuid.Parse(userIDStr) + if err != nil { + return false, "", err + } + + ent, err := s.getUserEntitlements(ctx, userID) + if err != nil || ent == nil { + return false, "", err + } + + // Check if feature is in the feature flags + for _, f := range ent.Features.FeatureFlags { + if f == feature { + return true, ent.PlanID, nil + } + } + + return false, ent.PlanID, nil +} + +// IncrementUsage increments a usage counter +func (s *EntitlementService) IncrementUsage(ctx context.Context, userID uuid.UUID, usageType string, amount int) error { + var column string + switch usageType { + case "ai_request": + column = "ai_requests_used" + case "document_created": + column = "documents_used" + default: + return nil + } + + query := ` + UPDATE user_entitlements SET + ` + column + ` = ` + column + ` + $2, + updated_at = NOW() + WHERE user_id = $1 + ` + + _, err := s.db.Pool.Exec(ctx, query, userID, amount) + return err +} + +// DeleteEntitlements removes entitlements for a user (on subscription cancellation) +func (s *EntitlementService) DeleteEntitlements(ctx context.Context, userID uuid.UUID) error { + query := `DELETE FROM user_entitlements WHERE user_id = $1` + _, err := s.db.Pool.Exec(ctx, query, userID) + return err +} diff --git a/billing-service/internal/services/stripe_service.go b/billing-service/internal/services/stripe_service.go new file mode 100644 index 0000000..fb67907 --- /dev/null +++ b/billing-service/internal/services/stripe_service.go @@ -0,0 +1,317 @@ +package services + +import ( + "context" + "fmt" + + "github.com/breakpilot/billing-service/internal/models" + "github.com/google/uuid" + "github.com/stripe/stripe-go/v76" + "github.com/stripe/stripe-go/v76/billingportal/session" + checkoutsession "github.com/stripe/stripe-go/v76/checkout/session" + "github.com/stripe/stripe-go/v76/customer" + "github.com/stripe/stripe-go/v76/price" + "github.com/stripe/stripe-go/v76/product" + "github.com/stripe/stripe-go/v76/subscription" +) + +// StripeService handles Stripe API interactions +type StripeService struct { + secretKey string + webhookSecret string + successURL string + cancelURL string + trialPeriodDays int64 + subService *SubscriptionService + mockMode bool // If true, don't make real Stripe API calls +} + +// NewStripeService creates a new StripeService +func NewStripeService(secretKey, webhookSecret, successURL, cancelURL string, trialPeriodDays int, subService *SubscriptionService) *StripeService { + // Initialize Stripe with the secret key (only if not empty) + if secretKey != "" { + stripe.Key = secretKey + } + + return &StripeService{ + secretKey: secretKey, + webhookSecret: webhookSecret, + successURL: successURL, + cancelURL: cancelURL, + trialPeriodDays: int64(trialPeriodDays), + subService: subService, + mockMode: false, + } +} + +// NewMockStripeService creates a mock StripeService for development +func NewMockStripeService(successURL, cancelURL string, trialPeriodDays int, subService *SubscriptionService) *StripeService { + return &StripeService{ + secretKey: "", + webhookSecret: "", + successURL: successURL, + cancelURL: cancelURL, + trialPeriodDays: int64(trialPeriodDays), + subService: subService, + mockMode: true, + } +} + +// IsMockMode returns true if running in mock mode +func (s *StripeService) IsMockMode() bool { + return s.mockMode +} + +// CreateCheckoutSession creates a Stripe Checkout session for trial start +func (s *StripeService) CreateCheckoutSession(ctx context.Context, userID uuid.UUID, email string, planID models.PlanID) (string, string, error) { + // Mock mode: return a fake URL for development + if s.mockMode { + mockSessionID := fmt.Sprintf("mock_cs_%s", uuid.New().String()[:8]) + mockURL := fmt.Sprintf("%s?session_id=%s&mock=true&plan=%s", s.successURL, mockSessionID, planID) + return mockURL, mockSessionID, nil + } + + // Get plan details + plan, err := s.subService.GetPlanByID(ctx, string(planID)) + if err != nil || plan == nil { + return "", "", fmt.Errorf("plan not found: %s", planID) + } + + // Ensure we have a Stripe price ID + if plan.StripePriceID == "" { + // Create product and price in Stripe if not exists + priceID, err := s.ensurePriceExists(ctx, plan) + if err != nil { + return "", "", fmt.Errorf("failed to create stripe price: %w", err) + } + plan.StripePriceID = priceID + } + + // Create checkout session parameters + params := &stripe.CheckoutSessionParams{ + Mode: stripe.String(string(stripe.CheckoutSessionModeSubscription)), + LineItems: []*stripe.CheckoutSessionLineItemParams{ + { + Price: stripe.String(plan.StripePriceID), + Quantity: stripe.Int64(1), + }, + }, + SuccessURL: stripe.String(s.successURL + "?session_id={CHECKOUT_SESSION_ID}"), + CancelURL: stripe.String(s.cancelURL), + SubscriptionData: &stripe.CheckoutSessionSubscriptionDataParams{ + TrialPeriodDays: stripe.Int64(s.trialPeriodDays), + Metadata: map[string]string{ + "user_id": userID.String(), + "plan_id": string(planID), + }, + }, + PaymentMethodCollection: stripe.String(string(stripe.CheckoutSessionPaymentMethodCollectionAlways)), + Metadata: map[string]string{ + "user_id": userID.String(), + "plan_id": string(planID), + }, + } + + // Set customer email if provided + if email != "" { + params.CustomerEmail = stripe.String(email) + } + + // Create the session + sess, err := checkoutsession.New(params) + if err != nil { + return "", "", fmt.Errorf("failed to create checkout session: %w", err) + } + + return sess.URL, sess.ID, nil +} + +// ensurePriceExists creates a Stripe product and price if they don't exist +func (s *StripeService) ensurePriceExists(ctx context.Context, plan *models.BillingPlan) (string, error) { + // Create product + productParams := &stripe.ProductParams{ + Name: stripe.String(plan.Name), + Description: stripe.String(plan.Description), + Metadata: map[string]string{ + "plan_id": string(plan.ID), + }, + } + + prod, err := product.New(productParams) + if err != nil { + return "", fmt.Errorf("failed to create product: %w", err) + } + + // Create price + priceParams := &stripe.PriceParams{ + Product: stripe.String(prod.ID), + UnitAmount: stripe.Int64(int64(plan.PriceCents)), + Currency: stripe.String(plan.Currency), + Recurring: &stripe.PriceRecurringParams{ + Interval: stripe.String(plan.Interval), + }, + Metadata: map[string]string{ + "plan_id": string(plan.ID), + }, + } + + pr, err := price.New(priceParams) + if err != nil { + return "", fmt.Errorf("failed to create price: %w", err) + } + + // Update plan with Stripe IDs + if err := s.subService.UpdatePlanStripePriceID(ctx, string(plan.ID), pr.ID, prod.ID); err != nil { + // Log but don't fail + fmt.Printf("Warning: Failed to update plan with Stripe IDs: %v\n", err) + } + + return pr.ID, nil +} + +// GetOrCreateCustomer gets or creates a Stripe customer for a user +func (s *StripeService) GetOrCreateCustomer(ctx context.Context, email, name string, userID uuid.UUID) (string, error) { + // Search for existing customer + params := &stripe.CustomerSearchParams{ + SearchParams: stripe.SearchParams{ + Query: fmt.Sprintf("email:'%s'", email), + }, + } + + iter := customer.Search(params) + for iter.Next() { + cust := iter.Customer() + // Check if this customer belongs to our user + if cust.Metadata["user_id"] == userID.String() { + return cust.ID, nil + } + } + + // Create new customer + customerParams := &stripe.CustomerParams{ + Email: stripe.String(email), + Name: stripe.String(name), + Metadata: map[string]string{ + "user_id": userID.String(), + }, + } + + cust, err := customer.New(customerParams) + if err != nil { + return "", fmt.Errorf("failed to create customer: %w", err) + } + + return cust.ID, nil +} + +// ChangePlan changes a subscription to a new plan +func (s *StripeService) ChangePlan(ctx context.Context, stripeSubID string, newPlanID models.PlanID) error { + // Mock mode: just return success + if s.mockMode { + return nil + } + + // Get new plan details + plan, err := s.subService.GetPlanByID(ctx, string(newPlanID)) + if err != nil || plan == nil { + return fmt.Errorf("plan not found: %s", newPlanID) + } + + if plan.StripePriceID == "" { + return fmt.Errorf("plan %s has no Stripe price ID", newPlanID) + } + + // Get current subscription + sub, err := subscription.Get(stripeSubID, nil) + if err != nil { + return fmt.Errorf("failed to get subscription: %w", err) + } + + // Update subscription with new price + params := &stripe.SubscriptionParams{ + Items: []*stripe.SubscriptionItemsParams{ + { + ID: stripe.String(sub.Items.Data[0].ID), + Price: stripe.String(plan.StripePriceID), + }, + }, + ProrationBehavior: stripe.String(string(stripe.SubscriptionSchedulePhaseProrationBehaviorCreateProrations)), + Metadata: map[string]string{ + "plan_id": string(newPlanID), + }, + } + + _, err = subscription.Update(stripeSubID, params) + if err != nil { + return fmt.Errorf("failed to update subscription: %w", err) + } + + return nil +} + +// CancelSubscription cancels a subscription at period end +func (s *StripeService) CancelSubscription(ctx context.Context, stripeSubID string) error { + // Mock mode: just return success + if s.mockMode { + return nil + } + + params := &stripe.SubscriptionParams{ + CancelAtPeriodEnd: stripe.Bool(true), + } + + _, err := subscription.Update(stripeSubID, params) + if err != nil { + return fmt.Errorf("failed to cancel subscription: %w", err) + } + + return nil +} + +// ReactivateSubscription removes the cancel_at_period_end flag +func (s *StripeService) ReactivateSubscription(ctx context.Context, stripeSubID string) error { + // Mock mode: just return success + if s.mockMode { + return nil + } + + params := &stripe.SubscriptionParams{ + CancelAtPeriodEnd: stripe.Bool(false), + } + + _, err := subscription.Update(stripeSubID, params) + if err != nil { + return fmt.Errorf("failed to reactivate subscription: %w", err) + } + + return nil +} + +// CreateCustomerPortalSession creates a Stripe Customer Portal session +func (s *StripeService) CreateCustomerPortalSession(ctx context.Context, customerID string) (string, error) { + // Mock mode: return a mock URL + if s.mockMode { + return fmt.Sprintf("%s?mock_portal=true", s.successURL), nil + } + + params := &stripe.BillingPortalSessionParams{ + Customer: stripe.String(customerID), + ReturnURL: stripe.String(s.successURL), + } + + sess, err := session.New(params) + if err != nil { + return "", fmt.Errorf("failed to create portal session: %w", err) + } + + return sess.URL, nil +} + +// GetSubscription retrieves a subscription from Stripe +func (s *StripeService) GetSubscription(ctx context.Context, stripeSubID string) (*stripe.Subscription, error) { + sub, err := subscription.Get(stripeSubID, nil) + if err != nil { + return nil, fmt.Errorf("failed to get subscription: %w", err) + } + return sub, nil +} diff --git a/billing-service/internal/services/subscription_service.go b/billing-service/internal/services/subscription_service.go new file mode 100644 index 0000000..557dd6c --- /dev/null +++ b/billing-service/internal/services/subscription_service.go @@ -0,0 +1,315 @@ +package services + +import ( + "context" + "encoding/json" + "time" + + "github.com/breakpilot/billing-service/internal/database" + "github.com/breakpilot/billing-service/internal/models" + "github.com/google/uuid" +) + +// SubscriptionService handles subscription-related operations +type SubscriptionService struct { + db *database.DB +} + +// NewSubscriptionService creates a new SubscriptionService +func NewSubscriptionService(db *database.DB) *SubscriptionService { + return &SubscriptionService{db: db} +} + +// GetByUserID retrieves a subscription by user ID +func (s *SubscriptionService) GetByUserID(ctx context.Context, userID uuid.UUID) (*models.Subscription, error) { + query := ` + SELECT id, user_id, stripe_customer_id, stripe_subscription_id, plan_id, + status, trial_end, current_period_end, cancel_at_period_end, + created_at, updated_at + FROM subscriptions + WHERE user_id = $1 + ` + + var sub models.Subscription + var stripeCustomerID, stripeSubID *string + var trialEnd, periodEnd *time.Time + + err := s.db.Pool.QueryRow(ctx, query, userID).Scan( + &sub.ID, &sub.UserID, &stripeCustomerID, &stripeSubID, &sub.PlanID, + &sub.Status, &trialEnd, &periodEnd, &sub.CancelAtPeriodEnd, + &sub.CreatedAt, &sub.UpdatedAt, + ) + + if err != nil { + if err.Error() == "no rows in result set" { + return nil, nil + } + return nil, err + } + + if stripeCustomerID != nil { + sub.StripeCustomerID = *stripeCustomerID + } + if stripeSubID != nil { + sub.StripeSubscriptionID = *stripeSubID + } + sub.TrialEnd = trialEnd + sub.CurrentPeriodEnd = periodEnd + + return &sub, nil +} + +// GetByStripeSubscriptionID retrieves a subscription by Stripe subscription ID +func (s *SubscriptionService) GetByStripeSubscriptionID(ctx context.Context, stripeSubID string) (*models.Subscription, error) { + query := ` + SELECT id, user_id, stripe_customer_id, stripe_subscription_id, plan_id, + status, trial_end, current_period_end, cancel_at_period_end, + created_at, updated_at + FROM subscriptions + WHERE stripe_subscription_id = $1 + ` + + var sub models.Subscription + var stripeCustomerID, subID *string + var trialEnd, periodEnd *time.Time + + err := s.db.Pool.QueryRow(ctx, query, stripeSubID).Scan( + &sub.ID, &sub.UserID, &stripeCustomerID, &subID, &sub.PlanID, + &sub.Status, &trialEnd, &periodEnd, &sub.CancelAtPeriodEnd, + &sub.CreatedAt, &sub.UpdatedAt, + ) + + if err != nil { + if err.Error() == "no rows in result set" { + return nil, nil + } + return nil, err + } + + if stripeCustomerID != nil { + sub.StripeCustomerID = *stripeCustomerID + } + if subID != nil { + sub.StripeSubscriptionID = *subID + } + sub.TrialEnd = trialEnd + sub.CurrentPeriodEnd = periodEnd + + return &sub, nil +} + +// Create creates a new subscription +func (s *SubscriptionService) Create(ctx context.Context, sub *models.Subscription) error { + query := ` + INSERT INTO subscriptions ( + user_id, stripe_customer_id, stripe_subscription_id, plan_id, + status, trial_end, current_period_end, cancel_at_period_end + ) VALUES ($1, $2, $3, $4, $5, $6, $7, $8) + RETURNING id, created_at, updated_at + ` + + return s.db.Pool.QueryRow(ctx, query, + sub.UserID, sub.StripeCustomerID, sub.StripeSubscriptionID, sub.PlanID, + sub.Status, sub.TrialEnd, sub.CurrentPeriodEnd, sub.CancelAtPeriodEnd, + ).Scan(&sub.ID, &sub.CreatedAt, &sub.UpdatedAt) +} + +// Update updates an existing subscription +func (s *SubscriptionService) Update(ctx context.Context, sub *models.Subscription) error { + query := ` + UPDATE subscriptions SET + stripe_customer_id = $2, + stripe_subscription_id = $3, + plan_id = $4, + status = $5, + trial_end = $6, + current_period_end = $7, + cancel_at_period_end = $8, + updated_at = NOW() + WHERE id = $1 + ` + + _, err := s.db.Pool.Exec(ctx, query, + sub.ID, sub.StripeCustomerID, sub.StripeSubscriptionID, sub.PlanID, + sub.Status, sub.TrialEnd, sub.CurrentPeriodEnd, sub.CancelAtPeriodEnd, + ) + return err +} + +// UpdateStatus updates the subscription status +func (s *SubscriptionService) UpdateStatus(ctx context.Context, id uuid.UUID, status models.SubscriptionStatus) error { + query := `UPDATE subscriptions SET status = $2, updated_at = NOW() WHERE id = $1` + _, err := s.db.Pool.Exec(ctx, query, id, status) + return err +} + +// GetAvailablePlans retrieves all active billing plans +func (s *SubscriptionService) GetAvailablePlans(ctx context.Context) ([]models.BillingPlan, error) { + query := ` + SELECT id, stripe_price_id, name, description, price_cents, + currency, interval, features, is_active, sort_order + FROM billing_plans + WHERE is_active = true + ORDER BY sort_order ASC + ` + + rows, err := s.db.Pool.Query(ctx, query) + if err != nil { + return nil, err + } + defer rows.Close() + + var plans []models.BillingPlan + for rows.Next() { + var plan models.BillingPlan + var stripePriceID *string + var featuresJSON []byte + + err := rows.Scan( + &plan.ID, &stripePriceID, &plan.Name, &plan.Description, + &plan.PriceCents, &plan.Currency, &plan.Interval, + &featuresJSON, &plan.IsActive, &plan.SortOrder, + ) + if err != nil { + return nil, err + } + + if stripePriceID != nil { + plan.StripePriceID = *stripePriceID + } + + // Parse features JSON + if len(featuresJSON) > 0 { + json.Unmarshal(featuresJSON, &plan.Features) + } + + plans = append(plans, plan) + } + + return plans, nil +} + +// GetPlanByID retrieves a billing plan by ID +func (s *SubscriptionService) GetPlanByID(ctx context.Context, planID string) (*models.BillingPlan, error) { + query := ` + SELECT id, stripe_price_id, name, description, price_cents, + currency, interval, features, is_active, sort_order + FROM billing_plans + WHERE id = $1 + ` + + var plan models.BillingPlan + var stripePriceID *string + var featuresJSON []byte + + err := s.db.Pool.QueryRow(ctx, query, planID).Scan( + &plan.ID, &stripePriceID, &plan.Name, &plan.Description, + &plan.PriceCents, &plan.Currency, &plan.Interval, + &featuresJSON, &plan.IsActive, &plan.SortOrder, + ) + + if err != nil { + if err.Error() == "no rows in result set" { + return nil, nil + } + return nil, err + } + + if stripePriceID != nil { + plan.StripePriceID = *stripePriceID + } + + if len(featuresJSON) > 0 { + json.Unmarshal(featuresJSON, &plan.Features) + } + + return &plan, nil +} + +// UpdatePlanStripePriceID updates the Stripe price ID for a plan +func (s *SubscriptionService) UpdatePlanStripePriceID(ctx context.Context, planID, stripePriceID, stripeProductID string) error { + query := ` + UPDATE billing_plans + SET stripe_price_id = $2, stripe_product_id = $3, updated_at = NOW() + WHERE id = $1 + ` + _, err := s.db.Pool.Exec(ctx, query, planID, stripePriceID, stripeProductID) + return err +} + +// ============================================= +// Webhook Event Tracking (Idempotency) +// ============================================= + +// IsEventProcessed checks if a webhook event has already been processed +func (s *SubscriptionService) IsEventProcessed(ctx context.Context, eventID string) (bool, error) { + query := `SELECT processed FROM stripe_webhook_events WHERE stripe_event_id = $1` + + var processed bool + err := s.db.Pool.QueryRow(ctx, query, eventID).Scan(&processed) + if err != nil { + if err.Error() == "no rows in result set" { + return false, nil + } + return false, err + } + + return processed, nil +} + +// MarkEventProcessing marks an event as being processed +func (s *SubscriptionService) MarkEventProcessing(ctx context.Context, eventID, eventType string) error { + query := ` + INSERT INTO stripe_webhook_events (stripe_event_id, event_type, processed) + VALUES ($1, $2, false) + ON CONFLICT (stripe_event_id) DO NOTHING + ` + _, err := s.db.Pool.Exec(ctx, query, eventID, eventType) + return err +} + +// MarkEventProcessed marks an event as successfully processed +func (s *SubscriptionService) MarkEventProcessed(ctx context.Context, eventID string) error { + query := ` + UPDATE stripe_webhook_events + SET processed = true, processed_at = NOW() + WHERE stripe_event_id = $1 + ` + _, err := s.db.Pool.Exec(ctx, query, eventID) + return err +} + +// MarkEventFailed marks an event as failed with an error message +func (s *SubscriptionService) MarkEventFailed(ctx context.Context, eventID, errorMsg string) error { + query := ` + UPDATE stripe_webhook_events + SET processed = false, error_message = $2, processed_at = NOW() + WHERE stripe_event_id = $1 + ` + _, err := s.db.Pool.Exec(ctx, query, eventID, errorMsg) + return err +} + +// ============================================= +// Audit Logging +// ============================================= + +// LogAuditEvent logs a billing audit event +func (s *SubscriptionService) LogAuditEvent(ctx context.Context, userID *uuid.UUID, action, entityType, entityID string, oldValue, newValue, metadata interface{}, ipAddress, userAgent string) error { + oldJSON, _ := json.Marshal(oldValue) + newJSON, _ := json.Marshal(newValue) + metaJSON, _ := json.Marshal(metadata) + + query := ` + INSERT INTO billing_audit_log ( + user_id, action, entity_type, entity_id, + old_value, new_value, metadata, ip_address, user_agent + ) VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9) + ` + + _, err := s.db.Pool.Exec(ctx, query, + userID, action, entityType, entityID, + oldJSON, newJSON, metaJSON, ipAddress, userAgent, + ) + return err +} diff --git a/billing-service/internal/services/subscription_service_test.go b/billing-service/internal/services/subscription_service_test.go new file mode 100644 index 0000000..f6cf5a8 --- /dev/null +++ b/billing-service/internal/services/subscription_service_test.go @@ -0,0 +1,326 @@ +package services + +import ( + "encoding/json" + "testing" + + "github.com/breakpilot/billing-service/internal/models" +) + +func TestSubscriptionStatus_Transitions(t *testing.T) { + // Test valid subscription status values + validStatuses := []models.SubscriptionStatus{ + models.StatusTrialing, + models.StatusActive, + models.StatusPastDue, + models.StatusCanceled, + models.StatusExpired, + } + + for _, status := range validStatuses { + if status == "" { + t.Errorf("Status should not be empty") + } + } +} + +func TestPlanID_ValidValues(t *testing.T) { + validPlanIDs := []models.PlanID{ + models.PlanBasic, + models.PlanStandard, + models.PlanPremium, + } + + expected := []string{"basic", "standard", "premium"} + + for i, planID := range validPlanIDs { + if string(planID) != expected[i] { + t.Errorf("PlanID should be '%s', got '%s'", expected[i], planID) + } + } +} + +func TestPlanFeatures_JSONSerialization(t *testing.T) { + features := models.PlanFeatures{ + MonthlyTaskAllowance: 100, + MaxTaskBalance: 500, + FeatureFlags: []string{"basic_ai", "templates"}, + MaxTeamMembers: 3, + PrioritySupport: false, + CustomBranding: false, + BatchProcessing: true, + CustomTemplates: true, + FairUseMode: false, + } + + // Test JSON serialization + data, err := json.Marshal(features) + if err != nil { + t.Fatalf("Failed to marshal PlanFeatures: %v", err) + } + + // Test JSON deserialization + var decoded models.PlanFeatures + err = json.Unmarshal(data, &decoded) + if err != nil { + t.Fatalf("Failed to unmarshal PlanFeatures: %v", err) + } + + // Verify fields + if decoded.MonthlyTaskAllowance != features.MonthlyTaskAllowance { + t.Errorf("MonthlyTaskAllowance mismatch: got %d, expected %d", + decoded.MonthlyTaskAllowance, features.MonthlyTaskAllowance) + } + if decoded.MaxTaskBalance != features.MaxTaskBalance { + t.Errorf("MaxTaskBalance mismatch: got %d, expected %d", + decoded.MaxTaskBalance, features.MaxTaskBalance) + } + if decoded.BatchProcessing != features.BatchProcessing { + t.Errorf("BatchProcessing mismatch: got %v, expected %v", + decoded.BatchProcessing, features.BatchProcessing) + } +} + +func TestBillingPlan_DefaultPlansAreValid(t *testing.T) { + plans := models.GetDefaultPlans() + + if len(plans) != 3 { + t.Fatalf("Expected 3 default plans, got %d", len(plans)) + } + + // Verify all plans have required fields + for _, plan := range plans { + if plan.ID == "" { + t.Errorf("Plan ID should not be empty") + } + if plan.Name == "" { + t.Errorf("Plan '%s' should have a name", plan.ID) + } + if plan.Description == "" { + t.Errorf("Plan '%s' should have a description", plan.ID) + } + if plan.PriceCents <= 0 { + t.Errorf("Plan '%s' should have a positive price, got %d", plan.ID, plan.PriceCents) + } + if plan.Currency != "eur" { + t.Errorf("Plan '%s' currency should be 'eur', got '%s'", plan.ID, plan.Currency) + } + if plan.Interval != "month" { + t.Errorf("Plan '%s' interval should be 'month', got '%s'", plan.ID, plan.Interval) + } + if !plan.IsActive { + t.Errorf("Plan '%s' should be active", plan.ID) + } + if plan.SortOrder <= 0 { + t.Errorf("Plan '%s' should have a positive sort order, got %d", plan.ID, plan.SortOrder) + } + } +} + +func TestBillingPlan_TaskAllowanceProgression(t *testing.T) { + plans := models.GetDefaultPlans() + + // Basic should have lowest allowance + basic := plans[0] + standard := plans[1] + premium := plans[2] + + if basic.Features.MonthlyTaskAllowance >= standard.Features.MonthlyTaskAllowance { + t.Error("Standard plan should have more tasks than Basic") + } + + if standard.Features.MonthlyTaskAllowance >= premium.Features.MonthlyTaskAllowance { + t.Error("Premium plan should have more tasks than Standard") + } +} + +func TestBillingPlan_PriceProgression(t *testing.T) { + plans := models.GetDefaultPlans() + + // Prices should increase with each tier + if plans[0].PriceCents >= plans[1].PriceCents { + t.Error("Standard should cost more than Basic") + } + if plans[1].PriceCents >= plans[2].PriceCents { + t.Error("Premium should cost more than Standard") + } +} + +func TestBillingPlan_FairUseModeOnlyForPremium(t *testing.T) { + plans := models.GetDefaultPlans() + + for _, plan := range plans { + if plan.ID == models.PlanPremium { + if !plan.Features.FairUseMode { + t.Error("Premium plan should have FairUseMode enabled") + } + } else { + if plan.Features.FairUseMode { + t.Errorf("Plan '%s' should not have FairUseMode enabled", plan.ID) + } + } + } +} + +func TestBillingPlan_MaxTaskBalanceCalculation(t *testing.T) { + plans := models.GetDefaultPlans() + + for _, plan := range plans { + expected := plan.Features.MonthlyTaskAllowance * models.CarryoverMonthsCap + if plan.Features.MaxTaskBalance != expected { + t.Errorf("Plan '%s' MaxTaskBalance should be %d (allowance * 5), got %d", + plan.ID, expected, plan.Features.MaxTaskBalance) + } + } +} + +func TestAuditLogJSON_Marshaling(t *testing.T) { + // Test that audit log values can be properly serialized + oldValue := map[string]interface{}{ + "plan_id": "basic", + "status": "active", + } + + newValue := map[string]interface{}{ + "plan_id": "standard", + "status": "active", + } + + metadata := map[string]interface{}{ + "reason": "upgrade", + } + + // Marshal all values + oldJSON, err := json.Marshal(oldValue) + if err != nil { + t.Fatalf("Failed to marshal oldValue: %v", err) + } + + newJSON, err := json.Marshal(newValue) + if err != nil { + t.Fatalf("Failed to marshal newValue: %v", err) + } + + metaJSON, err := json.Marshal(metadata) + if err != nil { + t.Fatalf("Failed to marshal metadata: %v", err) + } + + // Verify non-empty + if len(oldJSON) == 0 || len(newJSON) == 0 || len(metaJSON) == 0 { + t.Error("JSON outputs should not be empty") + } +} + +func TestSubscriptionTrialCalculation(t *testing.T) { + // Test trial days calculation logic + trialDays := 7 + + if trialDays <= 0 { + t.Error("Trial days should be positive") + } + + if trialDays > 30 { + t.Error("Trial days should not exceed 30") + } +} + +func TestSubscriptionInfo_TrialingStatus(t *testing.T) { + info := models.SubscriptionInfo{ + PlanID: models.PlanBasic, + PlanName: "Basic", + Status: models.StatusTrialing, + IsTrialing: true, + TrialDaysLeft: 5, + CancelAtPeriodEnd: false, + PriceCents: 990, + Currency: "eur", + } + + if !info.IsTrialing { + t.Error("Should be trialing") + } + if info.Status != models.StatusTrialing { + t.Errorf("Status should be 'trialing', got '%s'", info.Status) + } + if info.TrialDaysLeft <= 0 { + t.Error("TrialDaysLeft should be positive during trial") + } +} + +func TestSubscriptionInfo_ActiveStatus(t *testing.T) { + info := models.SubscriptionInfo{ + PlanID: models.PlanStandard, + PlanName: "Standard", + Status: models.StatusActive, + IsTrialing: false, + TrialDaysLeft: 0, + CancelAtPeriodEnd: false, + PriceCents: 1990, + Currency: "eur", + } + + if info.IsTrialing { + t.Error("Should not be trialing") + } + if info.Status != models.StatusActive { + t.Errorf("Status should be 'active', got '%s'", info.Status) + } +} + +func TestSubscriptionInfo_CanceledStatus(t *testing.T) { + info := models.SubscriptionInfo{ + PlanID: models.PlanStandard, + PlanName: "Standard", + Status: models.StatusActive, + IsTrialing: false, + CancelAtPeriodEnd: true, // Scheduled for cancellation + PriceCents: 1990, + Currency: "eur", + } + + if !info.CancelAtPeriodEnd { + t.Error("CancelAtPeriodEnd should be true") + } + // Status remains active until period end + if info.Status != models.StatusActive { + t.Errorf("Status should still be 'active', got '%s'", info.Status) + } +} + +func TestWebhookEventTypes(t *testing.T) { + // Test common Stripe webhook event types we handle + eventTypes := []string{ + "checkout.session.completed", + "customer.subscription.created", + "customer.subscription.updated", + "customer.subscription.deleted", + "invoice.paid", + "invoice.payment_failed", + } + + for _, eventType := range eventTypes { + if eventType == "" { + t.Error("Event type should not be empty") + } + } +} + +func TestIdempotencyKey_Format(t *testing.T) { + // Test that we can handle Stripe event IDs + sampleEventIDs := []string{ + "evt_1234567890abcdef", + "evt_test_abc123xyz789", + "evt_live_real_event_id", + } + + for _, eventID := range sampleEventIDs { + if len(eventID) < 10 { + t.Errorf("Event ID '%s' seems too short", eventID) + } + // Stripe event IDs typically start with "evt_" + if eventID[:4] != "evt_" { + t.Errorf("Event ID '%s' should start with 'evt_'", eventID) + } + } +} diff --git a/billing-service/internal/services/task_service.go b/billing-service/internal/services/task_service.go new file mode 100644 index 0000000..8f96d6e --- /dev/null +++ b/billing-service/internal/services/task_service.go @@ -0,0 +1,352 @@ +package services + +import ( + "context" + "errors" + "fmt" + "time" + + "github.com/breakpilot/billing-service/internal/database" + "github.com/breakpilot/billing-service/internal/models" + "github.com/google/uuid" +) + +var ( + // ErrTaskLimitReached is returned when task balance is 0 + ErrTaskLimitReached = errors.New("TASK_LIMIT_REACHED") + // ErrNoSubscription is returned when user has no subscription + ErrNoSubscription = errors.New("NO_SUBSCRIPTION") +) + +// TaskService handles task consumption and balance management +type TaskService struct { + db *database.DB + subService *SubscriptionService +} + +// NewTaskService creates a new TaskService +func NewTaskService(db *database.DB, subService *SubscriptionService) *TaskService { + return &TaskService{ + db: db, + subService: subService, + } +} + +// GetAccountUsage retrieves or creates account usage for a user +func (s *TaskService) GetAccountUsage(ctx context.Context, userID uuid.UUID) (*models.AccountUsage, error) { + query := ` + SELECT id, account_id, plan, monthly_task_allowance, carryover_months_cap, + max_task_balance, task_balance, last_renewal_at, created_at, updated_at + FROM account_usage + WHERE account_id = $1 + ` + + var usage models.AccountUsage + err := s.db.Pool.QueryRow(ctx, query, userID).Scan( + &usage.ID, &usage.AccountID, &usage.PlanID, &usage.MonthlyTaskAllowance, + &usage.CarryoverMonthsCap, &usage.MaxTaskBalance, &usage.TaskBalance, + &usage.LastRenewalAt, &usage.CreatedAt, &usage.UpdatedAt, + ) + + if err != nil { + if err.Error() == "no rows in result set" { + // Create new account usage based on subscription + return s.createAccountUsage(ctx, userID) + } + return nil, err + } + + // Check if month renewal is needed + if err := s.checkAndApplyMonthRenewal(ctx, &usage); err != nil { + return nil, err + } + + return &usage, nil +} + +// createAccountUsage creates account usage based on user's subscription +func (s *TaskService) createAccountUsage(ctx context.Context, userID uuid.UUID) (*models.AccountUsage, error) { + // Get subscription to determine plan + sub, err := s.subService.GetByUserID(ctx, userID) + if err != nil || sub == nil { + return nil, ErrNoSubscription + } + + // Get plan features + plan, err := s.subService.GetPlanByID(ctx, string(sub.PlanID)) + if err != nil || plan == nil { + return nil, fmt.Errorf("plan not found: %s", sub.PlanID) + } + + now := time.Now() + usage := &models.AccountUsage{ + AccountID: userID, + PlanID: sub.PlanID, + MonthlyTaskAllowance: plan.Features.MonthlyTaskAllowance, + CarryoverMonthsCap: models.CarryoverMonthsCap, + MaxTaskBalance: plan.Features.MaxTaskBalance, + TaskBalance: plan.Features.MonthlyTaskAllowance, // Start with one month's worth + LastRenewalAt: now, + } + + query := ` + INSERT INTO account_usage ( + account_id, plan, monthly_task_allowance, carryover_months_cap, + max_task_balance, task_balance, last_renewal_at + ) VALUES ($1, $2, $3, $4, $5, $6, $7) + RETURNING id, created_at, updated_at + ` + + err = s.db.Pool.QueryRow(ctx, query, + usage.AccountID, usage.PlanID, usage.MonthlyTaskAllowance, + usage.CarryoverMonthsCap, usage.MaxTaskBalance, usage.TaskBalance, usage.LastRenewalAt, + ).Scan(&usage.ID, &usage.CreatedAt, &usage.UpdatedAt) + + if err != nil { + return nil, err + } + + return usage, nil +} + +// checkAndApplyMonthRenewal checks if a month has passed and adds allowance +// Implements the carryover logic: tasks accumulate up to max_task_balance +func (s *TaskService) checkAndApplyMonthRenewal(ctx context.Context, usage *models.AccountUsage) error { + now := time.Now() + + // Check if at least one month has passed since last renewal + monthsSinceRenewal := monthsBetween(usage.LastRenewalAt, now) + if monthsSinceRenewal < 1 { + return nil + } + + // Calculate new balance with carryover + // Add monthly allowance for each month that passed + newBalance := usage.TaskBalance + for i := 0; i < monthsSinceRenewal; i++ { + newBalance += usage.MonthlyTaskAllowance + // Cap at max balance + if newBalance > usage.MaxTaskBalance { + newBalance = usage.MaxTaskBalance + break + } + } + + // Calculate new renewal date (add the number of months) + newRenewalAt := usage.LastRenewalAt.AddDate(0, monthsSinceRenewal, 0) + + // Update in database + query := ` + UPDATE account_usage + SET task_balance = $2, last_renewal_at = $3, updated_at = NOW() + WHERE id = $1 + ` + _, err := s.db.Pool.Exec(ctx, query, usage.ID, newBalance, newRenewalAt) + if err != nil { + return err + } + + // Update local struct + usage.TaskBalance = newBalance + usage.LastRenewalAt = newRenewalAt + + return nil +} + +// monthsBetween calculates full months between two dates +func monthsBetween(start, end time.Time) int { + months := 0 + for start.AddDate(0, months+1, 0).Before(end) || start.AddDate(0, months+1, 0).Equal(end) { + months++ + } + return months +} + +// CheckTaskAllowed checks if a task can be consumed (balance > 0) +func (s *TaskService) CheckTaskAllowed(ctx context.Context, userID uuid.UUID) (*models.CheckTaskAllowedResponse, error) { + usage, err := s.GetAccountUsage(ctx, userID) + if err != nil { + if errors.Is(err, ErrNoSubscription) { + return &models.CheckTaskAllowedResponse{ + Allowed: false, + PlanID: "", + Message: "Kein aktives Abonnement gefunden.", + }, nil + } + return nil, err + } + + // Premium Fair Use mode - always allow + plan, _ := s.subService.GetPlanByID(ctx, string(usage.PlanID)) + if plan != nil && plan.Features.FairUseMode { + return &models.CheckTaskAllowedResponse{ + Allowed: true, + TasksAvailable: usage.TaskBalance, + MaxTasks: usage.MaxTaskBalance, + PlanID: usage.PlanID, + }, nil + } + + allowed := usage.TaskBalance > 0 + + response := &models.CheckTaskAllowedResponse{ + Allowed: allowed, + TasksAvailable: usage.TaskBalance, + MaxTasks: usage.MaxTaskBalance, + PlanID: usage.PlanID, + } + + if !allowed { + response.Message = "Dein Aufgaben-Kontingent ist aufgebraucht." + } + + return response, nil +} + +// ConsumeTask consumes one task from the balance +// Returns error if balance is 0 +func (s *TaskService) ConsumeTask(ctx context.Context, userID uuid.UUID, taskType models.TaskType) (*models.ConsumeTaskResponse, error) { + // First check if allowed + checkResponse, err := s.CheckTaskAllowed(ctx, userID) + if err != nil { + return nil, err + } + + if !checkResponse.Allowed { + return &models.ConsumeTaskResponse{ + Success: false, + TasksRemaining: 0, + Message: checkResponse.Message, + }, ErrTaskLimitReached + } + + // Get current usage + usage, err := s.GetAccountUsage(ctx, userID) + if err != nil { + return nil, err + } + + // Start transaction + tx, err := s.db.Pool.Begin(ctx) + if err != nil { + return nil, err + } + defer tx.Rollback(ctx) + + // Decrement balance (only if not Premium Fair Use) + plan, _ := s.subService.GetPlanByID(ctx, string(usage.PlanID)) + newBalance := usage.TaskBalance + if plan == nil || !plan.Features.FairUseMode { + newBalance = usage.TaskBalance - 1 + _, err = tx.Exec(ctx, ` + UPDATE account_usage + SET task_balance = $2, updated_at = NOW() + WHERE account_id = $1 + `, userID, newBalance) + if err != nil { + return nil, err + } + } + + // Create task record + taskID := uuid.New() + _, err = tx.Exec(ctx, ` + INSERT INTO tasks (id, account_id, task_type, consumed, created_at) + VALUES ($1, $2, $3, true, NOW()) + `, taskID, userID, taskType) + if err != nil { + return nil, err + } + + // Commit transaction + if err = tx.Commit(ctx); err != nil { + return nil, err + } + + return &models.ConsumeTaskResponse{ + Success: true, + TaskID: taskID.String(), + TasksRemaining: newBalance, + }, nil +} + +// GetTaskUsageInfo returns formatted task usage info for display +func (s *TaskService) GetTaskUsageInfo(ctx context.Context, userID uuid.UUID) (*models.TaskUsageInfo, error) { + usage, err := s.GetAccountUsage(ctx, userID) + if err != nil { + return nil, err + } + + // Check for Fair Use mode (Premium) + plan, _ := s.subService.GetPlanByID(ctx, string(usage.PlanID)) + if plan != nil && plan.Features.FairUseMode { + return &models.TaskUsageInfo{ + TasksAvailable: usage.TaskBalance, + MaxTasks: usage.MaxTaskBalance, + InfoText: "Unbegrenzte Aufgaben (Fair Use)", + TooltipText: "Im Premium-Tarif gibt es keine praktische Begrenzung.", + }, nil + } + + return &models.TaskUsageInfo{ + TasksAvailable: usage.TaskBalance, + MaxTasks: usage.MaxTaskBalance, + InfoText: fmt.Sprintf("Aufgaben verfuegbar: %d von max. %d", usage.TaskBalance, usage.MaxTaskBalance), + TooltipText: "Aufgaben koennen sich bis zu 5 Monate ansammeln.", + }, nil +} + +// UpdatePlanForUser updates the plan and adjusts allowances +func (s *TaskService) UpdatePlanForUser(ctx context.Context, userID uuid.UUID, newPlanID models.PlanID) error { + plan, err := s.subService.GetPlanByID(ctx, string(newPlanID)) + if err != nil || plan == nil { + return fmt.Errorf("plan not found: %s", newPlanID) + } + + // Update account usage with new plan limits + query := ` + UPDATE account_usage + SET plan = $2, + monthly_task_allowance = $3, + max_task_balance = $4, + updated_at = NOW() + WHERE account_id = $1 + ` + + _, err = s.db.Pool.Exec(ctx, query, + userID, newPlanID, plan.Features.MonthlyTaskAllowance, plan.Features.MaxTaskBalance) + return err +} + +// GetTaskHistory returns task history for a user +func (s *TaskService) GetTaskHistory(ctx context.Context, userID uuid.UUID, limit int) ([]models.Task, error) { + if limit <= 0 { + limit = 50 + } + + query := ` + SELECT id, account_id, task_type, created_at, consumed + FROM tasks + WHERE account_id = $1 + ORDER BY created_at DESC + LIMIT $2 + ` + + rows, err := s.db.Pool.Query(ctx, query, userID, limit) + if err != nil { + return nil, err + } + defer rows.Close() + + var tasks []models.Task + for rows.Next() { + var task models.Task + err := rows.Scan(&task.ID, &task.AccountID, &task.TaskType, &task.CreatedAt, &task.Consumed) + if err != nil { + return nil, err + } + tasks = append(tasks, task) + } + + return tasks, nil +} diff --git a/billing-service/internal/services/task_service_test.go b/billing-service/internal/services/task_service_test.go new file mode 100644 index 0000000..e466ee0 --- /dev/null +++ b/billing-service/internal/services/task_service_test.go @@ -0,0 +1,397 @@ +package services + +import ( + "testing" + "time" +) + +func TestMonthsBetween(t *testing.T) { + tests := []struct { + name string + start time.Time + end time.Time + expected int + }{ + { + name: "Same day", + start: time.Date(2025, 1, 15, 0, 0, 0, 0, time.UTC), + end: time.Date(2025, 1, 15, 0, 0, 0, 0, time.UTC), + expected: 0, + }, + { + name: "Less than one month", + start: time.Date(2025, 1, 15, 0, 0, 0, 0, time.UTC), + end: time.Date(2025, 2, 10, 0, 0, 0, 0, time.UTC), + expected: 0, + }, + { + name: "Exactly one month", + start: time.Date(2025, 1, 15, 0, 0, 0, 0, time.UTC), + end: time.Date(2025, 2, 15, 0, 0, 0, 0, time.UTC), + expected: 1, + }, + { + name: "One month and one day", + start: time.Date(2025, 1, 15, 0, 0, 0, 0, time.UTC), + end: time.Date(2025, 2, 16, 0, 0, 0, 0, time.UTC), + expected: 1, + }, + { + name: "Two months", + start: time.Date(2025, 1, 15, 0, 0, 0, 0, time.UTC), + end: time.Date(2025, 3, 15, 0, 0, 0, 0, time.UTC), + expected: 2, + }, + { + name: "Five months exactly", + start: time.Date(2025, 1, 1, 0, 0, 0, 0, time.UTC), + end: time.Date(2025, 6, 1, 0, 0, 0, 0, time.UTC), + expected: 5, + }, + { + name: "Year boundary", + start: time.Date(2024, 11, 15, 0, 0, 0, 0, time.UTC), + end: time.Date(2025, 2, 15, 0, 0, 0, 0, time.UTC), + expected: 3, + }, + { + name: "Leap year February to March", + start: time.Date(2024, 2, 29, 0, 0, 0, 0, time.UTC), + end: time.Date(2024, 3, 29, 0, 0, 0, 0, time.UTC), + expected: 1, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + result := monthsBetween(tt.start, tt.end) + if result != tt.expected { + t.Errorf("monthsBetween(%v, %v) = %d, expected %d", + tt.start.Format("2006-01-02"), tt.end.Format("2006-01-02"), + result, tt.expected) + } + }) + } +} + +func TestCarryoverLogic(t *testing.T) { + // Test the carryover calculation logic + tests := []struct { + name string + currentBalance int + monthlyAllowance int + maxBalance int + monthsSinceRenewal int + expectedNewBalance int + }{ + { + name: "Normal renewal - add allowance", + currentBalance: 50, + monthlyAllowance: 30, + maxBalance: 150, + monthsSinceRenewal: 1, + expectedNewBalance: 80, + }, + { + name: "Two months missed", + currentBalance: 50, + monthlyAllowance: 30, + maxBalance: 150, + monthsSinceRenewal: 2, + expectedNewBalance: 110, + }, + { + name: "Cap at max balance", + currentBalance: 140, + monthlyAllowance: 30, + maxBalance: 150, + monthsSinceRenewal: 1, + expectedNewBalance: 150, + }, + { + name: "Already at max - no change", + currentBalance: 150, + monthlyAllowance: 30, + maxBalance: 150, + monthsSinceRenewal: 1, + expectedNewBalance: 150, + }, + { + name: "Multiple months - cap applies", + currentBalance: 100, + monthlyAllowance: 30, + maxBalance: 150, + monthsSinceRenewal: 5, + expectedNewBalance: 150, + }, + { + name: "Empty balance - add one month", + currentBalance: 0, + monthlyAllowance: 30, + maxBalance: 150, + monthsSinceRenewal: 1, + expectedNewBalance: 30, + }, + { + name: "Empty balance - add five months", + currentBalance: 0, + monthlyAllowance: 30, + maxBalance: 150, + monthsSinceRenewal: 5, + expectedNewBalance: 150, + }, + { + name: "Standard plan - normal case", + currentBalance: 200, + monthlyAllowance: 100, + maxBalance: 500, + monthsSinceRenewal: 1, + expectedNewBalance: 300, + }, + { + name: "Premium plan - Fair Use", + currentBalance: 1000, + monthlyAllowance: 1000, + maxBalance: 5000, + monthsSinceRenewal: 1, + expectedNewBalance: 2000, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + // Simulate the carryover logic + newBalance := tt.currentBalance + for i := 0; i < tt.monthsSinceRenewal; i++ { + newBalance += tt.monthlyAllowance + if newBalance > tt.maxBalance { + newBalance = tt.maxBalance + break + } + } + + if newBalance != tt.expectedNewBalance { + t.Errorf("Carryover for balance=%d, allowance=%d, max=%d, months=%d = %d, expected %d", + tt.currentBalance, tt.monthlyAllowance, tt.maxBalance, tt.monthsSinceRenewal, + newBalance, tt.expectedNewBalance) + } + }) + } +} + +func TestTaskBalanceAfterConsumption(t *testing.T) { + tests := []struct { + name string + currentBalance int + tasksToConsume int + expectedBalance int + shouldBeAllowed bool + }{ + { + name: "Normal consumption", + currentBalance: 50, + tasksToConsume: 1, + expectedBalance: 49, + shouldBeAllowed: true, + }, + { + name: "Last task", + currentBalance: 1, + tasksToConsume: 1, + expectedBalance: 0, + shouldBeAllowed: true, + }, + { + name: "Empty balance - not allowed", + currentBalance: 0, + tasksToConsume: 1, + expectedBalance: 0, + shouldBeAllowed: false, + }, + { + name: "Multiple tasks", + currentBalance: 50, + tasksToConsume: 5, + expectedBalance: 45, + shouldBeAllowed: true, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + // Test if allowed + allowed := tt.currentBalance > 0 + if allowed != tt.shouldBeAllowed { + t.Errorf("Task allowed with balance=%d: got %v, expected %v", + tt.currentBalance, allowed, tt.shouldBeAllowed) + } + + // Test balance calculation + if allowed { + newBalance := tt.currentBalance - tt.tasksToConsume + if newBalance != tt.expectedBalance { + t.Errorf("Balance after consuming %d tasks from %d: got %d, expected %d", + tt.tasksToConsume, tt.currentBalance, newBalance, tt.expectedBalance) + } + } + }) + } +} + +func TestTaskServiceErrors(t *testing.T) { + // Test error constants + if ErrTaskLimitReached == nil { + t.Error("ErrTaskLimitReached should not be nil") + } + if ErrTaskLimitReached.Error() != "TASK_LIMIT_REACHED" { + t.Errorf("ErrTaskLimitReached should be 'TASK_LIMIT_REACHED', got '%s'", ErrTaskLimitReached.Error()) + } + + if ErrNoSubscription == nil { + t.Error("ErrNoSubscription should not be nil") + } + if ErrNoSubscription.Error() != "NO_SUBSCRIPTION" { + t.Errorf("ErrNoSubscription should be 'NO_SUBSCRIPTION', got '%s'", ErrNoSubscription.Error()) + } +} + +func TestRenewalDateCalculation(t *testing.T) { + tests := []struct { + name string + lastRenewal time.Time + monthsToAdd int + expectedRenewal time.Time + }{ + { + name: "Add one month", + lastRenewal: time.Date(2025, 1, 15, 0, 0, 0, 0, time.UTC), + monthsToAdd: 1, + expectedRenewal: time.Date(2025, 2, 15, 0, 0, 0, 0, time.UTC), + }, + { + name: "Add three months", + lastRenewal: time.Date(2025, 1, 15, 0, 0, 0, 0, time.UTC), + monthsToAdd: 3, + expectedRenewal: time.Date(2025, 4, 15, 0, 0, 0, 0, time.UTC), + }, + { + name: "Year boundary", + lastRenewal: time.Date(2024, 11, 15, 0, 0, 0, 0, time.UTC), + monthsToAdd: 3, + expectedRenewal: time.Date(2025, 2, 15, 0, 0, 0, 0, time.UTC), + }, + { + name: "End of month adjustment", + lastRenewal: time.Date(2025, 1, 31, 0, 0, 0, 0, time.UTC), + monthsToAdd: 1, + // Go's AddDate handles this - February doesn't have 31 days + expectedRenewal: time.Date(2025, 3, 3, 0, 0, 0, 0, time.UTC), // Feb 31 -> March 3 + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + result := tt.lastRenewal.AddDate(0, tt.monthsToAdd, 0) + if !result.Equal(tt.expectedRenewal) { + t.Errorf("AddDate(%v, %d months) = %v, expected %v", + tt.lastRenewal.Format("2006-01-02"), tt.monthsToAdd, + result.Format("2006-01-02"), tt.expectedRenewal.Format("2006-01-02")) + } + }) + } +} + +func TestFairUseModeLogic(t *testing.T) { + // Test that Fair Use mode always allows tasks regardless of balance + tests := []struct { + name string + fairUseMode bool + balance int + shouldAllow bool + }{ + { + name: "Fair Use - zero balance still allowed", + fairUseMode: true, + balance: 0, + shouldAllow: true, + }, + { + name: "Fair Use - normal balance allowed", + fairUseMode: true, + balance: 1000, + shouldAllow: true, + }, + { + name: "Not Fair Use - zero balance not allowed", + fairUseMode: false, + balance: 0, + shouldAllow: false, + }, + { + name: "Not Fair Use - positive balance allowed", + fairUseMode: false, + balance: 50, + shouldAllow: true, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + // Simulate the check logic + var allowed bool + if tt.fairUseMode { + allowed = true // Fair Use always allows + } else { + allowed = tt.balance > 0 + } + + if allowed != tt.shouldAllow { + t.Errorf("FairUseMode=%v, balance=%d: allowed=%v, expected=%v", + tt.fairUseMode, tt.balance, allowed, tt.shouldAllow) + } + }) + } +} + +func TestBalanceDecrementLogic(t *testing.T) { + // Test that Fair Use mode doesn't decrement balance + tests := []struct { + name string + fairUseMode bool + initialBalance int + expectedAfter int + }{ + { + name: "Normal plan - decrement", + fairUseMode: false, + initialBalance: 50, + expectedAfter: 49, + }, + { + name: "Fair Use - no decrement", + fairUseMode: true, + initialBalance: 1000, + expectedAfter: 1000, + }, + { + name: "Normal plan - last task", + fairUseMode: false, + initialBalance: 1, + expectedAfter: 0, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + newBalance := tt.initialBalance + if !tt.fairUseMode { + newBalance = tt.initialBalance - 1 + } + + if newBalance != tt.expectedAfter { + t.Errorf("FairUseMode=%v, initial=%d: got %d, expected %d", + tt.fairUseMode, tt.initialBalance, newBalance, tt.expectedAfter) + } + }) + } +} diff --git a/billing-service/internal/services/usage_service.go b/billing-service/internal/services/usage_service.go new file mode 100644 index 0000000..e773af7 --- /dev/null +++ b/billing-service/internal/services/usage_service.go @@ -0,0 +1,194 @@ +package services + +import ( + "context" + "fmt" + "time" + + "github.com/breakpilot/billing-service/internal/database" + "github.com/breakpilot/billing-service/internal/models" + "github.com/google/uuid" +) + +// UsageService handles usage tracking operations +type UsageService struct { + db *database.DB + entitlementService *EntitlementService +} + +// NewUsageService creates a new UsageService +func NewUsageService(db *database.DB, entitlementService *EntitlementService) *UsageService { + return &UsageService{ + db: db, + entitlementService: entitlementService, + } +} + +// TrackUsage tracks usage for a user +func (s *UsageService) TrackUsage(ctx context.Context, userIDStr, usageType string, quantity int) error { + userID, err := uuid.Parse(userIDStr) + if err != nil { + return fmt.Errorf("invalid user ID: %w", err) + } + + // Get current period start (beginning of current month) + now := time.Now() + periodStart := time.Date(now.Year(), now.Month(), 1, 0, 0, 0, 0, time.UTC) + + // Upsert usage summary + query := ` + INSERT INTO usage_summary (user_id, usage_type, period_start, total_count) + VALUES ($1, $2, $3, $4) + ON CONFLICT (user_id, usage_type, period_start) DO UPDATE SET + total_count = usage_summary.total_count + EXCLUDED.total_count, + updated_at = NOW() + ` + + _, err = s.db.Pool.Exec(ctx, query, userID, usageType, periodStart, quantity) + if err != nil { + return fmt.Errorf("failed to track usage: %w", err) + } + + // Also update entitlements cache + return s.entitlementService.IncrementUsage(ctx, userID, usageType, quantity) +} + +// GetUsageSummary returns usage summary for a user +func (s *UsageService) GetUsageSummary(ctx context.Context, userID uuid.UUID) (*models.UsageInfo, error) { + // Get entitlements (which include current usage) + ent, err := s.entitlementService.getUserEntitlements(ctx, userID) + if err != nil || ent == nil { + return nil, err + } + + // Calculate percentages + aiPercent := 0.0 + if ent.AIRequestsLimit > 0 { + aiPercent = float64(ent.AIRequestsUsed) / float64(ent.AIRequestsLimit) * 100 + } + + docPercent := 0.0 + if ent.DocumentsLimit > 0 { + docPercent = float64(ent.DocumentsUsed) / float64(ent.DocumentsLimit) * 100 + } + + // Get period dates + now := time.Now() + periodStart := time.Date(now.Year(), now.Month(), 1, 0, 0, 0, 0, time.UTC) + periodEnd := periodStart.AddDate(0, 1, 0).Add(-time.Second) + + return &models.UsageInfo{ + AIRequestsUsed: ent.AIRequestsUsed, + AIRequestsLimit: ent.AIRequestsLimit, + AIRequestsPercent: aiPercent, + DocumentsUsed: ent.DocumentsUsed, + DocumentsLimit: ent.DocumentsLimit, + DocumentsPercent: docPercent, + PeriodStart: periodStart.Format("2006-01-02"), + PeriodEnd: periodEnd.Format("2006-01-02"), + }, nil +} + +// CheckUsageAllowed checks if a user is allowed to perform a usage action +func (s *UsageService) CheckUsageAllowed(ctx context.Context, userIDStr, usageType string) (*models.CheckUsageResponse, error) { + userID, err := uuid.Parse(userIDStr) + if err != nil { + return &models.CheckUsageResponse{ + Allowed: false, + Message: "Invalid user ID", + }, nil + } + + // Get entitlements + ent, err := s.entitlementService.getUserEntitlements(ctx, userID) + if err != nil { + return &models.CheckUsageResponse{ + Allowed: false, + Message: "Failed to get entitlements", + }, nil + } + + if ent == nil { + return &models.CheckUsageResponse{ + Allowed: false, + Message: "No subscription found", + }, nil + } + + var currentUsage, limit int + switch usageType { + case "ai_request": + currentUsage = ent.AIRequestsUsed + limit = ent.AIRequestsLimit + case "document_created": + currentUsage = ent.DocumentsUsed + limit = ent.DocumentsLimit + default: + return &models.CheckUsageResponse{ + Allowed: true, + Message: "Unknown usage type - allowing", + }, nil + } + + remaining := limit - currentUsage + allowed := remaining > 0 + + response := &models.CheckUsageResponse{ + Allowed: allowed, + CurrentUsage: currentUsage, + Limit: limit, + Remaining: remaining, + } + + if !allowed { + response.Message = fmt.Sprintf("Usage limit reached for %s (%d/%d)", usageType, currentUsage, limit) + } + + return response, nil +} + +// GetUsageHistory returns usage history for a user +func (s *UsageService) GetUsageHistory(ctx context.Context, userID uuid.UUID, months int) ([]models.UsageSummary, error) { + query := ` + SELECT id, user_id, usage_type, period_start, total_count, created_at, updated_at + FROM usage_summary + WHERE user_id = $1 + AND period_start >= $2 + ORDER BY period_start DESC, usage_type + ` + + // Calculate start date + startDate := time.Now().AddDate(0, -months, 0) + startDate = time.Date(startDate.Year(), startDate.Month(), 1, 0, 0, 0, 0, time.UTC) + + rows, err := s.db.Pool.Query(ctx, query, userID, startDate) + if err != nil { + return nil, err + } + defer rows.Close() + + var summaries []models.UsageSummary + for rows.Next() { + var summary models.UsageSummary + err := rows.Scan( + &summary.ID, &summary.UserID, &summary.UsageType, + &summary.PeriodStart, &summary.TotalCount, + &summary.CreatedAt, &summary.UpdatedAt, + ) + if err != nil { + return nil, err + } + summaries = append(summaries, summary) + } + + return summaries, nil +} + +// ResetPeriodUsage resets usage for a new billing period +func (s *UsageService) ResetPeriodUsage(ctx context.Context, userID uuid.UUID) error { + now := time.Now() + newPeriodStart := time.Date(now.Year(), now.Month(), 1, 0, 0, 0, 0, time.UTC) + newPeriodEnd := newPeriodStart.AddDate(0, 1, 0).Add(-time.Second) + + return s.entitlementService.ResetUsageCounters(ctx, userID, &newPeriodStart, &newPeriodEnd) +} diff --git a/docs-site/404.html b/docs-site/404.html deleted file mode 100644 index 1e2776c..0000000 --- a/docs-site/404.html +++ /dev/null @@ -1,1899 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - -
-
-
- - - -
-
-
- - - -
- -
- -

404 - Not found

- -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/Dockerfile b/docs-site/Dockerfile deleted file mode 100644 index a8711c6..0000000 --- a/docs-site/Dockerfile +++ /dev/null @@ -1,58 +0,0 @@ -# ============================================ -# Breakpilot Dokumentation - MkDocs Build -# Multi-stage build fuer minimale Image-Groesse -# ============================================ - -# Stage 1: Build MkDocs Site -FROM python:3.11-slim AS builder - -WORKDIR /docs - -# Install MkDocs with Material theme and plugins -RUN pip install --no-cache-dir \ - mkdocs==1.6.1 \ - mkdocs-material==9.5.47 \ - pymdown-extensions==10.12 - -# Copy configuration and source files -COPY mkdocs.yml /docs/ -COPY docs-src/ /docs/docs-src/ - -# Build static site -RUN mkdocs build - -# Stage 2: Serve with Nginx -FROM nginx:alpine - -# Copy built site from builder stage -COPY --from=builder /docs/docs-site /usr/share/nginx/html - -# Custom nginx config for SPA routing -RUN echo 'server { \ - listen 80; \ - server_name localhost; \ - root /usr/share/nginx/html; \ - index index.html; \ - \ - location / { \ - try_files $uri $uri/ /index.html; \ - } \ - \ - # Enable gzip compression \ - gzip on; \ - gzip_types text/plain text/css application/json application/javascript text/xml application/xml; \ - gzip_min_length 1000; \ - \ - # Cache static assets \ - location ~* \.(css|js|png|jpg|jpeg|gif|ico|svg|woff|woff2)$ { \ - expires 1y; \ - add_header Cache-Control "public, immutable"; \ - } \ -}' > /etc/nginx/conf.d/default.conf - -EXPOSE 80 - -HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ - CMD wget --no-verbose --tries=1 --spider http://localhost/ || exit 1 - -CMD ["nginx", "-g", "daemon off;"] diff --git a/docs-site/api/backend-api/index.html b/docs-site/api/backend-api/index.html deleted file mode 100644 index e606e38..0000000 --- a/docs-site/api/backend-api/index.html +++ /dev/null @@ -1,3133 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - Backend API - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - -
-
-
- - - -
-
-
- - - -
- -
- - - - - -

BreakPilot Backend API Dokumentation

-

Übersicht

-

Base URL: http://localhost:8000/api

-

Alle Endpoints erfordern Authentifizierung via JWT im Authorization-Header: -

Authorization: Bearer <token>
-

-
-

Worksheets API

-

Generiert Lernmaterialien (MC-Tests, Lückentexte, Mindmaps, Quiz).

-

POST /worksheets/generate/multiple-choice

-

Generiert Multiple-Choice-Fragen aus Quelltext.

-

Request Body: -

{
-  "source_text": "Der Text, aus dem Fragen generiert werden sollen...",
-  "num_questions": 5,
-  "difficulty": "medium",
-  "topic": "Thema",
-  "subject": "Deutsch"
-}
-

-

Response (200): -

{
-  "success": true,
-  "content": {
-    "type": "multiple_choice",
-    "data": {
-      "questions": [
-        {
-          "question": "Was ist...?",
-          "options": ["A", "B", "C", "D"],
-          "correct": 0,
-          "explanation": "Erklärung..."
-        }
-      ]
-    }
-  }
-}
-

-

POST /worksheets/generate/cloze

-

Generiert Lückentexte.

-

POST /worksheets/generate/mindmap

-

Generiert Mindmap als Mermaid-Diagramm.

-

POST /worksheets/generate/quiz

-

Generiert Mix aus verschiedenen Fragetypen.

-
-

Corrections API

-

OCR-basierte Klausurkorrektur mit automatischer Bewertung.

-

POST /corrections/

-

Erstellt neue Korrektur-Session.

-

POST /corrections/{id}/upload

-

Lädt gescannte Klausur hoch und startet OCR im Hintergrund.

-

GET /corrections/{id}

-

Ruft Korrektur-Status ab.

-

Status-Werte: -- uploaded - Datei hochgeladen -- processing - OCR läuft -- ocr_complete - OCR fertig -- analyzing - Analyse läuft -- analyzed - Analyse abgeschlossen -- completed - Fertig -- error - Fehler

-

POST /corrections/{id}/analyze

-

Analysiert extrahierten Text und bewertet Antworten.

-

GET /corrections/{id}/export-pdf

-

Exportiert korrigierte Arbeit als PDF.

-
-

Letters API

-

Elternbriefe mit GFK-Integration und PDF-Export.

-

POST /letters/

-

Erstellt neuen Elternbrief.

-

letter_type Werte: -- general - Allgemeine Information -- halbjahr - Halbjahresinformation -- fehlzeiten - Fehlzeiten-Mitteilung -- elternabend - Einladung Elternabend -- lob - Positives Feedback -- custom - Benutzerdefiniert

-

POST /letters/improve

-

Verbessert Text nach GFK-Prinzipien.

-
-

State Engine API

-

Begleiter-Modus mit Phasen-Management und Antizipation.

-

GET /state/dashboard

-

Komplettes Dashboard für Begleiter-Modus.

-

GET /state/suggestions

-

Ruft Vorschläge für Lehrer ab.

-

POST /state/milestone

-

Schließt Meilenstein ab.

-
-

Klausur-Korrektur API (Abitur)

-

Abitur-Klausurkorrektur mit 15-Punkte-System, Erst-/Zweitprüfer-Workflow und KI-gestützter Bewertung.

-

Klausur-Modi

- - - - - - - - - - - - - - - - - -
ModusBeschreibung
landes_abiturNiBiS Niedersachsen - rechtlich geklärte Aufgaben
vorabiturLehrer-erstellte Klausuren mit Rights-Gate
-

POST /klausur-korrektur/klausuren

-

Erstellt neue Abitur-Klausur.

-

POST /klausur-korrektur/students/{id}/evaluate

-

Startet KI-Bewertung.

-

Response (200): -

{
-  "criteria_scores": {
-    "rechtschreibung": {"score": 85, "weight": 0.15},
-    "grammatik": {"score": 90, "weight": 0.15},
-    "inhalt": {"score": 75, "weight": 0.40},
-    "struktur": {"score": 80, "weight": 0.15},
-    "stil": {"score": 85, "weight": 0.15}
-  },
-  "raw_points": 80,
-  "grade_points": 11,
-  "grade_label": "2"
-}
-

-

15-Punkte-Notenschlüssel

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
PunkteProzentNote
15≥95%1+
14≥90%1
13≥85%1-
12≥80%2+
11≥75%2
10≥70%2-
9≥65%3+
8≥60%3
7≥55%3-
6≥50%4+
5≥45%4
4≥40%4-
3≥33%5+
2≥27%5
1≥20%5-
0<20%6
-

Bewertungskriterien

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
KriteriumGewichtBeschreibung
rechtschreibung15%Orthografie
grammatik15%Grammatik & Syntax
inhalt40%Inhaltliche Qualität
struktur15%Aufbau & Gliederung
stil15%Ausdruck & Stil
-
-

Security API (DevSecOps Dashboard)

-

API fuer das Security Dashboard mit DevSecOps-Tools Integration.

-

GET /v1/security/tools

-

Gibt Status aller DevSecOps-Tools zurueck.

-

GET /v1/security/findings

-

Gibt alle Security-Findings zurueck.

-

GET /v1/security/sbom

-

Gibt SBOM (Software Bill of Materials) zurueck.

-

POST /v1/security/scan/{type}

-

Startet einen Security-Scan.

-

Path Parameter: -- type: Scan-Typ (secrets, sast, deps, containers, sbom, all)

-
-

Fehler-Responses

-

400 Bad Request

-
{
-  "detail": "Beschreibung des Fehlers"
-}
-
-

401 Unauthorized

-
{
-  "detail": "Not authenticated"
-}
-
-

404 Not Found

-
{
-  "detail": "Ressource nicht gefunden"
-}
-
-

500 Internal Server Error

-
{
-  "detail": "Interner Serverfehler"
-}
-
- - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/architecture/auth-system/index.html b/docs-site/architecture/auth-system/index.html deleted file mode 100644 index 23c3dfb..0000000 --- a/docs-site/architecture/auth-system/index.html +++ /dev/null @@ -1,2896 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - Auth-System - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - - - - - -
- -
- - - - - -

BreakPilot Authentifizierung & Autorisierung

-

Uebersicht

-

BreakPilot verwendet einen Hybrid-Ansatz fuer Authentifizierung und Autorisierung:

-
┌─────────────────────────────────────────────────────────────────────────┐
-│                        AUTHENTIFIZIERUNG                                 │
-│                     "Wer bist du?"                                       │
-│  ┌────────────────────────────────────────────────────────────────────┐ │
-│  │                    HybridAuthenticator                              │ │
-│  │  ┌─────────────────────┐      ┌─────────────────────────────────┐  │ │
-│  │  │   Keycloak          │      │   Lokales JWT                   │  │ │
-│  │  │   (Produktion)      │  OR  │   (Entwicklung)                 │  │ │
-│  │  │   RS256 + JWKS      │      │   HS256 + Secret                │  │ │
-│  │  └─────────────────────┘      └─────────────────────────────────┘  │ │
-│  └────────────────────────────────────────────────────────────────────┘ │
-└─────────────────────────────────────────────────────────────────────────┘
-                                    │
-                                    ▼
-┌─────────────────────────────────────────────────────────────────────────┐
-│                         AUTORISIERUNG                                    │
-│                      "Was darfst du?"                                    │
-│  ┌────────────────────────────────────────────────────────────────────┐ │
-│  │                    rbac.py (Eigenentwicklung)                       │ │
-│  │  ┌─────────────────┐  ┌─────────────────┐  ┌───────────────────┐   │ │
-│  │  │ Rollen-Hierarchie│  │ PolicySet       │  │ DEFAULT_PERMISSIONS│   │ │
-│  │  │ 15+ Rollen       │  │ Bundesland-     │  │ Matrix            │   │ │
-│  │  │ - Erstkorrektor  │  │ spezifisch      │  │ Rolle→Ressource→  │   │ │
-│  │  │ - Klassenlehrer  │  │ - Niedersachsen │  │ Aktion            │   │ │
-│  │  │ - Schulleitung   │  │ - Bayern        │  │                   │   │ │
-│  │  └─────────────────┘  └─────────────────┘  └───────────────────┘   │ │
-│  └────────────────────────────────────────────────────────────────────┘ │
-└─────────────────────────────────────────────────────────────────────────┘
-
-

Warum dieser Ansatz?

-

Alternative Loesungen (verworfen)

- - - - - - - - - - - - - - - - - - - - - - - - - -
ToolProblem fuer BreakPilot
CasbinZu generisch fuer Bundesland-spezifische Policies
CerbosOverhead: Externer PDP-Service fuer ~15 Rollen ueberdimensioniert
OpenFGAZanzibar-Modell optimiert fuer Graph-Beziehungen, nicht Hierarchien
Keycloak RBACKann keine ressourcen-spezifischen Zuweisungen (User X ist Erstkorrektor fuer Package Y)
-

Vorteile des Hybrid-Ansatzes

-
    -
  1. Keycloak fuer Authentifizierung:
  2. -
  3. Bewährtes IAM-System
  4. -
  5. SSO, Federation, MFA
  6. -
  7. -

    Apache-2.0 Lizenz

    -
  8. -
  9. -

    Eigenes rbac.py fuer Autorisierung:

    -
  10. -
  11. Domaenenspezifische Logik (Korrekturkette, Zeugnis-Workflow)
  12. -
  13. Bundesland-spezifische Regeln
  14. -
  15. Zeitlich begrenzte Zuweisungen
  16. -
  17. Key-Sharing fuer verschluesselte Klausuren
  18. -
-
-

Authentifizierung (auth/keycloak_auth.py)

-

Konfiguration

-
# Entwicklung: Lokales JWT (Standard)
-JWT_SECRET=your-secret-key
-
-# Produktion: Keycloak
-KEYCLOAK_SERVER_URL=https://keycloak.breakpilot.app
-KEYCLOAK_REALM=breakpilot
-KEYCLOAK_CLIENT_ID=breakpilot-backend
-KEYCLOAK_CLIENT_SECRET=your-client-secret
-
-

Token-Erkennung

-

Der HybridAuthenticator erkennt automatisch den Token-Typ:

-
# Keycloak-Token (RS256)
-{
-  "iss": "https://keycloak.breakpilot.app/realms/breakpilot",
-  "sub": "user-uuid",
-  "realm_access": {"roles": ["teacher", "admin"]},
-  ...
-}
-
-# Lokales JWT (HS256)
-{
-  "iss": "breakpilot",
-  "user_id": "user-uuid",
-  "role": "admin",
-  ...
-}
-
-

FastAPI Integration

-
from auth import get_current_user
-
-@app.get("/api/protected")
-async def protected_endpoint(user: dict = Depends(get_current_user)):
-    # user enthält: user_id, email, role, realm_roles, tenant_id
-    return {"user_id": user["user_id"]}
-
-
-

Autorisierung (klausur-service/backend/rbac.py)

-

Rollen (15+)

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
RolleBeschreibungBereich
erstkorrektorErster PrüferKlausur
zweitkorrektorZweiter PrüferKlausur
drittkorrektorDritter PrüferKlausur
klassenlehrerKlassenleitungZeugnis
fachlehrerFachlehrkraftNoten
fachvorsitzFachkonferenz-LeitungFachschaft
schulleitungSchulleiter/inSchule
zeugnisbeauftragterZeugnis-KoordinationZeugnis
sekretariatVerwaltungSchule
data_protection_officerDSBDSGVO
...
-

Ressourcentypen (25+)

-
class ResourceType(str, Enum):
-    EXAM_PACKAGE = "exam_package"         # Klausurpaket
-    STUDENT_SUBMISSION = "student_submission"
-    CORRECTION = "correction"
-    ZEUGNIS = "zeugnis"
-    FACHNOTE = "fachnote"
-    KOPFNOTE = "kopfnote"
-    BEMERKUNG = "bemerkung"
-    ...
-
-

Aktionen (17)

-
class Action(str, Enum):
-    CREATE = "create"
-    READ = "read"
-    UPDATE = "update"
-    DELETE = "delete"
-    SIGN_OFF = "sign_off"        # Freigabe
-    BREAK_GLASS = "break_glass"  # Notfall-Zugriff
-    SHARE_KEY = "share_key"      # Schlüssel teilen
-    ...
-
-

Permission-Pruefung

-
from klausur_service.backend.rbac import PolicyEngine
-
-engine = PolicyEngine()
-
-# Pruefe ob User X Klausur Y korrigieren darf
-allowed = engine.check_permission(
-    user_id="user-uuid",
-    action=Action.UPDATE,
-    resource_type=ResourceType.CORRECTION,
-    resource_id="klausur-uuid"
-)
-
-
-

Bundesland-spezifische Policies

-
@dataclass
-class PolicySet:
-    bundesland: str
-    abitur_type: str  # "landesabitur" | "zentralabitur"
-
-    # Korrekturkette
-    korrektoren_anzahl: int  # 2 oder 3
-    anonyme_erstkorrektur: bool
-
-    # Sichtbarkeit
-    zk_visibility_mode: ZKVisibilityMode  # BLIND | SEMI | FULL
-    eh_visibility_mode: EHVisibilityMode
-
-    # Zeugnis
-    kopfnoten_enabled: bool
-    ...
-
-

Beispiel: Niedersachsen

-
NIEDERSACHSEN_POLICY = PolicySet(
-    bundesland="niedersachsen",
-    abitur_type="landesabitur",
-    korrektoren_anzahl=2,
-    anonyme_erstkorrektur=True,
-    zk_visibility_mode=ZKVisibilityMode.BLIND,
-    eh_visibility_mode=EHVisibilityMode.SUMMARY_ONLY,
-    kopfnoten_enabled=True,
-)
-
-
-

Workflow-Beispiele

-

Klausurkorrektur-Workflow

-
1. Lehrer laedt Klausuren hoch
-   └── Rolle: "lehrer" + Action.CREATE auf EXAM_PACKAGE
-
-2. Erstkorrektor korrigiert
-   └── Rolle: "erstkorrektor" (ressourcen-spezifisch) + Action.UPDATE auf CORRECTION
-
-3. Zweitkorrektor ueberprueft
-   └── Rolle: "zweitkorrektor" + Action.READ auf CORRECTION
-   └── Policy: zk_visibility_mode bestimmt Sichtbarkeit
-
-4. Drittkorrektor (bei Abweichung)
-   └── Rolle: "drittkorrektor" + Action.SIGN_OFF
-
-

Zeugnis-Workflow

-
1. Fachlehrer traegt Noten ein
-   └── Rolle: "fachlehrer" + Action.CREATE auf FACHNOTE
-
-2. Klassenlehrer prueft
-   └── Rolle: "klassenlehrer" + Action.READ auf ZEUGNIS
-   └── Action.SIGN_OFF freigeben
-
-3. Zeugnisbeauftragter final
-   └── Rolle: "zeugnisbeauftragter" + Action.SIGN_OFF
-
-4. Schulleitung unterzeichnet
-   └── Rolle: "schulleitung" + Action.SIGN_OFF
-
-
-

Dateien

- - - - - - - - - - - - - - - - - - - - - - - - - -
DateiBeschreibung
backend/auth/__init__.pyAuth-Modul Exports
backend/auth/keycloak_auth.pyHybrid-Authentifizierung
klausur-service/backend/rbac.pyAutorisierungs-Engine
backend/rbac_api.pyREST API fuer Rollenverwaltung
-
-

Konfiguration

-

Entwicklung (ohne Keycloak)

-
# .env
-ENVIRONMENT=development
-JWT_SECRET=dev-secret-32-chars-minimum-here
-
-

Produktion (mit Keycloak)

-
# .env
-ENVIRONMENT=production
-JWT_SECRET=<openssl rand -hex 32>
-KEYCLOAK_SERVER_URL=https://keycloak.breakpilot.app
-KEYCLOAK_REALM=breakpilot
-KEYCLOAK_CLIENT_ID=breakpilot-backend
-KEYCLOAK_CLIENT_SECRET=<from keycloak admin console>
-
-
-

Sicherheitshinweise

-
    -
  1. Secrets niemals im Code - Immer Umgebungsvariablen verwenden
  2. -
  3. JWT_SECRET in Produktion - Mindestens 32 Bytes, generiert mit openssl rand -hex 32
  4. -
  5. Keycloak HTTPS - KEYCLOAK_VERIFY_SSL=true in Produktion
  6. -
  7. Token-Expiration - Keycloak-Tokens kurz halten (5-15 Minuten)
  8. -
  9. Audit-Trail - Alle Berechtigungspruefungen werden geloggt
  10. -
- - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/architecture/devsecops/index.html b/docs-site/architecture/devsecops/index.html deleted file mode 100644 index 505b100..0000000 --- a/docs-site/architecture/devsecops/index.html +++ /dev/null @@ -1,2699 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - DevSecOps - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - - - - - -
- -
- - - - - -

BreakPilot DevSecOps Architecture

-

Uebersicht

-

BreakPilot implementiert einen umfassenden DevSecOps-Ansatz mit Security-by-Design fuer die Entwicklung und den Betrieb der Bildungsplattform.

-
┌─────────────────────────────────────────────────────────────────────────────┐
-│                        DEVSECOPS PIPELINE                                    │
-│                                                                              │
-│  ┌─────────────┐    ┌─────────────┐    ┌─────────────┐    ┌─────────────┐   │
-│  │  Pre-Commit │───►│  CI/CD      │───►│  Build      │───►│  Deploy     │   │
-│  │  Hooks      │    │  Pipeline   │    │  & Scan     │    │  & Monitor  │   │
-│  └─────────────┘    └─────────────┘    └─────────────┘    └─────────────┘   │
-│        │                  │                  │                  │           │
-│        ▼                  ▼                  ▼                  ▼           │
-│  ┌─────────────┐    ┌─────────────┐    ┌─────────────┐    ┌─────────────┐   │
-│  │ Gitleaks    │    │ Semgrep     │    │ Trivy       │    │ Falco       │   │
-│  │ Bandit      │    │ OWASP DC    │    │ Grype       │    │ (optional)  │   │
-│  │ Secrets     │    │ SAST/SCA    │    │ SBOM        │    │ Runtime     │   │
-│  └─────────────┘    └─────────────┘    └─────────────┘    └─────────────┘   │
-└─────────────────────────────────────────────────────────────────────────────┘
-
-

Security Tools Stack

-

1. Secrets Detection

- - - - - - - - - - - - - - - - - - - - - - - -
ToolVersionLizenzVerwendung
Gitleaks8.18.xMITPre-commit Hook, CI/CD
detect-secrets1.4.xApache-2.0Zusaetzliche Baseline-Pruefung
-

Konfiguration: .gitleaks.toml

-
# Lokal ausfuehren
-gitleaks detect --source . -v
-
-# Pre-commit (automatisch)
-gitleaks protect --staged -v
-
-

2. Static Application Security Testing (SAST)

- - - - - - - - - - - - - - - - - - - - - - - -
ToolVersionLizenzSprachen
Semgrep1.52.xLGPL-2.1Python, Go, JavaScript, TypeScript
Bandit1.7.xApache-2.0Python (spezialisiert)
-

Konfiguration: .semgrep.yml

-
# Semgrep ausfuehren
-semgrep scan --config auto --config .semgrep.yml
-
-# Bandit ausfuehren
-bandit -r backend/ -ll
-
-

3. Software Composition Analysis (SCA)

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ToolVersionLizenzVerwendung
Trivy0.48.xApache-2.0Filesystem, Container, IaC
Grype0.74.xApache-2.0Vulnerability Scanning
OWASP Dependency-Check9.xApache-2.0CVE/NVD Abgleich
-

Konfiguration: .trivy.yaml

-
# Filesystem-Scan
-trivy fs . --severity HIGH,CRITICAL
-
-# Container-Scan
-trivy image breakpilot-pwa-backend:latest
-
-

4. SBOM (Software Bill of Materials)

- - - - - - - - - - - - - - - - - -
ToolVersionLizenzFormate
Syft0.100.xApache-2.0CycloneDX, SPDX
-
# SBOM generieren
-syft dir:. -o cyclonedx-json=sbom.json
-syft dir:. -o spdx-json=sbom-spdx.json
-
-

5. Dynamic Application Security Testing (DAST)

- - - - - - - - - - - - - - - - - -
ToolVersionLizenzVerwendung
OWASP ZAP2.14.xApache-2.0Staging-Scans (nightly)
-
# ZAP Scan gegen Staging
-docker run -t owasp/zap2docker-stable zap-baseline.py \
-    -t http://staging.breakpilot.app -r zap-report.html
-
-

Pre-Commit Hooks

-

Die Pre-Commit-Konfiguration (.pre-commit-config.yaml) fuehrt automatisch bei jedem Commit aus:

-
    -
  1. Schnelle Checks (< 10 Sekunden):
  2. -
  3. Gitleaks (Secrets)
  4. -
  5. Trailing Whitespace
  6. -
  7. -

    YAML/JSON Validierung

    -
  8. -
  9. -

    Code Quality (< 30 Sekunden):

    -
  10. -
  11. Black/Ruff (Python Formatting)
  12. -
  13. Go fmt/vet
  14. -
  15. -

    ESLint (JavaScript)

    -
  16. -
  17. -

    Security Checks (< 60 Sekunden):

    -
  18. -
  19. Bandit (Python Security)
  20. -
  21. Semgrep (Error-Severity)
  22. -
-

Installation

-
# Pre-commit installieren
-pip install pre-commit
-
-# Hooks aktivieren
-pre-commit install
-
-# Alle Checks manuell ausfuehren
-pre-commit run --all-files
-
-

Severity-Gates

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
PhaseSeverityAktion
Pre-CommitERRORCommit blockiert
PR/CICRITICAL, HIGHPipeline blockiert
Nightly ScanMEDIUM+Report generiert
Production DeployCRITICALDeploy blockiert
-

Security Dashboard

-

Das BreakPilot Admin Panel enthaelt ein integriertes Security Dashboard unter Verwaltung > Security.

-

Features

-

Fuer Entwickler: -- Scan-Ergebnisse auf einen Blick -- Pre-commit Hook Status -- Quick-Fix Suggestions -- SBOM Viewer mit Suchfunktion

-

Fuer Security-Experten: -- Vulnerability Severity Distribution (Critical/High/Medium/Low) -- CVE-Tracking mit Fix-Verfuegbarkeit -- Compliance-Status (OWASP Top 10, DSGVO) -- Secrets Detection History

-

Fuer Ops: -- Container Image Scan Results -- Dependency Update Status -- Security Scan Scheduling -- Auto-Refresh alle 30 Sekunden

-

API Endpoints

-
GET  /api/v1/security/tools      - Tool-Status
-GET  /api/v1/security/findings   - Alle Findings
-GET  /api/v1/security/summary    - Severity-Zusammenfassung
-GET  /api/v1/security/sbom       - SBOM-Daten
-GET  /api/v1/security/history    - Scan-Historie
-GET  /api/v1/security/reports/{tool} - Tool-spezifischer Report
-POST /api/v1/security/scan/{type} - Scan starten
-GET  /api/v1/security/health     - Health-Check
-
-

Compliance

-

Die DevSecOps-Pipeline unterstuetzt folgende Compliance-Anforderungen:

-
    -
  • DSGVO/GDPR: Automatische Erkennung von PII-Leaks
  • -
  • OWASP Top 10: SAST/DAST-Scans gegen bekannte Schwachstellen
  • -
  • Supply Chain Security: SBOM-Generierung fuer Audit-Trails
  • -
  • CVE Tracking: Automatischer Abgleich mit NVD/CVE-Datenbanken
  • -
-

Tool-Installation

-

macOS (Homebrew)

-
# Security Tools
-brew install gitleaks
-brew install trivy
-brew install syft
-brew install grype
-
-# Python Tools
-pip install semgrep bandit pre-commit
-
-

Linux (apt/snap)

-
# Gitleaks
-sudo snap install gitleaks
-
-# Trivy
-sudo apt-get install trivy
-
-# Python Tools
-pip install semgrep bandit pre-commit
-
- - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/architecture/environments/index.html b/docs-site/architecture/environments/index.html deleted file mode 100644 index a92a6b0..0000000 --- a/docs-site/architecture/environments/index.html +++ /dev/null @@ -1,2744 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - Environments - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - - - - - -
- -
- - - - - -

Umgebungs-Architektur

-

Übersicht

-

BreakPilot verwendet eine 3-Umgebungs-Strategie für sichere Entwicklung und Deployment:

-
┌─────────────────┐     ┌─────────────────┐     ┌─────────────────┐
-│   Development   │────▶│     Staging     │────▶│   Production    │
-│   (develop)     │     │    (staging)    │     │     (main)      │
-└─────────────────┘     └─────────────────┘     └─────────────────┘
-     Tägliche            Getesteter Code         Produktionsreif
-     Entwicklung
-
-

Umgebungen

-

Development (Dev)

-

Zweck: Tägliche Entwicklungsarbeit

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
EigenschaftWert
Git Branchdevelop
Compose Filedocker-compose.yml + docker-compose.override.yml (auto)
Env File.env.dev
Databasebreakpilot_dev
DebugAktiviert
Hot-ReloadAktiviert
-

Start: -

./scripts/start.sh dev
-# oder einfach:
-docker compose up -d
-

-

Staging

-

Zweck: Getesteter, freigegebener Code vor Produktion

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
EigenschaftWert
Git Branchstaging
Compose Filedocker-compose.yml + docker-compose.staging.yml
Env File.env.staging
Databasebreakpilot_staging (separates Volume)
DebugDeaktiviert
Hot-ReloadDeaktiviert
-

Start: -

./scripts/start.sh staging
-# oder:
-docker compose -f docker-compose.yml -f docker-compose.staging.yml up -d
-

-

Production (Prod)

-

Zweck: Live-System für Endbenutzer (ab Launch)

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
EigenschaftWert
Git Branchmain
Compose Filedocker-compose.yml + docker-compose.prod.yml
Env File.env.prod (NICHT im Repository!)
Databasebreakpilot_prod (separates Volume)
DebugDeaktiviert
VaultPflicht (keine Env-Fallbacks)
-

Datenbank-Trennung

-

Jede Umgebung verwendet separate Docker Volumes für vollständige Datenisolierung:

-
┌─────────────────────────────────────────────────────────────┐
-│                    PostgreSQL Volumes                        │
-├─────────────────────────────────────────────────────────────┤
-│  breakpilot-dev_postgres_data      │ Development Database   │
-│  breakpilot_staging_postgres       │ Staging Database       │
-│  breakpilot_prod_postgres          │ Production Database    │
-└─────────────────────────────────────────────────────────────┘
-
-

Port-Mapping

-

Um mehrere Umgebungen gleichzeitig laufen zu lassen, verwenden sie unterschiedliche Ports:

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ServiceDev PortStaging PortProd Port
Backend800080018000
PostgreSQL54325433- (intern)
MinIO9000/90019002/9003- (intern)
Qdrant6333/63346335/6336- (intern)
Mailpit8025/10258026/1026- (deaktiviert)
-

Git Branching Strategie

-
main (Prod)     ← Nur Release-Merges, geschützt
-    │
-    ▼
-staging         ← Getesteter Code, Review erforderlich
-    │
-    ▼
-develop (Dev)   ← Tägliche Arbeit, Default-Branch
-    │
-    ▼
-feature/*       ← Feature-Branches (optional)
-
-

Workflow

-
    -
  1. Entwicklung: Arbeite auf develop
  2. -
  3. Code-Review: Erstelle PR von Feature-Branch → develop
  4. -
  5. Staging: Promote developstaging mit Tests
  6. -
  7. Release: Promote stagingmain nach Freigabe
  8. -
-

Promotion-Befehle

-
# develop → staging
-./scripts/promote.sh dev-to-staging
-
-# staging → main (Production)
-./scripts/promote.sh staging-to-prod
-
-

Secrets Management

-

Development

-
    -
  • .env.dev enthält Entwicklungs-Credentials
  • -
  • Vault optional (Dev-Token)
  • -
  • Mailpit für E-Mail-Tests
  • -
-

Staging

-
    -
  • .env.staging enthält Test-Credentials
  • -
  • Vault empfohlen
  • -
  • Mailpit für E-Mail-Sicherheit
  • -
-

Production

-
    -
  • .env.prod NICHT im Repository
  • -
  • Vault PFLICHT
  • -
  • Echte SMTP-Konfiguration
  • -
-

Siehe auch: Secrets Management

-

Docker Compose Architektur

-
docker-compose.yml              ← Basis-Konfiguration
-        │
-        ├── docker-compose.override.yml  ← Dev (auto-geladen)
-        │
-        ├── docker-compose.staging.yml   ← Staging (explizit)
-        │
-        └── docker-compose.prod.yml      ← Production (explizit)
-
-

Automatisches Laden

-

Docker Compose lädt automatisch: -1. docker-compose.yml -2. docker-compose.override.yml (falls vorhanden)

-

Daher startet docker compose up automatisch die Dev-Umgebung.

-

Helper Scripts

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ScriptBeschreibung
scripts/env-switch.shWechselt zwischen Umgebungen
scripts/start.shStartet Services für Umgebung
scripts/stop.shStoppt Services
scripts/promote.shPromotet Code zwischen Branches
scripts/status.shZeigt aktuellen Status
-

Verifikation

-

Nach Setup prüfen:

-
# Status anzeigen
-./scripts/status.sh
-
-# Branches prüfen
-git branch -v
-
-# Volumes prüfen
-docker volume ls | grep breakpilot
-
-

Verwandte Dokumentation

- - - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/architecture/mail-rbac-architecture/index.html b/docs-site/architecture/mail-rbac-architecture/index.html deleted file mode 100644 index dc3d50f..0000000 --- a/docs-site/architecture/mail-rbac-architecture/index.html +++ /dev/null @@ -1,2628 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - Mail-RBAC - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - - - - - -
- -
- - - - - -

Mail-RBAC Architektur mit Mitarbeiter-Anonymisierung

-

Version: 1.0.0 -Status: Architekturplanung

-
-

Executive Summary

-

Dieses Dokument beschreibt eine neuartige Architektur, die E-Mail, Kalender und Videokonferenzen mit rollenbasierter Zugriffskontrolle (RBAC) verbindet. Das Kernkonzept ermöglicht die vollständige Anonymisierung von Mitarbeiterdaten bei Verlassen des Unternehmens, während geschäftliche Kommunikationshistorie erhalten bleibt.

-
-

1. Das Problem

-

Traditionelle E-Mail-Systeme

-
max.mustermann@firma.de → Person gebunden
-                        → DSGVO: Daten müssen gelöscht werden
-                        → Geschäftshistorie geht verloren
-
-

BreakPilot-Lösung: Rollenbasierte E-Mail

-
klassenlehrer.5a@schule.breakpilot.app → Rolle gebunden
-                                       → Person kann anonymisiert werden
-                                       → Kommunikationshistorie bleibt erhalten
-
-
-

2. Architektur-Übersicht

-
┌─────────────────────────────────────────────────────────────────┐
-│                     BreakPilot Groupware                        │
-├─────────────────────────────────────────────────────────────────┤
-│                                                                 │
-│  ┌─────────────┐  ┌─────────────┐  ┌─────────────┐             │
-│  │   Webmail   │  │  Kalender   │  │   Jitsi     │             │
-│  │   (SOGo)    │  │   (SOGo)    │  │  Meeting    │             │
-│  └──────┬──────┘  └──────┬──────┘  └──────┬──────┘             │
-│         │                │                │                     │
-│         └────────────────┼────────────────┘                     │
-│                          │                                      │
-│              ┌───────────┴───────────┐                         │
-│              │   RBAC-Mail-Bridge    │ ◄─── Neue Komponente    │
-│              │   (Python/Go)         │                         │
-│              └───────────┬───────────┘                         │
-│                          │                                      │
-│    ┌─────────────────────┼─────────────────────┐               │
-│    │                     │                     │                │
-│    ▼                     ▼                     ▼                │
-│ ┌──────────┐     ┌──────────────┐     ┌────────────┐           │
-│ │PostgreSQL│     │ Mail Server  │     │  MinIO     │           │
-│ │(RBAC DB) │     │ (Stalwart)   │     │ (Backups)  │           │
-│ └──────────┘     └──────────────┘     └────────────┘           │
-│                                                                 │
-└─────────────────────────────────────────────────────────────────┘
-
-
-

3. Komponenten-Auswahl

-

3.1 E-Mail Server: Stalwart Mail Server

-

Empfehlung: Stalwart Mail Server

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
KriteriumBewertung
LizenzAGPL-3.0 (Open Source)
SpracheRust (performant, sicher)
FeaturesIMAP, SMTP, JMAP, WebSocket
KalenderCalDAV integriert
KontakteCardDAV integriert
Spam/VirusIntegriert
APIREST API für Administration
-

3.2 Webmail-Client: SOGo oder Roundcube

-

Option A: SOGo (empfohlen) -- Lizenz: GPL-2.0 / LGPL-2.1 -- Kalender, Kontakte, Mail in einem -- ActiveSync Support -- Outlook-ähnliche Oberfläche

-

Option B: Roundcube -- Lizenz: GPL-3.0 -- Nur Webmail -- Benötigt separaten Kalender

-
-

4. Anonymisierungs-Workflow

-
Mitarbeiter kündigt
-        │
-        ▼
-┌───────────────────────────┐
-│ 1. Functional Mailboxes   │
-│    → Neu zuweisen oder    │
-│    → Deaktivieren         │
-└───────────┬───────────────┘
-            │
-            ▼
-┌───────────────────────────┐
-│ 2. Personal Email Account │
-│    → Anonymisieren:       │
-│    max.mustermann@...     │
-│    → mitarbeiter_a7x2@... │
-└───────────────────────────┘
-            │
-            ▼
-┌───────────────────────────┐
-│ 3. Users-Tabelle          │
-│    → Pseudonymisieren:    │
-│    name: "Max Mustermann" │
-│    → "Ehem. Mitarbeiter"  │
-└───────────────────────────┘
-            │
-            ▼
-┌───────────────────────────┐
-│ 4. Mailbox Assignments    │
-│    → Bleiben für Audit    │
-│    → User-Referenz zeigt  │
-│      auf anonymisierte    │
-│      Daten                │
-└───────────────────────────┘
-            │
-            ▼
-┌───────────────────────────┐
-│ 5. E-Mail-Archiv          │
-│    → Header anonymisieren │
-│    → Inhalte optional     │
-│      löschen              │
-└───────────────────────────┘
-
-
-

5. Unified Inbox Implementation

-

Implementierte Komponenten

-

Die Unified Inbox wurde als Teil des klausur-service implementiert:

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
KomponentePfadBeschreibung
Modelsklausur-service/backend/mail/models.pyPydantic Models für Accounts, E-Mails, Tasks
Databaseklausur-service/backend/mail/mail_db.pyPostgreSQL-Operationen mit asyncpg
Credentialsklausur-service/backend/mail/credentials.pyVault-Integration für IMAP/SMTP-Passwörter
Aggregatorklausur-service/backend/mail/aggregator.pyMulti-Account IMAP Sync
AI Serviceklausur-service/backend/mail/ai_service.pyKI-Analyse (Absender, Fristen, Kategorien)
Task Serviceklausur-service/backend/mail/task_service.pyArbeitsvorrat-Management
APIklausur-service/backend/mail/api.pyFastAPI Router mit 30+ Endpoints
-

API-Endpoints (Port 8086)

-
# Account Management
-POST   /api/v1/mail/accounts              - Neues Konto hinzufügen
-GET    /api/v1/mail/accounts              - Alle Konten auflisten
-DELETE /api/v1/mail/accounts/{id}         - Konto entfernen
-POST   /api/v1/mail/accounts/{id}/test    - Verbindung testen
-
-# Unified Inbox
-GET    /api/v1/mail/inbox                 - Aggregierte Inbox
-GET    /api/v1/mail/inbox/{id}            - Einzelne E-Mail
-POST   /api/v1/mail/send                  - E-Mail senden
-
-# KI-Features
-POST   /api/v1/mail/analyze/{id}          - E-Mail analysieren
-GET    /api/v1/mail/suggestions/{id}      - Antwortvorschläge
-
-# Arbeitsvorrat
-GET    /api/v1/mail/tasks                 - Alle Tasks
-POST   /api/v1/mail/tasks                 - Manuelle Task erstellen
-PATCH  /api/v1/mail/tasks/{id}            - Task aktualisieren
-GET    /api/v1/mail/tasks/dashboard       - Dashboard-Statistiken
-
-

Niedersachsen-spezifische Absendererkennung

-
KNOWN_AUTHORITIES_NI = {
-    "@mk.niedersachsen.de": "Kultusministerium Niedersachsen",
-    "@rlsb.de": "Regionales Landesamt für Schule und Bildung",
-    "@landesschulbehoerde-nds.de": "Landesschulbehörde",
-    "@nibis.de": "NiBiS",
-}
-
-
-

6. Lizenz-Übersicht

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
KomponenteLizenzKommerzielle NutzungVeröffentlichungspflicht
Stalwart MailAGPL-3.0JaNur bei Code-Änderungen
SOGoGPL-2.0/LGPLJaNur bei Code-Änderungen
RoundcubeGPL-3.0JaNur bei Code-Änderungen
RBAC-Mail-BridgeEigeneN/AKann proprietär bleiben
BreakPilot BackendEigeneN/AProprietär
-
-

7. Referenzen

- - - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/architecture/multi-agent/index.html b/docs-site/architecture/multi-agent/index.html deleted file mode 100644 index 6340ae2..0000000 --- a/docs-site/architecture/multi-agent/index.html +++ /dev/null @@ -1,3078 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - Multi-Agent - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - -
- -
- - - -
- -
- - - - - -

Multi-Agent Architektur - Entwicklerdokumentation

-

Status: Implementiert -Modul: /agent-core/

-
-

1. Übersicht

-

Die Multi-Agent-Architektur erweitert Breakpilot um ein verteiltes Agent-System basierend auf Mission Control Konzepten.

-

Kernkomponenten

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
KomponentePfadBeschreibung
Session Management/agent-core/sessions/Lifecycle & Recovery
Shared Brain/agent-core/brain/Langzeit-Gedächtnis
Orchestrator/agent-core/orchestrator/Koordination
SOUL Files/agent-core/soul/Agent-Persönlichkeiten
-
-

2. Agent-Typen

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
AgentAufgabeSOUL-Datei
TutorAgentLernbegleitung, Fragen beantwortentutor-agent.soul.md
GraderAgentKlausur-Korrektur, Bewertunggrader-agent.soul.md
QualityJudgeBQAS Qualitätsprüfungquality-judge.soul.md
AlertAgentMonitoring, Benachrichtigungenalert-agent.soul.md
OrchestratorTask-Koordinationorchestrator.soul.md
-
-

3. Wichtige Dateien

-

Session Management

-
agent-core/sessions/
-├── session_manager.py   # AgentSession, SessionManager, SessionState
-├── heartbeat.py         # HeartbeatMonitor, HeartbeatClient
-└── checkpoint.py        # CheckpointManager
-
-

Shared Brain

-
agent-core/brain/
-├── memory_store.py      # MemoryStore, Memory (mit TTL)
-├── context_manager.py   # ConversationContext, ContextManager
-└── knowledge_graph.py   # KnowledgeGraph, Entity, Relationship
-
-

Orchestrator

-
agent-core/orchestrator/
-├── message_bus.py       # MessageBus, AgentMessage, MessagePriority
-├── supervisor.py        # AgentSupervisor, AgentInfo, AgentStatus
-└── task_router.py       # TaskRouter, RoutingRule, RoutingResult
-
-
-

4. Datenbank-Schema

-

Die Migration befindet sich in: -/backend/migrations/add_agent_core_tables.sql

-

Tabellen

-
    -
  1. agent_sessions - Session-Daten mit Checkpoints
  2. -
  3. agent_memory - Langzeit-Gedächtnis mit TTL
  4. -
  5. agent_messages - Audit-Trail für Inter-Agent Kommunikation
  6. -
-

Helper-Funktionen

-
-- Abgelaufene Memories bereinigen
-SELECT cleanup_expired_agent_memory();
-
--- Inaktive Sessions bereinigen
-SELECT cleanup_stale_agent_sessions(48); -- 48 Stunden
-
-
-

5. Integration Voice-Service

-

Der EnhancedTaskOrchestrator erweitert den bestehenden TaskOrchestrator:

-
# voice-service/services/enhanced_task_orchestrator.py
-
-from agent_core.sessions import SessionManager
-from agent_core.orchestrator import MessageBus
-
-class EnhancedTaskOrchestrator(TaskOrchestrator):
-    # Nutzt Session-Checkpoints für Recovery
-    # Routet komplexe Tasks an spezialisierte Agents
-    # Führt Quality-Checks via BQAS durch
-
-

Wichtig: Der Enhanced Orchestrator ist abwärtskompatibel und kann parallel zum Original verwendet werden.

-
-

6. Integration BQAS

-

Der QualityJudgeAgent integriert BQAS mit dem Multi-Agent-System:

-
# voice-service/bqas/quality_judge_agent.py
-
-from bqas.judge import LLMJudge
-from agent_core.orchestrator import MessageBus
-
-class QualityJudgeAgent:
-    # Wertet Responses in Echtzeit aus
-    # Nutzt Memory für konsistente Bewertungen
-    # Empfängt Evaluierungs-Requests via Message Bus
-
-
-

7. Code-Beispiele

-

Session erstellen

-
from agent_core.sessions import SessionManager
-
-manager = SessionManager(redis_client=redis, db_pool=pool)
-session = await manager.create_session(
-    agent_type="tutor-agent",
-    user_id="user-123"
-)
-
-

Memory speichern

-
from agent_core.brain import MemoryStore
-
-store = MemoryStore(redis_client=redis, db_pool=pool)
-await store.remember(
-    key="student:123:progress",
-    value={"level": 5, "score": 85},
-    agent_id="tutor-agent",
-    ttl_days=30
-)
-
-

Nachricht senden

-
from agent_core.orchestrator import MessageBus, AgentMessage
-
-bus = MessageBus(redis_client=redis)
-await bus.publish(AgentMessage(
-    sender="orchestrator",
-    receiver="grader-agent",
-    message_type="grade_request",
-    payload={"exam_id": "exam-1"}
-))
-
-
-

8. Tests ausführen

-
# Alle Agent-Core Tests
-cd agent-core && pytest -v
-
-# Mit Coverage-Report
-pytest --cov=. --cov-report=html
-
-# Einzelne Module
-pytest tests/test_session_manager.py -v
-pytest tests/test_message_bus.py -v
-
-
-

9. Deployment-Schritte

-

1. Migration ausführen

-
psql -h localhost -U breakpilot -d breakpilot \
-  -f backend/migrations/add_agent_core_tables.sql
-
-

2. Voice-Service aktualisieren

-
# Sync zu Server
-rsync -avz --exclude 'node_modules' --exclude '.git' \
-  /path/to/breakpilot-pwa/ server:/path/to/breakpilot-pwa/
-
-# Container neu bauen
-docker compose build --no-cache voice-service
-
-# Starten
-docker compose up -d voice-service
-
-

3. Verifizieren

-
# Session-Tabelle prüfen
-psql -c "SELECT COUNT(*) FROM agent_sessions;"
-
-# Memory-Tabelle prüfen
-psql -c "SELECT COUNT(*) FROM agent_memory;"
-
-
-

10. Monitoring

-

Metriken

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
MetrikBeschreibung
agent_session_countAnzahl aktiver Sessions
agent_heartbeat_delay_msZeit seit letztem Heartbeat
agent_message_latency_msNachrichtenlatenz
agent_memory_countGespeicherte Memories
agent_routing_success_rateErfolgreiche Routings
-

Health-Check-Endpunkte

-
GET /api/v1/agents/health       # Supervisor Status
-GET /api/v1/agents/sessions     # Aktive Sessions
-GET /api/v1/agents/memory/stats # Memory-Statistiken
-
-
-

11. Troubleshooting

-

Problem: Session nicht gefunden

-
    -
  1. Prüfen ob Valkey läuft: redis-cli ping
  2. -
  3. Session-Timeout prüfen (default 24h)
  4. -
  5. Heartbeat-Status checken
  6. -
-

Problem: Message Bus Timeout

-
    -
  1. Redis Pub/Sub Status prüfen
  2. -
  3. Ziel-Agent registriert?
  4. -
  5. Timeout erhöhen (default 30s)
  6. -
-

Problem: Memory nicht gefunden

-
    -
  1. Namespace korrekt?
  2. -
  3. TTL abgelaufen?
  4. -
  5. Cleanup-Job gelaufen?
  6. -
-
-

12. Erweiterungen

-

Neuen Agent hinzufügen

-
    -
  1. SOUL-Datei erstellen in /agent-core/soul/
  2. -
  3. Routing-Regel in task_router.py hinzufügen
  4. -
  5. Handler beim Supervisor registrieren
  6. -
  7. Tests schreiben
  8. -
-

Neuen Memory-Typ hinzufügen

-
    -
  1. Key-Schema definieren (z.B. student:*:progress)
  2. -
  3. TTL festlegen
  4. -
  5. Access-Pattern dokumentieren
  6. -
-
-

13. Referenzen

-
    -
  • Agent-Core README: /agent-core/README.md
  • -
  • Migration: /backend/migrations/add_agent_core_tables.sql
  • -
  • Voice-Service Integration: /voice-service/services/enhanced_task_orchestrator.py
  • -
  • BQAS Integration: /voice-service/bqas/quality_judge_agent.py
  • -
  • Tests: /agent-core/tests/
  • -
- - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/architecture/sdk-protection/index.html b/docs-site/architecture/sdk-protection/index.html deleted file mode 100644 index 65c9977..0000000 --- a/docs-site/architecture/sdk-protection/index.html +++ /dev/null @@ -1,3087 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - SDK Protection - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - - - - - -
- -
- - - - - -

SDK Protection Middleware

-

1. Worum geht es?

-

Die SDK Protection Middleware schuetzt die Compliance-SDK-Endpunkte vor einer bestimmten Art von Angriff: der systematischen Enumeration. Was bedeutet das?

-
-

Ein Wettbewerber registriert sich als zahlender Kunde und laesst ein Skript langsam und verteilt alle TOM-Controls, alle Pruefaspekte und alle Assessment-Kriterien abfragen. Aus den Ergebnissen rekonstruiert er die gesamte Compliance-Framework-Logik.

-
-

Der klassische Rate Limiter (100 Requests/Minute) hilft hier nicht, weil ein cleverer Angreifer langsam vorgeht -- vielleicht nur 20 Anfragen pro Minute, dafuer systematisch und ueber Stunden. Die SDK Protection erkennt solche Muster und reagiert darauf.

-
-

Kern-Designprinzip

-

Normale Nutzer merken nichts. Ein Lehrer, der im TOM-Modul arbeitet, greift typischerweise auf 3-5 Kategorien zu und wiederholt Anfragen an gleiche Endpunkte. Ein Angreifer durchlaeuft dagegen 40+ Kategorien in alphabetischer Reihenfolge. Genau diesen Unterschied erkennt die Middleware.

-
-
-

2. Wie funktioniert der Schutz?

-

Die Middleware nutzt ein Anomaly-Score-System. Jeder Benutzer hat einen Score, der bei 0 beginnt. Verschiedene verdaechtige Verhaltensweisen erhoehen den Score. Ueber die Zeit sinkt er wieder ab. Je hoeher der Score, desto staerker wird der Benutzer gebremst.

-

Man kann es sich wie eine Ampel vorstellen:

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ScoreAmpelWirkungBeispiel
0-29GruenKeine EinschraenkungNormaler Nutzer
30-59Gelb1-3 Sekunden VerzoegerungLeicht auffaelliges Muster
60-84Orange5-10 Sekunden Verzoegerung, reduzierte DetailsDeutlich verdaechtiges Verhalten
85+RotZugriff blockiert (HTTP 429)Sehr wahrscheinlich automatisierter Angriff
-

Score-Zerfall

-

Der Score sinkt automatisch: Alle 5 Minuten wird er mit dem Faktor 0,95 multipliziert. Ein Score von 60 faellt also innerhalb einer Stunde auf etwa 30 -- wenn kein neues verdaechtiges Verhalten hinzukommt.

-
-

3. Was wird erkannt?

-

Die Middleware erkennt fuenf verschiedene Anomalie-Muster:

-

3.1 Hohe Kategorie-Diversitaet

-

Was: Ein Benutzer greift innerhalb einer Stunde auf mehr als 40 verschiedene SDK-Kategorien zu.

-

Warum verdaechtig: Ein normaler Nutzer arbeitet in der Regel mit 3-10 Kategorien. Wer systematisch alle durchlaeuft, sammelt vermutlich Daten.

-

Score-Erhoehung: +15

-
Normal:   tom/access-control → tom/access-control → tom/encryption → tom/encryption
-                               (3 verschiedene Kategorien in einer Stunde)
-
-Verdaechtig: tom/access-control → tom/encryption → tom/pseudonymization → tom/integrity
-             → tom/availability → tom/resilience → dsfa/threshold → dsfa/necessity → ...
-                               (40+ verschiedene Kategorien in einer Stunde)
-
-

3.2 Burst-Erkennung

-

Was: Ein Benutzer sendet mehr als 15 Anfragen an die gleiche Kategorie innerhalb von 2 Minuten.

-

Warum verdaechtig: Selbst ein eifriger Nutzer klickt nicht 15-mal pro Minute auf denselben Endpunkt. Das deutet auf automatisiertes Scraping hin.

-

Score-Erhoehung: +20

-

3.3 Sequentielle Enumeration

-

Was: Die letzten 10 aufgerufenen Kategorien sind zu mindestens 70% in alphabetischer oder numerischer Reihenfolge.

-

Warum verdaechtig: Menschen springen zwischen Kategorien -- sie arbeiten thematisch, nicht alphabetisch. Ein Skript dagegen iteriert oft ueber eine sortierte Liste.

-

Score-Erhoehung: +25

-
Verdaechtig: assessment_general → compliance_general → controls_general
-             → dsfa_measures → dsfa_necessity → dsfa_residual → dsfa_risks
-             → dsfa_threshold → eh_general → namespace_general
-             (alphabetisch sortiert = Skript-Verhalten)
-
-

3.4 Ungewoehnliche Uhrzeiten

-

Was: Anfragen zwischen 0:00 und 5:00 Uhr UTC.

-

Warum verdaechtig: Lehrer arbeiten tagsüber. Wer um 3 Uhr morgens SDK-Endpunkte abfragt, ist wahrscheinlich ein automatisierter Prozess.

-

Score-Erhoehung: +10

-

3.5 Multi-Tenant-Zugriff

-

Was: Ein Benutzer greift innerhalb einer Stunde auf mehr als 3 verschiedene Mandanten (Tenants) zu.

-

Warum verdaechtig: Ein normaler Nutzer gehoert zu einem Mandanten. Wer mehrere durchprobiert, koennte versuchen, mandantenuebergreifend Daten zu sammeln.

-

Score-Erhoehung: +15

-
-

4. Quota-System (Mengenbegrenzung)

-

Zusaetzlich zum Anomaly-Score gibt es klassische Mengenbegrenzungen in vier Zeitfenstern:

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Tierpro Minutepro Stundepro Tagpro Monat
Free305003.00050.000
Standard601.50010.000200.000
Enterprise1205.00050.0001.000.000
-

Wenn ein Limit in irgendeinem Zeitfenster ueberschritten wird, erhaelt der Nutzer sofort HTTP 429 -- unabhaengig vom Anomaly-Score.

-
-

5. Architektur

-

Datenfluss eines SDK-Requests

-
Request kommt an
-     │
-     ▼
-┌─────────────────────────────────────────────────────────────┐
-│  Ist der Pfad geschuetzt?                                    │
-│  (/api/sdk/*, /api/v1/tom/*, /api/v1/dsfa/*, ...)           │
-│  Nein → direkt weiterleiten                                  │
-└──────────────┬──────────────────────────────────────────────┘
-               │ Ja
-               ▼
-┌─────────────────────────────────────────────────────────────┐
-│  User + Tier + Kategorie extrahieren                         │
-│  (aus Session, API-Key oder X-SDK-Tier Header)               │
-└──────────────┬──────────────────────────────────────────────┘
-               │
-               ▼
-┌─────────────────────────────────────────────────────────────┐
-│  Multi-Window Quota pruefen                                  │
-│  (Minute / Stunde / Tag / Monat)                             │
-│  Ueberschritten → HTTP 429 zurueck                          │
-└──────────────┬──────────────────────────────────────────────┘
-               │ OK
-               ▼
-┌─────────────────────────────────────────────────────────────┐
-│  Anomaly-Score laden (aus Valkey)                            │
-│  Zeitbasierten Zerfall anwenden (×0,95 alle 5 min)           │
-└──────────────┬──────────────────────────────────────────────┘
-               │
-               ▼
-┌─────────────────────────────────────────────────────────────┐
-│  Anomalie-Detektoren ausfuehren:                             │
-│  ├── Diversity-Tracking     (+15 wenn >40 Kategorien/h)      │
-│  ├── Burst-Detection        (+20 wenn >15 gleiche/2min)      │
-│  ├── Sequential-Enumeration (+25 wenn sortiert)              │
-│  ├── Unusual-Hours          (+10 wenn 0-5 Uhr UTC)           │
-│  └── Multi-Tenant           (+15 wenn >3 Tenants/h)          │
-└──────────────┬──────────────────────────────────────────────┘
-               │
-               ▼
-┌─────────────────────────────────────────────────────────────┐
-│  Throttle-Level bestimmen                                    │
-│  Level 3 (Score ≥85) → HTTP 429                              │
-│  Level 2 (Score ≥60) → 5-10s Delay + reduzierte Details      │
-│  Level 1 (Score ≥30) → 1-3s Delay                            │
-│  Level 0             → keine Einschraenkung                  │
-└──────────────┬──────────────────────────────────────────────┘
-               │
-               ▼
-┌─────────────────────────────────────────────────────────────┐
-│  Request weiterleiten                                        │
-│  Response-Headers setzen:                                    │
-│  ├── X-SDK-Quota-Remaining-Minute/Hour                       │
-│  ├── X-SDK-Throttle-Level                                    │
-│  ├── X-SDK-Detail-Reduced (bei Level ≥2)                     │
-│  └── X-BP-Trace (HMAC-Watermark)                             │
-└─────────────────────────────────────────────────────────────┘
-
-

Valkey-Datenstrukturen

-

Die Middleware speichert alle Tracking-Daten in Valkey (Redis-Fork). Wenn Valkey nicht erreichbar ist, wird automatisch auf eine In-Memory-Implementierung zurueckgefallen.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ZweckValkey-TypKey-MusterTTL
Quota pro ZeitfensterSorted Setsdk_protect:quota:{user}:{window}Fenster + 10s
Kategorie-DiversitaetSetsdk_protect:diversity:{user}:{stunde}3660s
Burst-TrackingSorted Setsdk_protect:burst:{user}:{kategorie}130s
Sequenz-TrackingListsdk_protect:seq:{user}310s
Anomaly-ScoreHashsdk_protect:score:{user}86400s
Tenant-TrackingSetsdk_protect:tenants:{user}:{stunde}3660s
-

Watermarking

-

Jede Antwort enthaelt einen X-BP-Trace Header mit einem HMAC-basierten Fingerabdruck. Damit kann nachtraeglich nachgewiesen werden, welcher Benutzer wann welche Daten abgerufen hat -- ohne dass der Benutzer den Trace veraendern kann.

-
-

6. Geschuetzte Endpunkte

-

Die Middleware schuetzt alle Pfade, die SDK- und Compliance-relevante Daten liefern:

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Pfad-PrefixBereich
/api/sdk/*SDK-Hauptendpunkte
/api/compliance/*Compliance-Bewertungen
/api/v1/tom/*Technisch-organisatorische Massnahmen
/api/v1/dsfa/*Datenschutz-Folgenabschaetzung
/api/v1/vvt/*Verarbeitungsverzeichnis
/api/v1/controls/*Controls und Massnahmen
/api/v1/assessment/*Assessment-Bewertungen
/api/v1/eh/*Erwartungshorizonte
/api/v1/namespace/*Namespace-Verwaltung
-

Nicht geschuetzt sind /health, /metrics und /api/health.

-
-

7. Admin-Verwaltung

-

Ueber das Admin-Dashboard koennen Anomaly-Scores eingesehen und verwaltet werden:

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
EndpointMethodeBeschreibung
/api/admin/middleware/sdk-protection/scoresGETAktuelle Anomaly-Scores aller Benutzer
/api/admin/middleware/sdk-protection/statsGETStatistik: Benutzer pro Throttle-Level
/api/admin/middleware/sdk-protection/reset-score/{user_id}POSTScore eines Benutzers zuruecksetzen
/api/admin/middleware/sdk-protection/tiersGETTier-Konfigurationen anzeigen
/api/admin/middleware/sdk-protection/tiers/{name}PUTTier-Limits aendern
-
-

8. Dateien und Quellcode

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
DateiBeschreibung
backend/middleware/sdk_protection.pyKern-Middleware (~460 Zeilen)
backend/middleware/__init__.pyExport der Middleware-Klassen
backend/main.pyRegistrierung im FastAPI-Stack
backend/middleware_admin_api.pyAdmin-API-Endpoints
backend/migrations/add_sdk_protection_tables.sqlDatenbank-Migration
backend/tests/test_middleware.py14 Tests fuer alle Erkennungsmechanismen
-
-

9. Datenbank-Tabellen

-

sdk_anomaly_scores

-

Speichert Snapshots der Anomaly-Scores fuer Audit und Analyse.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
SpalteTypBeschreibung
idUUIDPrimaerschluessel
user_idVARCHAR(255)Benutzer-Identifikation
scoreDECIMAL(5,2)Aktueller Anomaly-Score
throttle_levelSMALLINTAktueller Throttle-Level (0-3)
triggered_rulesJSONBWelche Regeln ausgeloest wurden
endpoint_diversity_countINTAnzahl verschiedener Kategorien
request_count_1hINTAnfragen in der letzten Stunde
snapshot_atTIMESTAMPTZZeitpunkt des Snapshots
-

sdk_protection_tiers

-

Konfigurierbare Quota-Tiers, editierbar ueber die Admin-API.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
SpalteTypBeschreibung
tier_nameVARCHAR(50)Name des Tiers (free, standard, enterprise)
quota_per_minuteINTMaximale Anfragen pro Minute
quota_per_hourINTMaximale Anfragen pro Stunde
quota_per_dayINTMaximale Anfragen pro Tag
quota_per_monthINTMaximale Anfragen pro Monat
diversity_thresholdINTMax verschiedene Kategorien pro Stunde
burst_thresholdINTMax gleiche Kategorie in 2 Minuten
-
-

10. Konfiguration

-

Die Middleware wird in main.py registriert:

-
from middleware import SDKProtectionMiddleware
-
-app.add_middleware(SDKProtectionMiddleware)
-
-

Alle Parameter koennen ueber die SDKProtectionConfig Dataclass angepasst werden. Die wichtigsten Umgebungsvariablen:

- - - - - - - - - - - - - - - - - - - - -
VariableDefaultBeschreibung
VALKEY_URLredis://localhost:6379Verbindung zur Valkey-Instanz
SDK_WATERMARK_SECRET(generiert)HMAC-Secret fuer Watermarks
-
-

11. Tests

-

Die Middleware wird durch 14 automatisierte Tests abgedeckt:

-
# Alle SDK Protection Tests ausfuehren
-docker compose run --rm --no-deps backend \
-  python -m pytest tests/test_middleware.py -v -k sdk
-
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
TestPrueft
test_allows_normal_requestNormaler Request wird durchgelassen
test_blocks_after_quota_exceeded429 bei Quota-Ueberschreitung
test_diversity_tracking_increments_scoreViele Kategorien erhoehen den Score
test_burst_detectionSchnelle gleiche Anfragen erhoehen den Score
test_sequential_enumeration_detectionAlphabetische Muster werden erkannt
test_progressive_throttling_level_1Delay bei Score >= 30
test_progressive_throttling_level_3_blocksBlock bei Score >= 85
test_score_decay_over_timeScore sinkt ueber die Zeit
test_skips_non_protected_pathsNicht-SDK-Pfade bleiben frei
test_watermark_header_presentX-BP-Trace Header vorhanden
test_fallback_to_inmemoryFunktioniert ohne Valkey
test_no_user_passes_throughAnonyme Requests passieren
test_category_extractionKorrekte Kategorie-Zuordnung
test_quota_headers_presentResponse-Headers vorhanden
- - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/architecture/secrets-management/index.html b/docs-site/architecture/secrets-management/index.html deleted file mode 100644 index 188a3f4..0000000 --- a/docs-site/architecture/secrets-management/index.html +++ /dev/null @@ -1,2780 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - Secrets Management - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - - - - - -
- -
- - - - - -

BreakPilot Secrets Management

-

Uebersicht

-

BreakPilot verwendet HashiCorp Vault als zentrales Secrets-Management-System.

-
┌─────────────────────────────────────────────────────────────────────────┐
-│                        SECRETS MANAGEMENT                                │
-│                                                                          │
-│  ┌────────────────────────────────────────────────────────────────────┐ │
-│  │                    HashiCorp Vault                                  │ │
-│  │                       Port 8200                                     │ │
-│  │  ┌──────────────┐  ┌──────────────┐  ┌──────────────────────────┐  │ │
-│  │  │ KV v2 Engine │  │ AppRole Auth │  │ Audit Logging            │  │ │
-│  │  │ secret/      │  │ Token Auth   │  │ Verschluesselung         │  │ │
-│  │  └──────────────┘  └──────────────┘  └──────────────────────────┘  │ │
-│  └────────────────────────────────────────────────────────────────────┘ │
-│                                    │                                     │
-│              ┌─────────────────────┼─────────────────────┐              │
-│              ▼                     ▼                     ▼              │
-│  ┌─────────────────┐    ┌─────────────────┐    ┌─────────────────┐     │
-│  │  Python Backend │    │  Go Services    │    │  Frontend       │     │
-│  │  (hvac client)  │    │  (vault-client) │    │  (via Backend)  │     │
-│  └─────────────────┘    └─────────────────┘    └─────────────────┘     │
-└─────────────────────────────────────────────────────────────────────────┘
-
-

Warum Vault?

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
AlternativeNachteil
Environment VariablesKeine Audit-Logs, keine Verschluesselung, keine Rotation
Docker SecretsNur fuer Docker Swarm, keine zentrale Verwaltung
AWS Secrets ManagerCloud Lock-in, Kosten
Kubernetes SecretsKeine Verschluesselung by default, nur K8s
HashiCorp VaultOpen Source (BSL 1.1), Self-Hosted, Enterprise Features
-

Architektur

-

Secret-Hierarchie

-
secret/breakpilot/
-├── api_keys/
-│   ├── anthropic     # Anthropic Claude API Key
-│   ├── vast          # vast.ai GPU API Key
-│   ├── stripe        # Stripe Payment Key
-│   ├── stripe_webhook
-│   └── tavily        # Tavily Search API Key
-├── database/
-│   ├── postgres      # username, password, url
-│   └── synapse       # Matrix Synapse DB
-├── auth/
-│   ├── jwt           # secret, refresh_secret
-│   └── keycloak      # client_secret
-├── communication/
-│   ├── matrix        # access_token, db_password
-│   └── jitsi         # app_secret, jicofo, jvb passwords
-├── storage/
-│   └── minio         # access_key, secret_key
-└── infra/
-    └── vast          # api_key, instance_id, control_key
-
-

Python Integration

-
from secrets import get_secret
-
-# Einzelnes Secret abrufen
-api_key = get_secret("ANTHROPIC_API_KEY")
-
-# Mit Default-Wert
-debug = get_secret("DEBUG", default="false")
-
-# Als Pflicht-Secret
-db_url = get_secret("DATABASE_URL", required=True)
-
-

Fallback-Reihenfolge

-
1. HashiCorp Vault (wenn VAULT_ADDR gesetzt)
-   ↓ falls nicht verfuegbar
-2. Environment Variables
-   ↓ falls nicht gesetzt
-3. Docker Secrets (/run/secrets/)
-   ↓ falls nicht vorhanden
-4. Default-Wert (wenn angegeben)
-   ↓ sonst
-5. SecretNotFoundError (wenn required=True)
-
-

Setup

-

Entwicklung (Dev Mode)

-
# Vault starten (Dev Mode - NICHT fuer Produktion!)
-docker-compose -f docker-compose.vault.yml up -d vault
-
-# Warten bis healthy
-docker-compose -f docker-compose.vault.yml up vault-init
-
-# Environment setzen
-export VAULT_ADDR=http://localhost:8200
-export VAULT_TOKEN=breakpilot-dev-token
-
-

Secrets setzen

-
# Anthropic API Key
-vault kv put secret/breakpilot/api_keys/anthropic value='sk-ant-api03-...'
-
-# vast.ai Credentials
-vault kv put secret/breakpilot/infra/vast \
-    api_key='xxx' \
-    instance_id='123' \
-    control_key='yyy'
-
-# Database
-vault kv put secret/breakpilot/database/postgres \
-    username='breakpilot' \
-    password='supersecret' \
-    url='postgres://breakpilot:supersecret@localhost:5432/breakpilot_db'
-
-

Secrets lesen

-
# Liste aller Secrets
-vault kv list secret/breakpilot/
-
-# Secret anzeigen
-vault kv get secret/breakpilot/api_keys/anthropic
-
-# Nur den Wert
-vault kv get -field=value secret/breakpilot/api_keys/anthropic
-
-

Produktion

-

AppRole Authentication

-

In Produktion verwenden Services AppRole statt Token-Auth:

-
# 1. AppRole aktivieren (einmalig)
-vault auth enable approle
-
-# 2. Policy erstellen
-vault policy write breakpilot-backend - <<EOF
-path "secret/data/breakpilot/*" {
-  capabilities = ["read", "list"]
-}
-EOF
-
-# 3. Role erstellen
-vault write auth/approle/role/breakpilot-backend \
-    token_policies="breakpilot-backend" \
-    token_ttl=1h \
-    token_max_ttl=4h
-
-# 4. Role-ID holen (fix)
-vault read -field=role_id auth/approle/role/breakpilot-backend/role-id
-
-# 5. Secret-ID generieren (bei jedem Deploy neu)
-vault write -f auth/approle/role/breakpilot-backend/secret-id
-
-

Environment fuer Services

-
# Docker-Compose / Kubernetes
-VAULT_ADDR=https://vault.breakpilot.app:8200
-VAULT_AUTH_METHOD=approle
-VAULT_ROLE_ID=<role-id>
-VAULT_SECRET_ID=<secret-id>
-VAULT_SECRETS_PATH=breakpilot
-
-

Sicherheits-Checkliste

-

Muss erfuellt sein

-
    -
  • [ ] Keine echten Secrets in .env Dateien
  • -
  • [ ] .env in .gitignore
  • -
  • [ ] Vault im Sealed-State wenn nicht in Verwendung
  • -
  • [ ] TLS fuer Vault in Produktion
  • -
  • [ ] AppRole statt Token-Auth in Produktion
  • -
  • [ ] Audit-Logging aktiviert
  • -
  • [ ] Minimale Policies (Least Privilege)
  • -
-

Sollte erfuellt sein

-
    -
  • [ ] Automatische Secret-Rotation
  • -
  • [ ] Separate Vault-Instanz fuer Produktion
  • -
  • [ ] HSM-basiertes Auto-Unseal
  • -
  • [ ] Disaster Recovery Plan
  • -
-

Dateien

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
DateiBeschreibung
backend/secrets/__init__.pySecrets-Modul Exports
backend/secrets/vault_client.pyVault Client Implementation
docker-compose.vault.ymlVault Docker Configuration
vault/init-secrets.shEntwicklungs-Secrets Initialisierung
vault/policies/Vault Policy Files
-

Fehlerbehebung

-

Vault nicht erreichbar

-
# Status pruefen
-vault status
-
-# Falls sealed
-vault operator unseal <unseal-key>
-
-

Secret nicht gefunden

-
# Pfad pruefen
-vault kv list secret/breakpilot/
-
-# Cache leeren (Python)
-from secrets import get_secrets_manager
-get_secrets_manager().clear_cache()
-
-

Token abgelaufen

-
# Neuen Token holen (AppRole)
-vault write auth/approle/login \
-    role_id=$VAULT_ROLE_ID \
-    secret_id=$VAULT_SECRET_ID
-
-
-

Referenzen

- - - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/architecture/system-architecture/index.html b/docs-site/architecture/system-architecture/index.html deleted file mode 100644 index 97c03c3..0000000 --- a/docs-site/architecture/system-architecture/index.html +++ /dev/null @@ -1,3099 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - Systemuebersicht - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - - - - - -
- -
- - - - - -

BreakPilot PWA - System-Architektur

-

Übersicht

-

BreakPilot ist eine modulare Bildungsplattform für Lehrkräfte mit folgenden Hauptkomponenten:

-
┌─────────────────────────────────────────────────────────────────────┐
-│                           Browser                                    │
-│  ┌───────────────────────────────────────────────────────────────┐  │
-│  │                  Frontend (Studio UI)                          │  │
-│  │  ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────────────┐  │  │
-│  │  │Dashboard │ │Worksheets│ │Correction│ │Letters/Companion │  │  │
-│  │  └──────────┘ └──────────┘ └──────────┘ └──────────────────┘  │  │
-│  └───────────────────────────────────────────────────────────────┘  │
-└───────────────────────────┬─────────────────────────────────────────┘
-                            │ HTTP/REST
-                            ▼
-┌─────────────────────────────────────────────────────────────────────┐
-│                    Python Backend (FastAPI)                          │
-│                         Port 8000                                    │
-│  ┌────────────────────────────────────────────────────────────────┐ │
-│  │                      API Layer                                  │ │
-│  │  /api/worksheets  /api/corrections  /api/letters  /api/state   │ │
-│  │  /api/school      /api/certificates /api/messenger /api/jitsi  │ │
-│  └────────────────────────────────────────────────────────────────┘ │
-│  ┌────────────────────────────────────────────────────────────────┐ │
-│  │                    Service Layer                                │ │
-│  │  FileProcessor │ PDFService │ ContentGenerators │ StateEngine  │ │
-│  └────────────────────────────────────────────────────────────────┘ │
-└───────────────────────────┬─────────────────────────────────────────┘
-                            │
-              ┌─────────────┼─────────────┐
-              ▼             ▼             ▼
-┌─────────────────┐ ┌───────────────┐ ┌──────────────┐ ┌──────────────┐
-│  Go Consent     │ │  PostgreSQL   │ │  LLM Gateway │ │  HashiCorp   │
-│  Service        │ │  Database     │ │  (optional)  │ │  Vault       │
-│  Port 8081      │ │  Port 5432    │ │              │ │  Port 8200   │
-└─────────────────┘ └───────────────┘ └──────────────┘ └──────────────┘
-
-

Komponenten

-

1. Admin Frontend (Next.js Website)

-

Das Admin Frontend ist eine vollständige Next.js 15 Anwendung für Developer und Administratoren:

-

Technologie: Next.js 15, React 18, TypeScript, Tailwind CSS

-

Container: breakpilot-pwa-website auf Port 3000

-

Verzeichnis: /website

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ModulRouteBeschreibung
Dashboard/adminÜbersicht & Statistiken
GPU Infrastruktur/admin/gpuvast.ai GPU Management
Consent Verwaltung/admin/consentRechtliche Dokumente & Versionen
Datenschutzanfragen/admin/dsrDSGVO Art. 15-21 Anfragen
DSMS/admin/dsmsDatenschutz-Management-System
Education Search/admin/edu-searchBildungsquellen & Crawler
Personensuche/admin/staff-searchUni-Mitarbeiter & Publikationen
Uni-Crawler/admin/uni-crawlerUniversitäts-Crawling Orchestrator
LLM Vergleich/admin/llm-compareKI-Provider Vergleich
PCA Platform/admin/pca-platformBot-Erkennung & Monetarisierung
Production Backlog/admin/backlogGo-Live Checkliste
Developer Docs/admin/docsAPI & Architektur Dokumentation
Kommunikation/admin/communicationMatrix & Jitsi Monitoring
Security/admin/securityDevSecOps Dashboard, Scans, Findings
SBOM/admin/sbomSoftware Bill of Materials
-

2. Lehrer Frontend (Studio UI)

-

Das Lehrer Frontend ist ein Single-Page-Application-ähnliches System für Lehrkräfte, das in Python-Modulen organisiert ist:

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ModulDateiBeschreibung
Basefrontend/modules/base.pyTopBar, Sidebar, Theme, Login
Dashboardfrontend/modules/dashboard.pyÜbersichtsseite
Worksheetsfrontend/modules/worksheets.pyLerneinheiten-Generator
Correctionfrontend/modules/correction.pyOCR-Klausurkorrektur
Lettersfrontend/modules/letters.pyElternkommunikation
Companionfrontend/modules/companion.pyBegleiter-Modus mit State Engine
Schoolfrontend/modules/school.pySchulverwaltung
Gradebookfrontend/modules/gradebook.pyNotenbuch
ContentCreatorfrontend/modules/content_creator.pyH5P Content Creator
ContentFeedfrontend/modules/content_feed.pyContent Discovery
Messengerfrontend/modules/messenger.pyMatrix Messenger
Jitsifrontend/modules/jitsi.pyVideokonferenzen
KlausurKorrekturfrontend/modules/klausur_korrektur.pyAbitur-Klausurkorrektur (15-Punkte-System)
AbiturDocsAdminfrontend/modules/abitur_docs_admin.pyAdmin für Abitur-Dokumente (NiBiS)
-

Jedes Modul exportiert: -- get_css() - CSS-Styles -- get_html() - HTML-Template -- get_js() - JavaScript-Logik

-

3. Python Backend (FastAPI)

-

API-Router

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
RouterPräfixBeschreibung
worksheets_api/api/worksheetsContent-Generatoren (MC, Cloze, Mindmap, Quiz)
correction_api/api/correctionsOCR-Pipeline für Klausurkorrektur
letters_api/api/lettersElternbriefe mit GFK-Integration
state_engine_api/api/stateBegleiter-Modus Phasen & Vorschläge
school_api/api/schoolSchulverwaltung (Proxy zu school-service)
certificates_api/api/certificatesZeugniserstellung
messenger_api/api/messengerMatrix Messenger Integration
jitsi_api/api/jitsiJitsi Meeting-Einladungen
consent_api/api/consentDSGVO Consent-Verwaltung
gdpr_api/api/gdprGDPR-Export
klausur_korrektur_api/api/klausur-korrekturAbitur-Klausuren (15-Punkte, Gutachten, Fairness)
abitur_docs_api/api/abitur-docsNiBiS-Dokumentenverwaltung für RAG
-

Services

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ServiceDateiBeschreibung
FileProcessorservices/file_processor.pyOCR mit PaddleOCR
PDFServiceservices/pdf_service.pyPDF-Generierung
ContentGeneratorsservices/content_generators/MC, Cloze, Mindmap, Quiz
StateEnginestate_engine/Phasen-Management & Antizipation
-

4. Klausur-Korrektur System (Abitur)

-

Das Klausur-Korrektur-System implementiert die vollständige Abitur-Bewertungspipeline:

-
┌─────────────────────────────────────────────────────────────────────┐
-│                    Klausur-Korrektur Modul                          │
-│                                                                     │
-│  ┌─────────────┐    ┌──────────────────┐    ┌─────────────────┐    │
-│  │ Modus-Wahl  │───►│ Text-Quellen &   │───►│ Erwartungs-     │    │
-│  │ LandesAbi/  │    │ Rights-Gate      │    │ horizont        │    │
-│  │ Vorabitur   │    └──────────────────┘    └─────────────────┘    │
-│  └─────────────┘                                      │            │
-│                                                       ▼            │
-│  ┌─────────────────────────────────────────────────────────────┐   │
-│  │                   Schülerarbeiten-Pipeline                   │   │
-│  │  Upload → OCR → KI-Bewertung → Gutachten → 15-Punkte-Note   │   │
-│  └─────────────────────────────────────────────────────────────┘   │
-│                                                       │            │
-│                                                       ▼            │
-│  ┌────────────────────┐    ┌──────────────────────────────────┐   │
-│  │ Erst-/Zweitprüfer  │───►│ Fairness-Analyse & PDF-Export   │   │
-│  └────────────────────┘    └──────────────────────────────────┘   │
-└─────────────────────────────────────────────────────────────────────┘
-
-

15-Punkte-Notensystem

-

Das System verwendet den deutschen Abitur-Notenschlüssel:

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
PunkteProzentNote
15-1395-85%1+/1/1-
12-1080-70%2+/2/2-
9-765-55%3+/3/3-
6-450-40%4+/4/4-
3-133-20%5+/5/5-
0<20%6
-

Bewertungskriterien

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
KriteriumGewichtBeschreibung
Rechtschreibung15%Orthografie
Grammatik15%Grammatik & Syntax
Inhalt40%Inhaltliche Qualität (höchste Gewichtung)
Struktur15%Aufbau & Gliederung
Stil15%Ausdruck & Stil
- -

Verwaltet DSGVO-Einwilligungen:

-
consent-service/
-├── cmd/server/        # Main entry point
-├── internal/
-│   ├── handlers/      # HTTP Handler
-│   ├── services/      # Business Logic
-│   ├── models/        # Data Models
-│   └── middleware/    # Auth Middleware
-└── migrations/        # SQL Migrations
-
-

6. LLM Gateway (Optional)

-

Wenn LLM_GATEWAY_ENABLED=true:

-
llm_gateway/
-├── routes/
-│   ├── chat.py            # Chat-Completion API
-│   ├── communication.py   # GFK-Validierung
-│   ├── edu_search_seeds.py # Bildungssuche
-│   └── legal_crawler.py   # Schulgesetz-Crawler
-└── services/
-    └── communication_service.py
-
-

Datenfluss

-

Worksheet-Generierung

-
User Input → Frontend (worksheets.py)
-    ↓
-POST /api/worksheets/generate/multiple-choice
-    ↓
-worksheets_api.py → MCGenerator (services/content_generators/)
-    ↓
-Optional: LLM für erweiterte Generierung
-    ↓
-Response: WorksheetContent → Frontend rendert Ergebnis
-
-

Klausurkorrektur

-
File Upload → Frontend (correction.py)
-    ↓
-POST /api/corrections/ (erstellen)
-POST /api/corrections/{id}/upload (Datei)
-    ↓
-Background Task: OCR via FileProcessor
-    ↓
-Poll GET /api/corrections/{id} bis status="ocr_complete"
-    ↓
-POST /api/corrections/{id}/analyze
-    ↓
-Review Interface → PUT /api/corrections/{id} (Anpassungen)
-    ↓
-GET /api/corrections/{id}/export-pdf
-
-

Sicherheit

-

Authentifizierung & Autorisierung

-

BreakPilot verwendet einen Hybrid-Ansatz:

- - - - - - - - - - - - - - - - - - - - -
SchichtKomponenteBeschreibung
AuthentifizierungKeycloak (Prod) / Lokales JWT (Dev)Token-Validierung via JWKS oder HS256
Autorisierungrbac.py (Eigenentwicklung)Domaenenspezifische Berechtigungen
-

Siehe: Auth-System

-

Basis-Rollen

- - - - - - - - - - - - - - - - - - - - - - - - - -
RolleBeschreibung
userNormaler Benutzer
teacher / lehrerLehrkraft
adminAdministrator
data_protection_officerDatenschutzbeauftragter
-

Erweiterte Rollen (rbac.py)

-

15+ domaenenspezifische Rollen fuer Klausurkorrektur und Zeugnisse: -- erstkorrektor, zweitkorrektor, drittkorrektor -- klassenlehrer, fachlehrer, fachvorsitz -- schulleitung, zeugnisbeauftragter, sekretariat

-

Sicherheitsfeatures

-
    -
  • JWT-basierte Authentifizierung (RS256/HS256)
  • -
  • CORS konfiguriert für Frontend-Zugriff
  • -
  • DSGVO-konformes Consent-Management
  • -
  • HashiCorp Vault fuer Secrets-Management (keine hardcodierten Secrets)
  • -
  • Bundesland-spezifische Policy-Sets
  • -
  • DevSecOps Pipeline mit automatisierten Security-Scans (SAST, SCA, Secrets Detection)
  • -
-

Siehe: -- Secrets Management -- DevSecOps

-

Deployment

-
services:
-  backend:
-    build: ./backend
-    ports: ["8000:8000"]
-    environment:
-      - DATABASE_URL=postgresql://...
-      - LLM_GATEWAY_ENABLED=false
-
-  consent-service:
-    build: ./consent-service
-    ports: ["8081:8081"]
-
-  postgres:
-    image: postgres:15
-    volumes:
-      - pgdata:/var/lib/postgresql/data
-
-

Erweiterung

-

Neues Frontend-Modul hinzufügen:

-
    -
  1. Modul erstellen: frontend/modules/new_module.py
  2. -
  3. Klasse mit get_css(), get_html(), get_js() implementieren
  4. -
  5. In frontend/modules/__init__.py importieren und exportieren
  6. -
  7. Optional: Zugehörige API in new_module_api.py erstellen
  8. -
  9. In main.py Router registrieren
  10. -
- - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/architecture/zeugnis-system/index.html b/docs-site/architecture/zeugnis-system/index.html deleted file mode 100644 index 5b67bae..0000000 --- a/docs-site/architecture/zeugnis-system/index.html +++ /dev/null @@ -1,2660 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - Zeugnis-System - Breakpilot Dokumentation - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - Zum Inhalt - - -
-
- -
- - - - -
- - -
- -
- - - - - - - - - -
-
- - - -
-
-
- - - - - - - -
-
-
- - - - - - - -
- -
- - - - - -

Zeugnis-System - Architecture Documentation

-

Overview

-

The Zeugnis (Certificate) System enables schools to generate official school certificates with grades, attendance data, and remarks. It extends the existing School-Service with comprehensive grade management and certificate generation workflows.

-

Architecture Diagram

-
                                         ┌─────────────────────────────────────┐
-                                         │      Python Backend (Port 8000)     │
-                                         │   backend/frontend/modules/school.py │
-                                         │                                     │
-                                         │  ┌─────────────────────────────────┐ │
-                                         │  │   panel-school-certificates     │ │
-                                         │  │   - Klassenauswahl              │ │
-                                         │  │   - Notenspiegel                │ │
-                                         │  │   - Zeugnis-Wizard (5 Steps)    │ │
-                                         │  │   - Workflow-Status             │ │
-                                         │  └─────────────────────────────────┘ │
-                                         └──────────────────┬──────────────────┘
-                                                            │
-                                                            ▼
-┌─────────────────────────────────────────────────────────────────────────────────────────┐
-│                              School-Service (Go, Port 8084)                              │
-├─────────────────────────────────────────────────────────────────────────────────────────┤
-│                                                                                         │
-│  ┌─────────────────────┐  ┌─────────────────────┐  ┌─────────────────────────────────┐  │
-│  │  Grade Handlers     │  │ Statistics Handlers │  │    Certificate Handlers         │  │
-│  │                     │  │                     │  │                                 │  │
-│  │ GetClassGrades      │  │ GetClassStatistics  │  │ GetCertificateTemplates         │  │
-│  │ GetStudentGrades    │  │ GetSubjectStatistics│  │ GetClassCertificates            │  │
-│  │ UpdateOralGrade     │  │ GetStudentStatistics│  │ GenerateCertificate             │  │
-│  │ CalculateFinalGrades│  │ GetNotenspiegel     │  │ BulkGenerateCertificates        │  │
-│  │ LockFinalGrade      │  │                     │  │ FinalizeCertificate             │  │
-│  │ UpdateGradeWeights  │  │                     │  │ GetCertificatePDF               │  │
-│  └─────────────────────┘  └─────────────────────┘  └─────────────────────────────────┘  │
-│                                                                                         │
-└─────────────────────────────────────────────────────────────────────────────────────────┘
-                                                            │
-                                                            ▼
-                                         ┌─────────────────────────────────────┐
-                                         │         PostgreSQL Database          │
-                                         │                                     │
-                                         │  Tables:                            │
-                                         │  - grade_overview                   │
-                                         │  - exam_results                     │
-                                         │  - students                         │
-                                         │  - classes                          │
-                                         │  - subjects                         │
-                                         │  - certificates                     │
-                                         │  - attendance                       │
-                                         └─────────────────────────────────────┘
-
-

Zeugnis Workflow (Role Chain)

-

The certificate workflow follows a strict approval chain from subject teachers to school principal:

-
┌──────────────────┐    ┌──────────────────┐    ┌────────────────────────┐    ┌────────────────────┐    ┌──────────────────┐
-│   FACHLEHRER     │───▶│  KLASSENLEHRER   │───▶│  ZEUGNISBEAUFTRAGTER   │───▶│    SCHULLEITUNG    │───▶│   SEKRETARIAT    │
-│   (Subject       │    │  (Class          │    │  (Certificate          │    │    (Principal)     │    │   (Secretary)    │
-│   Teacher)       │    │   Teacher)       │    │   Coordinator)         │    │                    │    │                  │
-└──────────────────┘    └──────────────────┘    └────────────────────────┘    └────────────────────┘    └──────────────────┘
-        │                       │                         │                           │                        │
-        ▼                       ▼                         ▼                           ▼                        ▼
-   Grades Entry            Approve               Quality Check              Sign-off & Lock            Print & Archive
-   (Oral/Written)          Grades                 & Review
-
-

Workflow States

-
┌─────────────┐     ┌─────────────┐     ┌─────────────┐     ┌─────────────┐     ┌─────────────┐
-│   DRAFT     │────▶│  SUBMITTED  │────▶│  REVIEWED   │────▶│   SIGNED    │────▶│   PRINTED   │
-│   (Entwurf) │     │ (Eingereicht)│    │ (Geprueft)  │     │(Unterzeichnet)    │ (Gedruckt)  │
-└─────────────┘     └─────────────┘     └─────────────┘     └─────────────┘     └─────────────┘
-      │                   │                   │                   │
-      ▼                   ▼                   ▼                   ▼
-  Fachlehrer        Klassenlehrer      Zeugnisbeauftragter   Schulleitung
-
-

RBAC Integration

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
RoleGermanDescription
FACHLEHRERFachlehrerSubject teacher - enters grades
KLASSENLEHRERKlassenlehrerClass teacher - approves class grades
ZEUGNISBEAUFTRAGTERZeugnisbeauftragterCertificate coordinator - quality control
SCHULLEITUNGSchulleitungPrincipal - final sign-off
SEKRETARIATSekretariatSecretary - printing & archiving
-

Certificate Resource Types

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ResourceTypeDescription
ZEUGNISFinal certificate document
ZEUGNIS_VORLAGECertificate template (per Bundesland)
ZEUGNIS_ENTWURFDraft certificate (before approval)
FACHNOTESubject grade
KOPFNOTEHead grade (Arbeits-/Sozialverhalten)
BEMERKUNGCertificate remarks
STATISTIKClass/subject statistics
NOTENSPIEGELGrade distribution chart
-

German Grading System

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
GradeMeaningPoints
1sehr gut (excellent)15-13
2gut (good)12-10
3befriedigend (satisfactory)9-7
4ausreichend (adequate)6-4
5mangelhaft (poor)3-1
6ungenuegend (inadequate)0
-

Grade Calculation

-
Final Grade = (Written Weight * Written Avg) + (Oral Weight * Oral Avg)
-
-Default weights:
-- Written (Klassenarbeiten): 50%
-- Oral (muendliche Note): 50%
-
-Customizable per subject/student via UpdateGradeWeights endpoint.
-
-

API Routes (School-Service)

-

Grade Management

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
MethodEndpointDescription
GET/api/v1/school/grades/:classIdGet class grades
GET/api/v1/school/grades/student/:studentIdGet student grades
PUT/api/v1/school/grades/:studentId/:subjectId/oralUpdate oral grade
POST/api/v1/school/grades/calculateCalculate final grades
PUT/api/v1/school/grades/:studentId/:subjectId/lockLock final grade
-

Statistics

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
MethodEndpointDescription
GET/api/v1/school/statistics/:classIdClass statistics
GET/api/v1/school/statistics/:classId/subject/:subjectIdSubject statistics
GET/api/v1/school/statistics/student/:studentIdStudent statistics
GET/api/v1/school/statistics/:classId/notenspiegelGrade distribution
-

Certificates

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
MethodEndpointDescription
GET/api/v1/school/certificates/templatesList templates
GET/api/v1/school/certificates/class/:classIdClass certificates
POST/api/v1/school/certificates/generateGenerate single
POST/api/v1/school/certificates/generate-bulkGenerate bulk
GET/api/v1/school/certificates/detail/:id/pdfDownload PDF
-

Security Considerations

-
    -
  1. RBAC Enforcement: All certificate operations check user role permissions
  2. -
  3. Tenant Isolation: Teachers only see their own classes/students
  4. -
  5. Audit Trail: All grade changes and approvals logged
  6. -
  7. Lock Mechanism: Finalized certificates cannot be modified
  8. -
  9. Workflow Enforcement: Cannot skip approval steps
  10. -
- - - - - - - - - - - - - -
-
- - - - - -
- - - -
- - - -
-
-
-
- - - - - - - - - - - - - \ No newline at end of file diff --git a/docs-site/assets/images/favicon.png b/docs-site/assets/images/favicon.png deleted file mode 100644 index 1cf13b9..0000000 Binary files a/docs-site/assets/images/favicon.png and /dev/null differ diff --git a/docs-site/assets/javascripts/bundle.79ae519e.min.js b/docs-site/assets/javascripts/bundle.79ae519e.min.js deleted file mode 100644 index 3df3e5e..0000000 --- a/docs-site/assets/javascripts/bundle.79ae519e.min.js +++ /dev/null @@ -1,16 +0,0 @@ -"use strict";(()=>{var Zi=Object.create;var _r=Object.defineProperty;var ea=Object.getOwnPropertyDescriptor;var ta=Object.getOwnPropertyNames,Bt=Object.getOwnPropertySymbols,ra=Object.getPrototypeOf,Ar=Object.prototype.hasOwnProperty,bo=Object.prototype.propertyIsEnumerable;var ho=(e,t,r)=>t in e?_r(e,t,{enumerable:!0,configurable:!0,writable:!0,value:r}):e[t]=r,P=(e,t)=>{for(var r in t||(t={}))Ar.call(t,r)&&ho(e,r,t[r]);if(Bt)for(var r of Bt(t))bo.call(t,r)&&ho(e,r,t[r]);return e};var vo=(e,t)=>{var r={};for(var o in e)Ar.call(e,o)&&t.indexOf(o)<0&&(r[o]=e[o]);if(e!=null&&Bt)for(var o of Bt(e))t.indexOf(o)<0&&bo.call(e,o)&&(r[o]=e[o]);return r};var Cr=(e,t)=>()=>(t||e((t={exports:{}}).exports,t),t.exports);var oa=(e,t,r,o)=>{if(t&&typeof t=="object"||typeof t=="function")for(let n of ta(t))!Ar.call(e,n)&&n!==r&&_r(e,n,{get:()=>t[n],enumerable:!(o=ea(t,n))||o.enumerable});return e};var $t=(e,t,r)=>(r=e!=null?Zi(ra(e)):{},oa(t||!e||!e.__esModule?_r(r,"default",{value:e,enumerable:!0}):r,e));var go=(e,t,r)=>new Promise((o,n)=>{var i=c=>{try{a(r.next(c))}catch(p){n(p)}},s=c=>{try{a(r.throw(c))}catch(p){n(p)}},a=c=>c.done?o(c.value):Promise.resolve(c.value).then(i,s);a((r=r.apply(e,t)).next())});var xo=Cr((kr,yo)=>{(function(e,t){typeof kr=="object"&&typeof yo!="undefined"?t():typeof define=="function"&&define.amd?define(t):t()})(kr,(function(){"use strict";function e(r){var o=!0,n=!1,i=null,s={text:!0,search:!0,url:!0,tel:!0,email:!0,password:!0,number:!0,date:!0,month:!0,week:!0,time:!0,datetime:!0,"datetime-local":!0};function a(k){return!!(k&&k!==document&&k.nodeName!=="HTML"&&k.nodeName!=="BODY"&&"classList"in k&&"contains"in k.classList)}function c(k){var ut=k.type,je=k.tagName;return!!(je==="INPUT"&&s[ut]&&!k.readOnly||je==="TEXTAREA"&&!k.readOnly||k.isContentEditable)}function p(k){k.classList.contains("focus-visible")||(k.classList.add("focus-visible"),k.setAttribute("data-focus-visible-added",""))}function l(k){k.hasAttribute("data-focus-visible-added")&&(k.classList.remove("focus-visible"),k.removeAttribute("data-focus-visible-added"))}function f(k){k.metaKey||k.altKey||k.ctrlKey||(a(r.activeElement)&&p(r.activeElement),o=!0)}function u(k){o=!1}function d(k){a(k.target)&&(o||c(k.target))&&p(k.target)}function v(k){a(k.target)&&(k.target.classList.contains("focus-visible")||k.target.hasAttribute("data-focus-visible-added"))&&(n=!0,window.clearTimeout(i),i=window.setTimeout(function(){n=!1},100),l(k.target))}function S(k){document.visibilityState==="hidden"&&(n&&(o=!0),X())}function X(){document.addEventListener("mousemove",ee),document.addEventListener("mousedown",ee),document.addEventListener("mouseup",ee),document.addEventListener("pointermove",ee),document.addEventListener("pointerdown",ee),document.addEventListener("pointerup",ee),document.addEventListener("touchmove",ee),document.addEventListener("touchstart",ee),document.addEventListener("touchend",ee)}function re(){document.removeEventListener("mousemove",ee),document.removeEventListener("mousedown",ee),document.removeEventListener("mouseup",ee),document.removeEventListener("pointermove",ee),document.removeEventListener("pointerdown",ee),document.removeEventListener("pointerup",ee),document.removeEventListener("touchmove",ee),document.removeEventListener("touchstart",ee),document.removeEventListener("touchend",ee)}function ee(k){k.target.nodeName&&k.target.nodeName.toLowerCase()==="html"||(o=!1,re())}document.addEventListener("keydown",f,!0),document.addEventListener("mousedown",u,!0),document.addEventListener("pointerdown",u,!0),document.addEventListener("touchstart",u,!0),document.addEventListener("visibilitychange",S,!0),X(),r.addEventListener("focus",d,!0),r.addEventListener("blur",v,!0),r.nodeType===Node.DOCUMENT_FRAGMENT_NODE&&r.host?r.host.setAttribute("data-js-focus-visible",""):r.nodeType===Node.DOCUMENT_NODE&&(document.documentElement.classList.add("js-focus-visible"),document.documentElement.setAttribute("data-js-focus-visible",""))}if(typeof window!="undefined"&&typeof document!="undefined"){window.applyFocusVisiblePolyfill=e;var t;try{t=new CustomEvent("focus-visible-polyfill-ready")}catch(r){t=document.createEvent("CustomEvent"),t.initCustomEvent("focus-visible-polyfill-ready",!1,!1,{})}window.dispatchEvent(t)}typeof document!="undefined"&&e(document)}))});var ro=Cr((jy,Rn)=>{"use strict";/*! - * escape-html - * Copyright(c) 2012-2013 TJ Holowaychuk - * Copyright(c) 2015 Andreas Lubbe - * Copyright(c) 2015 Tiancheng "Timothy" Gu - * MIT Licensed - */var qa=/["'&<>]/;Rn.exports=Ka;function Ka(e){var t=""+e,r=qa.exec(t);if(!r)return t;var o,n="",i=0,s=0;for(i=r.index;i{/*! - * clipboard.js v2.0.11 - * https://clipboardjs.com/ - * - * Licensed MIT © Zeno Rocha - */(function(t,r){typeof Nt=="object"&&typeof io=="object"?io.exports=r():typeof define=="function"&&define.amd?define([],r):typeof Nt=="object"?Nt.ClipboardJS=r():t.ClipboardJS=r()})(Nt,function(){return(function(){var e={686:(function(o,n,i){"use strict";i.d(n,{default:function(){return Xi}});var s=i(279),a=i.n(s),c=i(370),p=i.n(c),l=i(817),f=i.n(l);function u(q){try{return document.execCommand(q)}catch(C){return!1}}var d=function(C){var _=f()(C);return u("cut"),_},v=d;function S(q){var C=document.documentElement.getAttribute("dir")==="rtl",_=document.createElement("textarea");_.style.fontSize="12pt",_.style.border="0",_.style.padding="0",_.style.margin="0",_.style.position="absolute",_.style[C?"right":"left"]="-9999px";var D=window.pageYOffset||document.documentElement.scrollTop;return _.style.top="".concat(D,"px"),_.setAttribute("readonly",""),_.value=q,_}var X=function(C,_){var D=S(C);_.container.appendChild(D);var N=f()(D);return u("copy"),D.remove(),N},re=function(C){var _=arguments.length>1&&arguments[1]!==void 0?arguments[1]:{container:document.body},D="";return typeof C=="string"?D=X(C,_):C instanceof HTMLInputElement&&!["text","search","url","tel","password"].includes(C==null?void 0:C.type)?D=X(C.value,_):(D=f()(C),u("copy")),D},ee=re;function k(q){"@babel/helpers - typeof";return typeof Symbol=="function"&&typeof Symbol.iterator=="symbol"?k=function(_){return typeof _}:k=function(_){return _&&typeof Symbol=="function"&&_.constructor===Symbol&&_!==Symbol.prototype?"symbol":typeof _},k(q)}var ut=function(){var C=arguments.length>0&&arguments[0]!==void 0?arguments[0]:{},_=C.action,D=_===void 0?"copy":_,N=C.container,G=C.target,We=C.text;if(D!=="copy"&&D!=="cut")throw new Error('Invalid "action" value, use either "copy" or "cut"');if(G!==void 0)if(G&&k(G)==="object"&&G.nodeType===1){if(D==="copy"&&G.hasAttribute("disabled"))throw new Error('Invalid "target" attribute. Please use "readonly" instead of "disabled" attribute');if(D==="cut"&&(G.hasAttribute("readonly")||G.hasAttribute("disabled")))throw new Error(`Invalid "target" attribute. You can't cut text from elements with "readonly" or "disabled" attributes`)}else throw new Error('Invalid "target" value, use a valid Element');if(We)return ee(We,{container:N});if(G)return D==="cut"?v(G):ee(G,{container:N})},je=ut;function R(q){"@babel/helpers - typeof";return typeof Symbol=="function"&&typeof Symbol.iterator=="symbol"?R=function(_){return typeof _}:R=function(_){return _&&typeof Symbol=="function"&&_.constructor===Symbol&&_!==Symbol.prototype?"symbol":typeof _},R(q)}function se(q,C){if(!(q instanceof C))throw new TypeError("Cannot call a class as a function")}function ce(q,C){for(var _=0;_0&&arguments[0]!==void 0?arguments[0]:{};this.action=typeof N.action=="function"?N.action:this.defaultAction,this.target=typeof N.target=="function"?N.target:this.defaultTarget,this.text=typeof N.text=="function"?N.text:this.defaultText,this.container=R(N.container)==="object"?N.container:document.body}},{key:"listenClick",value:function(N){var G=this;this.listener=p()(N,"click",function(We){return G.onClick(We)})}},{key:"onClick",value:function(N){var G=N.delegateTarget||N.currentTarget,We=this.action(G)||"copy",Yt=je({action:We,container:this.container,target:this.target(G),text:this.text(G)});this.emit(Yt?"success":"error",{action:We,text:Yt,trigger:G,clearSelection:function(){G&&G.focus(),window.getSelection().removeAllRanges()}})}},{key:"defaultAction",value:function(N){return Mr("action",N)}},{key:"defaultTarget",value:function(N){var G=Mr("target",N);if(G)return document.querySelector(G)}},{key:"defaultText",value:function(N){return Mr("text",N)}},{key:"destroy",value:function(){this.listener.destroy()}}],[{key:"copy",value:function(N){var G=arguments.length>1&&arguments[1]!==void 0?arguments[1]:{container:document.body};return ee(N,G)}},{key:"cut",value:function(N){return v(N)}},{key:"isSupported",value:function(){var N=arguments.length>0&&arguments[0]!==void 0?arguments[0]:["copy","cut"],G=typeof N=="string"?[N]:N,We=!!document.queryCommandSupported;return G.forEach(function(Yt){We=We&&!!document.queryCommandSupported(Yt)}),We}}]),_})(a()),Xi=Ji}),828:(function(o){var n=9;if(typeof Element!="undefined"&&!Element.prototype.matches){var i=Element.prototype;i.matches=i.matchesSelector||i.mozMatchesSelector||i.msMatchesSelector||i.oMatchesSelector||i.webkitMatchesSelector}function s(a,c){for(;a&&a.nodeType!==n;){if(typeof a.matches=="function"&&a.matches(c))return a;a=a.parentNode}}o.exports=s}),438:(function(o,n,i){var s=i(828);function a(l,f,u,d,v){var S=p.apply(this,arguments);return l.addEventListener(u,S,v),{destroy:function(){l.removeEventListener(u,S,v)}}}function c(l,f,u,d,v){return typeof l.addEventListener=="function"?a.apply(null,arguments):typeof u=="function"?a.bind(null,document).apply(null,arguments):(typeof l=="string"&&(l=document.querySelectorAll(l)),Array.prototype.map.call(l,function(S){return a(S,f,u,d,v)}))}function p(l,f,u,d){return function(v){v.delegateTarget=s(v.target,f),v.delegateTarget&&d.call(l,v)}}o.exports=c}),879:(function(o,n){n.node=function(i){return i!==void 0&&i instanceof HTMLElement&&i.nodeType===1},n.nodeList=function(i){var s=Object.prototype.toString.call(i);return i!==void 0&&(s==="[object NodeList]"||s==="[object HTMLCollection]")&&"length"in i&&(i.length===0||n.node(i[0]))},n.string=function(i){return typeof i=="string"||i instanceof String},n.fn=function(i){var s=Object.prototype.toString.call(i);return s==="[object Function]"}}),370:(function(o,n,i){var s=i(879),a=i(438);function c(u,d,v){if(!u&&!d&&!v)throw new Error("Missing required arguments");if(!s.string(d))throw new TypeError("Second argument must be a String");if(!s.fn(v))throw new TypeError("Third argument must be a Function");if(s.node(u))return p(u,d,v);if(s.nodeList(u))return l(u,d,v);if(s.string(u))return f(u,d,v);throw new TypeError("First argument must be a String, HTMLElement, HTMLCollection, or NodeList")}function p(u,d,v){return u.addEventListener(d,v),{destroy:function(){u.removeEventListener(d,v)}}}function l(u,d,v){return Array.prototype.forEach.call(u,function(S){S.addEventListener(d,v)}),{destroy:function(){Array.prototype.forEach.call(u,function(S){S.removeEventListener(d,v)})}}}function f(u,d,v){return a(document.body,u,d,v)}o.exports=c}),817:(function(o){function n(i){var s;if(i.nodeName==="SELECT")i.focus(),s=i.value;else if(i.nodeName==="INPUT"||i.nodeName==="TEXTAREA"){var a=i.hasAttribute("readonly");a||i.setAttribute("readonly",""),i.select(),i.setSelectionRange(0,i.value.length),a||i.removeAttribute("readonly"),s=i.value}else{i.hasAttribute("contenteditable")&&i.focus();var c=window.getSelection(),p=document.createRange();p.selectNodeContents(i),c.removeAllRanges(),c.addRange(p),s=c.toString()}return s}o.exports=n}),279:(function(o){function n(){}n.prototype={on:function(i,s,a){var c=this.e||(this.e={});return(c[i]||(c[i]=[])).push({fn:s,ctx:a}),this},once:function(i,s,a){var c=this;function p(){c.off(i,p),s.apply(a,arguments)}return p._=s,this.on(i,p,a)},emit:function(i){var s=[].slice.call(arguments,1),a=((this.e||(this.e={}))[i]||[]).slice(),c=0,p=a.length;for(c;c0&&i[i.length-1])&&(p[0]===6||p[0]===2)){r=0;continue}if(p[0]===3&&(!i||p[1]>i[0]&&p[1]=e.length&&(e=void 0),{value:e&&e[o++],done:!e}}};throw new TypeError(t?"Object is not iterable.":"Symbol.iterator is not defined.")}function K(e,t){var r=typeof Symbol=="function"&&e[Symbol.iterator];if(!r)return e;var o=r.call(e),n,i=[],s;try{for(;(t===void 0||t-- >0)&&!(n=o.next()).done;)i.push(n.value)}catch(a){s={error:a}}finally{try{n&&!n.done&&(r=o.return)&&r.call(o)}finally{if(s)throw s.error}}return i}function B(e,t,r){if(r||arguments.length===2)for(var o=0,n=t.length,i;o1||c(d,S)})},v&&(n[d]=v(n[d])))}function c(d,v){try{p(o[d](v))}catch(S){u(i[0][3],S)}}function p(d){d.value instanceof dt?Promise.resolve(d.value.v).then(l,f):u(i[0][2],d)}function l(d){c("next",d)}function f(d){c("throw",d)}function u(d,v){d(v),i.shift(),i.length&&c(i[0][0],i[0][1])}}function To(e){if(!Symbol.asyncIterator)throw new TypeError("Symbol.asyncIterator is not defined.");var t=e[Symbol.asyncIterator],r;return t?t.call(e):(e=typeof Oe=="function"?Oe(e):e[Symbol.iterator](),r={},o("next"),o("throw"),o("return"),r[Symbol.asyncIterator]=function(){return this},r);function o(i){r[i]=e[i]&&function(s){return new Promise(function(a,c){s=e[i](s),n(a,c,s.done,s.value)})}}function n(i,s,a,c){Promise.resolve(c).then(function(p){i({value:p,done:a})},s)}}function I(e){return typeof e=="function"}function yt(e){var t=function(o){Error.call(o),o.stack=new Error().stack},r=e(t);return r.prototype=Object.create(Error.prototype),r.prototype.constructor=r,r}var Jt=yt(function(e){return function(r){e(this),this.message=r?r.length+` errors occurred during unsubscription: -`+r.map(function(o,n){return n+1+") "+o.toString()}).join(` - `):"",this.name="UnsubscriptionError",this.errors=r}});function Ze(e,t){if(e){var r=e.indexOf(t);0<=r&&e.splice(r,1)}}var qe=(function(){function e(t){this.initialTeardown=t,this.closed=!1,this._parentage=null,this._finalizers=null}return e.prototype.unsubscribe=function(){var t,r,o,n,i;if(!this.closed){this.closed=!0;var s=this._parentage;if(s)if(this._parentage=null,Array.isArray(s))try{for(var a=Oe(s),c=a.next();!c.done;c=a.next()){var p=c.value;p.remove(this)}}catch(S){t={error:S}}finally{try{c&&!c.done&&(r=a.return)&&r.call(a)}finally{if(t)throw t.error}}else s.remove(this);var l=this.initialTeardown;if(I(l))try{l()}catch(S){i=S instanceof Jt?S.errors:[S]}var f=this._finalizers;if(f){this._finalizers=null;try{for(var u=Oe(f),d=u.next();!d.done;d=u.next()){var v=d.value;try{So(v)}catch(S){i=i!=null?i:[],S instanceof Jt?i=B(B([],K(i)),K(S.errors)):i.push(S)}}}catch(S){o={error:S}}finally{try{d&&!d.done&&(n=u.return)&&n.call(u)}finally{if(o)throw o.error}}}if(i)throw new Jt(i)}},e.prototype.add=function(t){var r;if(t&&t!==this)if(this.closed)So(t);else{if(t instanceof e){if(t.closed||t._hasParent(this))return;t._addParent(this)}(this._finalizers=(r=this._finalizers)!==null&&r!==void 0?r:[]).push(t)}},e.prototype._hasParent=function(t){var r=this._parentage;return r===t||Array.isArray(r)&&r.includes(t)},e.prototype._addParent=function(t){var r=this._parentage;this._parentage=Array.isArray(r)?(r.push(t),r):r?[r,t]:t},e.prototype._removeParent=function(t){var r=this._parentage;r===t?this._parentage=null:Array.isArray(r)&&Ze(r,t)},e.prototype.remove=function(t){var r=this._finalizers;r&&Ze(r,t),t instanceof e&&t._removeParent(this)},e.EMPTY=(function(){var t=new e;return t.closed=!0,t})(),e})();var $r=qe.EMPTY;function Xt(e){return e instanceof qe||e&&"closed"in e&&I(e.remove)&&I(e.add)&&I(e.unsubscribe)}function So(e){I(e)?e():e.unsubscribe()}var De={onUnhandledError:null,onStoppedNotification:null,Promise:void 0,useDeprecatedSynchronousErrorHandling:!1,useDeprecatedNextContext:!1};var xt={setTimeout:function(e,t){for(var r=[],o=2;o0},enumerable:!1,configurable:!0}),t.prototype._trySubscribe=function(r){return this._throwIfClosed(),e.prototype._trySubscribe.call(this,r)},t.prototype._subscribe=function(r){return this._throwIfClosed(),this._checkFinalizedStatuses(r),this._innerSubscribe(r)},t.prototype._innerSubscribe=function(r){var o=this,n=this,i=n.hasError,s=n.isStopped,a=n.observers;return i||s?$r:(this.currentObservers=null,a.push(r),new qe(function(){o.currentObservers=null,Ze(a,r)}))},t.prototype._checkFinalizedStatuses=function(r){var o=this,n=o.hasError,i=o.thrownError,s=o.isStopped;n?r.error(i):s&&r.complete()},t.prototype.asObservable=function(){var r=new F;return r.source=this,r},t.create=function(r,o){return new Ho(r,o)},t})(F);var Ho=(function(e){ie(t,e);function t(r,o){var n=e.call(this)||this;return n.destination=r,n.source=o,n}return t.prototype.next=function(r){var o,n;(n=(o=this.destination)===null||o===void 0?void 0:o.next)===null||n===void 0||n.call(o,r)},t.prototype.error=function(r){var o,n;(n=(o=this.destination)===null||o===void 0?void 0:o.error)===null||n===void 0||n.call(o,r)},t.prototype.complete=function(){var r,o;(o=(r=this.destination)===null||r===void 0?void 0:r.complete)===null||o===void 0||o.call(r)},t.prototype._subscribe=function(r){var o,n;return(n=(o=this.source)===null||o===void 0?void 0:o.subscribe(r))!==null&&n!==void 0?n:$r},t})(T);var jr=(function(e){ie(t,e);function t(r){var o=e.call(this)||this;return o._value=r,o}return Object.defineProperty(t.prototype,"value",{get:function(){return this.getValue()},enumerable:!1,configurable:!0}),t.prototype._subscribe=function(r){var o=e.prototype._subscribe.call(this,r);return!o.closed&&r.next(this._value),o},t.prototype.getValue=function(){var r=this,o=r.hasError,n=r.thrownError,i=r._value;if(o)throw n;return this._throwIfClosed(),i},t.prototype.next=function(r){e.prototype.next.call(this,this._value=r)},t})(T);var Rt={now:function(){return(Rt.delegate||Date).now()},delegate:void 0};var It=(function(e){ie(t,e);function t(r,o,n){r===void 0&&(r=1/0),o===void 0&&(o=1/0),n===void 0&&(n=Rt);var i=e.call(this)||this;return i._bufferSize=r,i._windowTime=o,i._timestampProvider=n,i._buffer=[],i._infiniteTimeWindow=!0,i._infiniteTimeWindow=o===1/0,i._bufferSize=Math.max(1,r),i._windowTime=Math.max(1,o),i}return t.prototype.next=function(r){var o=this,n=o.isStopped,i=o._buffer,s=o._infiniteTimeWindow,a=o._timestampProvider,c=o._windowTime;n||(i.push(r),!s&&i.push(a.now()+c)),this._trimBuffer(),e.prototype.next.call(this,r)},t.prototype._subscribe=function(r){this._throwIfClosed(),this._trimBuffer();for(var o=this._innerSubscribe(r),n=this,i=n._infiniteTimeWindow,s=n._buffer,a=s.slice(),c=0;c0?e.prototype.schedule.call(this,r,o):(this.delay=o,this.state=r,this.scheduler.flush(this),this)},t.prototype.execute=function(r,o){return o>0||this.closed?e.prototype.execute.call(this,r,o):this._execute(r,o)},t.prototype.requestAsyncId=function(r,o,n){return n===void 0&&(n=0),n!=null&&n>0||n==null&&this.delay>0?e.prototype.requestAsyncId.call(this,r,o,n):(r.flush(this),0)},t})(St);var Ro=(function(e){ie(t,e);function t(){return e!==null&&e.apply(this,arguments)||this}return t})(Ot);var Dr=new Ro(Po);var Io=(function(e){ie(t,e);function t(r,o){var n=e.call(this,r,o)||this;return n.scheduler=r,n.work=o,n}return t.prototype.requestAsyncId=function(r,o,n){return n===void 0&&(n=0),n!==null&&n>0?e.prototype.requestAsyncId.call(this,r,o,n):(r.actions.push(this),r._scheduled||(r._scheduled=Tt.requestAnimationFrame(function(){return r.flush(void 0)})))},t.prototype.recycleAsyncId=function(r,o,n){var i;if(n===void 0&&(n=0),n!=null?n>0:this.delay>0)return e.prototype.recycleAsyncId.call(this,r,o,n);var s=r.actions;o!=null&&o===r._scheduled&&((i=s[s.length-1])===null||i===void 0?void 0:i.id)!==o&&(Tt.cancelAnimationFrame(o),r._scheduled=void 0)},t})(St);var Fo=(function(e){ie(t,e);function t(){return e!==null&&e.apply(this,arguments)||this}return t.prototype.flush=function(r){this._active=!0;var o;r?o=r.id:(o=this._scheduled,this._scheduled=void 0);var n=this.actions,i;r=r||n.shift();do if(i=r.execute(r.state,r.delay))break;while((r=n[0])&&r.id===o&&n.shift());if(this._active=!1,i){for(;(r=n[0])&&r.id===o&&n.shift();)r.unsubscribe();throw i}},t})(Ot);var ye=new Fo(Io);var y=new F(function(e){return e.complete()});function tr(e){return e&&I(e.schedule)}function Vr(e){return e[e.length-1]}function pt(e){return I(Vr(e))?e.pop():void 0}function Fe(e){return tr(Vr(e))?e.pop():void 0}function rr(e,t){return typeof Vr(e)=="number"?e.pop():t}var Lt=(function(e){return e&&typeof e.length=="number"&&typeof e!="function"});function or(e){return I(e==null?void 0:e.then)}function nr(e){return I(e[wt])}function ir(e){return Symbol.asyncIterator&&I(e==null?void 0:e[Symbol.asyncIterator])}function ar(e){return new TypeError("You provided "+(e!==null&&typeof e=="object"?"an invalid object":"'"+e+"'")+" where a stream was expected. You can provide an Observable, Promise, ReadableStream, Array, AsyncIterable, or Iterable.")}function fa(){return typeof Symbol!="function"||!Symbol.iterator?"@@iterator":Symbol.iterator}var sr=fa();function cr(e){return I(e==null?void 0:e[sr])}function pr(e){return wo(this,arguments,function(){var r,o,n,i;return Gt(this,function(s){switch(s.label){case 0:r=e.getReader(),s.label=1;case 1:s.trys.push([1,,9,10]),s.label=2;case 2:return[4,dt(r.read())];case 3:return o=s.sent(),n=o.value,i=o.done,i?[4,dt(void 0)]:[3,5];case 4:return[2,s.sent()];case 5:return[4,dt(n)];case 6:return[4,s.sent()];case 7:return s.sent(),[3,2];case 8:return[3,10];case 9:return r.releaseLock(),[7];case 10:return[2]}})})}function lr(e){return I(e==null?void 0:e.getReader)}function U(e){if(e instanceof F)return e;if(e!=null){if(nr(e))return ua(e);if(Lt(e))return da(e);if(or(e))return ha(e);if(ir(e))return jo(e);if(cr(e))return ba(e);if(lr(e))return va(e)}throw ar(e)}function ua(e){return new F(function(t){var r=e[wt]();if(I(r.subscribe))return r.subscribe(t);throw new TypeError("Provided object does not correctly implement Symbol.observable")})}function da(e){return new F(function(t){for(var r=0;r=2;return function(o){return o.pipe(e?g(function(n,i){return e(n,i,o)}):be,Ee(1),r?Qe(t):tn(function(){return new fr}))}}function Yr(e){return e<=0?function(){return y}:E(function(t,r){var o=[];t.subscribe(w(r,function(n){o.push(n),e=2,!0))}function le(e){e===void 0&&(e={});var t=e.connector,r=t===void 0?function(){return new T}:t,o=e.resetOnError,n=o===void 0?!0:o,i=e.resetOnComplete,s=i===void 0?!0:i,a=e.resetOnRefCountZero,c=a===void 0?!0:a;return function(p){var l,f,u,d=0,v=!1,S=!1,X=function(){f==null||f.unsubscribe(),f=void 0},re=function(){X(),l=u=void 0,v=S=!1},ee=function(){var k=l;re(),k==null||k.unsubscribe()};return E(function(k,ut){d++,!S&&!v&&X();var je=u=u!=null?u:r();ut.add(function(){d--,d===0&&!S&&!v&&(f=Br(ee,c))}),je.subscribe(ut),!l&&d>0&&(l=new bt({next:function(R){return je.next(R)},error:function(R){S=!0,X(),f=Br(re,n,R),je.error(R)},complete:function(){v=!0,X(),f=Br(re,s),je.complete()}}),U(k).subscribe(l))})(p)}}function Br(e,t){for(var r=[],o=2;oe.next(document)),e}function M(e,t=document){return Array.from(t.querySelectorAll(e))}function j(e,t=document){let r=ue(e,t);if(typeof r=="undefined")throw new ReferenceError(`Missing element: expected "${e}" to be present`);return r}function ue(e,t=document){return t.querySelector(e)||void 0}function Ne(){var e,t,r,o;return(o=(r=(t=(e=document.activeElement)==null?void 0:e.shadowRoot)==null?void 0:t.activeElement)!=null?r:document.activeElement)!=null?o:void 0}var Ra=L(h(document.body,"focusin"),h(document.body,"focusout")).pipe(Ae(1),Q(void 0),m(()=>Ne()||document.body),Z(1));function Ye(e){return Ra.pipe(m(t=>e.contains(t)),Y())}function it(e,t){return H(()=>L(h(e,"mouseenter").pipe(m(()=>!0)),h(e,"mouseleave").pipe(m(()=>!1))).pipe(t?jt(r=>He(+!r*t)):be,Q(e.matches(":hover"))))}function sn(e,t){if(typeof t=="string"||typeof t=="number")e.innerHTML+=t.toString();else if(t instanceof Node)e.appendChild(t);else if(Array.isArray(t))for(let r of t)sn(e,r)}function x(e,t,...r){let o=document.createElement(e);if(t)for(let n of Object.keys(t))typeof t[n]!="undefined"&&(typeof t[n]!="boolean"?o.setAttribute(n,t[n]):o.setAttribute(n,""));for(let n of r)sn(o,n);return o}function br(e){if(e>999){let t=+((e-950)%1e3>99);return`${((e+1e-6)/1e3).toFixed(t)}k`}else return e.toString()}function _t(e){let t=x("script",{src:e});return H(()=>(document.head.appendChild(t),L(h(t,"load"),h(t,"error").pipe(b(()=>Nr(()=>new ReferenceError(`Invalid script: ${e}`))))).pipe(m(()=>{}),A(()=>document.head.removeChild(t)),Ee(1))))}var cn=new T,Ia=H(()=>typeof ResizeObserver=="undefined"?_t("https://unpkg.com/resize-observer-polyfill"):$(void 0)).pipe(m(()=>new ResizeObserver(e=>e.forEach(t=>cn.next(t)))),b(e=>L(tt,$(e)).pipe(A(()=>e.disconnect()))),Z(1));function de(e){return{width:e.offsetWidth,height:e.offsetHeight}}function Le(e){let t=e;for(;t.clientWidth===0&&t.parentElement;)t=t.parentElement;return Ia.pipe(O(r=>r.observe(t)),b(r=>cn.pipe(g(o=>o.target===t),A(()=>r.unobserve(t)))),m(()=>de(e)),Q(de(e)))}function At(e){return{width:e.scrollWidth,height:e.scrollHeight}}function vr(e){let t=e.parentElement;for(;t&&(e.scrollWidth<=t.scrollWidth&&e.scrollHeight<=t.scrollHeight);)t=(e=t).parentElement;return t?e:void 0}function pn(e){let t=[],r=e.parentElement;for(;r;)(e.clientWidth>r.clientWidth||e.clientHeight>r.clientHeight)&&t.push(r),r=(e=r).parentElement;return t.length===0&&t.push(document.documentElement),t}function Be(e){return{x:e.offsetLeft,y:e.offsetTop}}function ln(e){let t=e.getBoundingClientRect();return{x:t.x+window.scrollX,y:t.y+window.scrollY}}function mn(e){return L(h(window,"load"),h(window,"resize")).pipe($e(0,ye),m(()=>Be(e)),Q(Be(e)))}function gr(e){return{x:e.scrollLeft,y:e.scrollTop}}function Ge(e){return L(h(e,"scroll"),h(window,"scroll"),h(window,"resize")).pipe($e(0,ye),m(()=>gr(e)),Q(gr(e)))}var fn=new T,Fa=H(()=>$(new IntersectionObserver(e=>{for(let t of e)fn.next(t)},{threshold:0}))).pipe(b(e=>L(tt,$(e)).pipe(A(()=>e.disconnect()))),Z(1));function mt(e){return Fa.pipe(O(t=>t.observe(e)),b(t=>fn.pipe(g(({target:r})=>r===e),A(()=>t.unobserve(e)),m(({isIntersecting:r})=>r))))}function un(e,t=16){return Ge(e).pipe(m(({y:r})=>{let o=de(e),n=At(e);return r>=n.height-o.height-t}),Y())}var yr={drawer:j("[data-md-toggle=drawer]"),search:j("[data-md-toggle=search]")};function dn(e){return yr[e].checked}function at(e,t){yr[e].checked!==t&&yr[e].click()}function Je(e){let t=yr[e];return h(t,"change").pipe(m(()=>t.checked),Q(t.checked))}function ja(e,t){switch(e.constructor){case HTMLInputElement:return e.type==="radio"?/^Arrow/.test(t):!0;case HTMLSelectElement:case HTMLTextAreaElement:return!0;default:return e.isContentEditable}}function Ua(){return L(h(window,"compositionstart").pipe(m(()=>!0)),h(window,"compositionend").pipe(m(()=>!1))).pipe(Q(!1))}function hn(){let e=h(window,"keydown").pipe(g(t=>!(t.metaKey||t.ctrlKey)),m(t=>({mode:dn("search")?"search":"global",type:t.key,claim(){t.preventDefault(),t.stopPropagation()}})),g(({mode:t,type:r})=>{if(t==="global"){let o=Ne();if(typeof o!="undefined")return!ja(o,r)}return!0}),le());return Ua().pipe(b(t=>t?y:e))}function we(){return new URL(location.href)}function st(e,t=!1){if(V("navigation.instant")&&!t){let r=x("a",{href:e.href});document.body.appendChild(r),r.click(),r.remove()}else location.href=e.href}function bn(){return new T}function vn(){return location.hash.slice(1)}function gn(e){let t=x("a",{href:e});t.addEventListener("click",r=>r.stopPropagation()),t.click()}function Zr(e){return L(h(window,"hashchange"),e).pipe(m(vn),Q(vn()),g(t=>t.length>0),Z(1))}function yn(e){return Zr(e).pipe(m(t=>ue(`[id="${t}"]`)),g(t=>typeof t!="undefined"))}function Wt(e){let t=matchMedia(e);return ur(r=>t.addListener(()=>r(t.matches))).pipe(Q(t.matches))}function xn(){let e=matchMedia("print");return L(h(window,"beforeprint").pipe(m(()=>!0)),h(window,"afterprint").pipe(m(()=>!1))).pipe(Q(e.matches))}function eo(e,t){return e.pipe(b(r=>r?t():y))}function to(e,t){return new F(r=>{let o=new XMLHttpRequest;return o.open("GET",`${e}`),o.responseType="blob",o.addEventListener("load",()=>{o.status>=200&&o.status<300?(r.next(o.response),r.complete()):r.error(new Error(o.statusText))}),o.addEventListener("error",()=>{r.error(new Error("Network error"))}),o.addEventListener("abort",()=>{r.complete()}),typeof(t==null?void 0:t.progress$)!="undefined"&&(o.addEventListener("progress",n=>{var i;if(n.lengthComputable)t.progress$.next(n.loaded/n.total*100);else{let s=(i=o.getResponseHeader("Content-Length"))!=null?i:0;t.progress$.next(n.loaded/+s*100)}}),t.progress$.next(5)),o.send(),()=>o.abort()})}function ze(e,t){return to(e,t).pipe(b(r=>r.text()),m(r=>JSON.parse(r)),Z(1))}function xr(e,t){let r=new DOMParser;return to(e,t).pipe(b(o=>o.text()),m(o=>r.parseFromString(o,"text/html")),Z(1))}function En(e,t){let r=new DOMParser;return to(e,t).pipe(b(o=>o.text()),m(o=>r.parseFromString(o,"text/xml")),Z(1))}function wn(){return{x:Math.max(0,scrollX),y:Math.max(0,scrollY)}}function Tn(){return L(h(window,"scroll",{passive:!0}),h(window,"resize",{passive:!0})).pipe(m(wn),Q(wn()))}function Sn(){return{width:innerWidth,height:innerHeight}}function On(){return h(window,"resize",{passive:!0}).pipe(m(Sn),Q(Sn()))}function Ln(){return z([Tn(),On()]).pipe(m(([e,t])=>({offset:e,size:t})),Z(1))}function Er(e,{viewport$:t,header$:r}){let o=t.pipe(ne("size")),n=z([o,r]).pipe(m(()=>Be(e)));return z([r,t,n]).pipe(m(([{height:i},{offset:s,size:a},{x:c,y:p}])=>({offset:{x:s.x-c,y:s.y-p+i},size:a})))}function Wa(e){return h(e,"message",t=>t.data)}function Da(e){let t=new T;return t.subscribe(r=>e.postMessage(r)),t}function Mn(e,t=new Worker(e)){let r=Wa(t),o=Da(t),n=new T;n.subscribe(o);let i=o.pipe(oe(),ae(!0));return n.pipe(oe(),Ve(r.pipe(W(i))),le())}var Va=j("#__config"),Ct=JSON.parse(Va.textContent);Ct.base=`${new URL(Ct.base,we())}`;function Te(){return Ct}function V(e){return Ct.features.includes(e)}function Me(e,t){return typeof t!="undefined"?Ct.translations[e].replace("#",t.toString()):Ct.translations[e]}function Ce(e,t=document){return j(`[data-md-component=${e}]`,t)}function me(e,t=document){return M(`[data-md-component=${e}]`,t)}function Na(e){let t=j(".md-typeset > :first-child",e);return h(t,"click",{once:!0}).pipe(m(()=>j(".md-typeset",e)),m(r=>({hash:__md_hash(r.innerHTML)})))}function _n(e){if(!V("announce.dismiss")||!e.childElementCount)return y;if(!e.hidden){let t=j(".md-typeset",e);__md_hash(t.innerHTML)===__md_get("__announce")&&(e.hidden=!0)}return H(()=>{let t=new T;return t.subscribe(({hash:r})=>{e.hidden=!0,__md_set("__announce",r)}),Na(e).pipe(O(r=>t.next(r)),A(()=>t.complete()),m(r=>P({ref:e},r)))})}function za(e,{target$:t}){return t.pipe(m(r=>({hidden:r!==e})))}function An(e,t){let r=new T;return r.subscribe(({hidden:o})=>{e.hidden=o}),za(e,t).pipe(O(o=>r.next(o)),A(()=>r.complete()),m(o=>P({ref:e},o)))}function Dt(e,t){return t==="inline"?x("div",{class:"md-tooltip md-tooltip--inline",id:e,role:"tooltip"},x("div",{class:"md-tooltip__inner md-typeset"})):x("div",{class:"md-tooltip",id:e,role:"tooltip"},x("div",{class:"md-tooltip__inner md-typeset"}))}function wr(...e){return x("div",{class:"md-tooltip2",role:"dialog"},x("div",{class:"md-tooltip2__inner md-typeset"},e))}function Cn(...e){return x("div",{class:"md-tooltip2",role:"tooltip"},x("div",{class:"md-tooltip2__inner md-typeset"},e))}function kn(e,t){if(t=t?`${t}_annotation_${e}`:void 0,t){let r=t?`#${t}`:void 0;return x("aside",{class:"md-annotation",tabIndex:0},Dt(t),x("a",{href:r,class:"md-annotation__index",tabIndex:-1},x("span",{"data-md-annotation-id":e})))}else return x("aside",{class:"md-annotation",tabIndex:0},Dt(t),x("span",{class:"md-annotation__index",tabIndex:-1},x("span",{"data-md-annotation-id":e})))}function Hn(e){return x("button",{class:"md-code__button",title:Me("clipboard.copy"),"data-clipboard-target":`#${e} > code`,"data-md-type":"copy"})}function $n(){return x("button",{class:"md-code__button",title:"Toggle line selection","data-md-type":"select"})}function Pn(){return x("nav",{class:"md-code__nav"})}var In=$t(ro());function oo(e,t){let r=t&2,o=t&1,n=Object.keys(e.terms).filter(c=>!e.terms[c]).reduce((c,p)=>[...c,x("del",null,(0,In.default)(p))," "],[]).slice(0,-1),i=Te(),s=new URL(e.location,i.base);V("search.highlight")&&s.searchParams.set("h",Object.entries(e.terms).filter(([,c])=>c).reduce((c,[p])=>`${c} ${p}`.trim(),""));let{tags:a}=Te();return x("a",{href:`${s}`,class:"md-search-result__link",tabIndex:-1},x("article",{class:"md-search-result__article md-typeset","data-md-score":e.score.toFixed(2)},r>0&&x("div",{class:"md-search-result__icon md-icon"}),r>0&&x("h1",null,e.title),r<=0&&x("h2",null,e.title),o>0&&e.text.length>0&&e.text,e.tags&&x("nav",{class:"md-tags"},e.tags.map(c=>{let p=a?c in a?`md-tag-icon md-tag--${a[c]}`:"md-tag-icon":"";return x("span",{class:`md-tag ${p}`},c)})),o>0&&n.length>0&&x("p",{class:"md-search-result__terms"},Me("search.result.term.missing"),": ",...n)))}function Fn(e){let t=e[0].score,r=[...e],o=Te(),n=r.findIndex(l=>!`${new URL(l.location,o.base)}`.includes("#")),[i]=r.splice(n,1),s=r.findIndex(l=>l.scoreoo(l,1)),...c.length?[x("details",{class:"md-search-result__more"},x("summary",{tabIndex:-1},x("div",null,c.length>0&&c.length===1?Me("search.result.more.one"):Me("search.result.more.other",c.length))),...c.map(l=>oo(l,1)))]:[]];return x("li",{class:"md-search-result__item"},p)}function jn(e){return x("ul",{class:"md-source__facts"},Object.entries(e).map(([t,r])=>x("li",{class:`md-source__fact md-source__fact--${t}`},typeof r=="number"?br(r):r)))}function no(e){let t=`tabbed-control tabbed-control--${e}`;return x("div",{class:t,hidden:!0},x("button",{class:"tabbed-button",tabIndex:-1,"aria-hidden":"true"}))}function Un(e){return x("div",{class:"md-typeset__scrollwrap"},x("div",{class:"md-typeset__table"},e))}function Qa(e){var o;let t=Te(),r=new URL(`../${e.version}/`,t.base);return x("li",{class:"md-version__item"},x("a",{href:`${r}`,class:"md-version__link"},e.title,((o=t.version)==null?void 0:o.alias)&&e.aliases.length>0&&x("span",{class:"md-version__alias"},e.aliases[0])))}function Wn(e,t){var o;let r=Te();return e=e.filter(n=>{var i;return!((i=n.properties)!=null&&i.hidden)}),x("div",{class:"md-version"},x("button",{class:"md-version__current","aria-label":Me("select.version")},t.title,((o=r.version)==null?void 0:o.alias)&&t.aliases.length>0&&x("span",{class:"md-version__alias"},t.aliases[0])),x("ul",{class:"md-version__list"},e.map(Qa)))}var Ya=0;function Ba(e,t=250){let r=z([Ye(e),it(e,t)]).pipe(m(([n,i])=>n||i),Y()),o=H(()=>pn(e)).pipe(J(Ge),gt(1),Pe(r),m(()=>ln(e)));return r.pipe(Re(n=>n),b(()=>z([r,o])),m(([n,i])=>({active:n,offset:i})),le())}function Vt(e,t,r=250){let{content$:o,viewport$:n}=t,i=`__tooltip2_${Ya++}`;return H(()=>{let s=new T,a=new jr(!1);s.pipe(oe(),ae(!1)).subscribe(a);let c=a.pipe(jt(l=>He(+!l*250,Dr)),Y(),b(l=>l?o:y),O(l=>l.id=i),le());z([s.pipe(m(({active:l})=>l)),c.pipe(b(l=>it(l,250)),Q(!1))]).pipe(m(l=>l.some(f=>f))).subscribe(a);let p=a.pipe(g(l=>l),te(c,n),m(([l,f,{size:u}])=>{let d=e.getBoundingClientRect(),v=d.width/2;if(f.role==="tooltip")return{x:v,y:8+d.height};if(d.y>=u.height/2){let{height:S}=de(f);return{x:v,y:-16-S}}else return{x:v,y:16+d.height}}));return z([c,s,p]).subscribe(([l,{offset:f},u])=>{l.style.setProperty("--md-tooltip-host-x",`${f.x}px`),l.style.setProperty("--md-tooltip-host-y",`${f.y}px`),l.style.setProperty("--md-tooltip-x",`${u.x}px`),l.style.setProperty("--md-tooltip-y",`${u.y}px`),l.classList.toggle("md-tooltip2--top",u.y<0),l.classList.toggle("md-tooltip2--bottom",u.y>=0)}),a.pipe(g(l=>l),te(c,(l,f)=>f),g(l=>l.role==="tooltip")).subscribe(l=>{let f=de(j(":scope > *",l));l.style.setProperty("--md-tooltip-width",`${f.width}px`),l.style.setProperty("--md-tooltip-tail","0px")}),a.pipe(Y(),xe(ye),te(c)).subscribe(([l,f])=>{f.classList.toggle("md-tooltip2--active",l)}),z([a.pipe(g(l=>l)),c]).subscribe(([l,f])=>{f.role==="dialog"?(e.setAttribute("aria-controls",i),e.setAttribute("aria-haspopup","dialog")):e.setAttribute("aria-describedby",i)}),a.pipe(g(l=>!l)).subscribe(()=>{e.removeAttribute("aria-controls"),e.removeAttribute("aria-describedby"),e.removeAttribute("aria-haspopup")}),Ba(e,r).pipe(O(l=>s.next(l)),A(()=>s.complete()),m(l=>P({ref:e},l)))})}function Xe(e,{viewport$:t},r=document.body){return Vt(e,{content$:new F(o=>{let n=e.title,i=Cn(n);return o.next(i),e.removeAttribute("title"),r.append(i),()=>{i.remove(),e.setAttribute("title",n)}}),viewport$:t},0)}function Ga(e,t){let r=H(()=>z([mn(e),Ge(t)])).pipe(m(([{x:o,y:n},i])=>{let{width:s,height:a}=de(e);return{x:o-i.x+s/2,y:n-i.y+a/2}}));return Ye(e).pipe(b(o=>r.pipe(m(n=>({active:o,offset:n})),Ee(+!o||1/0))))}function Dn(e,t,{target$:r}){let[o,n]=Array.from(e.children);return H(()=>{let i=new T,s=i.pipe(oe(),ae(!0));return i.subscribe({next({offset:a}){e.style.setProperty("--md-tooltip-x",`${a.x}px`),e.style.setProperty("--md-tooltip-y",`${a.y}px`)},complete(){e.style.removeProperty("--md-tooltip-x"),e.style.removeProperty("--md-tooltip-y")}}),mt(e).pipe(W(s)).subscribe(a=>{e.toggleAttribute("data-md-visible",a)}),L(i.pipe(g(({active:a})=>a)),i.pipe(Ae(250),g(({active:a})=>!a))).subscribe({next({active:a}){a?e.prepend(o):o.remove()},complete(){e.prepend(o)}}),i.pipe($e(16,ye)).subscribe(({active:a})=>{o.classList.toggle("md-tooltip--active",a)}),i.pipe(gt(125,ye),g(()=>!!e.offsetParent),m(()=>e.offsetParent.getBoundingClientRect()),m(({x:a})=>a)).subscribe({next(a){a?e.style.setProperty("--md-tooltip-0",`${-a}px`):e.style.removeProperty("--md-tooltip-0")},complete(){e.style.removeProperty("--md-tooltip-0")}}),h(n,"click").pipe(W(s),g(a=>!(a.metaKey||a.ctrlKey))).subscribe(a=>{a.stopPropagation(),a.preventDefault()}),h(n,"mousedown").pipe(W(s),te(i)).subscribe(([a,{active:c}])=>{var p;if(a.button!==0||a.metaKey||a.ctrlKey)a.preventDefault();else if(c){a.preventDefault();let l=e.parentElement.closest(".md-annotation");l instanceof HTMLElement?l.focus():(p=Ne())==null||p.blur()}}),r.pipe(W(s),g(a=>a===o),nt(125)).subscribe(()=>e.focus()),Ga(e,t).pipe(O(a=>i.next(a)),A(()=>i.complete()),m(a=>P({ref:e},a)))})}function Ja(e){let t=Te();if(e.tagName!=="CODE")return[e];let r=[".c",".c1",".cm"];if(t.annotate&&typeof t.annotate=="object"){let o=e.closest("[class|=language]");if(o)for(let n of Array.from(o.classList)){if(!n.startsWith("language-"))continue;let[,i]=n.split("-");i in t.annotate&&r.push(...t.annotate[i])}}return M(r.join(", "),e)}function Xa(e){let t=[];for(let r of Ja(e)){let o=[],n=document.createNodeIterator(r,NodeFilter.SHOW_TEXT);for(let i=n.nextNode();i;i=n.nextNode())o.push(i);for(let i of o){let s;for(;s=/(\(\d+\))(!)?/.exec(i.textContent);){let[,a,c]=s;if(typeof c=="undefined"){let p=i.splitText(s.index);i=p.splitText(a.length),t.push(p)}else{i.textContent=a,t.push(i);break}}}}return t}function Vn(e,t){t.append(...Array.from(e.childNodes))}function Tr(e,t,{target$:r,print$:o}){let n=t.closest("[id]"),i=n==null?void 0:n.id,s=new Map;for(let a of Xa(t)){let[,c]=a.textContent.match(/\((\d+)\)/);ue(`:scope > li:nth-child(${c})`,e)&&(s.set(c,kn(c,i)),a.replaceWith(s.get(c)))}return s.size===0?y:H(()=>{let a=new T,c=a.pipe(oe(),ae(!0)),p=[];for(let[l,f]of s)p.push([j(".md-typeset",f),j(`:scope > li:nth-child(${l})`,e)]);return o.pipe(W(c)).subscribe(l=>{e.hidden=!l,e.classList.toggle("md-annotation-list",l);for(let[f,u]of p)l?Vn(f,u):Vn(u,f)}),L(...[...s].map(([,l])=>Dn(l,t,{target$:r}))).pipe(A(()=>a.complete()),le())})}function Nn(e){if(e.nextElementSibling){let t=e.nextElementSibling;if(t.tagName==="OL")return t;if(t.tagName==="P"&&!t.children.length)return Nn(t)}}function zn(e,t){return H(()=>{let r=Nn(e);return typeof r!="undefined"?Tr(r,e,t):y})}var Kn=$t(ao());var Za=0,qn=L(h(window,"keydown").pipe(m(()=>!0)),L(h(window,"keyup"),h(window,"contextmenu")).pipe(m(()=>!1))).pipe(Q(!1),Z(1));function Qn(e){if(e.nextElementSibling){let t=e.nextElementSibling;if(t.tagName==="OL")return t;if(t.tagName==="P"&&!t.children.length)return Qn(t)}}function es(e){return Le(e).pipe(m(({width:t})=>({scrollable:At(e).width>t})),ne("scrollable"))}function Yn(e,t){let{matches:r}=matchMedia("(hover)"),o=H(()=>{let n=new T,i=n.pipe(Yr(1));n.subscribe(({scrollable:d})=>{d&&r?e.setAttribute("tabindex","0"):e.removeAttribute("tabindex")});let s=[],a=e.closest("pre"),c=a.closest("[id]"),p=c?c.id:Za++;a.id=`__code_${p}`;let l=[],f=e.closest(".highlight");if(f instanceof HTMLElement){let d=Qn(f);if(typeof d!="undefined"&&(f.classList.contains("annotate")||V("content.code.annotate"))){let v=Tr(d,e,t);l.push(Le(f).pipe(W(i),m(({width:S,height:X})=>S&&X),Y(),b(S=>S?v:y)))}}let u=M(":scope > span[id]",e);if(u.length&&(e.classList.add("md-code__content"),e.closest(".select")||V("content.code.select")&&!e.closest(".no-select"))){let d=+u[0].id.split("-").pop(),v=$n();s.push(v),V("content.tooltips")&&l.push(Xe(v,{viewport$}));let S=h(v,"click").pipe(Ut(R=>!R,!1),O(()=>v.blur()),le());S.subscribe(R=>{v.classList.toggle("md-code__button--active",R)});let X=fe(u).pipe(J(R=>it(R).pipe(m(se=>[R,se]))));S.pipe(b(R=>R?X:y)).subscribe(([R,se])=>{let ce=ue(".hll.select",R);if(ce&&!se)ce.replaceWith(...Array.from(ce.childNodes));else if(!ce&&se){let he=document.createElement("span");he.className="hll select",he.append(...Array.from(R.childNodes).slice(1)),R.append(he)}});let re=fe(u).pipe(J(R=>h(R,"mousedown").pipe(O(se=>se.preventDefault()),m(()=>R)))),ee=S.pipe(b(R=>R?re:y),te(qn),m(([R,se])=>{var he;let ce=u.indexOf(R)+d;if(se===!1)return[ce,ce];{let Se=M(".hll",e).map(Ue=>u.indexOf(Ue.parentElement)+d);return(he=window.getSelection())==null||he.removeAllRanges(),[Math.min(ce,...Se),Math.max(ce,...Se)]}})),k=Zr(y).pipe(g(R=>R.startsWith(`__codelineno-${p}-`)));k.subscribe(R=>{let[,,se]=R.split("-"),ce=se.split(":").map(Se=>+Se-d+1);ce.length===1&&ce.push(ce[0]);for(let Se of M(".hll:not(.select)",e))Se.replaceWith(...Array.from(Se.childNodes));let he=u.slice(ce[0]-1,ce[1]);for(let Se of he){let Ue=document.createElement("span");Ue.className="hll",Ue.append(...Array.from(Se.childNodes).slice(1)),Se.append(Ue)}}),k.pipe(Ee(1),xe(pe)).subscribe(R=>{if(R.includes(":")){let se=document.getElementById(R.split(":")[0]);se&&setTimeout(()=>{let ce=se,he=-64;for(;ce!==document.body;)he+=ce.offsetTop,ce=ce.offsetParent;window.scrollTo({top:he})},1)}});let je=fe(M('a[href^="#__codelineno"]',f)).pipe(J(R=>h(R,"click").pipe(O(se=>se.preventDefault()),m(()=>R)))).pipe(W(i),te(qn),m(([R,se])=>{let he=+j(`[id="${R.hash.slice(1)}"]`).parentElement.id.split("-").pop();if(se===!1)return[he,he];{let Se=M(".hll",e).map(Ue=>+Ue.parentElement.id.split("-").pop());return[Math.min(he,...Se),Math.max(he,...Se)]}}));L(ee,je).subscribe(R=>{let se=`#__codelineno-${p}-`;R[0]===R[1]?se+=R[0]:se+=`${R[0]}:${R[1]}`,history.replaceState({},"",se),window.dispatchEvent(new HashChangeEvent("hashchange",{newURL:window.location.origin+window.location.pathname+se,oldURL:window.location.href}))})}if(Kn.default.isSupported()&&(e.closest(".copy")||V("content.code.copy")&&!e.closest(".no-copy"))){let d=Hn(a.id);s.push(d),V("content.tooltips")&&l.push(Xe(d,{viewport$}))}if(s.length){let d=Pn();d.append(...s),a.insertBefore(d,e)}return es(e).pipe(O(d=>n.next(d)),A(()=>n.complete()),m(d=>P({ref:e},d)),Ve(L(...l).pipe(W(i))))});return V("content.lazy")?mt(e).pipe(g(n=>n),Ee(1),b(()=>o)):o}function ts(e,{target$:t,print$:r}){let o=!0;return L(t.pipe(m(n=>n.closest("details:not([open])")),g(n=>e===n),m(()=>({action:"open",reveal:!0}))),r.pipe(g(n=>n||!o),O(()=>o=e.open),m(n=>({action:n?"open":"close"}))))}function Bn(e,t){return H(()=>{let r=new T;return r.subscribe(({action:o,reveal:n})=>{e.toggleAttribute("open",o==="open"),n&&e.scrollIntoView()}),ts(e,t).pipe(O(o=>r.next(o)),A(()=>r.complete()),m(o=>P({ref:e},o)))})}var Gn=0;function rs(e){let t=document.createElement("h3");t.innerHTML=e.innerHTML;let r=[t],o=e.nextElementSibling;for(;o&&!(o instanceof HTMLHeadingElement);)r.push(o),o=o.nextElementSibling;return r}function os(e,t){for(let r of M("[href], [src]",e))for(let o of["href","src"]){let n=r.getAttribute(o);if(n&&!/^(?:[a-z]+:)?\/\//i.test(n)){r[o]=new URL(r.getAttribute(o),t).toString();break}}for(let r of M("[name^=__], [for]",e))for(let o of["id","for","name"]){let n=r.getAttribute(o);n&&r.setAttribute(o,`${n}$preview_${Gn}`)}return Gn++,$(e)}function Jn(e,t){let{sitemap$:r}=t;if(!(e instanceof HTMLAnchorElement))return y;if(!(V("navigation.instant.preview")||e.hasAttribute("data-preview")))return y;e.removeAttribute("title");let o=z([Ye(e),it(e)]).pipe(m(([i,s])=>i||s),Y(),g(i=>i));return rt([r,o]).pipe(b(([i])=>{let s=new URL(e.href);return s.search=s.hash="",i.has(`${s}`)?$(s):y}),b(i=>xr(i).pipe(b(s=>os(s,i)))),b(i=>{let s=e.hash?`article [id="${e.hash.slice(1)}"]`:"article h1",a=ue(s,i);return typeof a=="undefined"?y:$(rs(a))})).pipe(b(i=>{let s=new F(a=>{let c=wr(...i);return a.next(c),document.body.append(c),()=>c.remove()});return Vt(e,P({content$:s},t))}))}var Xn=".node circle,.node ellipse,.node path,.node polygon,.node rect{fill:var(--md-mermaid-node-bg-color);stroke:var(--md-mermaid-node-fg-color)}marker{fill:var(--md-mermaid-edge-color)!important}.edgeLabel .label rect{fill:#0000}.flowchartTitleText{fill:var(--md-mermaid-label-fg-color)}.label{color:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}.label foreignObject{line-height:normal;overflow:visible}.label div .edgeLabel{color:var(--md-mermaid-label-fg-color)}.edgeLabel,.edgeLabel p,.label div .edgeLabel{background-color:var(--md-mermaid-label-bg-color)}.edgeLabel,.edgeLabel p{fill:var(--md-mermaid-label-bg-color);color:var(--md-mermaid-edge-color)}.edgePath .path,.flowchart-link{stroke:var(--md-mermaid-edge-color)}.edgePath .arrowheadPath{fill:var(--md-mermaid-edge-color);stroke:none}.cluster rect{fill:var(--md-default-fg-color--lightest);stroke:var(--md-default-fg-color--lighter)}.cluster span{color:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}g #flowchart-circleEnd,g #flowchart-circleStart,g #flowchart-crossEnd,g #flowchart-crossStart,g #flowchart-pointEnd,g #flowchart-pointStart{stroke:none}.classDiagramTitleText{fill:var(--md-mermaid-label-fg-color)}g.classGroup line,g.classGroup rect{fill:var(--md-mermaid-node-bg-color);stroke:var(--md-mermaid-node-fg-color)}g.classGroup text{fill:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}.classLabel .box{fill:var(--md-mermaid-label-bg-color);background-color:var(--md-mermaid-label-bg-color);opacity:1}.classLabel .label{fill:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}.node .divider{stroke:var(--md-mermaid-node-fg-color)}.relation{stroke:var(--md-mermaid-edge-color)}.cardinality{fill:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}.cardinality text{fill:inherit!important}defs marker.marker.composition.class path,defs marker.marker.dependency.class path,defs marker.marker.extension.class path{fill:var(--md-mermaid-edge-color)!important;stroke:var(--md-mermaid-edge-color)!important}defs marker.marker.aggregation.class path{fill:var(--md-mermaid-label-bg-color)!important;stroke:var(--md-mermaid-edge-color)!important}.statediagramTitleText{fill:var(--md-mermaid-label-fg-color)}g.stateGroup rect{fill:var(--md-mermaid-node-bg-color);stroke:var(--md-mermaid-node-fg-color)}g.stateGroup .state-title{fill:var(--md-mermaid-label-fg-color)!important;font-family:var(--md-mermaid-font-family)}g.stateGroup .composit{fill:var(--md-mermaid-label-bg-color)}.nodeLabel,.nodeLabel p{color:var(--md-mermaid-label-fg-color);font-family:var(--md-mermaid-font-family)}a .nodeLabel{text-decoration:underline}.node circle.state-end,.node circle.state-start,.start-state{fill:var(--md-mermaid-edge-color);stroke:none}.end-state-inner,.end-state-outer{fill:var(--md-mermaid-edge-color)}.end-state-inner,.node circle.state-end{stroke:var(--md-mermaid-label-bg-color)}.transition{stroke:var(--md-mermaid-edge-color)}[id^=state-fork] rect,[id^=state-join] rect{fill:var(--md-mermaid-edge-color)!important;stroke:none!important}.statediagram-cluster.statediagram-cluster .inner{fill:var(--md-default-bg-color)}.statediagram-cluster rect{fill:var(--md-mermaid-node-bg-color);stroke:var(--md-mermaid-node-fg-color)}.statediagram-state rect.divider{fill:var(--md-default-fg-color--lightest);stroke:var(--md-default-fg-color--lighter)}defs #statediagram-barbEnd{stroke:var(--md-mermaid-edge-color)}[id^=entity] path,[id^=entity] rect{fill:var(--md-default-bg-color)}.relationshipLine{stroke:var(--md-mermaid-edge-color)}defs .marker.oneOrMore.er *,defs .marker.onlyOne.er *,defs .marker.zeroOrMore.er *,defs .marker.zeroOrOne.er *{stroke:var(--md-mermaid-edge-color)!important}text:not([class]):last-child{fill:var(--md-mermaid-label-fg-color)}.actor{fill:var(--md-mermaid-sequence-actor-bg-color);stroke:var(--md-mermaid-sequence-actor-border-color)}text.actor>tspan{fill:var(--md-mermaid-sequence-actor-fg-color);font-family:var(--md-mermaid-font-family)}line{stroke:var(--md-mermaid-sequence-actor-line-color)}.actor-man circle,.actor-man line{fill:var(--md-mermaid-sequence-actorman-bg-color);stroke:var(--md-mermaid-sequence-actorman-line-color)}.messageLine0,.messageLine1{stroke:var(--md-mermaid-sequence-message-line-color)}.note{fill:var(--md-mermaid-sequence-note-bg-color);stroke:var(--md-mermaid-sequence-note-border-color)}.loopText,.loopText>tspan,.messageText,.noteText>tspan{stroke:none;font-family:var(--md-mermaid-font-family)!important}.messageText{fill:var(--md-mermaid-sequence-message-fg-color)}.loopText,.loopText>tspan{fill:var(--md-mermaid-sequence-loop-fg-color)}.noteText>tspan{fill:var(--md-mermaid-sequence-note-fg-color)}#arrowhead path{fill:var(--md-mermaid-sequence-message-line-color);stroke:none}.loopLine{fill:var(--md-mermaid-sequence-loop-bg-color);stroke:var(--md-mermaid-sequence-loop-border-color)}.labelBox{fill:var(--md-mermaid-sequence-label-bg-color);stroke:none}.labelText,.labelText>span{fill:var(--md-mermaid-sequence-label-fg-color);font-family:var(--md-mermaid-font-family)}.sequenceNumber{fill:var(--md-mermaid-sequence-number-fg-color)}rect.rect{fill:var(--md-mermaid-sequence-box-bg-color);stroke:none}rect.rect+text.text{fill:var(--md-mermaid-sequence-box-fg-color)}defs #sequencenumber{fill:var(--md-mermaid-sequence-number-bg-color)!important}";var so,is=0;function as(){return typeof mermaid=="undefined"||mermaid instanceof Element?_t("https://unpkg.com/mermaid@11/dist/mermaid.min.js"):$(void 0)}function Zn(e){return e.classList.remove("mermaid"),so||(so=as().pipe(O(()=>mermaid.initialize({startOnLoad:!1,themeCSS:Xn,sequence:{actorFontSize:"16px",messageFontSize:"16px",noteFontSize:"16px"}})),m(()=>{}),Z(1))),so.subscribe(()=>go(null,null,function*(){e.classList.add("mermaid");let t=`__mermaid_${is++}`,r=x("div",{class:"mermaid"}),o=e.textContent,{svg:n,fn:i}=yield mermaid.render(t,o),s=r.attachShadow({mode:"closed"});s.innerHTML=n,e.replaceWith(r),i==null||i(s)})),so.pipe(m(()=>({ref:e})))}var ei=x("table");function ti(e){return e.replaceWith(ei),ei.replaceWith(Un(e)),$({ref:e})}function ss(e){let t=e.find(r=>r.checked)||e[0];return L(...e.map(r=>h(r,"change").pipe(m(()=>j(`label[for="${r.id}"]`))))).pipe(Q(j(`label[for="${t.id}"]`)),m(r=>({active:r})))}function ri(e,{viewport$:t,target$:r}){let o=j(".tabbed-labels",e),n=M(":scope > input",e),i=no("prev");e.append(i);let s=no("next");return e.append(s),H(()=>{let a=new T,c=a.pipe(oe(),ae(!0));z([a,Le(e),mt(e)]).pipe(W(c),$e(1,ye)).subscribe({next([{active:p},l]){let f=Be(p),{width:u}=de(p);e.style.setProperty("--md-indicator-x",`${f.x}px`),e.style.setProperty("--md-indicator-width",`${u}px`);let d=gr(o);(f.xd.x+l.width)&&o.scrollTo({left:Math.max(0,f.x-16),behavior:"smooth"})},complete(){e.style.removeProperty("--md-indicator-x"),e.style.removeProperty("--md-indicator-width")}}),z([Ge(o),Le(o)]).pipe(W(c)).subscribe(([p,l])=>{let f=At(o);i.hidden=p.x<16,s.hidden=p.x>f.width-l.width-16}),L(h(i,"click").pipe(m(()=>-1)),h(s,"click").pipe(m(()=>1))).pipe(W(c)).subscribe(p=>{let{width:l}=de(o);o.scrollBy({left:l*p,behavior:"smooth"})}),r.pipe(W(c),g(p=>n.includes(p))).subscribe(p=>p.click()),o.classList.add("tabbed-labels--linked");for(let p of n){let l=j(`label[for="${p.id}"]`);l.replaceChildren(x("a",{href:`#${l.htmlFor}`,tabIndex:-1},...Array.from(l.childNodes))),h(l.firstElementChild,"click").pipe(W(c),g(f=>!(f.metaKey||f.ctrlKey)),O(f=>{f.preventDefault(),f.stopPropagation()})).subscribe(()=>{history.replaceState({},"",`#${l.htmlFor}`),l.click()})}return V("content.tabs.link")&&a.pipe(Ie(1),te(t)).subscribe(([{active:p},{offset:l}])=>{let f=p.innerText.trim();if(p.hasAttribute("data-md-switching"))p.removeAttribute("data-md-switching");else{let u=e.offsetTop-l.y;for(let v of M("[data-tabs]"))for(let S of M(":scope > input",v)){let X=j(`label[for="${S.id}"]`);if(X!==p&&X.innerText.trim()===f){X.setAttribute("data-md-switching",""),S.click();break}}window.scrollTo({top:e.offsetTop-u});let d=__md_get("__tabs")||[];__md_set("__tabs",[...new Set([f,...d])])}}),a.pipe(W(c)).subscribe(()=>{for(let p of M("audio, video",e))p.offsetWidth&&p.autoplay?p.play().catch(()=>{}):p.pause()}),ss(n).pipe(O(p=>a.next(p)),A(()=>a.complete()),m(p=>P({ref:e},p)))}).pipe(et(pe))}function oi(e,t){let{viewport$:r,target$:o,print$:n}=t;return L(...M(".annotate:not(.highlight)",e).map(i=>zn(i,{target$:o,print$:n})),...M("pre:not(.mermaid) > code",e).map(i=>Yn(i,{target$:o,print$:n})),...M("a",e).map(i=>Jn(i,t)),...M("pre.mermaid",e).map(i=>Zn(i)),...M("table:not([class])",e).map(i=>ti(i)),...M("details",e).map(i=>Bn(i,{target$:o,print$:n})),...M("[data-tabs]",e).map(i=>ri(i,{viewport$:r,target$:o})),...M("[title]:not([data-preview])",e).filter(()=>V("content.tooltips")).map(i=>Xe(i,{viewport$:r})),...M(".footnote-ref",e).filter(()=>V("content.footnote.tooltips")).map(i=>Vt(i,{content$:new F(s=>{let a=new URL(i.href).hash.slice(1),c=Array.from(document.getElementById(a).cloneNode(!0).children),p=wr(...c);return s.next(p),document.body.append(p),()=>p.remove()}),viewport$:r})))}function cs(e,{alert$:t}){return t.pipe(b(r=>L($(!0),$(!1).pipe(nt(2e3))).pipe(m(o=>({message:r,active:o})))))}function ni(e,t){let r=j(".md-typeset",e);return H(()=>{let o=new T;return o.subscribe(({message:n,active:i})=>{e.classList.toggle("md-dialog--active",i),r.textContent=n}),cs(e,t).pipe(O(n=>o.next(n)),A(()=>o.complete()),m(n=>P({ref:e},n)))})}var ps=0;function ls(e,t){document.body.append(e);let{width:r}=de(e);e.style.setProperty("--md-tooltip-width",`${r}px`),e.remove();let o=vr(t),n=typeof o!="undefined"?Ge(o):$({x:0,y:0}),i=L(Ye(t),it(t)).pipe(Y());return z([i,n]).pipe(m(([s,a])=>{let{x:c,y:p}=Be(t),l=de(t),f=t.closest("table");return f&&t.parentElement&&(c+=f.offsetLeft+t.parentElement.offsetLeft,p+=f.offsetTop+t.parentElement.offsetTop),{active:s,offset:{x:c-a.x+l.width/2-r/2,y:p-a.y+l.height+8}}}))}function ii(e){let t=e.title;if(!t.length)return y;let r=`__tooltip_${ps++}`,o=Dt(r,"inline"),n=j(".md-typeset",o);return n.innerHTML=t,H(()=>{let i=new T;return i.subscribe({next({offset:s}){o.style.setProperty("--md-tooltip-x",`${s.x}px`),o.style.setProperty("--md-tooltip-y",`${s.y}px`)},complete(){o.style.removeProperty("--md-tooltip-x"),o.style.removeProperty("--md-tooltip-y")}}),L(i.pipe(g(({active:s})=>s)),i.pipe(Ae(250),g(({active:s})=>!s))).subscribe({next({active:s}){s?(e.insertAdjacentElement("afterend",o),e.setAttribute("aria-describedby",r),e.removeAttribute("title")):(o.remove(),e.removeAttribute("aria-describedby"),e.setAttribute("title",t))},complete(){o.remove(),e.removeAttribute("aria-describedby"),e.setAttribute("title",t)}}),i.pipe($e(16,ye)).subscribe(({active:s})=>{o.classList.toggle("md-tooltip--active",s)}),i.pipe(gt(125,ye),g(()=>!!e.offsetParent),m(()=>e.offsetParent.getBoundingClientRect()),m(({x:s})=>s)).subscribe({next(s){s?o.style.setProperty("--md-tooltip-0",`${-s}px`):o.style.removeProperty("--md-tooltip-0")},complete(){o.style.removeProperty("--md-tooltip-0")}}),ls(o,e).pipe(O(s=>i.next(s)),A(()=>i.complete()),m(s=>P({ref:e},s)))}).pipe(et(pe))}function ms({viewport$:e}){if(!V("header.autohide"))return $(!1);let t=e.pipe(m(({offset:{y:n}})=>n),ot(2,1),m(([n,i])=>[nMath.abs(i-n.y)>100),m(([,[n]])=>n),Y()),o=Je("search");return z([e,o]).pipe(m(([{offset:n},i])=>n.y>400&&!i),Y(),b(n=>n?r:$(!1)),Q(!1))}function ai(e,t){return H(()=>z([Le(e),ms(t)])).pipe(m(([{height:r},o])=>({height:r,hidden:o})),Y((r,o)=>r.height===o.height&&r.hidden===o.hidden),Z(1))}function si(e,{header$:t,main$:r}){return H(()=>{let o=new T,n=o.pipe(oe(),ae(!0));o.pipe(ne("active"),Pe(t)).subscribe(([{active:s},{hidden:a}])=>{e.classList.toggle("md-header--shadow",s&&!a),e.hidden=a});let i=fe(M("[title]",e)).pipe(g(()=>V("content.tooltips")),J(s=>ii(s)));return r.subscribe(o),t.pipe(W(n),m(s=>P({ref:e},s)),Ve(i.pipe(W(n))))})}function fs(e,{viewport$:t,header$:r}){return Er(e,{viewport$:t,header$:r}).pipe(m(({offset:{y:o}})=>{let{height:n}=de(e);return{active:n>0&&o>=n}}),ne("active"))}function ci(e,t){return H(()=>{let r=new T;r.subscribe({next({active:n}){e.classList.toggle("md-header__title--active",n)},complete(){e.classList.remove("md-header__title--active")}});let o=ue(".md-content h1");return typeof o=="undefined"?y:fs(o,t).pipe(O(n=>r.next(n)),A(()=>r.complete()),m(n=>P({ref:e},n)))})}function pi(e,{viewport$:t,header$:r}){let o=r.pipe(m(({height:i})=>i),Y()),n=o.pipe(b(()=>Le(e).pipe(m(({height:i})=>({top:e.offsetTop,bottom:e.offsetTop+i})),ne("bottom"))));return z([o,n,t]).pipe(m(([i,{top:s,bottom:a},{offset:{y:c},size:{height:p}}])=>(p=Math.max(0,p-Math.max(0,s-c,i)-Math.max(0,p+c-a)),{offset:s-i,height:p,active:s-i<=c})),Y((i,s)=>i.offset===s.offset&&i.height===s.height&&i.active===s.active))}function us(e){let t=__md_get("__palette")||{index:e.findIndex(o=>matchMedia(o.getAttribute("data-md-color-media")).matches)},r=Math.max(0,Math.min(t.index,e.length-1));return $(...e).pipe(J(o=>h(o,"change").pipe(m(()=>o))),Q(e[r]),m(o=>({index:e.indexOf(o),color:{media:o.getAttribute("data-md-color-media"),scheme:o.getAttribute("data-md-color-scheme"),primary:o.getAttribute("data-md-color-primary"),accent:o.getAttribute("data-md-color-accent")}})),Z(1))}function li(e){let t=M("input",e),r=x("meta",{name:"theme-color"});document.head.appendChild(r);let o=x("meta",{name:"color-scheme"});document.head.appendChild(o);let n=Wt("(prefers-color-scheme: light)");return H(()=>{let i=new T;return i.subscribe(s=>{if(document.body.setAttribute("data-md-color-switching",""),s.color.media==="(prefers-color-scheme)"){let a=matchMedia("(prefers-color-scheme: light)"),c=document.querySelector(a.matches?"[data-md-color-media='(prefers-color-scheme: light)']":"[data-md-color-media='(prefers-color-scheme: dark)']");s.color.scheme=c.getAttribute("data-md-color-scheme"),s.color.primary=c.getAttribute("data-md-color-primary"),s.color.accent=c.getAttribute("data-md-color-accent")}for(let[a,c]of Object.entries(s.color))document.body.setAttribute(`data-md-color-${a}`,c);for(let a=0;as.key==="Enter"),te(i,(s,a)=>a)).subscribe(({index:s})=>{s=(s+1)%t.length,t[s].click(),t[s].focus()}),i.pipe(m(()=>{let s=Ce("header"),a=window.getComputedStyle(s);return o.content=a.colorScheme,a.backgroundColor.match(/\d+/g).map(c=>(+c).toString(16).padStart(2,"0")).join("")})).subscribe(s=>r.content=`#${s}`),i.pipe(xe(pe)).subscribe(()=>{document.body.removeAttribute("data-md-color-switching")}),us(t).pipe(W(n.pipe(Ie(1))),vt(),O(s=>i.next(s)),A(()=>i.complete()),m(s=>P({ref:e},s)))})}function mi(e,{progress$:t}){return H(()=>{let r=new T;return r.subscribe(({value:o})=>{e.style.setProperty("--md-progress-value",`${o}`)}),t.pipe(O(o=>r.next({value:o})),A(()=>r.complete()),m(o=>({ref:e,value:o})))})}function fi(e,t){return e.protocol=t.protocol,e.hostname=t.hostname,e}function ds(e,t){let r=new Map;for(let o of M("url",e)){let n=j("loc",o),i=[fi(new URL(n.textContent),t)];r.set(`${i[0]}`,i);for(let s of M("[rel=alternate]",o)){let a=s.getAttribute("href");a!=null&&i.push(fi(new URL(a),t))}}return r}function kt(e){return En(new URL("sitemap.xml",e)).pipe(m(t=>ds(t,new URL(e))),ve(()=>$(new Map)),le())}function ui({document$:e}){let t=new Map;e.pipe(b(()=>M("link[rel=alternate]")),m(r=>new URL(r.href)),g(r=>!t.has(r.toString())),J(r=>kt(r).pipe(m(o=>[r,o]),ve(()=>y)))).subscribe(([r,o])=>{t.set(r.toString().replace(/\/$/,""),o)}),h(document.body,"click").pipe(g(r=>!r.metaKey&&!r.ctrlKey),b(r=>{if(r.target instanceof Element){let o=r.target.closest("a");if(o&&!o.target){let n=[...t].find(([f])=>o.href.startsWith(`${f}/`));if(typeof n=="undefined")return y;let[i,s]=n,a=we();if(a.href.startsWith(i))return y;let c=Te(),p=a.href.replace(c.base,"");p=`${i}/${p}`;let l=s.has(p.split("#")[0])?new URL(p,c.base):new URL(i);return r.preventDefault(),$(l)}}return y})).subscribe(r=>st(r,!0))}var co=$t(ao());function hs(e){e.setAttribute("data-md-copying","");let t=e.closest("[data-copy]"),r=t?t.getAttribute("data-copy"):e.innerText;return e.removeAttribute("data-md-copying"),r.trimEnd()}function di({alert$:e}){co.default.isSupported()&&new F(t=>{new co.default("[data-clipboard-target], [data-clipboard-text]",{text:r=>r.getAttribute("data-clipboard-text")||hs(j(r.getAttribute("data-clipboard-target")))}).on("success",r=>t.next(r))}).pipe(O(t=>{t.trigger.focus()}),m(()=>Me("clipboard.copied"))).subscribe(e)}function hi(e,t){if(!(e.target instanceof Element))return y;let r=e.target.closest("a");if(r===null)return y;if(r.target||e.metaKey||e.ctrlKey)return y;let o=new URL(r.href);return o.search=o.hash="",t.has(`${o}`)?(e.preventDefault(),$(r)):y}function bi(e){let t=new Map;for(let r of M(":scope > *",e.head))t.set(r.outerHTML,r);return t}function vi(e){for(let t of M("[href], [src]",e))for(let r of["href","src"]){let o=t.getAttribute(r);if(o&&!/^(?:[a-z]+:)?\/\//i.test(o)){t[r]=t[r];break}}return $(e)}function bs(e){for(let o of["[data-md-component=announce]","[data-md-component=container]","[data-md-component=header-topic]","[data-md-component=outdated]","[data-md-component=logo]","[data-md-component=skip]",...V("navigation.tabs.sticky")?["[data-md-component=tabs]"]:[]]){let n=ue(o),i=ue(o,e);typeof n!="undefined"&&typeof i!="undefined"&&n.replaceWith(i)}let t=bi(document);for(let[o,n]of bi(e))t.has(o)?t.delete(o):document.head.appendChild(n);for(let o of t.values()){let n=o.getAttribute("name");n!=="theme-color"&&n!=="color-scheme"&&o.remove()}let r=Ce("container");return Ke(M("script",r)).pipe(b(o=>{let n=e.createElement("script");if(o.src){for(let i of o.getAttributeNames())n.setAttribute(i,o.getAttribute(i));return o.replaceWith(n),new F(i=>{n.onload=()=>i.complete()})}else return n.textContent=o.textContent,o.replaceWith(n),y}),oe(),ae(document))}function gi({sitemap$:e,location$:t,viewport$:r,progress$:o}){if(location.protocol==="file:")return y;$(document).subscribe(vi);let n=h(document.body,"click").pipe(Pe(e),b(([a,c])=>hi(a,c)),m(({href:a})=>new URL(a)),le()),i=h(window,"popstate").pipe(m(we),le());n.pipe(te(r)).subscribe(([a,{offset:c}])=>{history.replaceState(c,""),history.pushState(null,"",a)}),L(n,i).subscribe(t);let s=t.pipe(ne("pathname"),b(a=>xr(a,{progress$:o}).pipe(ve(()=>(st(a,!0),y)))),b(vi),b(bs),le());return L(s.pipe(te(t,(a,c)=>c)),s.pipe(b(()=>t),ne("hash")),t.pipe(Y((a,c)=>a.pathname===c.pathname&&a.hash===c.hash),b(()=>n),O(()=>history.back()))).subscribe(a=>{var c,p;history.state!==null||!a.hash?window.scrollTo(0,(p=(c=history.state)==null?void 0:c.y)!=null?p:0):(history.scrollRestoration="auto",gn(a.hash),history.scrollRestoration="manual")}),t.subscribe(()=>{history.scrollRestoration="manual"}),h(window,"beforeunload").subscribe(()=>{history.scrollRestoration="auto"}),r.pipe(ne("offset"),Ae(100)).subscribe(({offset:a})=>{history.replaceState(a,"")}),V("navigation.instant.prefetch")&&L(h(document.body,"mousemove"),h(document.body,"focusin")).pipe(Pe(e),b(([a,c])=>hi(a,c)),Ae(25),Qr(({href:a})=>a),hr(a=>{let c=document.createElement("link");return c.rel="prefetch",c.href=a.toString(),document.head.appendChild(c),h(c,"load").pipe(m(()=>c),Ee(1))})).subscribe(a=>a.remove()),s}var yi=$t(ro());function xi(e){let t=e.separator.split("|").map(n=>n.replace(/(\(\?[!=<][^)]+\))/g,"").length===0?"\uFFFD":n).join("|"),r=new RegExp(t,"img"),o=(n,i,s)=>`${i}${s}`;return n=>{n=n.replace(/[\s*+\-:~^]+/g," ").replace(/&/g,"&").trim();let i=new RegExp(`(^|${e.separator}|)(${n.replace(/[|\\{}()[\]^$+*?.-]/g,"\\$&").replace(r,"|")})`,"img");return s=>(0,yi.default)(s).replace(i,o).replace(/<\/mark>(\s+)]*>/img,"$1")}}function zt(e){return e.type===1}function Sr(e){return e.type===3}function Ei(e,t){let r=Mn(e);return L($(location.protocol!=="file:"),Je("search")).pipe(Re(o=>o),b(()=>t)).subscribe(({config:o,docs:n})=>r.next({type:0,data:{config:o,docs:n,options:{suggest:V("search.suggest")}}})),r}function wi(e){var l;let{selectedVersionSitemap:t,selectedVersionBaseURL:r,currentLocation:o,currentBaseURL:n}=e,i=(l=po(n))==null?void 0:l.pathname;if(i===void 0)return;let s=ys(o.pathname,i);if(s===void 0)return;let a=Es(t.keys());if(!t.has(a))return;let c=po(s,a);if(!c||!t.has(c.href))return;let p=po(s,r);if(p)return p.hash=o.hash,p.search=o.search,p}function po(e,t){try{return new URL(e,t)}catch(r){return}}function ys(e,t){if(e.startsWith(t))return e.slice(t.length)}function xs(e,t){let r=Math.min(e.length,t.length),o;for(o=0;oy)),o=r.pipe(m(n=>{let[,i]=t.base.match(/([^/]+)\/?$/);return n.find(({version:s,aliases:a})=>s===i||a.includes(i))||n[0]}));r.pipe(m(n=>new Map(n.map(i=>[`${new URL(`../${i.version}/`,t.base)}`,i]))),b(n=>h(document.body,"click").pipe(g(i=>!i.metaKey&&!i.ctrlKey),te(o),b(([i,s])=>{if(i.target instanceof Element){let a=i.target.closest("a");if(a&&!a.target&&n.has(a.href)){let c=a.href;return!i.target.closest(".md-version")&&n.get(c)===s?y:(i.preventDefault(),$(new URL(c)))}}return y}),b(i=>kt(i).pipe(m(s=>{var a;return(a=wi({selectedVersionSitemap:s,selectedVersionBaseURL:i,currentLocation:we(),currentBaseURL:t.base}))!=null?a:i})))))).subscribe(n=>st(n,!0)),z([r,o]).subscribe(([n,i])=>{j(".md-header__topic").appendChild(Wn(n,i))}),e.pipe(b(()=>o)).subscribe(n=>{var a;let i=new URL(t.base),s=__md_get("__outdated",sessionStorage,i);if(s===null){s=!0;let c=((a=t.version)==null?void 0:a.default)||"latest";Array.isArray(c)||(c=[c]);e:for(let p of c)for(let l of n.aliases.concat(n.version))if(new RegExp(p,"i").test(l)){s=!1;break e}__md_set("__outdated",s,sessionStorage,i)}if(s)for(let c of me("outdated"))c.hidden=!1})}function ws(e,{worker$:t}){let{searchParams:r}=we();r.has("q")&&(at("search",!0),e.value=r.get("q"),e.focus(),Je("search").pipe(Re(i=>!i)).subscribe(()=>{let i=we();i.searchParams.delete("q"),history.replaceState({},"",`${i}`)}));let o=Ye(e),n=L(t.pipe(Re(zt)),h(e,"keyup"),o).pipe(m(()=>e.value),Y());return z([n,o]).pipe(m(([i,s])=>({value:i,focus:s})),Z(1))}function Si(e,{worker$:t}){let r=new T,o=r.pipe(oe(),ae(!0));z([t.pipe(Re(zt)),r],(i,s)=>s).pipe(ne("value")).subscribe(({value:i})=>t.next({type:2,data:i})),r.pipe(ne("focus")).subscribe(({focus:i})=>{i&&at("search",i)}),h(e.form,"reset").pipe(W(o)).subscribe(()=>e.focus());let n=j("header [for=__search]");return h(n,"click").subscribe(()=>e.focus()),ws(e,{worker$:t}).pipe(O(i=>r.next(i)),A(()=>r.complete()),m(i=>P({ref:e},i)),Z(1))}function Oi(e,{worker$:t,query$:r}){let o=new T,n=un(e.parentElement).pipe(g(Boolean)),i=e.parentElement,s=j(":scope > :first-child",e),a=j(":scope > :last-child",e);Je("search").subscribe(l=>{a.setAttribute("role",l?"list":"presentation"),a.hidden=!l}),o.pipe(te(r),Gr(t.pipe(Re(zt)))).subscribe(([{items:l},{value:f}])=>{switch(l.length){case 0:s.textContent=f.length?Me("search.result.none"):Me("search.result.placeholder");break;case 1:s.textContent=Me("search.result.one");break;default:let u=br(l.length);s.textContent=Me("search.result.other",u)}});let c=o.pipe(O(()=>a.innerHTML=""),b(({items:l})=>L($(...l.slice(0,10)),$(...l.slice(10)).pipe(ot(4),Xr(n),b(([f])=>f)))),m(Fn),le());return c.subscribe(l=>a.appendChild(l)),c.pipe(J(l=>{let f=ue("details",l);return typeof f=="undefined"?y:h(f,"toggle").pipe(W(o),m(()=>f))})).subscribe(l=>{l.open===!1&&l.offsetTop<=i.scrollTop&&i.scrollTo({top:l.offsetTop})}),t.pipe(g(Sr),m(({data:l})=>l)).pipe(O(l=>o.next(l)),A(()=>o.complete()),m(l=>P({ref:e},l)))}function Ts(e,{query$:t}){return t.pipe(m(({value:r})=>{let o=we();return o.hash="",r=r.replace(/\s+/g,"+").replace(/&/g,"%26").replace(/=/g,"%3D"),o.search=`q=${r}`,{url:o}}))}function Li(e,t){let r=new T,o=r.pipe(oe(),ae(!0));return r.subscribe(({url:n})=>{e.setAttribute("data-clipboard-text",e.href),e.href=`${n}`}),h(e,"click").pipe(W(o)).subscribe(n=>n.preventDefault()),Ts(e,t).pipe(O(n=>r.next(n)),A(()=>r.complete()),m(n=>P({ref:e},n)))}function Mi(e,{worker$:t,keyboard$:r}){let o=new T,n=Ce("search-query"),i=L(h(n,"keydown"),h(n,"focus")).pipe(xe(pe),m(()=>n.value),Y());return o.pipe(Pe(i),m(([{suggest:a},c])=>{let p=c.split(/([\s-]+)/);if(a!=null&&a.length&&p[p.length-1]){let l=a[a.length-1];l.startsWith(p[p.length-1])&&(p[p.length-1]=l)}else p.length=0;return p})).subscribe(a=>e.innerHTML=a.join("").replace(/\s/g," ")),r.pipe(g(({mode:a})=>a==="search")).subscribe(a=>{a.type==="ArrowRight"&&e.innerText.length&&n.selectionStart===n.value.length&&(n.value=e.innerText)}),t.pipe(g(Sr),m(({data:a})=>a)).pipe(O(a=>o.next(a)),A(()=>o.complete()),m(()=>({ref:e})))}function _i(e,{index$:t,keyboard$:r}){let o=Te();try{let n=Ei(o.search,t),i=Ce("search-query",e),s=Ce("search-result",e);h(e,"click").pipe(g(({target:c})=>c instanceof Element&&!!c.closest("a"))).subscribe(()=>at("search",!1)),r.pipe(g(({mode:c})=>c==="search")).subscribe(c=>{let p=Ne();switch(c.type){case"Enter":if(p===i){let l=new Map;for(let f of M(":first-child [href]",s)){let u=f.firstElementChild;l.set(f,parseFloat(u.getAttribute("data-md-score")))}if(l.size){let[[f]]=[...l].sort(([,u],[,d])=>d-u);f.click()}c.claim()}break;case"Escape":case"Tab":at("search",!1),i.blur();break;case"ArrowUp":case"ArrowDown":if(typeof p=="undefined")i.focus();else{let l=[i,...M(":not(details) > [href], summary, details[open] [href]",s)],f=Math.max(0,(Math.max(0,l.indexOf(p))+l.length+(c.type==="ArrowUp"?-1:1))%l.length);l[f].focus()}c.claim();break;default:i!==Ne()&&i.focus()}}),r.pipe(g(({mode:c})=>c==="global")).subscribe(c=>{switch(c.type){case"f":case"s":case"/":i.focus(),i.select(),c.claim();break}});let a=Si(i,{worker$:n});return L(a,Oi(s,{worker$:n,query$:a})).pipe(Ve(...me("search-share",e).map(c=>Li(c,{query$:a})),...me("search-suggest",e).map(c=>Mi(c,{worker$:n,keyboard$:r}))))}catch(n){return e.hidden=!0,tt}}function Ai(e,{index$:t,location$:r}){return z([t,r.pipe(Q(we()),g(o=>!!o.searchParams.get("h")))]).pipe(m(([o,n])=>xi(o.config)(n.searchParams.get("h"))),m(o=>{var s;let n=new Map,i=document.createNodeIterator(e,NodeFilter.SHOW_TEXT);for(let a=i.nextNode();a;a=i.nextNode())if((s=a.parentElement)!=null&&s.offsetHeight){let c=a.textContent,p=o(c);p.length>c.length&&n.set(a,p)}for(let[a,c]of n){let{childNodes:p}=x("span",null,c);a.replaceWith(...Array.from(p))}return{ref:e,nodes:n}}))}function Ss(e,{viewport$:t,main$:r}){let o=e.closest(".md-grid"),n=o.offsetTop-o.parentElement.offsetTop;return z([r,t]).pipe(m(([{offset:i,height:s},{offset:{y:a}}])=>(s=s+Math.min(n,Math.max(0,a-i))-n,{height:s,locked:a>=i+n})),Y((i,s)=>i.height===s.height&&i.locked===s.locked))}function lo(e,o){var n=o,{header$:t}=n,r=vo(n,["header$"]);let i=j(".md-sidebar__scrollwrap",e),{y:s}=Be(i);return H(()=>{let a=new T,c=a.pipe(oe(),ae(!0)),p=a.pipe($e(0,ye));return p.pipe(te(t)).subscribe({next([{height:l},{height:f}]){i.style.height=`${l-2*s}px`,e.style.top=`${f}px`},complete(){i.style.height="",e.style.top=""}}),p.pipe(Re()).subscribe(()=>{for(let l of M(".md-nav__link--active[href]",e)){if(!l.clientHeight)continue;let f=l.closest(".md-sidebar__scrollwrap");if(typeof f!="undefined"){let u=l.offsetTop-f.offsetTop,{height:d}=de(f);f.scrollTo({top:u-d/2})}}}),fe(M("label[tabindex]",e)).pipe(J(l=>h(l,"click").pipe(xe(pe),m(()=>l),W(c)))).subscribe(l=>{let f=j(`[id="${l.htmlFor}"]`);j(`[aria-labelledby="${l.id}"]`).setAttribute("aria-expanded",`${f.checked}`)}),V("content.tooltips")&&fe(M("abbr[title]",e)).pipe(J(l=>Xe(l,{viewport$})),W(c)).subscribe(),Ss(e,r).pipe(O(l=>a.next(l)),A(()=>a.complete()),m(l=>P({ref:e},l)))})}function Ci(e,t){if(typeof t!="undefined"){let r=`https://api.github.com/repos/${e}/${t}`;return rt(ze(`${r}/releases/latest`).pipe(ve(()=>y),m(o=>({version:o.tag_name})),Qe({})),ze(r).pipe(ve(()=>y),m(o=>({stars:o.stargazers_count,forks:o.forks_count})),Qe({}))).pipe(m(([o,n])=>P(P({},o),n)))}else{let r=`https://api.github.com/users/${e}`;return ze(r).pipe(m(o=>({repositories:o.public_repos})),Qe({}))}}function ki(e,t){let r=`https://${e}/api/v4/projects/${encodeURIComponent(t)}`;return rt(ze(`${r}/releases/permalink/latest`).pipe(ve(()=>y),m(({tag_name:o})=>({version:o})),Qe({})),ze(r).pipe(ve(()=>y),m(({star_count:o,forks_count:n})=>({stars:o,forks:n})),Qe({}))).pipe(m(([o,n])=>P(P({},o),n)))}function Hi(e){let t=e.match(/^.+github\.com\/([^/]+)\/?([^/]+)?/i);if(t){let[,r,o]=t;return Ci(r,o)}if(t=e.match(/^.+?([^/]*gitlab[^/]+)\/(.+?)\/?$/i),t){let[,r,o]=t;return ki(r,o)}return y}var Os;function Ls(e){return Os||(Os=H(()=>{let t=__md_get("__source",sessionStorage);if(t)return $(t);if(me("consent").length){let o=__md_get("__consent");if(!(o&&o.github))return y}return Hi(e.href).pipe(O(o=>__md_set("__source",o,sessionStorage)))}).pipe(ve(()=>y),g(t=>Object.keys(t).length>0),m(t=>({facts:t})),Z(1)))}function $i(e){let t=j(":scope > :last-child",e);return H(()=>{let r=new T;return r.subscribe(({facts:o})=>{t.appendChild(jn(o)),t.classList.add("md-source__repository--active")}),Ls(e).pipe(O(o=>r.next(o)),A(()=>r.complete()),m(o=>P({ref:e},o)))})}function Ms(e,{viewport$:t,header$:r}){return Le(document.body).pipe(b(()=>Er(e,{header$:r,viewport$:t})),m(({offset:{y:o}})=>({hidden:o>=10})),ne("hidden"))}function Pi(e,t){return H(()=>{let r=new T;return r.subscribe({next({hidden:o}){e.hidden=o},complete(){e.hidden=!1}}),(V("navigation.tabs.sticky")?$({hidden:!1}):Ms(e,t)).pipe(O(o=>r.next(o)),A(()=>r.complete()),m(o=>P({ref:e},o)))})}function _s(e,{viewport$:t,header$:r}){let o=new Map,n=M(".md-nav__link",e);for(let a of n){let c=decodeURIComponent(a.hash.substring(1)),p=ue(`[id="${c}"]`);typeof p!="undefined"&&o.set(a,p)}let i=r.pipe(ne("height"),m(({height:a})=>{let c=Ce("main"),p=j(":scope > :first-child",c);return a+.8*(p.offsetTop-c.offsetTop)}),le());return Le(document.body).pipe(ne("height"),b(a=>H(()=>{let c=[];return $([...o].reduce((p,[l,f])=>{for(;c.length&&o.get(c[c.length-1]).tagName>=f.tagName;)c.pop();let u=f.offsetTop;for(;!u&&f.parentElement;)f=f.parentElement,u=f.offsetTop;let d=f.offsetParent;for(;d;d=d.offsetParent)u+=d.offsetTop;return p.set([...c=[...c,l]].reverse(),u)},new Map))}).pipe(m(c=>new Map([...c].sort(([,p],[,l])=>p-l))),Pe(i),b(([c,p])=>t.pipe(Ut(([l,f],{offset:{y:u},size:d})=>{let v=u+d.height>=Math.floor(a.height);for(;f.length;){let[,S]=f[0];if(S-p=u&&!v)f=[l.pop(),...f];else break}return[l,f]},[[],[...c]]),Y((l,f)=>l[0]===f[0]&&l[1]===f[1])))))).pipe(m(([a,c])=>({prev:a.map(([p])=>p),next:c.map(([p])=>p)})),Q({prev:[],next:[]}),ot(2,1),m(([a,c])=>a.prev.length{let i=new T,s=i.pipe(oe(),ae(!0));if(i.subscribe(({prev:a,next:c})=>{for(let[p]of c)p.classList.remove("md-nav__link--passed"),p.classList.remove("md-nav__link--active");for(let[p,[l]]of a.entries())l.classList.add("md-nav__link--passed"),l.classList.toggle("md-nav__link--active",p===a.length-1)}),V("toc.follow")){let a=L(t.pipe(Ae(1),m(()=>{})),t.pipe(Ae(250),m(()=>"smooth")));i.pipe(g(({prev:c})=>c.length>0),Pe(o.pipe(xe(pe))),te(a)).subscribe(([[{prev:c}],p])=>{let[l]=c[c.length-1];if(l.offsetHeight){let f=vr(l);if(typeof f!="undefined"){let u=l.offsetTop-f.offsetTop,{height:d}=de(f);f.scrollTo({top:u-d/2,behavior:p})}}})}return V("navigation.tracking")&&t.pipe(W(s),ne("offset"),Ae(250),Ie(1),W(n.pipe(Ie(1))),vt({delay:250}),te(i)).subscribe(([,{prev:a}])=>{let c=we(),p=a[a.length-1];if(p&&p.length){let[l]=p,{hash:f}=new URL(l.href);c.hash!==f&&(c.hash=f,history.replaceState({},"",`${c}`))}else c.hash="",history.replaceState({},"",`${c}`)}),_s(e,{viewport$:t,header$:r}).pipe(O(a=>i.next(a)),A(()=>i.complete()),m(a=>P({ref:e},a)))})}function As(e,{viewport$:t,main$:r,target$:o}){let n=t.pipe(m(({offset:{y:s}})=>s),ot(2,1),m(([s,a])=>s>a&&a>0),Y()),i=r.pipe(m(({active:s})=>s));return z([i,n]).pipe(m(([s,a])=>!(s&&a)),Y(),W(o.pipe(Ie(1))),ae(!0),vt({delay:250}),m(s=>({hidden:s})))}function Ii(e,{viewport$:t,header$:r,main$:o,target$:n}){let i=new T,s=i.pipe(oe(),ae(!0));return i.subscribe({next({hidden:a}){e.hidden=a,a?(e.setAttribute("tabindex","-1"),e.blur()):e.removeAttribute("tabindex")},complete(){e.style.top="",e.hidden=!0,e.removeAttribute("tabindex")}}),r.pipe(W(s),ne("height")).subscribe(({height:a})=>{e.style.top=`${a+16}px`}),h(e,"click").subscribe(a=>{a.preventDefault(),window.scrollTo({top:0})}),As(e,{viewport$:t,main$:o,target$:n}).pipe(O(a=>i.next(a)),A(()=>i.complete()),m(a=>P({ref:e},a)))}function Fi({document$:e,viewport$:t}){e.pipe(b(()=>M(".md-ellipsis")),J(r=>mt(r).pipe(W(e.pipe(Ie(1))),g(o=>o),m(()=>r),Ee(1))),g(r=>r.offsetWidth{let o=r.innerText,n=r.closest("a")||r;return n.title=o,V("content.tooltips")?Xe(n,{viewport$:t}).pipe(W(e.pipe(Ie(1))),A(()=>n.removeAttribute("title"))):y})).subscribe(),V("content.tooltips")&&e.pipe(b(()=>M(".md-status")),J(r=>Xe(r,{viewport$:t}))).subscribe()}function ji({document$:e,tablet$:t}){e.pipe(b(()=>M(".md-toggle--indeterminate")),O(r=>{r.indeterminate=!0,r.checked=!1}),J(r=>h(r,"change").pipe(Jr(()=>r.classList.contains("md-toggle--indeterminate")),m(()=>r))),te(t)).subscribe(([r,o])=>{r.classList.remove("md-toggle--indeterminate"),o&&(r.checked=!1)})}function Cs(){return/(iPad|iPhone|iPod)/.test(navigator.userAgent)}function Ui({document$:e}){e.pipe(b(()=>M("[data-md-scrollfix]")),O(t=>t.removeAttribute("data-md-scrollfix")),g(Cs),J(t=>h(t,"touchstart").pipe(m(()=>t)))).subscribe(t=>{let r=t.scrollTop;r===0?t.scrollTop=1:r+t.offsetHeight===t.scrollHeight&&(t.scrollTop=r-1)})}function Wi({viewport$:e,tablet$:t}){z([Je("search"),t]).pipe(m(([r,o])=>r&&!o),b(r=>$(r).pipe(nt(r?400:100))),te(e)).subscribe(([r,{offset:{y:o}}])=>{if(r)document.body.setAttribute("data-md-scrolllock",""),document.body.style.top=`-${o}px`;else{let n=-1*parseInt(document.body.style.top,10);document.body.removeAttribute("data-md-scrolllock"),document.body.style.top="",n&&window.scrollTo(0,n)}})}Object.entries||(Object.entries=function(e){let t=[];for(let r of Object.keys(e))t.push([r,e[r]]);return t});Object.values||(Object.values=function(e){let t=[];for(let r of Object.keys(e))t.push(e[r]);return t});typeof Element!="undefined"&&(Element.prototype.scrollTo||(Element.prototype.scrollTo=function(e,t){typeof e=="object"?(this.scrollLeft=e.left,this.scrollTop=e.top):(this.scrollLeft=e,this.scrollTop=t)}),Element.prototype.replaceWith||(Element.prototype.replaceWith=function(...e){let t=this.parentNode;if(t){e.length===0&&t.removeChild(this);for(let r=e.length-1;r>=0;r--){let o=e[r];typeof o=="string"?o=document.createTextNode(o):o.parentNode&&o.parentNode.removeChild(o),r?t.insertBefore(this.previousSibling,o):t.replaceChild(o,this)}}}));function ks(){return location.protocol==="file:"?_t(`${new URL("search/search_index.js",Or.base)}`).pipe(m(()=>__index),Z(1)):ze(new URL("search/search_index.json",Or.base))}document.documentElement.classList.remove("no-js");document.documentElement.classList.add("js");var ct=an(),Kt=bn(),Ht=yn(Kt),mo=hn(),ke=Ln(),Lr=Wt("(min-width: 60em)"),Vi=Wt("(min-width: 76.25em)"),Ni=xn(),Or=Te(),zi=document.forms.namedItem("search")?ks():tt,fo=new T;di({alert$:fo});ui({document$:ct});var uo=new T,qi=kt(Or.base);V("navigation.instant")&&gi({sitemap$:qi,location$:Kt,viewport$:ke,progress$:uo}).subscribe(ct);var Di;((Di=Or.version)==null?void 0:Di.provider)==="mike"&&Ti({document$:ct});L(Kt,Ht).pipe(nt(125)).subscribe(()=>{at("drawer",!1),at("search",!1)});mo.pipe(g(({mode:e})=>e==="global")).subscribe(e=>{switch(e.type){case"p":case",":let t=ue("link[rel=prev]");typeof t!="undefined"&&st(t);break;case"n":case".":let r=ue("link[rel=next]");typeof r!="undefined"&&st(r);break;case"Enter":let o=Ne();o instanceof HTMLLabelElement&&o.click()}});Fi({viewport$:ke,document$:ct});ji({document$:ct,tablet$:Lr});Ui({document$:ct});Wi({viewport$:ke,tablet$:Lr});var ft=ai(Ce("header"),{viewport$:ke}),qt=ct.pipe(m(()=>Ce("main")),b(e=>pi(e,{viewport$:ke,header$:ft})),Z(1)),Hs=L(...me("consent").map(e=>An(e,{target$:Ht})),...me("dialog").map(e=>ni(e,{alert$:fo})),...me("palette").map(e=>li(e)),...me("progress").map(e=>mi(e,{progress$:uo})),...me("search").map(e=>_i(e,{index$:zi,keyboard$:mo})),...me("source").map(e=>$i(e))),$s=H(()=>L(...me("announce").map(e=>_n(e)),...me("content").map(e=>oi(e,{sitemap$:qi,viewport$:ke,target$:Ht,print$:Ni})),...me("content").map(e=>V("search.highlight")?Ai(e,{index$:zi,location$:Kt}):y),...me("header").map(e=>si(e,{viewport$:ke,header$:ft,main$:qt})),...me("header-title").map(e=>ci(e,{viewport$:ke,header$:ft})),...me("sidebar").map(e=>e.getAttribute("data-md-type")==="navigation"?eo(Vi,()=>lo(e,{viewport$:ke,header$:ft,main$:qt})):eo(Lr,()=>lo(e,{viewport$:ke,header$:ft,main$:qt}))),...me("tabs").map(e=>Pi(e,{viewport$:ke,header$:ft})),...me("toc").map(e=>Ri(e,{viewport$:ke,header$:ft,main$:qt,target$:Ht})),...me("top").map(e=>Ii(e,{viewport$:ke,header$:ft,main$:qt,target$:Ht})))),Ki=ct.pipe(b(()=>$s),Ve(Hs),Z(1));Ki.subscribe();window.document$=ct;window.location$=Kt;window.target$=Ht;window.keyboard$=mo;window.viewport$=ke;window.tablet$=Lr;window.screen$=Vi;window.print$=Ni;window.alert$=fo;window.progress$=uo;window.component$=Ki;})(); -//# sourceMappingURL=bundle.79ae519e.min.js.map - diff --git a/docs-site/assets/javascripts/bundle.79ae519e.min.js.map b/docs-site/assets/javascripts/bundle.79ae519e.min.js.map deleted file mode 100644 index 5cf0289..0000000 --- a/docs-site/assets/javascripts/bundle.79ae519e.min.js.map +++ /dev/null @@ -1,7 +0,0 @@ -{ - "version": 3, - "sources": ["node_modules/focus-visible/dist/focus-visible.js", "node_modules/escape-html/index.js", "node_modules/clipboard/dist/clipboard.js", "src/templates/assets/javascripts/bundle.ts", "node_modules/tslib/tslib.es6.mjs", "node_modules/rxjs/src/internal/util/isFunction.ts", "node_modules/rxjs/src/internal/util/createErrorClass.ts", "node_modules/rxjs/src/internal/util/UnsubscriptionError.ts", "node_modules/rxjs/src/internal/util/arrRemove.ts", "node_modules/rxjs/src/internal/Subscription.ts", "node_modules/rxjs/src/internal/config.ts", "node_modules/rxjs/src/internal/scheduler/timeoutProvider.ts", "node_modules/rxjs/src/internal/util/reportUnhandledError.ts", "node_modules/rxjs/src/internal/util/noop.ts", "node_modules/rxjs/src/internal/NotificationFactories.ts", "node_modules/rxjs/src/internal/util/errorContext.ts", "node_modules/rxjs/src/internal/Subscriber.ts", "node_modules/rxjs/src/internal/symbol/observable.ts", "node_modules/rxjs/src/internal/util/identity.ts", "node_modules/rxjs/src/internal/util/pipe.ts", "node_modules/rxjs/src/internal/Observable.ts", "node_modules/rxjs/src/internal/util/lift.ts", "node_modules/rxjs/src/internal/operators/OperatorSubscriber.ts", "node_modules/rxjs/src/internal/scheduler/animationFrameProvider.ts", "node_modules/rxjs/src/internal/util/ObjectUnsubscribedError.ts", "node_modules/rxjs/src/internal/Subject.ts", "node_modules/rxjs/src/internal/BehaviorSubject.ts", "node_modules/rxjs/src/internal/scheduler/dateTimestampProvider.ts", "node_modules/rxjs/src/internal/ReplaySubject.ts", "node_modules/rxjs/src/internal/scheduler/Action.ts", "node_modules/rxjs/src/internal/scheduler/intervalProvider.ts", "node_modules/rxjs/src/internal/scheduler/AsyncAction.ts", "node_modules/rxjs/src/internal/Scheduler.ts", "node_modules/rxjs/src/internal/scheduler/AsyncScheduler.ts", "node_modules/rxjs/src/internal/scheduler/async.ts", "node_modules/rxjs/src/internal/scheduler/QueueAction.ts", "node_modules/rxjs/src/internal/scheduler/QueueScheduler.ts", "node_modules/rxjs/src/internal/scheduler/queue.ts", "node_modules/rxjs/src/internal/scheduler/AnimationFrameAction.ts", "node_modules/rxjs/src/internal/scheduler/AnimationFrameScheduler.ts", "node_modules/rxjs/src/internal/scheduler/animationFrame.ts", "node_modules/rxjs/src/internal/observable/empty.ts", "node_modules/rxjs/src/internal/util/isScheduler.ts", "node_modules/rxjs/src/internal/util/args.ts", "node_modules/rxjs/src/internal/util/isArrayLike.ts", "node_modules/rxjs/src/internal/util/isPromise.ts", "node_modules/rxjs/src/internal/util/isInteropObservable.ts", "node_modules/rxjs/src/internal/util/isAsyncIterable.ts", "node_modules/rxjs/src/internal/util/throwUnobservableError.ts", "node_modules/rxjs/src/internal/symbol/iterator.ts", "node_modules/rxjs/src/internal/util/isIterable.ts", "node_modules/rxjs/src/internal/util/isReadableStreamLike.ts", "node_modules/rxjs/src/internal/observable/innerFrom.ts", "node_modules/rxjs/src/internal/util/executeSchedule.ts", "node_modules/rxjs/src/internal/operators/observeOn.ts", "node_modules/rxjs/src/internal/operators/subscribeOn.ts", "node_modules/rxjs/src/internal/scheduled/scheduleObservable.ts", "node_modules/rxjs/src/internal/scheduled/schedulePromise.ts", "node_modules/rxjs/src/internal/scheduled/scheduleArray.ts", "node_modules/rxjs/src/internal/scheduled/scheduleIterable.ts", "node_modules/rxjs/src/internal/scheduled/scheduleAsyncIterable.ts", "node_modules/rxjs/src/internal/scheduled/scheduleReadableStreamLike.ts", "node_modules/rxjs/src/internal/scheduled/scheduled.ts", "node_modules/rxjs/src/internal/observable/from.ts", "node_modules/rxjs/src/internal/observable/of.ts", "node_modules/rxjs/src/internal/observable/throwError.ts", "node_modules/rxjs/src/internal/util/EmptyError.ts", "node_modules/rxjs/src/internal/util/isDate.ts", "node_modules/rxjs/src/internal/operators/map.ts", "node_modules/rxjs/src/internal/util/mapOneOrManyArgs.ts", "node_modules/rxjs/src/internal/util/argsArgArrayOrObject.ts", "node_modules/rxjs/src/internal/util/createObject.ts", "node_modules/rxjs/src/internal/observable/combineLatest.ts", "node_modules/rxjs/src/internal/operators/mergeInternals.ts", "node_modules/rxjs/src/internal/operators/mergeMap.ts", "node_modules/rxjs/src/internal/operators/mergeAll.ts", "node_modules/rxjs/src/internal/operators/concatAll.ts", "node_modules/rxjs/src/internal/observable/concat.ts", "node_modules/rxjs/src/internal/observable/defer.ts", "node_modules/rxjs/src/internal/observable/fromEvent.ts", "node_modules/rxjs/src/internal/observable/fromEventPattern.ts", "node_modules/rxjs/src/internal/observable/timer.ts", "node_modules/rxjs/src/internal/observable/merge.ts", "node_modules/rxjs/src/internal/observable/never.ts", "node_modules/rxjs/src/internal/util/argsOrArgArray.ts", "node_modules/rxjs/src/internal/operators/filter.ts", "node_modules/rxjs/src/internal/observable/zip.ts", "node_modules/rxjs/src/internal/operators/audit.ts", "node_modules/rxjs/src/internal/operators/auditTime.ts", "node_modules/rxjs/src/internal/operators/bufferCount.ts", "node_modules/rxjs/src/internal/operators/catchError.ts", "node_modules/rxjs/src/internal/operators/scanInternals.ts", "node_modules/rxjs/src/internal/operators/combineLatest.ts", "node_modules/rxjs/src/internal/operators/combineLatestWith.ts", "node_modules/rxjs/src/internal/operators/debounce.ts", "node_modules/rxjs/src/internal/operators/debounceTime.ts", "node_modules/rxjs/src/internal/operators/defaultIfEmpty.ts", "node_modules/rxjs/src/internal/operators/take.ts", "node_modules/rxjs/src/internal/operators/ignoreElements.ts", "node_modules/rxjs/src/internal/operators/mapTo.ts", "node_modules/rxjs/src/internal/operators/delayWhen.ts", "node_modules/rxjs/src/internal/operators/delay.ts", "node_modules/rxjs/src/internal/operators/distinct.ts", "node_modules/rxjs/src/internal/operators/distinctUntilChanged.ts", "node_modules/rxjs/src/internal/operators/distinctUntilKeyChanged.ts", "node_modules/rxjs/src/internal/operators/throwIfEmpty.ts", "node_modules/rxjs/src/internal/operators/endWith.ts", "node_modules/rxjs/src/internal/operators/exhaustMap.ts", "node_modules/rxjs/src/internal/operators/finalize.ts", "node_modules/rxjs/src/internal/operators/first.ts", "node_modules/rxjs/src/internal/operators/takeLast.ts", "node_modules/rxjs/src/internal/operators/merge.ts", "node_modules/rxjs/src/internal/operators/mergeWith.ts", "node_modules/rxjs/src/internal/operators/repeat.ts", "node_modules/rxjs/src/internal/operators/scan.ts", "node_modules/rxjs/src/internal/operators/share.ts", "node_modules/rxjs/src/internal/operators/shareReplay.ts", "node_modules/rxjs/src/internal/operators/skip.ts", "node_modules/rxjs/src/internal/operators/skipUntil.ts", "node_modules/rxjs/src/internal/operators/startWith.ts", "node_modules/rxjs/src/internal/operators/switchMap.ts", "node_modules/rxjs/src/internal/operators/takeUntil.ts", "node_modules/rxjs/src/internal/operators/takeWhile.ts", "node_modules/rxjs/src/internal/operators/tap.ts", "node_modules/rxjs/src/internal/operators/throttle.ts", "node_modules/rxjs/src/internal/operators/throttleTime.ts", "node_modules/rxjs/src/internal/operators/withLatestFrom.ts", "node_modules/rxjs/src/internal/operators/zip.ts", "node_modules/rxjs/src/internal/operators/zipWith.ts", "src/templates/assets/javascripts/browser/document/index.ts", "src/templates/assets/javascripts/browser/element/_/index.ts", "src/templates/assets/javascripts/browser/element/focus/index.ts", "src/templates/assets/javascripts/browser/element/hover/index.ts", "src/templates/assets/javascripts/utilities/h/index.ts", "src/templates/assets/javascripts/utilities/round/index.ts", "src/templates/assets/javascripts/browser/script/index.ts", "src/templates/assets/javascripts/browser/element/size/_/index.ts", "src/templates/assets/javascripts/browser/element/size/content/index.ts", "src/templates/assets/javascripts/browser/element/offset/_/index.ts", "src/templates/assets/javascripts/browser/element/offset/content/index.ts", "src/templates/assets/javascripts/browser/element/visibility/index.ts", "src/templates/assets/javascripts/browser/toggle/index.ts", "src/templates/assets/javascripts/browser/keyboard/index.ts", "src/templates/assets/javascripts/browser/location/_/index.ts", "src/templates/assets/javascripts/browser/location/hash/index.ts", "src/templates/assets/javascripts/browser/media/index.ts", "src/templates/assets/javascripts/browser/request/index.ts", "src/templates/assets/javascripts/browser/viewport/offset/index.ts", "src/templates/assets/javascripts/browser/viewport/size/index.ts", "src/templates/assets/javascripts/browser/viewport/_/index.ts", "src/templates/assets/javascripts/browser/viewport/at/index.ts", "src/templates/assets/javascripts/browser/worker/index.ts", "src/templates/assets/javascripts/_/index.ts", "src/templates/assets/javascripts/components/_/index.ts", "src/templates/assets/javascripts/components/announce/index.ts", "src/templates/assets/javascripts/components/consent/index.ts", "src/templates/assets/javascripts/templates/tooltip/index.tsx", "src/templates/assets/javascripts/templates/annotation/index.tsx", "src/templates/assets/javascripts/templates/clipboard/index.tsx", "src/templates/assets/javascripts/templates/search/index.tsx", "src/templates/assets/javascripts/templates/source/index.tsx", "src/templates/assets/javascripts/templates/tabbed/index.tsx", "src/templates/assets/javascripts/templates/table/index.tsx", "src/templates/assets/javascripts/templates/version/index.tsx", "src/templates/assets/javascripts/components/tooltip2/index.ts", "src/templates/assets/javascripts/components/content/annotation/_/index.ts", "src/templates/assets/javascripts/components/content/annotation/list/index.ts", "src/templates/assets/javascripts/components/content/annotation/block/index.ts", "src/templates/assets/javascripts/components/content/code/_/index.ts", "src/templates/assets/javascripts/components/content/details/index.ts", "src/templates/assets/javascripts/components/content/link/index.ts", "src/templates/assets/javascripts/components/content/mermaid/index.css", "src/templates/assets/javascripts/components/content/mermaid/index.ts", "src/templates/assets/javascripts/components/content/table/index.ts", "src/templates/assets/javascripts/components/content/tabs/index.ts", "src/templates/assets/javascripts/components/content/_/index.ts", "src/templates/assets/javascripts/components/dialog/index.ts", "src/templates/assets/javascripts/components/tooltip/index.ts", "src/templates/assets/javascripts/components/header/_/index.ts", "src/templates/assets/javascripts/components/header/title/index.ts", "src/templates/assets/javascripts/components/main/index.ts", "src/templates/assets/javascripts/components/palette/index.ts", "src/templates/assets/javascripts/components/progress/index.ts", "src/templates/assets/javascripts/integrations/sitemap/index.ts", "src/templates/assets/javascripts/integrations/alternate/index.ts", "src/templates/assets/javascripts/integrations/clipboard/index.ts", "src/templates/assets/javascripts/integrations/instant/index.ts", "src/templates/assets/javascripts/integrations/search/highlighter/index.ts", "src/templates/assets/javascripts/integrations/search/worker/message/index.ts", "src/templates/assets/javascripts/integrations/search/worker/_/index.ts", "src/templates/assets/javascripts/integrations/version/findurl/index.ts", "src/templates/assets/javascripts/integrations/version/index.ts", "src/templates/assets/javascripts/components/search/query/index.ts", "src/templates/assets/javascripts/components/search/result/index.ts", "src/templates/assets/javascripts/components/search/share/index.ts", "src/templates/assets/javascripts/components/search/suggest/index.ts", "src/templates/assets/javascripts/components/search/_/index.ts", "src/templates/assets/javascripts/components/search/highlight/index.ts", "src/templates/assets/javascripts/components/sidebar/index.ts", "src/templates/assets/javascripts/components/source/facts/github/index.ts", "src/templates/assets/javascripts/components/source/facts/gitlab/index.ts", "src/templates/assets/javascripts/components/source/facts/_/index.ts", "src/templates/assets/javascripts/components/source/_/index.ts", "src/templates/assets/javascripts/components/tabs/index.ts", "src/templates/assets/javascripts/components/toc/index.ts", "src/templates/assets/javascripts/components/top/index.ts", "src/templates/assets/javascripts/patches/ellipsis/index.ts", "src/templates/assets/javascripts/patches/indeterminate/index.ts", "src/templates/assets/javascripts/patches/scrollfix/index.ts", "src/templates/assets/javascripts/patches/scrolllock/index.ts", "src/templates/assets/javascripts/polyfills/index.ts"], - "sourcesContent": ["(function (global, factory) {\n typeof exports === 'object' && typeof module !== 'undefined' ? factory() :\n typeof define === 'function' && define.amd ? define(factory) :\n (factory());\n}(this, (function () { 'use strict';\n\n /**\n * Applies the :focus-visible polyfill at the given scope.\n * A scope in this case is either the top-level Document or a Shadow Root.\n *\n * @param {(Document|ShadowRoot)} scope\n * @see https://github.com/WICG/focus-visible\n */\n function applyFocusVisiblePolyfill(scope) {\n var hadKeyboardEvent = true;\n var hadFocusVisibleRecently = false;\n var hadFocusVisibleRecentlyTimeout = null;\n\n var inputTypesAllowlist = {\n text: true,\n search: true,\n url: true,\n tel: true,\n email: true,\n password: true,\n number: true,\n date: true,\n month: true,\n week: true,\n time: true,\n datetime: true,\n 'datetime-local': true\n };\n\n /**\n * Helper function for legacy browsers and iframes which sometimes focus\n * elements like document, body, and non-interactive SVG.\n * @param {Element} el\n */\n function isValidFocusTarget(el) {\n if (\n el &&\n el !== document &&\n el.nodeName !== 'HTML' &&\n el.nodeName !== 'BODY' &&\n 'classList' in el &&\n 'contains' in el.classList\n ) {\n return true;\n }\n return false;\n }\n\n /**\n * Computes whether the given element should automatically trigger the\n * `focus-visible` class being added, i.e. whether it should always match\n * `:focus-visible` when focused.\n * @param {Element} el\n * @return {boolean}\n */\n function focusTriggersKeyboardModality(el) {\n var type = el.type;\n var tagName = el.tagName;\n\n if (tagName === 'INPUT' && inputTypesAllowlist[type] && !el.readOnly) {\n return true;\n }\n\n if (tagName === 'TEXTAREA' && !el.readOnly) {\n return true;\n }\n\n if (el.isContentEditable) {\n return true;\n }\n\n return false;\n }\n\n /**\n * Add the `focus-visible` class to the given element if it was not added by\n * the author.\n * @param {Element} el\n */\n function addFocusVisibleClass(el) {\n if (el.classList.contains('focus-visible')) {\n return;\n }\n el.classList.add('focus-visible');\n el.setAttribute('data-focus-visible-added', '');\n }\n\n /**\n * Remove the `focus-visible` class from the given element if it was not\n * originally added by the author.\n * @param {Element} el\n */\n function removeFocusVisibleClass(el) {\n if (!el.hasAttribute('data-focus-visible-added')) {\n return;\n }\n el.classList.remove('focus-visible');\n el.removeAttribute('data-focus-visible-added');\n }\n\n /**\n * If the most recent user interaction was via the keyboard;\n * and the key press did not include a meta, alt/option, or control key;\n * then the modality is keyboard. Otherwise, the modality is not keyboard.\n * Apply `focus-visible` to any current active element and keep track\n * of our keyboard modality state with `hadKeyboardEvent`.\n * @param {KeyboardEvent} e\n */\n function onKeyDown(e) {\n if (e.metaKey || e.altKey || e.ctrlKey) {\n return;\n }\n\n if (isValidFocusTarget(scope.activeElement)) {\n addFocusVisibleClass(scope.activeElement);\n }\n\n hadKeyboardEvent = true;\n }\n\n /**\n * If at any point a user clicks with a pointing device, ensure that we change\n * the modality away from keyboard.\n * This avoids the situation where a user presses a key on an already focused\n * element, and then clicks on a different element, focusing it with a\n * pointing device, while we still think we're in keyboard modality.\n * @param {Event} e\n */\n function onPointerDown(e) {\n hadKeyboardEvent = false;\n }\n\n /**\n * On `focus`, add the `focus-visible` class to the target if:\n * - the target received focus as a result of keyboard navigation, or\n * - the event target is an element that will likely require interaction\n * via the keyboard (e.g. a text box)\n * @param {Event} e\n */\n function onFocus(e) {\n // Prevent IE from focusing the document or HTML element.\n if (!isValidFocusTarget(e.target)) {\n return;\n }\n\n if (hadKeyboardEvent || focusTriggersKeyboardModality(e.target)) {\n addFocusVisibleClass(e.target);\n }\n }\n\n /**\n * On `blur`, remove the `focus-visible` class from the target.\n * @param {Event} e\n */\n function onBlur(e) {\n if (!isValidFocusTarget(e.target)) {\n return;\n }\n\n if (\n e.target.classList.contains('focus-visible') ||\n e.target.hasAttribute('data-focus-visible-added')\n ) {\n // To detect a tab/window switch, we look for a blur event followed\n // rapidly by a visibility change.\n // If we don't see a visibility change within 100ms, it's probably a\n // regular focus change.\n hadFocusVisibleRecently = true;\n window.clearTimeout(hadFocusVisibleRecentlyTimeout);\n hadFocusVisibleRecentlyTimeout = window.setTimeout(function() {\n hadFocusVisibleRecently = false;\n }, 100);\n removeFocusVisibleClass(e.target);\n }\n }\n\n /**\n * If the user changes tabs, keep track of whether or not the previously\n * focused element had .focus-visible.\n * @param {Event} e\n */\n function onVisibilityChange(e) {\n if (document.visibilityState === 'hidden') {\n // If the tab becomes active again, the browser will handle calling focus\n // on the element (Safari actually calls it twice).\n // If this tab change caused a blur on an element with focus-visible,\n // re-apply the class when the user switches back to the tab.\n if (hadFocusVisibleRecently) {\n hadKeyboardEvent = true;\n }\n addInitialPointerMoveListeners();\n }\n }\n\n /**\n * Add a group of listeners to detect usage of any pointing devices.\n * These listeners will be added when the polyfill first loads, and anytime\n * the window is blurred, so that they are active when the window regains\n * focus.\n */\n function addInitialPointerMoveListeners() {\n document.addEventListener('mousemove', onInitialPointerMove);\n document.addEventListener('mousedown', onInitialPointerMove);\n document.addEventListener('mouseup', onInitialPointerMove);\n document.addEventListener('pointermove', onInitialPointerMove);\n document.addEventListener('pointerdown', onInitialPointerMove);\n document.addEventListener('pointerup', onInitialPointerMove);\n document.addEventListener('touchmove', onInitialPointerMove);\n document.addEventListener('touchstart', onInitialPointerMove);\n document.addEventListener('touchend', onInitialPointerMove);\n }\n\n function removeInitialPointerMoveListeners() {\n document.removeEventListener('mousemove', onInitialPointerMove);\n document.removeEventListener('mousedown', onInitialPointerMove);\n document.removeEventListener('mouseup', onInitialPointerMove);\n document.removeEventListener('pointermove', onInitialPointerMove);\n document.removeEventListener('pointerdown', onInitialPointerMove);\n document.removeEventListener('pointerup', onInitialPointerMove);\n document.removeEventListener('touchmove', onInitialPointerMove);\n document.removeEventListener('touchstart', onInitialPointerMove);\n document.removeEventListener('touchend', onInitialPointerMove);\n }\n\n /**\n * When the polfyill first loads, assume the user is in keyboard modality.\n * If any event is received from a pointing device (e.g. mouse, pointer,\n * touch), turn off keyboard modality.\n * This accounts for situations where focus enters the page from the URL bar.\n * @param {Event} e\n */\n function onInitialPointerMove(e) {\n // Work around a Safari quirk that fires a mousemove on whenever the\n // window blurs, even if you're tabbing out of the page. \u00AF\\_(\u30C4)_/\u00AF\n if (e.target.nodeName && e.target.nodeName.toLowerCase() === 'html') {\n return;\n }\n\n hadKeyboardEvent = false;\n removeInitialPointerMoveListeners();\n }\n\n // For some kinds of state, we are interested in changes at the global scope\n // only. For example, global pointer input, global key presses and global\n // visibility change should affect the state at every scope:\n document.addEventListener('keydown', onKeyDown, true);\n document.addEventListener('mousedown', onPointerDown, true);\n document.addEventListener('pointerdown', onPointerDown, true);\n document.addEventListener('touchstart', onPointerDown, true);\n document.addEventListener('visibilitychange', onVisibilityChange, true);\n\n addInitialPointerMoveListeners();\n\n // For focus and blur, we specifically care about state changes in the local\n // scope. This is because focus / blur events that originate from within a\n // shadow root are not re-dispatched from the host element if it was already\n // the active element in its own scope:\n scope.addEventListener('focus', onFocus, true);\n scope.addEventListener('blur', onBlur, true);\n\n // We detect that a node is a ShadowRoot by ensuring that it is a\n // DocumentFragment and also has a host property. This check covers native\n // implementation and polyfill implementation transparently. If we only cared\n // about the native implementation, we could just check if the scope was\n // an instance of a ShadowRoot.\n if (scope.nodeType === Node.DOCUMENT_FRAGMENT_NODE && scope.host) {\n // Since a ShadowRoot is a special kind of DocumentFragment, it does not\n // have a root element to add a class to. So, we add this attribute to the\n // host element instead:\n scope.host.setAttribute('data-js-focus-visible', '');\n } else if (scope.nodeType === Node.DOCUMENT_NODE) {\n document.documentElement.classList.add('js-focus-visible');\n document.documentElement.setAttribute('data-js-focus-visible', '');\n }\n }\n\n // It is important to wrap all references to global window and document in\n // these checks to support server-side rendering use cases\n // @see https://github.com/WICG/focus-visible/issues/199\n if (typeof window !== 'undefined' && typeof document !== 'undefined') {\n // Make the polyfill helper globally available. This can be used as a signal\n // to interested libraries that wish to coordinate with the polyfill for e.g.,\n // applying the polyfill to a shadow root:\n window.applyFocusVisiblePolyfill = applyFocusVisiblePolyfill;\n\n // Notify interested libraries of the polyfill's presence, in case the\n // polyfill was loaded lazily:\n var event;\n\n try {\n event = new CustomEvent('focus-visible-polyfill-ready');\n } catch (error) {\n // IE11 does not support using CustomEvent as a constructor directly:\n event = document.createEvent('CustomEvent');\n event.initCustomEvent('focus-visible-polyfill-ready', false, false, {});\n }\n\n window.dispatchEvent(event);\n }\n\n if (typeof document !== 'undefined') {\n // Apply the polyfill to the global document, so that no JavaScript\n // coordination is required to use the polyfill in the top-level document:\n applyFocusVisiblePolyfill(document);\n }\n\n})));\n", "/*!\n * escape-html\n * Copyright(c) 2012-2013 TJ Holowaychuk\n * Copyright(c) 2015 Andreas Lubbe\n * Copyright(c) 2015 Tiancheng \"Timothy\" Gu\n * MIT Licensed\n */\n\n'use strict';\n\n/**\n * Module variables.\n * @private\n */\n\nvar matchHtmlRegExp = /[\"'&<>]/;\n\n/**\n * Module exports.\n * @public\n */\n\nmodule.exports = escapeHtml;\n\n/**\n * Escape special characters in the given string of html.\n *\n * @param {string} string The string to escape for inserting into HTML\n * @return {string}\n * @public\n */\n\nfunction escapeHtml(string) {\n var str = '' + string;\n var match = matchHtmlRegExp.exec(str);\n\n if (!match) {\n return str;\n }\n\n var escape;\n var html = '';\n var index = 0;\n var lastIndex = 0;\n\n for (index = match.index; index < str.length; index++) {\n switch (str.charCodeAt(index)) {\n case 34: // \"\n escape = '"';\n break;\n case 38: // &\n escape = '&';\n break;\n case 39: // '\n escape = ''';\n break;\n case 60: // <\n escape = '<';\n break;\n case 62: // >\n escape = '>';\n break;\n default:\n continue;\n }\n\n if (lastIndex !== index) {\n html += str.substring(lastIndex, index);\n }\n\n lastIndex = index + 1;\n html += escape;\n }\n\n return lastIndex !== index\n ? html + str.substring(lastIndex, index)\n : html;\n}\n", "/*!\n * clipboard.js v2.0.11\n * https://clipboardjs.com/\n *\n * Licensed MIT \u00A9 Zeno Rocha\n */\n(function webpackUniversalModuleDefinition(root, factory) {\n\tif(typeof exports === 'object' && typeof module === 'object')\n\t\tmodule.exports = factory();\n\telse if(typeof define === 'function' && define.amd)\n\t\tdefine([], factory);\n\telse if(typeof exports === 'object')\n\t\texports[\"ClipboardJS\"] = factory();\n\telse\n\t\troot[\"ClipboardJS\"] = factory();\n})(this, function() {\nreturn /******/ (function() { // webpackBootstrap\n/******/ \tvar __webpack_modules__ = ({\n\n/***/ 686:\n/***/ (function(__unused_webpack_module, __webpack_exports__, __webpack_require__) {\n\n\"use strict\";\n\n// EXPORTS\n__webpack_require__.d(__webpack_exports__, {\n \"default\": function() { return /* binding */ clipboard; }\n});\n\n// EXTERNAL MODULE: ./node_modules/tiny-emitter/index.js\nvar tiny_emitter = __webpack_require__(279);\nvar tiny_emitter_default = /*#__PURE__*/__webpack_require__.n(tiny_emitter);\n// EXTERNAL MODULE: ./node_modules/good-listener/src/listen.js\nvar listen = __webpack_require__(370);\nvar listen_default = /*#__PURE__*/__webpack_require__.n(listen);\n// EXTERNAL MODULE: ./node_modules/select/src/select.js\nvar src_select = __webpack_require__(817);\nvar select_default = /*#__PURE__*/__webpack_require__.n(src_select);\n;// CONCATENATED MODULE: ./src/common/command.js\n/**\n * Executes a given operation type.\n * @param {String} type\n * @return {Boolean}\n */\nfunction command(type) {\n try {\n return document.execCommand(type);\n } catch (err) {\n return false;\n }\n}\n;// CONCATENATED MODULE: ./src/actions/cut.js\n\n\n/**\n * Cut action wrapper.\n * @param {String|HTMLElement} target\n * @return {String}\n */\n\nvar ClipboardActionCut = function ClipboardActionCut(target) {\n var selectedText = select_default()(target);\n command('cut');\n return selectedText;\n};\n\n/* harmony default export */ var actions_cut = (ClipboardActionCut);\n;// CONCATENATED MODULE: ./src/common/create-fake-element.js\n/**\n * Creates a fake textarea element with a value.\n * @param {String} value\n * @return {HTMLElement}\n */\nfunction createFakeElement(value) {\n var isRTL = document.documentElement.getAttribute('dir') === 'rtl';\n var fakeElement = document.createElement('textarea'); // Prevent zooming on iOS\n\n fakeElement.style.fontSize = '12pt'; // Reset box model\n\n fakeElement.style.border = '0';\n fakeElement.style.padding = '0';\n fakeElement.style.margin = '0'; // Move element out of screen horizontally\n\n fakeElement.style.position = 'absolute';\n fakeElement.style[isRTL ? 'right' : 'left'] = '-9999px'; // Move element to the same position vertically\n\n var yPosition = window.pageYOffset || document.documentElement.scrollTop;\n fakeElement.style.top = \"\".concat(yPosition, \"px\");\n fakeElement.setAttribute('readonly', '');\n fakeElement.value = value;\n return fakeElement;\n}\n;// CONCATENATED MODULE: ./src/actions/copy.js\n\n\n\n/**\n * Create fake copy action wrapper using a fake element.\n * @param {String} target\n * @param {Object} options\n * @return {String}\n */\n\nvar fakeCopyAction = function fakeCopyAction(value, options) {\n var fakeElement = createFakeElement(value);\n options.container.appendChild(fakeElement);\n var selectedText = select_default()(fakeElement);\n command('copy');\n fakeElement.remove();\n return selectedText;\n};\n/**\n * Copy action wrapper.\n * @param {String|HTMLElement} target\n * @param {Object} options\n * @return {String}\n */\n\n\nvar ClipboardActionCopy = function ClipboardActionCopy(target) {\n var options = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {\n container: document.body\n };\n var selectedText = '';\n\n if (typeof target === 'string') {\n selectedText = fakeCopyAction(target, options);\n } else if (target instanceof HTMLInputElement && !['text', 'search', 'url', 'tel', 'password'].includes(target === null || target === void 0 ? void 0 : target.type)) {\n // If input type doesn't support `setSelectionRange`. Simulate it. https://developer.mozilla.org/en-US/docs/Web/API/HTMLInputElement/setSelectionRange\n selectedText = fakeCopyAction(target.value, options);\n } else {\n selectedText = select_default()(target);\n command('copy');\n }\n\n return selectedText;\n};\n\n/* harmony default export */ var actions_copy = (ClipboardActionCopy);\n;// CONCATENATED MODULE: ./src/actions/default.js\nfunction _typeof(obj) { \"@babel/helpers - typeof\"; if (typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\") { _typeof = function _typeof(obj) { return typeof obj; }; } else { _typeof = function _typeof(obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; }; } return _typeof(obj); }\n\n\n\n/**\n * Inner function which performs selection from either `text` or `target`\n * properties and then executes copy or cut operations.\n * @param {Object} options\n */\n\nvar ClipboardActionDefault = function ClipboardActionDefault() {\n var options = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n // Defines base properties passed from constructor.\n var _options$action = options.action,\n action = _options$action === void 0 ? 'copy' : _options$action,\n container = options.container,\n target = options.target,\n text = options.text; // Sets the `action` to be performed which can be either 'copy' or 'cut'.\n\n if (action !== 'copy' && action !== 'cut') {\n throw new Error('Invalid \"action\" value, use either \"copy\" or \"cut\"');\n } // Sets the `target` property using an element that will be have its content copied.\n\n\n if (target !== undefined) {\n if (target && _typeof(target) === 'object' && target.nodeType === 1) {\n if (action === 'copy' && target.hasAttribute('disabled')) {\n throw new Error('Invalid \"target\" attribute. Please use \"readonly\" instead of \"disabled\" attribute');\n }\n\n if (action === 'cut' && (target.hasAttribute('readonly') || target.hasAttribute('disabled'))) {\n throw new Error('Invalid \"target\" attribute. You can\\'t cut text from elements with \"readonly\" or \"disabled\" attributes');\n }\n } else {\n throw new Error('Invalid \"target\" value, use a valid Element');\n }\n } // Define selection strategy based on `text` property.\n\n\n if (text) {\n return actions_copy(text, {\n container: container\n });\n } // Defines which selection strategy based on `target` property.\n\n\n if (target) {\n return action === 'cut' ? actions_cut(target) : actions_copy(target, {\n container: container\n });\n }\n};\n\n/* harmony default export */ var actions_default = (ClipboardActionDefault);\n;// CONCATENATED MODULE: ./src/clipboard.js\nfunction clipboard_typeof(obj) { \"@babel/helpers - typeof\"; if (typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\") { clipboard_typeof = function _typeof(obj) { return typeof obj; }; } else { clipboard_typeof = function _typeof(obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; }; } return clipboard_typeof(obj); }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } }\n\nfunction _createClass(Constructor, protoProps, staticProps) { if (protoProps) _defineProperties(Constructor.prototype, protoProps); if (staticProps) _defineProperties(Constructor, staticProps); return Constructor; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function\"); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, writable: true, configurable: true } }); if (superClass) _setPrototypeOf(subClass, superClass); }\n\nfunction _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf || function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }\n\nfunction _createSuper(Derived) { var hasNativeReflectConstruct = _isNativeReflectConstruct(); return function _createSuperInternal() { var Super = _getPrototypeOf(Derived), result; if (hasNativeReflectConstruct) { var NewTarget = _getPrototypeOf(this).constructor; result = Reflect.construct(Super, arguments, NewTarget); } else { result = Super.apply(this, arguments); } return _possibleConstructorReturn(this, result); }; }\n\nfunction _possibleConstructorReturn(self, call) { if (call && (clipboard_typeof(call) === \"object\" || typeof call === \"function\")) { return call; } return _assertThisInitialized(self); }\n\nfunction _assertThisInitialized(self) { if (self === void 0) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return self; }\n\nfunction _isNativeReflectConstruct() { if (typeof Reflect === \"undefined\" || !Reflect.construct) return false; if (Reflect.construct.sham) return false; if (typeof Proxy === \"function\") return true; try { Date.prototype.toString.call(Reflect.construct(Date, [], function () {})); return true; } catch (e) { return false; } }\n\nfunction _getPrototypeOf(o) { _getPrototypeOf = Object.setPrototypeOf ? Object.getPrototypeOf : function _getPrototypeOf(o) { return o.__proto__ || Object.getPrototypeOf(o); }; return _getPrototypeOf(o); }\n\n\n\n\n\n\n/**\n * Helper function to retrieve attribute value.\n * @param {String} suffix\n * @param {Element} element\n */\n\nfunction getAttributeValue(suffix, element) {\n var attribute = \"data-clipboard-\".concat(suffix);\n\n if (!element.hasAttribute(attribute)) {\n return;\n }\n\n return element.getAttribute(attribute);\n}\n/**\n * Base class which takes one or more elements, adds event listeners to them,\n * and instantiates a new `ClipboardAction` on each click.\n */\n\n\nvar Clipboard = /*#__PURE__*/function (_Emitter) {\n _inherits(Clipboard, _Emitter);\n\n var _super = _createSuper(Clipboard);\n\n /**\n * @param {String|HTMLElement|HTMLCollection|NodeList} trigger\n * @param {Object} options\n */\n function Clipboard(trigger, options) {\n var _this;\n\n _classCallCheck(this, Clipboard);\n\n _this = _super.call(this);\n\n _this.resolveOptions(options);\n\n _this.listenClick(trigger);\n\n return _this;\n }\n /**\n * Defines if attributes would be resolved using internal setter functions\n * or custom functions that were passed in the constructor.\n * @param {Object} options\n */\n\n\n _createClass(Clipboard, [{\n key: \"resolveOptions\",\n value: function resolveOptions() {\n var options = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n this.action = typeof options.action === 'function' ? options.action : this.defaultAction;\n this.target = typeof options.target === 'function' ? options.target : this.defaultTarget;\n this.text = typeof options.text === 'function' ? options.text : this.defaultText;\n this.container = clipboard_typeof(options.container) === 'object' ? options.container : document.body;\n }\n /**\n * Adds a click event listener to the passed trigger.\n * @param {String|HTMLElement|HTMLCollection|NodeList} trigger\n */\n\n }, {\n key: \"listenClick\",\n value: function listenClick(trigger) {\n var _this2 = this;\n\n this.listener = listen_default()(trigger, 'click', function (e) {\n return _this2.onClick(e);\n });\n }\n /**\n * Defines a new `ClipboardAction` on each click event.\n * @param {Event} e\n */\n\n }, {\n key: \"onClick\",\n value: function onClick(e) {\n var trigger = e.delegateTarget || e.currentTarget;\n var action = this.action(trigger) || 'copy';\n var text = actions_default({\n action: action,\n container: this.container,\n target: this.target(trigger),\n text: this.text(trigger)\n }); // Fires an event based on the copy operation result.\n\n this.emit(text ? 'success' : 'error', {\n action: action,\n text: text,\n trigger: trigger,\n clearSelection: function clearSelection() {\n if (trigger) {\n trigger.focus();\n }\n\n window.getSelection().removeAllRanges();\n }\n });\n }\n /**\n * Default `action` lookup function.\n * @param {Element} trigger\n */\n\n }, {\n key: \"defaultAction\",\n value: function defaultAction(trigger) {\n return getAttributeValue('action', trigger);\n }\n /**\n * Default `target` lookup function.\n * @param {Element} trigger\n */\n\n }, {\n key: \"defaultTarget\",\n value: function defaultTarget(trigger) {\n var selector = getAttributeValue('target', trigger);\n\n if (selector) {\n return document.querySelector(selector);\n }\n }\n /**\n * Allow fire programmatically a copy action\n * @param {String|HTMLElement} target\n * @param {Object} options\n * @returns Text copied.\n */\n\n }, {\n key: \"defaultText\",\n\n /**\n * Default `text` lookup function.\n * @param {Element} trigger\n */\n value: function defaultText(trigger) {\n return getAttributeValue('text', trigger);\n }\n /**\n * Destroy lifecycle.\n */\n\n }, {\n key: \"destroy\",\n value: function destroy() {\n this.listener.destroy();\n }\n }], [{\n key: \"copy\",\n value: function copy(target) {\n var options = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {\n container: document.body\n };\n return actions_copy(target, options);\n }\n /**\n * Allow fire programmatically a cut action\n * @param {String|HTMLElement} target\n * @returns Text cutted.\n */\n\n }, {\n key: \"cut\",\n value: function cut(target) {\n return actions_cut(target);\n }\n /**\n * Returns the support of the given action, or all actions if no action is\n * given.\n * @param {String} [action]\n */\n\n }, {\n key: \"isSupported\",\n value: function isSupported() {\n var action = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : ['copy', 'cut'];\n var actions = typeof action === 'string' ? [action] : action;\n var support = !!document.queryCommandSupported;\n actions.forEach(function (action) {\n support = support && !!document.queryCommandSupported(action);\n });\n return support;\n }\n }]);\n\n return Clipboard;\n}((tiny_emitter_default()));\n\n/* harmony default export */ var clipboard = (Clipboard);\n\n/***/ }),\n\n/***/ 828:\n/***/ (function(module) {\n\nvar DOCUMENT_NODE_TYPE = 9;\n\n/**\n * A polyfill for Element.matches()\n */\nif (typeof Element !== 'undefined' && !Element.prototype.matches) {\n var proto = Element.prototype;\n\n proto.matches = proto.matchesSelector ||\n proto.mozMatchesSelector ||\n proto.msMatchesSelector ||\n proto.oMatchesSelector ||\n proto.webkitMatchesSelector;\n}\n\n/**\n * Finds the closest parent that matches a selector.\n *\n * @param {Element} element\n * @param {String} selector\n * @return {Function}\n */\nfunction closest (element, selector) {\n while (element && element.nodeType !== DOCUMENT_NODE_TYPE) {\n if (typeof element.matches === 'function' &&\n element.matches(selector)) {\n return element;\n }\n element = element.parentNode;\n }\n}\n\nmodule.exports = closest;\n\n\n/***/ }),\n\n/***/ 438:\n/***/ (function(module, __unused_webpack_exports, __webpack_require__) {\n\nvar closest = __webpack_require__(828);\n\n/**\n * Delegates event to a selector.\n *\n * @param {Element} element\n * @param {String} selector\n * @param {String} type\n * @param {Function} callback\n * @param {Boolean} useCapture\n * @return {Object}\n */\nfunction _delegate(element, selector, type, callback, useCapture) {\n var listenerFn = listener.apply(this, arguments);\n\n element.addEventListener(type, listenerFn, useCapture);\n\n return {\n destroy: function() {\n element.removeEventListener(type, listenerFn, useCapture);\n }\n }\n}\n\n/**\n * Delegates event to a selector.\n *\n * @param {Element|String|Array} [elements]\n * @param {String} selector\n * @param {String} type\n * @param {Function} callback\n * @param {Boolean} useCapture\n * @return {Object}\n */\nfunction delegate(elements, selector, type, callback, useCapture) {\n // Handle the regular Element usage\n if (typeof elements.addEventListener === 'function') {\n return _delegate.apply(null, arguments);\n }\n\n // Handle Element-less usage, it defaults to global delegation\n if (typeof type === 'function') {\n // Use `document` as the first parameter, then apply arguments\n // This is a short way to .unshift `arguments` without running into deoptimizations\n return _delegate.bind(null, document).apply(null, arguments);\n }\n\n // Handle Selector-based usage\n if (typeof elements === 'string') {\n elements = document.querySelectorAll(elements);\n }\n\n // Handle Array-like based usage\n return Array.prototype.map.call(elements, function (element) {\n return _delegate(element, selector, type, callback, useCapture);\n });\n}\n\n/**\n * Finds closest match and invokes callback.\n *\n * @param {Element} element\n * @param {String} selector\n * @param {String} type\n * @param {Function} callback\n * @return {Function}\n */\nfunction listener(element, selector, type, callback) {\n return function(e) {\n e.delegateTarget = closest(e.target, selector);\n\n if (e.delegateTarget) {\n callback.call(element, e);\n }\n }\n}\n\nmodule.exports = delegate;\n\n\n/***/ }),\n\n/***/ 879:\n/***/ (function(__unused_webpack_module, exports) {\n\n/**\n * Check if argument is a HTML element.\n *\n * @param {Object} value\n * @return {Boolean}\n */\nexports.node = function(value) {\n return value !== undefined\n && value instanceof HTMLElement\n && value.nodeType === 1;\n};\n\n/**\n * Check if argument is a list of HTML elements.\n *\n * @param {Object} value\n * @return {Boolean}\n */\nexports.nodeList = function(value) {\n var type = Object.prototype.toString.call(value);\n\n return value !== undefined\n && (type === '[object NodeList]' || type === '[object HTMLCollection]')\n && ('length' in value)\n && (value.length === 0 || exports.node(value[0]));\n};\n\n/**\n * Check if argument is a string.\n *\n * @param {Object} value\n * @return {Boolean}\n */\nexports.string = function(value) {\n return typeof value === 'string'\n || value instanceof String;\n};\n\n/**\n * Check if argument is a function.\n *\n * @param {Object} value\n * @return {Boolean}\n */\nexports.fn = function(value) {\n var type = Object.prototype.toString.call(value);\n\n return type === '[object Function]';\n};\n\n\n/***/ }),\n\n/***/ 370:\n/***/ (function(module, __unused_webpack_exports, __webpack_require__) {\n\nvar is = __webpack_require__(879);\nvar delegate = __webpack_require__(438);\n\n/**\n * Validates all params and calls the right\n * listener function based on its target type.\n *\n * @param {String|HTMLElement|HTMLCollection|NodeList} target\n * @param {String} type\n * @param {Function} callback\n * @return {Object}\n */\nfunction listen(target, type, callback) {\n if (!target && !type && !callback) {\n throw new Error('Missing required arguments');\n }\n\n if (!is.string(type)) {\n throw new TypeError('Second argument must be a String');\n }\n\n if (!is.fn(callback)) {\n throw new TypeError('Third argument must be a Function');\n }\n\n if (is.node(target)) {\n return listenNode(target, type, callback);\n }\n else if (is.nodeList(target)) {\n return listenNodeList(target, type, callback);\n }\n else if (is.string(target)) {\n return listenSelector(target, type, callback);\n }\n else {\n throw new TypeError('First argument must be a String, HTMLElement, HTMLCollection, or NodeList');\n }\n}\n\n/**\n * Adds an event listener to a HTML element\n * and returns a remove listener function.\n *\n * @param {HTMLElement} node\n * @param {String} type\n * @param {Function} callback\n * @return {Object}\n */\nfunction listenNode(node, type, callback) {\n node.addEventListener(type, callback);\n\n return {\n destroy: function() {\n node.removeEventListener(type, callback);\n }\n }\n}\n\n/**\n * Add an event listener to a list of HTML elements\n * and returns a remove listener function.\n *\n * @param {NodeList|HTMLCollection} nodeList\n * @param {String} type\n * @param {Function} callback\n * @return {Object}\n */\nfunction listenNodeList(nodeList, type, callback) {\n Array.prototype.forEach.call(nodeList, function(node) {\n node.addEventListener(type, callback);\n });\n\n return {\n destroy: function() {\n Array.prototype.forEach.call(nodeList, function(node) {\n node.removeEventListener(type, callback);\n });\n }\n }\n}\n\n/**\n * Add an event listener to a selector\n * and returns a remove listener function.\n *\n * @param {String} selector\n * @param {String} type\n * @param {Function} callback\n * @return {Object}\n */\nfunction listenSelector(selector, type, callback) {\n return delegate(document.body, selector, type, callback);\n}\n\nmodule.exports = listen;\n\n\n/***/ }),\n\n/***/ 817:\n/***/ (function(module) {\n\nfunction select(element) {\n var selectedText;\n\n if (element.nodeName === 'SELECT') {\n element.focus();\n\n selectedText = element.value;\n }\n else if (element.nodeName === 'INPUT' || element.nodeName === 'TEXTAREA') {\n var isReadOnly = element.hasAttribute('readonly');\n\n if (!isReadOnly) {\n element.setAttribute('readonly', '');\n }\n\n element.select();\n element.setSelectionRange(0, element.value.length);\n\n if (!isReadOnly) {\n element.removeAttribute('readonly');\n }\n\n selectedText = element.value;\n }\n else {\n if (element.hasAttribute('contenteditable')) {\n element.focus();\n }\n\n var selection = window.getSelection();\n var range = document.createRange();\n\n range.selectNodeContents(element);\n selection.removeAllRanges();\n selection.addRange(range);\n\n selectedText = selection.toString();\n }\n\n return selectedText;\n}\n\nmodule.exports = select;\n\n\n/***/ }),\n\n/***/ 279:\n/***/ (function(module) {\n\nfunction E () {\n // Keep this empty so it's easier to inherit from\n // (via https://github.com/lipsmack from https://github.com/scottcorgan/tiny-emitter/issues/3)\n}\n\nE.prototype = {\n on: function (name, callback, ctx) {\n var e = this.e || (this.e = {});\n\n (e[name] || (e[name] = [])).push({\n fn: callback,\n ctx: ctx\n });\n\n return this;\n },\n\n once: function (name, callback, ctx) {\n var self = this;\n function listener () {\n self.off(name, listener);\n callback.apply(ctx, arguments);\n };\n\n listener._ = callback\n return this.on(name, listener, ctx);\n },\n\n emit: function (name) {\n var data = [].slice.call(arguments, 1);\n var evtArr = ((this.e || (this.e = {}))[name] || []).slice();\n var i = 0;\n var len = evtArr.length;\n\n for (i; i < len; i++) {\n evtArr[i].fn.apply(evtArr[i].ctx, data);\n }\n\n return this;\n },\n\n off: function (name, callback) {\n var e = this.e || (this.e = {});\n var evts = e[name];\n var liveEvents = [];\n\n if (evts && callback) {\n for (var i = 0, len = evts.length; i < len; i++) {\n if (evts[i].fn !== callback && evts[i].fn._ !== callback)\n liveEvents.push(evts[i]);\n }\n }\n\n // Remove event from queue to prevent memory leak\n // Suggested by https://github.com/lazd\n // Ref: https://github.com/scottcorgan/tiny-emitter/commit/c6ebfaa9bc973b33d110a84a307742b7cf94c953#commitcomment-5024910\n\n (liveEvents.length)\n ? e[name] = liveEvents\n : delete e[name];\n\n return this;\n }\n};\n\nmodule.exports = E;\nmodule.exports.TinyEmitter = E;\n\n\n/***/ })\n\n/******/ \t});\n/************************************************************************/\n/******/ \t// The module cache\n/******/ \tvar __webpack_module_cache__ = {};\n/******/ \t\n/******/ \t// The require function\n/******/ \tfunction __webpack_require__(moduleId) {\n/******/ \t\t// Check if module is in cache\n/******/ \t\tif(__webpack_module_cache__[moduleId]) {\n/******/ \t\t\treturn __webpack_module_cache__[moduleId].exports;\n/******/ \t\t}\n/******/ \t\t// Create a new module (and put it into the cache)\n/******/ \t\tvar module = __webpack_module_cache__[moduleId] = {\n/******/ \t\t\t// no module.id needed\n/******/ \t\t\t// no module.loaded needed\n/******/ \t\t\texports: {}\n/******/ \t\t};\n/******/ \t\n/******/ \t\t// Execute the module function\n/******/ \t\t__webpack_modules__[moduleId](module, module.exports, __webpack_require__);\n/******/ \t\n/******/ \t\t// Return the exports of the module\n/******/ \t\treturn module.exports;\n/******/ \t}\n/******/ \t\n/************************************************************************/\n/******/ \t/* webpack/runtime/compat get default export */\n/******/ \t!function() {\n/******/ \t\t// getDefaultExport function for compatibility with non-harmony modules\n/******/ \t\t__webpack_require__.n = function(module) {\n/******/ \t\t\tvar getter = module && module.__esModule ?\n/******/ \t\t\t\tfunction() { return module['default']; } :\n/******/ \t\t\t\tfunction() { return module; };\n/******/ \t\t\t__webpack_require__.d(getter, { a: getter });\n/******/ \t\t\treturn getter;\n/******/ \t\t};\n/******/ \t}();\n/******/ \t\n/******/ \t/* webpack/runtime/define property getters */\n/******/ \t!function() {\n/******/ \t\t// define getter functions for harmony exports\n/******/ \t\t__webpack_require__.d = function(exports, definition) {\n/******/ \t\t\tfor(var key in definition) {\n/******/ \t\t\t\tif(__webpack_require__.o(definition, key) && !__webpack_require__.o(exports, key)) {\n/******/ \t\t\t\t\tObject.defineProperty(exports, key, { enumerable: true, get: definition[key] });\n/******/ \t\t\t\t}\n/******/ \t\t\t}\n/******/ \t\t};\n/******/ \t}();\n/******/ \t\n/******/ \t/* webpack/runtime/hasOwnProperty shorthand */\n/******/ \t!function() {\n/******/ \t\t__webpack_require__.o = function(obj, prop) { return Object.prototype.hasOwnProperty.call(obj, prop); }\n/******/ \t}();\n/******/ \t\n/************************************************************************/\n/******/ \t// module exports must be returned from runtime so entry inlining is disabled\n/******/ \t// startup\n/******/ \t// Load entry module and return exports\n/******/ \treturn __webpack_require__(686);\n/******/ })()\n.default;\n});", "/*\n * Copyright (c) 2016-2025 Martin Donath \n *\n * Permission is hereby granted, free of charge, to any person obtaining a copy\n * of this software and associated documentation files (the \"Software\"), to\n * deal in the Software without restriction, including without limitation the\n * rights to use, copy, modify, merge, publish, distribute, sublicense, and/or\n * sell copies of the Software, and to permit persons to whom the Software is\n * furnished to do so, subject to the following conditions:\n *\n * The above copyright notice and this permission notice shall be included in\n * all copies or substantial portions of the Software.\n *\n * THE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\n * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\n * FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT. IN NO EVENT SHALL THE\n * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\n * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING\n * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS\n * IN THE SOFTWARE.\n */\n\nimport \"focus-visible\"\n\nimport {\n EMPTY,\n NEVER,\n Observable,\n Subject,\n defer,\n delay,\n filter,\n map,\n merge,\n mergeWith,\n shareReplay,\n switchMap\n} from \"rxjs\"\n\nimport { configuration, feature } from \"./_\"\nimport {\n at,\n getActiveElement,\n getOptionalElement,\n requestJSON,\n setLocation,\n setToggle,\n watchDocument,\n watchKeyboard,\n watchLocation,\n watchLocationTarget,\n watchMedia,\n watchPrint,\n watchScript,\n watchViewport\n} from \"./browser\"\nimport {\n getComponentElement,\n getComponentElements,\n mountAnnounce,\n mountBackToTop,\n mountConsent,\n mountContent,\n mountDialog,\n mountHeader,\n mountHeaderTitle,\n mountPalette,\n mountProgress,\n mountSearch,\n mountSearchHiglight,\n mountSidebar,\n mountSource,\n mountTableOfContents,\n mountTabs,\n watchHeader,\n watchMain\n} from \"./components\"\nimport {\n SearchIndex,\n fetchSitemap,\n setupAlternate,\n setupClipboardJS,\n setupInstantNavigation,\n setupVersionSelector\n} from \"./integrations\"\nimport {\n patchEllipsis,\n patchIndeterminate,\n patchScrollfix,\n patchScrolllock\n} from \"./patches\"\nimport \"./polyfills\"\n\n/* ----------------------------------------------------------------------------\n * Functions - @todo refactor\n * ------------------------------------------------------------------------- */\n\n/**\n * Fetch search index\n *\n * @returns Search index observable\n */\nfunction fetchSearchIndex(): Observable {\n if (location.protocol === \"file:\") {\n return watchScript(\n `${new URL(\"search/search_index.js\", config.base)}`\n )\n .pipe(\n // @ts-ignore - @todo fix typings\n map(() => __index),\n shareReplay(1)\n )\n } else {\n return requestJSON(\n new URL(\"search/search_index.json\", config.base)\n )\n }\n}\n\n/* ----------------------------------------------------------------------------\n * Application\n * ------------------------------------------------------------------------- */\n\n/* Yay, JavaScript is available */\ndocument.documentElement.classList.remove(\"no-js\")\ndocument.documentElement.classList.add(\"js\")\n\n/* Set up navigation observables and subjects */\nconst document$ = watchDocument()\nconst location$ = watchLocation()\nconst target$ = watchLocationTarget(location$)\nconst keyboard$ = watchKeyboard()\n\n/* Set up media observables */\nconst viewport$ = watchViewport()\nconst tablet$ = watchMedia(\"(min-width: 60em)\")\nconst screen$ = watchMedia(\"(min-width: 76.25em)\")\nconst print$ = watchPrint()\n\n/* Retrieve search index, if search is enabled */\nconst config = configuration()\nconst index$ = document.forms.namedItem(\"search\")\n ? fetchSearchIndex()\n : NEVER\n\n/* Set up Clipboard.js integration */\nconst alert$ = new Subject()\nsetupClipboardJS({ alert$ })\n\n/* Set up language selector */\nsetupAlternate({ document$ })\n\n/* Set up progress indicator */\nconst progress$ = new Subject()\n\n/* Set up sitemap for instant navigation and previews */\nconst sitemap$ = fetchSitemap(config.base)\n\n/* Set up instant navigation, if enabled */\nif (feature(\"navigation.instant\"))\n setupInstantNavigation({ sitemap$, location$, viewport$, progress$ })\n .subscribe(document$)\n\n/* Set up version selector */\nif (config.version?.provider === \"mike\")\n setupVersionSelector({ document$ })\n\n/* Always close drawer and search on navigation */\nmerge(location$, target$)\n .pipe(\n delay(125)\n )\n .subscribe(() => {\n setToggle(\"drawer\", false)\n setToggle(\"search\", false)\n })\n\n/* Set up global keyboard handlers */\nkeyboard$\n .pipe(\n filter(({ mode }) => mode === \"global\")\n )\n .subscribe(key => {\n switch (key.type) {\n\n /* Go to previous page */\n case \"p\":\n case \",\":\n const prev = getOptionalElement(\"link[rel=prev]\")\n if (typeof prev !== \"undefined\")\n setLocation(prev)\n break\n\n /* Go to next page */\n case \"n\":\n case \".\":\n const next = getOptionalElement(\"link[rel=next]\")\n if (typeof next !== \"undefined\")\n setLocation(next)\n break\n\n /* Expand navigation, see https://bit.ly/3ZjG5io */\n case \"Enter\":\n const active = getActiveElement()\n if (active instanceof HTMLLabelElement)\n active.click()\n }\n })\n\n/* Set up patches */\npatchEllipsis({ viewport$, document$ })\npatchIndeterminate({ document$, tablet$ })\npatchScrollfix({ document$ })\npatchScrolllock({ viewport$, tablet$ })\n\n/* Set up header and main area observable */\nconst header$ = watchHeader(getComponentElement(\"header\"), { viewport$ })\nconst main$ = document$\n .pipe(\n map(() => getComponentElement(\"main\")),\n switchMap(el => watchMain(el, { viewport$, header$ })),\n shareReplay(1)\n )\n\n/* Set up control component observables */\nconst control$ = merge(\n\n /* Consent */\n ...getComponentElements(\"consent\")\n .map(el => mountConsent(el, { target$ })),\n\n /* Dialog */\n ...getComponentElements(\"dialog\")\n .map(el => mountDialog(el, { alert$ })),\n\n /* Color palette */\n ...getComponentElements(\"palette\")\n .map(el => mountPalette(el)),\n\n /* Progress bar */\n ...getComponentElements(\"progress\")\n .map(el => mountProgress(el, { progress$ })),\n\n /* Search */\n ...getComponentElements(\"search\")\n .map(el => mountSearch(el, { index$, keyboard$ })),\n\n /* Repository information */\n ...getComponentElements(\"source\")\n .map(el => mountSource(el))\n)\n\n/* Set up content component observables */\nconst content$ = defer(() => merge(\n\n /* Announcement bar */\n ...getComponentElements(\"announce\")\n .map(el => mountAnnounce(el)),\n\n /* Content */\n ...getComponentElements(\"content\")\n .map(el => mountContent(el, { sitemap$, viewport$, target$, print$ })),\n\n /* Search highlighting */\n ...getComponentElements(\"content\")\n .map(el => feature(\"search.highlight\")\n ? mountSearchHiglight(el, { index$, location$ })\n : EMPTY\n ),\n\n /* Header */\n ...getComponentElements(\"header\")\n .map(el => mountHeader(el, { viewport$, header$, main$ })),\n\n /* Header title */\n ...getComponentElements(\"header-title\")\n .map(el => mountHeaderTitle(el, { viewport$, header$ })),\n\n /* Sidebar */\n ...getComponentElements(\"sidebar\")\n .map(el => el.getAttribute(\"data-md-type\") === \"navigation\"\n ? at(screen$, () => mountSidebar(el, { viewport$, header$, main$ }))\n : at(tablet$, () => mountSidebar(el, { viewport$, header$, main$ }))\n ),\n\n /* Navigation tabs */\n ...getComponentElements(\"tabs\")\n .map(el => mountTabs(el, { viewport$, header$ })),\n\n /* Table of contents */\n ...getComponentElements(\"toc\")\n .map(el => mountTableOfContents(el, {\n viewport$, header$, main$, target$\n })),\n\n /* Back-to-top button */\n ...getComponentElements(\"top\")\n .map(el => mountBackToTop(el, { viewport$, header$, main$, target$ }))\n))\n\n/* Set up component observables */\nconst component$ = document$\n .pipe(\n switchMap(() => content$),\n mergeWith(control$),\n shareReplay(1)\n )\n\n/* Subscribe to all components */\ncomponent$.subscribe()\n\n/* ----------------------------------------------------------------------------\n * Exports\n * ------------------------------------------------------------------------- */\n\nwindow.document$ = document$ /* Document observable */\nwindow.location$ = location$ /* Location subject */\nwindow.target$ = target$ /* Location target observable */\nwindow.keyboard$ = keyboard$ /* Keyboard observable */\nwindow.viewport$ = viewport$ /* Viewport observable */\nwindow.tablet$ = tablet$ /* Media tablet observable */\nwindow.screen$ = screen$ /* Media screen observable */\nwindow.print$ = print$ /* Media print observable */\nwindow.alert$ = alert$ /* Alert subject */\nwindow.progress$ = progress$ /* Progress indicator subject */\nwindow.component$ = component$ /* Component observable */\n", "/******************************************************************************\nCopyright (c) Microsoft Corporation.\n\nPermission to use, copy, modify, and/or distribute this software for any\npurpose with or without fee is hereby granted.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH\nREGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY\nAND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,\nINDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM\nLOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR\nOTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR\nPERFORMANCE OF THIS SOFTWARE.\n***************************************************************************** */\n/* global Reflect, Promise, SuppressedError, Symbol, Iterator */\n\nvar extendStatics = function(d, b) {\n extendStatics = Object.setPrototypeOf ||\n ({ __proto__: [] } instanceof Array && function (d, b) { d.__proto__ = b; }) ||\n function (d, b) { for (var p in b) if (Object.prototype.hasOwnProperty.call(b, p)) d[p] = b[p]; };\n return extendStatics(d, b);\n};\n\nexport function __extends(d, b) {\n if (typeof b !== \"function\" && b !== null)\n throw new TypeError(\"Class extends value \" + String(b) + \" is not a constructor or null\");\n extendStatics(d, b);\n function __() { this.constructor = d; }\n d.prototype = b === null ? Object.create(b) : (__.prototype = b.prototype, new __());\n}\n\nexport var __assign = function() {\n __assign = Object.assign || function __assign(t) {\n for (var s, i = 1, n = arguments.length; i < n; i++) {\n s = arguments[i];\n for (var p in s) if (Object.prototype.hasOwnProperty.call(s, p)) t[p] = s[p];\n }\n return t;\n }\n return __assign.apply(this, arguments);\n}\n\nexport function __rest(s, e) {\n var t = {};\n for (var p in s) if (Object.prototype.hasOwnProperty.call(s, p) && e.indexOf(p) < 0)\n t[p] = s[p];\n if (s != null && typeof Object.getOwnPropertySymbols === \"function\")\n for (var i = 0, p = Object.getOwnPropertySymbols(s); i < p.length; i++) {\n if (e.indexOf(p[i]) < 0 && Object.prototype.propertyIsEnumerable.call(s, p[i]))\n t[p[i]] = s[p[i]];\n }\n return t;\n}\n\nexport function __decorate(decorators, target, key, desc) {\n var c = arguments.length, r = c < 3 ? target : desc === null ? desc = Object.getOwnPropertyDescriptor(target, key) : desc, d;\n if (typeof Reflect === \"object\" && typeof Reflect.decorate === \"function\") r = Reflect.decorate(decorators, target, key, desc);\n else for (var i = decorators.length - 1; i >= 0; i--) if (d = decorators[i]) r = (c < 3 ? d(r) : c > 3 ? d(target, key, r) : d(target, key)) || r;\n return c > 3 && r && Object.defineProperty(target, key, r), r;\n}\n\nexport function __param(paramIndex, decorator) {\n return function (target, key) { decorator(target, key, paramIndex); }\n}\n\nexport function __esDecorate(ctor, descriptorIn, decorators, contextIn, initializers, extraInitializers) {\n function accept(f) { if (f !== void 0 && typeof f !== \"function\") throw new TypeError(\"Function expected\"); return f; }\n var kind = contextIn.kind, key = kind === \"getter\" ? \"get\" : kind === \"setter\" ? \"set\" : \"value\";\n var target = !descriptorIn && ctor ? contextIn[\"static\"] ? ctor : ctor.prototype : null;\n var descriptor = descriptorIn || (target ? Object.getOwnPropertyDescriptor(target, contextIn.name) : {});\n var _, done = false;\n for (var i = decorators.length - 1; i >= 0; i--) {\n var context = {};\n for (var p in contextIn) context[p] = p === \"access\" ? {} : contextIn[p];\n for (var p in contextIn.access) context.access[p] = contextIn.access[p];\n context.addInitializer = function (f) { if (done) throw new TypeError(\"Cannot add initializers after decoration has completed\"); extraInitializers.push(accept(f || null)); };\n var result = (0, decorators[i])(kind === \"accessor\" ? { get: descriptor.get, set: descriptor.set } : descriptor[key], context);\n if (kind === \"accessor\") {\n if (result === void 0) continue;\n if (result === null || typeof result !== \"object\") throw new TypeError(\"Object expected\");\n if (_ = accept(result.get)) descriptor.get = _;\n if (_ = accept(result.set)) descriptor.set = _;\n if (_ = accept(result.init)) initializers.unshift(_);\n }\n else if (_ = accept(result)) {\n if (kind === \"field\") initializers.unshift(_);\n else descriptor[key] = _;\n }\n }\n if (target) Object.defineProperty(target, contextIn.name, descriptor);\n done = true;\n};\n\nexport function __runInitializers(thisArg, initializers, value) {\n var useValue = arguments.length > 2;\n for (var i = 0; i < initializers.length; i++) {\n value = useValue ? initializers[i].call(thisArg, value) : initializers[i].call(thisArg);\n }\n return useValue ? value : void 0;\n};\n\nexport function __propKey(x) {\n return typeof x === \"symbol\" ? x : \"\".concat(x);\n};\n\nexport function __setFunctionName(f, name, prefix) {\n if (typeof name === \"symbol\") name = name.description ? \"[\".concat(name.description, \"]\") : \"\";\n return Object.defineProperty(f, \"name\", { configurable: true, value: prefix ? \"\".concat(prefix, \" \", name) : name });\n};\n\nexport function __metadata(metadataKey, metadataValue) {\n if (typeof Reflect === \"object\" && typeof Reflect.metadata === \"function\") return Reflect.metadata(metadataKey, metadataValue);\n}\n\nexport function __awaiter(thisArg, _arguments, P, generator) {\n function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }\n return new (P || (P = Promise))(function (resolve, reject) {\n function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }\n function rejected(value) { try { step(generator[\"throw\"](value)); } catch (e) { reject(e); } }\n function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }\n step((generator = generator.apply(thisArg, _arguments || [])).next());\n });\n}\n\nexport function __generator(thisArg, body) {\n var _ = { label: 0, sent: function() { if (t[0] & 1) throw t[1]; return t[1]; }, trys: [], ops: [] }, f, y, t, g = Object.create((typeof Iterator === \"function\" ? Iterator : Object).prototype);\n return g.next = verb(0), g[\"throw\"] = verb(1), g[\"return\"] = verb(2), typeof Symbol === \"function\" && (g[Symbol.iterator] = function() { return this; }), g;\n function verb(n) { return function (v) { return step([n, v]); }; }\n function step(op) {\n if (f) throw new TypeError(\"Generator is already executing.\");\n while (g && (g = 0, op[0] && (_ = 0)), _) try {\n if (f = 1, y && (t = op[0] & 2 ? y[\"return\"] : op[0] ? y[\"throw\"] || ((t = y[\"return\"]) && t.call(y), 0) : y.next) && !(t = t.call(y, op[1])).done) return t;\n if (y = 0, t) op = [op[0] & 2, t.value];\n switch (op[0]) {\n case 0: case 1: t = op; break;\n case 4: _.label++; return { value: op[1], done: false };\n case 5: _.label++; y = op[1]; op = [0]; continue;\n case 7: op = _.ops.pop(); _.trys.pop(); continue;\n default:\n if (!(t = _.trys, t = t.length > 0 && t[t.length - 1]) && (op[0] === 6 || op[0] === 2)) { _ = 0; continue; }\n if (op[0] === 3 && (!t || (op[1] > t[0] && op[1] < t[3]))) { _.label = op[1]; break; }\n if (op[0] === 6 && _.label < t[1]) { _.label = t[1]; t = op; break; }\n if (t && _.label < t[2]) { _.label = t[2]; _.ops.push(op); break; }\n if (t[2]) _.ops.pop();\n _.trys.pop(); continue;\n }\n op = body.call(thisArg, _);\n } catch (e) { op = [6, e]; y = 0; } finally { f = t = 0; }\n if (op[0] & 5) throw op[1]; return { value: op[0] ? op[1] : void 0, done: true };\n }\n}\n\nexport var __createBinding = Object.create ? (function(o, m, k, k2) {\n if (k2 === undefined) k2 = k;\n var desc = Object.getOwnPropertyDescriptor(m, k);\n if (!desc || (\"get\" in desc ? !m.__esModule : desc.writable || desc.configurable)) {\n desc = { enumerable: true, get: function() { return m[k]; } };\n }\n Object.defineProperty(o, k2, desc);\n}) : (function(o, m, k, k2) {\n if (k2 === undefined) k2 = k;\n o[k2] = m[k];\n});\n\nexport function __exportStar(m, o) {\n for (var p in m) if (p !== \"default\" && !Object.prototype.hasOwnProperty.call(o, p)) __createBinding(o, m, p);\n}\n\nexport function __values(o) {\n var s = typeof Symbol === \"function\" && Symbol.iterator, m = s && o[s], i = 0;\n if (m) return m.call(o);\n if (o && typeof o.length === \"number\") return {\n next: function () {\n if (o && i >= o.length) o = void 0;\n return { value: o && o[i++], done: !o };\n }\n };\n throw new TypeError(s ? \"Object is not iterable.\" : \"Symbol.iterator is not defined.\");\n}\n\nexport function __read(o, n) {\n var m = typeof Symbol === \"function\" && o[Symbol.iterator];\n if (!m) return o;\n var i = m.call(o), r, ar = [], e;\n try {\n while ((n === void 0 || n-- > 0) && !(r = i.next()).done) ar.push(r.value);\n }\n catch (error) { e = { error: error }; }\n finally {\n try {\n if (r && !r.done && (m = i[\"return\"])) m.call(i);\n }\n finally { if (e) throw e.error; }\n }\n return ar;\n}\n\n/** @deprecated */\nexport function __spread() {\n for (var ar = [], i = 0; i < arguments.length; i++)\n ar = ar.concat(__read(arguments[i]));\n return ar;\n}\n\n/** @deprecated */\nexport function __spreadArrays() {\n for (var s = 0, i = 0, il = arguments.length; i < il; i++) s += arguments[i].length;\n for (var r = Array(s), k = 0, i = 0; i < il; i++)\n for (var a = arguments[i], j = 0, jl = a.length; j < jl; j++, k++)\n r[k] = a[j];\n return r;\n}\n\nexport function __spreadArray(to, from, pack) {\n if (pack || arguments.length === 2) for (var i = 0, l = from.length, ar; i < l; i++) {\n if (ar || !(i in from)) {\n if (!ar) ar = Array.prototype.slice.call(from, 0, i);\n ar[i] = from[i];\n }\n }\n return to.concat(ar || Array.prototype.slice.call(from));\n}\n\nexport function __await(v) {\n return this instanceof __await ? (this.v = v, this) : new __await(v);\n}\n\nexport function __asyncGenerator(thisArg, _arguments, generator) {\n if (!Symbol.asyncIterator) throw new TypeError(\"Symbol.asyncIterator is not defined.\");\n var g = generator.apply(thisArg, _arguments || []), i, q = [];\n return i = Object.create((typeof AsyncIterator === \"function\" ? AsyncIterator : Object).prototype), verb(\"next\"), verb(\"throw\"), verb(\"return\", awaitReturn), i[Symbol.asyncIterator] = function () { return this; }, i;\n function awaitReturn(f) { return function (v) { return Promise.resolve(v).then(f, reject); }; }\n function verb(n, f) { if (g[n]) { i[n] = function (v) { return new Promise(function (a, b) { q.push([n, v, a, b]) > 1 || resume(n, v); }); }; if (f) i[n] = f(i[n]); } }\n function resume(n, v) { try { step(g[n](v)); } catch (e) { settle(q[0][3], e); } }\n function step(r) { r.value instanceof __await ? Promise.resolve(r.value.v).then(fulfill, reject) : settle(q[0][2], r); }\n function fulfill(value) { resume(\"next\", value); }\n function reject(value) { resume(\"throw\", value); }\n function settle(f, v) { if (f(v), q.shift(), q.length) resume(q[0][0], q[0][1]); }\n}\n\nexport function __asyncDelegator(o) {\n var i, p;\n return i = {}, verb(\"next\"), verb(\"throw\", function (e) { throw e; }), verb(\"return\"), i[Symbol.iterator] = function () { return this; }, i;\n function verb(n, f) { i[n] = o[n] ? function (v) { return (p = !p) ? { value: __await(o[n](v)), done: false } : f ? f(v) : v; } : f; }\n}\n\nexport function __asyncValues(o) {\n if (!Symbol.asyncIterator) throw new TypeError(\"Symbol.asyncIterator is not defined.\");\n var m = o[Symbol.asyncIterator], i;\n return m ? m.call(o) : (o = typeof __values === \"function\" ? __values(o) : o[Symbol.iterator](), i = {}, verb(\"next\"), verb(\"throw\"), verb(\"return\"), i[Symbol.asyncIterator] = function () { return this; }, i);\n function verb(n) { i[n] = o[n] && function (v) { return new Promise(function (resolve, reject) { v = o[n](v), settle(resolve, reject, v.done, v.value); }); }; }\n function settle(resolve, reject, d, v) { Promise.resolve(v).then(function(v) { resolve({ value: v, done: d }); }, reject); }\n}\n\nexport function __makeTemplateObject(cooked, raw) {\n if (Object.defineProperty) { Object.defineProperty(cooked, \"raw\", { value: raw }); } else { cooked.raw = raw; }\n return cooked;\n};\n\nvar __setModuleDefault = Object.create ? (function(o, v) {\n Object.defineProperty(o, \"default\", { enumerable: true, value: v });\n}) : function(o, v) {\n o[\"default\"] = v;\n};\n\nexport function __importStar(mod) {\n if (mod && mod.__esModule) return mod;\n var result = {};\n if (mod != null) for (var k in mod) if (k !== \"default\" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);\n __setModuleDefault(result, mod);\n return result;\n}\n\nexport function __importDefault(mod) {\n return (mod && mod.__esModule) ? mod : { default: mod };\n}\n\nexport function __classPrivateFieldGet(receiver, state, kind, f) {\n if (kind === \"a\" && !f) throw new TypeError(\"Private accessor was defined without a getter\");\n if (typeof state === \"function\" ? receiver !== state || !f : !state.has(receiver)) throw new TypeError(\"Cannot read private member from an object whose class did not declare it\");\n return kind === \"m\" ? f : kind === \"a\" ? f.call(receiver) : f ? f.value : state.get(receiver);\n}\n\nexport function __classPrivateFieldSet(receiver, state, value, kind, f) {\n if (kind === \"m\") throw new TypeError(\"Private method is not writable\");\n if (kind === \"a\" && !f) throw new TypeError(\"Private accessor was defined without a setter\");\n if (typeof state === \"function\" ? receiver !== state || !f : !state.has(receiver)) throw new TypeError(\"Cannot write private member to an object whose class did not declare it\");\n return (kind === \"a\" ? f.call(receiver, value) : f ? f.value = value : state.set(receiver, value)), value;\n}\n\nexport function __classPrivateFieldIn(state, receiver) {\n if (receiver === null || (typeof receiver !== \"object\" && typeof receiver !== \"function\")) throw new TypeError(\"Cannot use 'in' operator on non-object\");\n return typeof state === \"function\" ? receiver === state : state.has(receiver);\n}\n\nexport function __addDisposableResource(env, value, async) {\n if (value !== null && value !== void 0) {\n if (typeof value !== \"object\" && typeof value !== \"function\") throw new TypeError(\"Object expected.\");\n var dispose, inner;\n if (async) {\n if (!Symbol.asyncDispose) throw new TypeError(\"Symbol.asyncDispose is not defined.\");\n dispose = value[Symbol.asyncDispose];\n }\n if (dispose === void 0) {\n if (!Symbol.dispose) throw new TypeError(\"Symbol.dispose is not defined.\");\n dispose = value[Symbol.dispose];\n if (async) inner = dispose;\n }\n if (typeof dispose !== \"function\") throw new TypeError(\"Object not disposable.\");\n if (inner) dispose = function() { try { inner.call(this); } catch (e) { return Promise.reject(e); } };\n env.stack.push({ value: value, dispose: dispose, async: async });\n }\n else if (async) {\n env.stack.push({ async: true });\n }\n return value;\n}\n\nvar _SuppressedError = typeof SuppressedError === \"function\" ? SuppressedError : function (error, suppressed, message) {\n var e = new Error(message);\n return e.name = \"SuppressedError\", e.error = error, e.suppressed = suppressed, e;\n};\n\nexport function __disposeResources(env) {\n function fail(e) {\n env.error = env.hasError ? new _SuppressedError(e, env.error, \"An error was suppressed during disposal.\") : e;\n env.hasError = true;\n }\n var r, s = 0;\n function next() {\n while (r = env.stack.pop()) {\n try {\n if (!r.async && s === 1) return s = 0, env.stack.push(r), Promise.resolve().then(next);\n if (r.dispose) {\n var result = r.dispose.call(r.value);\n if (r.async) return s |= 2, Promise.resolve(result).then(next, function(e) { fail(e); return next(); });\n }\n else s |= 1;\n }\n catch (e) {\n fail(e);\n }\n }\n if (s === 1) return env.hasError ? Promise.reject(env.error) : Promise.resolve();\n if (env.hasError) throw env.error;\n }\n return next();\n}\n\nexport default {\n __extends,\n __assign,\n __rest,\n __decorate,\n __param,\n __metadata,\n __awaiter,\n __generator,\n __createBinding,\n __exportStar,\n __values,\n __read,\n __spread,\n __spreadArrays,\n __spreadArray,\n __await,\n __asyncGenerator,\n __asyncDelegator,\n __asyncValues,\n __makeTemplateObject,\n __importStar,\n __importDefault,\n __classPrivateFieldGet,\n __classPrivateFieldSet,\n __classPrivateFieldIn,\n __addDisposableResource,\n __disposeResources,\n};\n", "/**\n * Returns true if the object is a function.\n * @param value The value to check\n */\nexport function isFunction(value: any): value is (...args: any[]) => any {\n return typeof value === 'function';\n}\n", "/**\n * Used to create Error subclasses until the community moves away from ES5.\n *\n * This is because compiling from TypeScript down to ES5 has issues with subclassing Errors\n * as well as other built-in types: https://github.com/Microsoft/TypeScript/issues/12123\n *\n * @param createImpl A factory function to create the actual constructor implementation. The returned\n * function should be a named function that calls `_super` internally.\n */\nexport function createErrorClass(createImpl: (_super: any) => any): T {\n const _super = (instance: any) => {\n Error.call(instance);\n instance.stack = new Error().stack;\n };\n\n const ctorFunc = createImpl(_super);\n ctorFunc.prototype = Object.create(Error.prototype);\n ctorFunc.prototype.constructor = ctorFunc;\n return ctorFunc;\n}\n", "import { createErrorClass } from './createErrorClass';\n\nexport interface UnsubscriptionError extends Error {\n readonly errors: any[];\n}\n\nexport interface UnsubscriptionErrorCtor {\n /**\n * @deprecated Internal implementation detail. Do not construct error instances.\n * Cannot be tagged as internal: https://github.com/ReactiveX/rxjs/issues/6269\n */\n new (errors: any[]): UnsubscriptionError;\n}\n\n/**\n * An error thrown when one or more errors have occurred during the\n * `unsubscribe` of a {@link Subscription}.\n */\nexport const UnsubscriptionError: UnsubscriptionErrorCtor = createErrorClass(\n (_super) =>\n function UnsubscriptionErrorImpl(this: any, errors: (Error | string)[]) {\n _super(this);\n this.message = errors\n ? `${errors.length} errors occurred during unsubscription:\n${errors.map((err, i) => `${i + 1}) ${err.toString()}`).join('\\n ')}`\n : '';\n this.name = 'UnsubscriptionError';\n this.errors = errors;\n }\n);\n", "/**\n * Removes an item from an array, mutating it.\n * @param arr The array to remove the item from\n * @param item The item to remove\n */\nexport function arrRemove(arr: T[] | undefined | null, item: T) {\n if (arr) {\n const index = arr.indexOf(item);\n 0 <= index && arr.splice(index, 1);\n }\n}\n", "import { isFunction } from './util/isFunction';\nimport { UnsubscriptionError } from './util/UnsubscriptionError';\nimport { SubscriptionLike, TeardownLogic, Unsubscribable } from './types';\nimport { arrRemove } from './util/arrRemove';\n\n/**\n * Represents a disposable resource, such as the execution of an Observable. A\n * Subscription has one important method, `unsubscribe`, that takes no argument\n * and just disposes the resource held by the subscription.\n *\n * Additionally, subscriptions may be grouped together through the `add()`\n * method, which will attach a child Subscription to the current Subscription.\n * When a Subscription is unsubscribed, all its children (and its grandchildren)\n * will be unsubscribed as well.\n */\nexport class Subscription implements SubscriptionLike {\n public static EMPTY = (() => {\n const empty = new Subscription();\n empty.closed = true;\n return empty;\n })();\n\n /**\n * A flag to indicate whether this Subscription has already been unsubscribed.\n */\n public closed = false;\n\n private _parentage: Subscription[] | Subscription | null = null;\n\n /**\n * The list of registered finalizers to execute upon unsubscription. Adding and removing from this\n * list occurs in the {@link #add} and {@link #remove} methods.\n */\n private _finalizers: Exclude[] | null = null;\n\n /**\n * @param initialTeardown A function executed first as part of the finalization\n * process that is kicked off when {@link #unsubscribe} is called.\n */\n constructor(private initialTeardown?: () => void) {}\n\n /**\n * Disposes the resources held by the subscription. May, for instance, cancel\n * an ongoing Observable execution or cancel any other type of work that\n * started when the Subscription was created.\n */\n unsubscribe(): void {\n let errors: any[] | undefined;\n\n if (!this.closed) {\n this.closed = true;\n\n // Remove this from it's parents.\n const { _parentage } = this;\n if (_parentage) {\n this._parentage = null;\n if (Array.isArray(_parentage)) {\n for (const parent of _parentage) {\n parent.remove(this);\n }\n } else {\n _parentage.remove(this);\n }\n }\n\n const { initialTeardown: initialFinalizer } = this;\n if (isFunction(initialFinalizer)) {\n try {\n initialFinalizer();\n } catch (e) {\n errors = e instanceof UnsubscriptionError ? e.errors : [e];\n }\n }\n\n const { _finalizers } = this;\n if (_finalizers) {\n this._finalizers = null;\n for (const finalizer of _finalizers) {\n try {\n execFinalizer(finalizer);\n } catch (err) {\n errors = errors ?? [];\n if (err instanceof UnsubscriptionError) {\n errors = [...errors, ...err.errors];\n } else {\n errors.push(err);\n }\n }\n }\n }\n\n if (errors) {\n throw new UnsubscriptionError(errors);\n }\n }\n }\n\n /**\n * Adds a finalizer to this subscription, so that finalization will be unsubscribed/called\n * when this subscription is unsubscribed. If this subscription is already {@link #closed},\n * because it has already been unsubscribed, then whatever finalizer is passed to it\n * will automatically be executed (unless the finalizer itself is also a closed subscription).\n *\n * Closed Subscriptions cannot be added as finalizers to any subscription. Adding a closed\n * subscription to a any subscription will result in no operation. (A noop).\n *\n * Adding a subscription to itself, or adding `null` or `undefined` will not perform any\n * operation at all. (A noop).\n *\n * `Subscription` instances that are added to this instance will automatically remove themselves\n * if they are unsubscribed. Functions and {@link Unsubscribable} objects that you wish to remove\n * will need to be removed manually with {@link #remove}\n *\n * @param teardown The finalization logic to add to this subscription.\n */\n add(teardown: TeardownLogic): void {\n // Only add the finalizer if it's not undefined\n // and don't add a subscription to itself.\n if (teardown && teardown !== this) {\n if (this.closed) {\n // If this subscription is already closed,\n // execute whatever finalizer is handed to it automatically.\n execFinalizer(teardown);\n } else {\n if (teardown instanceof Subscription) {\n // We don't add closed subscriptions, and we don't add the same subscription\n // twice. Subscription unsubscribe is idempotent.\n if (teardown.closed || teardown._hasParent(this)) {\n return;\n }\n teardown._addParent(this);\n }\n (this._finalizers = this._finalizers ?? []).push(teardown);\n }\n }\n }\n\n /**\n * Checks to see if a this subscription already has a particular parent.\n * This will signal that this subscription has already been added to the parent in question.\n * @param parent the parent to check for\n */\n private _hasParent(parent: Subscription) {\n const { _parentage } = this;\n return _parentage === parent || (Array.isArray(_parentage) && _parentage.includes(parent));\n }\n\n /**\n * Adds a parent to this subscription so it can be removed from the parent if it\n * unsubscribes on it's own.\n *\n * NOTE: THIS ASSUMES THAT {@link _hasParent} HAS ALREADY BEEN CHECKED.\n * @param parent The parent subscription to add\n */\n private _addParent(parent: Subscription) {\n const { _parentage } = this;\n this._parentage = Array.isArray(_parentage) ? (_parentage.push(parent), _parentage) : _parentage ? [_parentage, parent] : parent;\n }\n\n /**\n * Called on a child when it is removed via {@link #remove}.\n * @param parent The parent to remove\n */\n private _removeParent(parent: Subscription) {\n const { _parentage } = this;\n if (_parentage === parent) {\n this._parentage = null;\n } else if (Array.isArray(_parentage)) {\n arrRemove(_parentage, parent);\n }\n }\n\n /**\n * Removes a finalizer from this subscription that was previously added with the {@link #add} method.\n *\n * Note that `Subscription` instances, when unsubscribed, will automatically remove themselves\n * from every other `Subscription` they have been added to. This means that using the `remove` method\n * is not a common thing and should be used thoughtfully.\n *\n * If you add the same finalizer instance of a function or an unsubscribable object to a `Subscription` instance\n * more than once, you will need to call `remove` the same number of times to remove all instances.\n *\n * All finalizer instances are removed to free up memory upon unsubscription.\n *\n * @param teardown The finalizer to remove from this subscription\n */\n remove(teardown: Exclude): void {\n const { _finalizers } = this;\n _finalizers && arrRemove(_finalizers, teardown);\n\n if (teardown instanceof Subscription) {\n teardown._removeParent(this);\n }\n }\n}\n\nexport const EMPTY_SUBSCRIPTION = Subscription.EMPTY;\n\nexport function isSubscription(value: any): value is Subscription {\n return (\n value instanceof Subscription ||\n (value && 'closed' in value && isFunction(value.remove) && isFunction(value.add) && isFunction(value.unsubscribe))\n );\n}\n\nfunction execFinalizer(finalizer: Unsubscribable | (() => void)) {\n if (isFunction(finalizer)) {\n finalizer();\n } else {\n finalizer.unsubscribe();\n }\n}\n", "import { Subscriber } from './Subscriber';\nimport { ObservableNotification } from './types';\n\n/**\n * The {@link GlobalConfig} object for RxJS. It is used to configure things\n * like how to react on unhandled errors.\n */\nexport const config: GlobalConfig = {\n onUnhandledError: null,\n onStoppedNotification: null,\n Promise: undefined,\n useDeprecatedSynchronousErrorHandling: false,\n useDeprecatedNextContext: false,\n};\n\n/**\n * The global configuration object for RxJS, used to configure things\n * like how to react on unhandled errors. Accessible via {@link config}\n * object.\n */\nexport interface GlobalConfig {\n /**\n * A registration point for unhandled errors from RxJS. These are errors that\n * cannot were not handled by consuming code in the usual subscription path. For\n * example, if you have this configured, and you subscribe to an observable without\n * providing an error handler, errors from that subscription will end up here. This\n * will _always_ be called asynchronously on another job in the runtime. This is because\n * we do not want errors thrown in this user-configured handler to interfere with the\n * behavior of the library.\n */\n onUnhandledError: ((err: any) => void) | null;\n\n /**\n * A registration point for notifications that cannot be sent to subscribers because they\n * have completed, errored or have been explicitly unsubscribed. By default, next, complete\n * and error notifications sent to stopped subscribers are noops. However, sometimes callers\n * might want a different behavior. For example, with sources that attempt to report errors\n * to stopped subscribers, a caller can configure RxJS to throw an unhandled error instead.\n * This will _always_ be called asynchronously on another job in the runtime. This is because\n * we do not want errors thrown in this user-configured handler to interfere with the\n * behavior of the library.\n */\n onStoppedNotification: ((notification: ObservableNotification, subscriber: Subscriber) => void) | null;\n\n /**\n * The promise constructor used by default for {@link Observable#toPromise toPromise} and {@link Observable#forEach forEach}\n * methods.\n *\n * @deprecated As of version 8, RxJS will no longer support this sort of injection of a\n * Promise constructor. If you need a Promise implementation other than native promises,\n * please polyfill/patch Promise as you see appropriate. Will be removed in v8.\n */\n Promise?: PromiseConstructorLike;\n\n /**\n * If true, turns on synchronous error rethrowing, which is a deprecated behavior\n * in v6 and higher. This behavior enables bad patterns like wrapping a subscribe\n * call in a try/catch block. It also enables producer interference, a nasty bug\n * where a multicast can be broken for all observers by a downstream consumer with\n * an unhandled error. DO NOT USE THIS FLAG UNLESS IT'S NEEDED TO BUY TIME\n * FOR MIGRATION REASONS.\n *\n * @deprecated As of version 8, RxJS will no longer support synchronous throwing\n * of unhandled errors. All errors will be thrown on a separate call stack to prevent bad\n * behaviors described above. Will be removed in v8.\n */\n useDeprecatedSynchronousErrorHandling: boolean;\n\n /**\n * If true, enables an as-of-yet undocumented feature from v5: The ability to access\n * `unsubscribe()` via `this` context in `next` functions created in observers passed\n * to `subscribe`.\n *\n * This is being removed because the performance was severely problematic, and it could also cause\n * issues when types other than POJOs are passed to subscribe as subscribers, as they will likely have\n * their `this` context overwritten.\n *\n * @deprecated As of version 8, RxJS will no longer support altering the\n * context of next functions provided as part of an observer to Subscribe. Instead,\n * you will have access to a subscription or a signal or token that will allow you to do things like\n * unsubscribe and test closed status. Will be removed in v8.\n */\n useDeprecatedNextContext: boolean;\n}\n", "import type { TimerHandle } from './timerHandle';\ntype SetTimeoutFunction = (handler: () => void, timeout?: number, ...args: any[]) => TimerHandle;\ntype ClearTimeoutFunction = (handle: TimerHandle) => void;\n\ninterface TimeoutProvider {\n setTimeout: SetTimeoutFunction;\n clearTimeout: ClearTimeoutFunction;\n delegate:\n | {\n setTimeout: SetTimeoutFunction;\n clearTimeout: ClearTimeoutFunction;\n }\n | undefined;\n}\n\nexport const timeoutProvider: TimeoutProvider = {\n // When accessing the delegate, use the variable rather than `this` so that\n // the functions can be called without being bound to the provider.\n setTimeout(handler: () => void, timeout?: number, ...args) {\n const { delegate } = timeoutProvider;\n if (delegate?.setTimeout) {\n return delegate.setTimeout(handler, timeout, ...args);\n }\n return setTimeout(handler, timeout, ...args);\n },\n clearTimeout(handle) {\n const { delegate } = timeoutProvider;\n return (delegate?.clearTimeout || clearTimeout)(handle as any);\n },\n delegate: undefined,\n};\n", "import { config } from '../config';\nimport { timeoutProvider } from '../scheduler/timeoutProvider';\n\n/**\n * Handles an error on another job either with the user-configured {@link onUnhandledError},\n * or by throwing it on that new job so it can be picked up by `window.onerror`, `process.on('error')`, etc.\n *\n * This should be called whenever there is an error that is out-of-band with the subscription\n * or when an error hits a terminal boundary of the subscription and no error handler was provided.\n *\n * @param err the error to report\n */\nexport function reportUnhandledError(err: any) {\n timeoutProvider.setTimeout(() => {\n const { onUnhandledError } = config;\n if (onUnhandledError) {\n // Execute the user-configured error handler.\n onUnhandledError(err);\n } else {\n // Throw so it is picked up by the runtime's uncaught error mechanism.\n throw err;\n }\n });\n}\n", "/* tslint:disable:no-empty */\nexport function noop() { }\n", "import { CompleteNotification, NextNotification, ErrorNotification } from './types';\n\n/**\n * A completion object optimized for memory use and created to be the\n * same \"shape\" as other notifications in v8.\n * @internal\n */\nexport const COMPLETE_NOTIFICATION = (() => createNotification('C', undefined, undefined) as CompleteNotification)();\n\n/**\n * Internal use only. Creates an optimized error notification that is the same \"shape\"\n * as other notifications.\n * @internal\n */\nexport function errorNotification(error: any): ErrorNotification {\n return createNotification('E', undefined, error) as any;\n}\n\n/**\n * Internal use only. Creates an optimized next notification that is the same \"shape\"\n * as other notifications.\n * @internal\n */\nexport function nextNotification(value: T) {\n return createNotification('N', value, undefined) as NextNotification;\n}\n\n/**\n * Ensures that all notifications created internally have the same \"shape\" in v8.\n *\n * TODO: This is only exported to support a crazy legacy test in `groupBy`.\n * @internal\n */\nexport function createNotification(kind: 'N' | 'E' | 'C', value: any, error: any) {\n return {\n kind,\n value,\n error,\n };\n}\n", "import { config } from '../config';\n\nlet context: { errorThrown: boolean; error: any } | null = null;\n\n/**\n * Handles dealing with errors for super-gross mode. Creates a context, in which\n * any synchronously thrown errors will be passed to {@link captureError}. Which\n * will record the error such that it will be rethrown after the call back is complete.\n * TODO: Remove in v8\n * @param cb An immediately executed function.\n */\nexport function errorContext(cb: () => void) {\n if (config.useDeprecatedSynchronousErrorHandling) {\n const isRoot = !context;\n if (isRoot) {\n context = { errorThrown: false, error: null };\n }\n cb();\n if (isRoot) {\n const { errorThrown, error } = context!;\n context = null;\n if (errorThrown) {\n throw error;\n }\n }\n } else {\n // This is the general non-deprecated path for everyone that\n // isn't crazy enough to use super-gross mode (useDeprecatedSynchronousErrorHandling)\n cb();\n }\n}\n\n/**\n * Captures errors only in super-gross mode.\n * @param err the error to capture\n */\nexport function captureError(err: any) {\n if (config.useDeprecatedSynchronousErrorHandling && context) {\n context.errorThrown = true;\n context.error = err;\n }\n}\n", "import { isFunction } from './util/isFunction';\nimport { Observer, ObservableNotification } from './types';\nimport { isSubscription, Subscription } from './Subscription';\nimport { config } from './config';\nimport { reportUnhandledError } from './util/reportUnhandledError';\nimport { noop } from './util/noop';\nimport { nextNotification, errorNotification, COMPLETE_NOTIFICATION } from './NotificationFactories';\nimport { timeoutProvider } from './scheduler/timeoutProvider';\nimport { captureError } from './util/errorContext';\n\n/**\n * Implements the {@link Observer} interface and extends the\n * {@link Subscription} class. While the {@link Observer} is the public API for\n * consuming the values of an {@link Observable}, all Observers get converted to\n * a Subscriber, in order to provide Subscription-like capabilities such as\n * `unsubscribe`. Subscriber is a common type in RxJS, and crucial for\n * implementing operators, but it is rarely used as a public API.\n */\nexport class Subscriber extends Subscription implements Observer {\n /**\n * A static factory for a Subscriber, given a (potentially partial) definition\n * of an Observer.\n * @param next The `next` callback of an Observer.\n * @param error The `error` callback of an\n * Observer.\n * @param complete The `complete` callback of an\n * Observer.\n * @return A Subscriber wrapping the (partially defined)\n * Observer represented by the given arguments.\n * @deprecated Do not use. Will be removed in v8. There is no replacement for this\n * method, and there is no reason to be creating instances of `Subscriber` directly.\n * If you have a specific use case, please file an issue.\n */\n static create(next?: (x?: T) => void, error?: (e?: any) => void, complete?: () => void): Subscriber {\n return new SafeSubscriber(next, error, complete);\n }\n\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n protected isStopped: boolean = false;\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n protected destination: Subscriber | Observer; // this `any` is the escape hatch to erase extra type param (e.g. R)\n\n /**\n * @deprecated Internal implementation detail, do not use directly. Will be made internal in v8.\n * There is no reason to directly create an instance of Subscriber. This type is exported for typings reasons.\n */\n constructor(destination?: Subscriber | Observer) {\n super();\n if (destination) {\n this.destination = destination;\n // Automatically chain subscriptions together here.\n // if destination is a Subscription, then it is a Subscriber.\n if (isSubscription(destination)) {\n destination.add(this);\n }\n } else {\n this.destination = EMPTY_OBSERVER;\n }\n }\n\n /**\n * The {@link Observer} callback to receive notifications of type `next` from\n * the Observable, with a value. The Observable may call this method 0 or more\n * times.\n * @param value The `next` value.\n */\n next(value: T): void {\n if (this.isStopped) {\n handleStoppedNotification(nextNotification(value), this);\n } else {\n this._next(value!);\n }\n }\n\n /**\n * The {@link Observer} callback to receive notifications of type `error` from\n * the Observable, with an attached `Error`. Notifies the Observer that\n * the Observable has experienced an error condition.\n * @param err The `error` exception.\n */\n error(err?: any): void {\n if (this.isStopped) {\n handleStoppedNotification(errorNotification(err), this);\n } else {\n this.isStopped = true;\n this._error(err);\n }\n }\n\n /**\n * The {@link Observer} callback to receive a valueless notification of type\n * `complete` from the Observable. Notifies the Observer that the Observable\n * has finished sending push-based notifications.\n */\n complete(): void {\n if (this.isStopped) {\n handleStoppedNotification(COMPLETE_NOTIFICATION, this);\n } else {\n this.isStopped = true;\n this._complete();\n }\n }\n\n unsubscribe(): void {\n if (!this.closed) {\n this.isStopped = true;\n super.unsubscribe();\n this.destination = null!;\n }\n }\n\n protected _next(value: T): void {\n this.destination.next(value);\n }\n\n protected _error(err: any): void {\n try {\n this.destination.error(err);\n } finally {\n this.unsubscribe();\n }\n }\n\n protected _complete(): void {\n try {\n this.destination.complete();\n } finally {\n this.unsubscribe();\n }\n }\n}\n\n/**\n * This bind is captured here because we want to be able to have\n * compatibility with monoid libraries that tend to use a method named\n * `bind`. In particular, a library called Monio requires this.\n */\nconst _bind = Function.prototype.bind;\n\nfunction bind any>(fn: Fn, thisArg: any): Fn {\n return _bind.call(fn, thisArg);\n}\n\n/**\n * Internal optimization only, DO NOT EXPOSE.\n * @internal\n */\nclass ConsumerObserver implements Observer {\n constructor(private partialObserver: Partial>) {}\n\n next(value: T): void {\n const { partialObserver } = this;\n if (partialObserver.next) {\n try {\n partialObserver.next(value);\n } catch (error) {\n handleUnhandledError(error);\n }\n }\n }\n\n error(err: any): void {\n const { partialObserver } = this;\n if (partialObserver.error) {\n try {\n partialObserver.error(err);\n } catch (error) {\n handleUnhandledError(error);\n }\n } else {\n handleUnhandledError(err);\n }\n }\n\n complete(): void {\n const { partialObserver } = this;\n if (partialObserver.complete) {\n try {\n partialObserver.complete();\n } catch (error) {\n handleUnhandledError(error);\n }\n }\n }\n}\n\nexport class SafeSubscriber extends Subscriber {\n constructor(\n observerOrNext?: Partial> | ((value: T) => void) | null,\n error?: ((e?: any) => void) | null,\n complete?: (() => void) | null\n ) {\n super();\n\n let partialObserver: Partial>;\n if (isFunction(observerOrNext) || !observerOrNext) {\n // The first argument is a function, not an observer. The next\n // two arguments *could* be observers, or they could be empty.\n partialObserver = {\n next: (observerOrNext ?? undefined) as ((value: T) => void) | undefined,\n error: error ?? undefined,\n complete: complete ?? undefined,\n };\n } else {\n // The first argument is a partial observer.\n let context: any;\n if (this && config.useDeprecatedNextContext) {\n // This is a deprecated path that made `this.unsubscribe()` available in\n // next handler functions passed to subscribe. This only exists behind a flag\n // now, as it is *very* slow.\n context = Object.create(observerOrNext);\n context.unsubscribe = () => this.unsubscribe();\n partialObserver = {\n next: observerOrNext.next && bind(observerOrNext.next, context),\n error: observerOrNext.error && bind(observerOrNext.error, context),\n complete: observerOrNext.complete && bind(observerOrNext.complete, context),\n };\n } else {\n // The \"normal\" path. Just use the partial observer directly.\n partialObserver = observerOrNext;\n }\n }\n\n // Wrap the partial observer to ensure it's a full observer, and\n // make sure proper error handling is accounted for.\n this.destination = new ConsumerObserver(partialObserver);\n }\n}\n\nfunction handleUnhandledError(error: any) {\n if (config.useDeprecatedSynchronousErrorHandling) {\n captureError(error);\n } else {\n // Ideal path, we report this as an unhandled error,\n // which is thrown on a new call stack.\n reportUnhandledError(error);\n }\n}\n\n/**\n * An error handler used when no error handler was supplied\n * to the SafeSubscriber -- meaning no error handler was supplied\n * do the `subscribe` call on our observable.\n * @param err The error to handle\n */\nfunction defaultErrorHandler(err: any) {\n throw err;\n}\n\n/**\n * A handler for notifications that cannot be sent to a stopped subscriber.\n * @param notification The notification being sent.\n * @param subscriber The stopped subscriber.\n */\nfunction handleStoppedNotification(notification: ObservableNotification, subscriber: Subscriber) {\n const { onStoppedNotification } = config;\n onStoppedNotification && timeoutProvider.setTimeout(() => onStoppedNotification(notification, subscriber));\n}\n\n/**\n * The observer used as a stub for subscriptions where the user did not\n * pass any arguments to `subscribe`. Comes with the default error handling\n * behavior.\n */\nexport const EMPTY_OBSERVER: Readonly> & { closed: true } = {\n closed: true,\n next: noop,\n error: defaultErrorHandler,\n complete: noop,\n};\n", "/**\n * Symbol.observable or a string \"@@observable\". Used for interop\n *\n * @deprecated We will no longer be exporting this symbol in upcoming versions of RxJS.\n * Instead polyfill and use Symbol.observable directly *or* use https://www.npmjs.com/package/symbol-observable\n */\nexport const observable: string | symbol = (() => (typeof Symbol === 'function' && Symbol.observable) || '@@observable')();\n", "/**\n * This function takes one parameter and just returns it. Simply put,\n * this is like `(x: T): T => x`.\n *\n * ## Examples\n *\n * This is useful in some cases when using things like `mergeMap`\n *\n * ```ts\n * import { interval, take, map, range, mergeMap, identity } from 'rxjs';\n *\n * const source$ = interval(1000).pipe(take(5));\n *\n * const result$ = source$.pipe(\n * map(i => range(i)),\n * mergeMap(identity) // same as mergeMap(x => x)\n * );\n *\n * result$.subscribe({\n * next: console.log\n * });\n * ```\n *\n * Or when you want to selectively apply an operator\n *\n * ```ts\n * import { interval, take, identity } from 'rxjs';\n *\n * const shouldLimit = () => Math.random() < 0.5;\n *\n * const source$ = interval(1000);\n *\n * const result$ = source$.pipe(shouldLimit() ? take(5) : identity);\n *\n * result$.subscribe({\n * next: console.log\n * });\n * ```\n *\n * @param x Any value that is returned by this function\n * @returns The value passed as the first parameter to this function\n */\nexport function identity(x: T): T {\n return x;\n}\n", "import { identity } from './identity';\nimport { UnaryFunction } from '../types';\n\nexport function pipe(): typeof identity;\nexport function pipe(fn1: UnaryFunction): UnaryFunction;\nexport function pipe(fn1: UnaryFunction, fn2: UnaryFunction): UnaryFunction;\nexport function pipe(fn1: UnaryFunction, fn2: UnaryFunction, fn3: UnaryFunction): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction,\n fn7: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction,\n fn7: UnaryFunction,\n fn8: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction,\n fn7: UnaryFunction,\n fn8: UnaryFunction,\n fn9: UnaryFunction\n): UnaryFunction;\nexport function pipe(\n fn1: UnaryFunction,\n fn2: UnaryFunction,\n fn3: UnaryFunction,\n fn4: UnaryFunction,\n fn5: UnaryFunction,\n fn6: UnaryFunction,\n fn7: UnaryFunction,\n fn8: UnaryFunction,\n fn9: UnaryFunction,\n ...fns: UnaryFunction[]\n): UnaryFunction;\n\n/**\n * pipe() can be called on one or more functions, each of which can take one argument (\"UnaryFunction\")\n * and uses it to return a value.\n * It returns a function that takes one argument, passes it to the first UnaryFunction, and then\n * passes the result to the next one, passes that result to the next one, and so on. \n */\nexport function pipe(...fns: Array>): UnaryFunction {\n return pipeFromArray(fns);\n}\n\n/** @internal */\nexport function pipeFromArray(fns: Array>): UnaryFunction {\n if (fns.length === 0) {\n return identity as UnaryFunction;\n }\n\n if (fns.length === 1) {\n return fns[0];\n }\n\n return function piped(input: T): R {\n return fns.reduce((prev: any, fn: UnaryFunction) => fn(prev), input as any);\n };\n}\n", "import { Operator } from './Operator';\nimport { SafeSubscriber, Subscriber } from './Subscriber';\nimport { isSubscription, Subscription } from './Subscription';\nimport { TeardownLogic, OperatorFunction, Subscribable, Observer } from './types';\nimport { observable as Symbol_observable } from './symbol/observable';\nimport { pipeFromArray } from './util/pipe';\nimport { config } from './config';\nimport { isFunction } from './util/isFunction';\nimport { errorContext } from './util/errorContext';\n\n/**\n * A representation of any set of values over any amount of time. This is the most basic building block\n * of RxJS.\n */\nexport class Observable implements Subscribable {\n /**\n * @deprecated Internal implementation detail, do not use directly. Will be made internal in v8.\n */\n source: Observable | undefined;\n\n /**\n * @deprecated Internal implementation detail, do not use directly. Will be made internal in v8.\n */\n operator: Operator | undefined;\n\n /**\n * @param subscribe The function that is called when the Observable is\n * initially subscribed to. This function is given a Subscriber, to which new values\n * can be `next`ed, or an `error` method can be called to raise an error, or\n * `complete` can be called to notify of a successful completion.\n */\n constructor(subscribe?: (this: Observable, subscriber: Subscriber) => TeardownLogic) {\n if (subscribe) {\n this._subscribe = subscribe;\n }\n }\n\n // HACK: Since TypeScript inherits static properties too, we have to\n // fight against TypeScript here so Subject can have a different static create signature\n /**\n * Creates a new Observable by calling the Observable constructor\n * @param subscribe the subscriber function to be passed to the Observable constructor\n * @return A new observable.\n * @deprecated Use `new Observable()` instead. Will be removed in v8.\n */\n static create: (...args: any[]) => any = (subscribe?: (subscriber: Subscriber) => TeardownLogic) => {\n return new Observable(subscribe);\n };\n\n /**\n * Creates a new Observable, with this Observable instance as the source, and the passed\n * operator defined as the new observable's operator.\n * @param operator the operator defining the operation to take on the observable\n * @return A new observable with the Operator applied.\n * @deprecated Internal implementation detail, do not use directly. Will be made internal in v8.\n * If you have implemented an operator using `lift`, it is recommended that you create an\n * operator by simply returning `new Observable()` directly. See \"Creating new operators from\n * scratch\" section here: https://rxjs.dev/guide/operators\n */\n lift(operator?: Operator): Observable {\n const observable = new Observable();\n observable.source = this;\n observable.operator = operator;\n return observable;\n }\n\n subscribe(observerOrNext?: Partial> | ((value: T) => void)): Subscription;\n /** @deprecated Instead of passing separate callback arguments, use an observer argument. Signatures taking separate callback arguments will be removed in v8. Details: https://rxjs.dev/deprecations/subscribe-arguments */\n subscribe(next?: ((value: T) => void) | null, error?: ((error: any) => void) | null, complete?: (() => void) | null): Subscription;\n /**\n * Invokes an execution of an Observable and registers Observer handlers for notifications it will emit.\n *\n * Use it when you have all these Observables, but still nothing is happening.\n *\n * `subscribe` is not a regular operator, but a method that calls Observable's internal `subscribe` function. It\n * might be for example a function that you passed to Observable's constructor, but most of the time it is\n * a library implementation, which defines what will be emitted by an Observable, and when it be will emitted. This means\n * that calling `subscribe` is actually the moment when Observable starts its work, not when it is created, as it is often\n * the thought.\n *\n * Apart from starting the execution of an Observable, this method allows you to listen for values\n * that an Observable emits, as well as for when it completes or errors. You can achieve this in two\n * of the following ways.\n *\n * The first way is creating an object that implements {@link Observer} interface. It should have methods\n * defined by that interface, but note that it should be just a regular JavaScript object, which you can create\n * yourself in any way you want (ES6 class, classic function constructor, object literal etc.). In particular, do\n * not attempt to use any RxJS implementation details to create Observers - you don't need them. Remember also\n * that your object does not have to implement all methods. If you find yourself creating a method that doesn't\n * do anything, you can simply omit it. Note however, if the `error` method is not provided and an error happens,\n * it will be thrown asynchronously. Errors thrown asynchronously cannot be caught using `try`/`catch`. Instead,\n * use the {@link onUnhandledError} configuration option or use a runtime handler (like `window.onerror` or\n * `process.on('error)`) to be notified of unhandled errors. Because of this, it's recommended that you provide\n * an `error` method to avoid missing thrown errors.\n *\n * The second way is to give up on Observer object altogether and simply provide callback functions in place of its methods.\n * This means you can provide three functions as arguments to `subscribe`, where the first function is equivalent\n * of a `next` method, the second of an `error` method and the third of a `complete` method. Just as in case of an Observer,\n * if you do not need to listen for something, you can omit a function by passing `undefined` or `null`,\n * since `subscribe` recognizes these functions by where they were placed in function call. When it comes\n * to the `error` function, as with an Observer, if not provided, errors emitted by an Observable will be thrown asynchronously.\n *\n * You can, however, subscribe with no parameters at all. This may be the case where you're not interested in terminal events\n * and you also handled emissions internally by using operators (e.g. using `tap`).\n *\n * Whichever style of calling `subscribe` you use, in both cases it returns a Subscription object.\n * This object allows you to call `unsubscribe` on it, which in turn will stop the work that an Observable does and will clean\n * up all resources that an Observable used. Note that cancelling a subscription will not call `complete` callback\n * provided to `subscribe` function, which is reserved for a regular completion signal that comes from an Observable.\n *\n * Remember that callbacks provided to `subscribe` are not guaranteed to be called asynchronously.\n * It is an Observable itself that decides when these functions will be called. For example {@link of}\n * by default emits all its values synchronously. Always check documentation for how given Observable\n * will behave when subscribed and if its default behavior can be modified with a `scheduler`.\n *\n * #### Examples\n *\n * Subscribe with an {@link guide/observer Observer}\n *\n * ```ts\n * import { of } from 'rxjs';\n *\n * const sumObserver = {\n * sum: 0,\n * next(value) {\n * console.log('Adding: ' + value);\n * this.sum = this.sum + value;\n * },\n * error() {\n * // We actually could just remove this method,\n * // since we do not really care about errors right now.\n * },\n * complete() {\n * console.log('Sum equals: ' + this.sum);\n * }\n * };\n *\n * of(1, 2, 3) // Synchronously emits 1, 2, 3 and then completes.\n * .subscribe(sumObserver);\n *\n * // Logs:\n * // 'Adding: 1'\n * // 'Adding: 2'\n * // 'Adding: 3'\n * // 'Sum equals: 6'\n * ```\n *\n * Subscribe with functions ({@link deprecations/subscribe-arguments deprecated})\n *\n * ```ts\n * import { of } from 'rxjs'\n *\n * let sum = 0;\n *\n * of(1, 2, 3).subscribe(\n * value => {\n * console.log('Adding: ' + value);\n * sum = sum + value;\n * },\n * undefined,\n * () => console.log('Sum equals: ' + sum)\n * );\n *\n * // Logs:\n * // 'Adding: 1'\n * // 'Adding: 2'\n * // 'Adding: 3'\n * // 'Sum equals: 6'\n * ```\n *\n * Cancel a subscription\n *\n * ```ts\n * import { interval } from 'rxjs';\n *\n * const subscription = interval(1000).subscribe({\n * next(num) {\n * console.log(num)\n * },\n * complete() {\n * // Will not be called, even when cancelling subscription.\n * console.log('completed!');\n * }\n * });\n *\n * setTimeout(() => {\n * subscription.unsubscribe();\n * console.log('unsubscribed!');\n * }, 2500);\n *\n * // Logs:\n * // 0 after 1s\n * // 1 after 2s\n * // 'unsubscribed!' after 2.5s\n * ```\n *\n * @param observerOrNext Either an {@link Observer} with some or all callback methods,\n * or the `next` handler that is called for each value emitted from the subscribed Observable.\n * @param error A handler for a terminal event resulting from an error. If no error handler is provided,\n * the error will be thrown asynchronously as unhandled.\n * @param complete A handler for a terminal event resulting from successful completion.\n * @return A subscription reference to the registered handlers.\n */\n subscribe(\n observerOrNext?: Partial> | ((value: T) => void) | null,\n error?: ((error: any) => void) | null,\n complete?: (() => void) | null\n ): Subscription {\n const subscriber = isSubscriber(observerOrNext) ? observerOrNext : new SafeSubscriber(observerOrNext, error, complete);\n\n errorContext(() => {\n const { operator, source } = this;\n subscriber.add(\n operator\n ? // We're dealing with a subscription in the\n // operator chain to one of our lifted operators.\n operator.call(subscriber, source)\n : source\n ? // If `source` has a value, but `operator` does not, something that\n // had intimate knowledge of our API, like our `Subject`, must have\n // set it. We're going to just call `_subscribe` directly.\n this._subscribe(subscriber)\n : // In all other cases, we're likely wrapping a user-provided initializer\n // function, so we need to catch errors and handle them appropriately.\n this._trySubscribe(subscriber)\n );\n });\n\n return subscriber;\n }\n\n /** @internal */\n protected _trySubscribe(sink: Subscriber): TeardownLogic {\n try {\n return this._subscribe(sink);\n } catch (err) {\n // We don't need to return anything in this case,\n // because it's just going to try to `add()` to a subscription\n // above.\n sink.error(err);\n }\n }\n\n /**\n * Used as a NON-CANCELLABLE means of subscribing to an observable, for use with\n * APIs that expect promises, like `async/await`. You cannot unsubscribe from this.\n *\n * **WARNING**: Only use this with observables you *know* will complete. If the source\n * observable does not complete, you will end up with a promise that is hung up, and\n * potentially all of the state of an async function hanging out in memory. To avoid\n * this situation, look into adding something like {@link timeout}, {@link take},\n * {@link takeWhile}, or {@link takeUntil} amongst others.\n *\n * #### Example\n *\n * ```ts\n * import { interval, take } from 'rxjs';\n *\n * const source$ = interval(1000).pipe(take(4));\n *\n * async function getTotal() {\n * let total = 0;\n *\n * await source$.forEach(value => {\n * total += value;\n * console.log('observable -> ' + value);\n * });\n *\n * return total;\n * }\n *\n * getTotal().then(\n * total => console.log('Total: ' + total)\n * );\n *\n * // Expected:\n * // 'observable -> 0'\n * // 'observable -> 1'\n * // 'observable -> 2'\n * // 'observable -> 3'\n * // 'Total: 6'\n * ```\n *\n * @param next A handler for each value emitted by the observable.\n * @return A promise that either resolves on observable completion or\n * rejects with the handled error.\n */\n forEach(next: (value: T) => void): Promise;\n\n /**\n * @param next a handler for each value emitted by the observable\n * @param promiseCtor a constructor function used to instantiate the Promise\n * @return a promise that either resolves on observable completion or\n * rejects with the handled error\n * @deprecated Passing a Promise constructor will no longer be available\n * in upcoming versions of RxJS. This is because it adds weight to the library, for very\n * little benefit. If you need this functionality, it is recommended that you either\n * polyfill Promise, or you create an adapter to convert the returned native promise\n * to whatever promise implementation you wanted. Will be removed in v8.\n */\n forEach(next: (value: T) => void, promiseCtor: PromiseConstructorLike): Promise;\n\n forEach(next: (value: T) => void, promiseCtor?: PromiseConstructorLike): Promise {\n promiseCtor = getPromiseCtor(promiseCtor);\n\n return new promiseCtor((resolve, reject) => {\n const subscriber = new SafeSubscriber({\n next: (value) => {\n try {\n next(value);\n } catch (err) {\n reject(err);\n subscriber.unsubscribe();\n }\n },\n error: reject,\n complete: resolve,\n });\n this.subscribe(subscriber);\n }) as Promise;\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): TeardownLogic {\n return this.source?.subscribe(subscriber);\n }\n\n /**\n * An interop point defined by the es7-observable spec https://github.com/zenparsing/es-observable\n * @return This instance of the observable.\n */\n [Symbol_observable]() {\n return this;\n }\n\n /* tslint:disable:max-line-length */\n pipe(): Observable;\n pipe(op1: OperatorFunction): Observable;\n pipe(op1: OperatorFunction, op2: OperatorFunction): Observable;\n pipe(op1: OperatorFunction, op2: OperatorFunction, op3: OperatorFunction): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction,\n op7: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction,\n op7: OperatorFunction,\n op8: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction,\n op7: OperatorFunction,\n op8: OperatorFunction,\n op9: OperatorFunction\n ): Observable;\n pipe(\n op1: OperatorFunction,\n op2: OperatorFunction,\n op3: OperatorFunction,\n op4: OperatorFunction,\n op5: OperatorFunction,\n op6: OperatorFunction,\n op7: OperatorFunction,\n op8: OperatorFunction,\n op9: OperatorFunction,\n ...operations: OperatorFunction[]\n ): Observable;\n /* tslint:enable:max-line-length */\n\n /**\n * Used to stitch together functional operators into a chain.\n *\n * ## Example\n *\n * ```ts\n * import { interval, filter, map, scan } from 'rxjs';\n *\n * interval(1000)\n * .pipe(\n * filter(x => x % 2 === 0),\n * map(x => x + x),\n * scan((acc, x) => acc + x)\n * )\n * .subscribe(x => console.log(x));\n * ```\n *\n * @return The Observable result of all the operators having been called\n * in the order they were passed in.\n */\n pipe(...operations: OperatorFunction[]): Observable {\n return pipeFromArray(operations)(this);\n }\n\n /* tslint:disable:max-line-length */\n /** @deprecated Replaced with {@link firstValueFrom} and {@link lastValueFrom}. Will be removed in v8. Details: https://rxjs.dev/deprecations/to-promise */\n toPromise(): Promise;\n /** @deprecated Replaced with {@link firstValueFrom} and {@link lastValueFrom}. Will be removed in v8. Details: https://rxjs.dev/deprecations/to-promise */\n toPromise(PromiseCtor: typeof Promise): Promise;\n /** @deprecated Replaced with {@link firstValueFrom} and {@link lastValueFrom}. Will be removed in v8. Details: https://rxjs.dev/deprecations/to-promise */\n toPromise(PromiseCtor: PromiseConstructorLike): Promise;\n /* tslint:enable:max-line-length */\n\n /**\n * Subscribe to this Observable and get a Promise resolving on\n * `complete` with the last emission (if any).\n *\n * **WARNING**: Only use this with observables you *know* will complete. If the source\n * observable does not complete, you will end up with a promise that is hung up, and\n * potentially all of the state of an async function hanging out in memory. To avoid\n * this situation, look into adding something like {@link timeout}, {@link take},\n * {@link takeWhile}, or {@link takeUntil} amongst others.\n *\n * @param [promiseCtor] a constructor function used to instantiate\n * the Promise\n * @return A Promise that resolves with the last value emit, or\n * rejects on an error. If there were no emissions, Promise\n * resolves with undefined.\n * @deprecated Replaced with {@link firstValueFrom} and {@link lastValueFrom}. Will be removed in v8. Details: https://rxjs.dev/deprecations/to-promise\n */\n toPromise(promiseCtor?: PromiseConstructorLike): Promise {\n promiseCtor = getPromiseCtor(promiseCtor);\n\n return new promiseCtor((resolve, reject) => {\n let value: T | undefined;\n this.subscribe(\n (x: T) => (value = x),\n (err: any) => reject(err),\n () => resolve(value)\n );\n }) as Promise;\n }\n}\n\n/**\n * Decides between a passed promise constructor from consuming code,\n * A default configured promise constructor, and the native promise\n * constructor and returns it. If nothing can be found, it will throw\n * an error.\n * @param promiseCtor The optional promise constructor to passed by consuming code\n */\nfunction getPromiseCtor(promiseCtor: PromiseConstructorLike | undefined) {\n return promiseCtor ?? config.Promise ?? Promise;\n}\n\nfunction isObserver(value: any): value is Observer {\n return value && isFunction(value.next) && isFunction(value.error) && isFunction(value.complete);\n}\n\nfunction isSubscriber(value: any): value is Subscriber {\n return (value && value instanceof Subscriber) || (isObserver(value) && isSubscription(value));\n}\n", "import { Observable } from '../Observable';\nimport { Subscriber } from '../Subscriber';\nimport { OperatorFunction } from '../types';\nimport { isFunction } from './isFunction';\n\n/**\n * Used to determine if an object is an Observable with a lift function.\n */\nexport function hasLift(source: any): source is { lift: InstanceType['lift'] } {\n return isFunction(source?.lift);\n}\n\n/**\n * Creates an `OperatorFunction`. Used to define operators throughout the library in a concise way.\n * @param init The logic to connect the liftedSource to the subscriber at the moment of subscription.\n */\nexport function operate(\n init: (liftedSource: Observable, subscriber: Subscriber) => (() => void) | void\n): OperatorFunction {\n return (source: Observable) => {\n if (hasLift(source)) {\n return source.lift(function (this: Subscriber, liftedSource: Observable) {\n try {\n return init(liftedSource, this);\n } catch (err) {\n this.error(err);\n }\n });\n }\n throw new TypeError('Unable to lift unknown Observable type');\n };\n}\n", "import { Subscriber } from '../Subscriber';\n\n/**\n * Creates an instance of an `OperatorSubscriber`.\n * @param destination The downstream subscriber.\n * @param onNext Handles next values, only called if this subscriber is not stopped or closed. Any\n * error that occurs in this function is caught and sent to the `error` method of this subscriber.\n * @param onError Handles errors from the subscription, any errors that occur in this handler are caught\n * and send to the `destination` error handler.\n * @param onComplete Handles completion notification from the subscription. Any errors that occur in\n * this handler are sent to the `destination` error handler.\n * @param onFinalize Additional teardown logic here. This will only be called on teardown if the\n * subscriber itself is not already closed. This is called after all other teardown logic is executed.\n */\nexport function createOperatorSubscriber(\n destination: Subscriber,\n onNext?: (value: T) => void,\n onComplete?: () => void,\n onError?: (err: any) => void,\n onFinalize?: () => void\n): Subscriber {\n return new OperatorSubscriber(destination, onNext, onComplete, onError, onFinalize);\n}\n\n/**\n * A generic helper for allowing operators to be created with a Subscriber and\n * use closures to capture necessary state from the operator function itself.\n */\nexport class OperatorSubscriber extends Subscriber {\n /**\n * Creates an instance of an `OperatorSubscriber`.\n * @param destination The downstream subscriber.\n * @param onNext Handles next values, only called if this subscriber is not stopped or closed. Any\n * error that occurs in this function is caught and sent to the `error` method of this subscriber.\n * @param onError Handles errors from the subscription, any errors that occur in this handler are caught\n * and send to the `destination` error handler.\n * @param onComplete Handles completion notification from the subscription. Any errors that occur in\n * this handler are sent to the `destination` error handler.\n * @param onFinalize Additional finalization logic here. This will only be called on finalization if the\n * subscriber itself is not already closed. This is called after all other finalization logic is executed.\n * @param shouldUnsubscribe An optional check to see if an unsubscribe call should truly unsubscribe.\n * NOTE: This currently **ONLY** exists to support the strange behavior of {@link groupBy}, where unsubscription\n * to the resulting observable does not actually disconnect from the source if there are active subscriptions\n * to any grouped observable. (DO NOT EXPOSE OR USE EXTERNALLY!!!)\n */\n constructor(\n destination: Subscriber,\n onNext?: (value: T) => void,\n onComplete?: () => void,\n onError?: (err: any) => void,\n private onFinalize?: () => void,\n private shouldUnsubscribe?: () => boolean\n ) {\n // It's important - for performance reasons - that all of this class's\n // members are initialized and that they are always initialized in the same\n // order. This will ensure that all OperatorSubscriber instances have the\n // same hidden class in V8. This, in turn, will help keep the number of\n // hidden classes involved in property accesses within the base class as\n // low as possible. If the number of hidden classes involved exceeds four,\n // the property accesses will become megamorphic and performance penalties\n // will be incurred - i.e. inline caches won't be used.\n //\n // The reasons for ensuring all instances have the same hidden class are\n // further discussed in this blog post from Benedikt Meurer:\n // https://benediktmeurer.de/2018/03/23/impact-of-polymorphism-on-component-based-frameworks-like-react/\n super(destination);\n this._next = onNext\n ? function (this: OperatorSubscriber, value: T) {\n try {\n onNext(value);\n } catch (err) {\n destination.error(err);\n }\n }\n : super._next;\n this._error = onError\n ? function (this: OperatorSubscriber, err: any) {\n try {\n onError(err);\n } catch (err) {\n // Send any errors that occur down stream.\n destination.error(err);\n } finally {\n // Ensure finalization.\n this.unsubscribe();\n }\n }\n : super._error;\n this._complete = onComplete\n ? function (this: OperatorSubscriber) {\n try {\n onComplete();\n } catch (err) {\n // Send any errors that occur down stream.\n destination.error(err);\n } finally {\n // Ensure finalization.\n this.unsubscribe();\n }\n }\n : super._complete;\n }\n\n unsubscribe() {\n if (!this.shouldUnsubscribe || this.shouldUnsubscribe()) {\n const { closed } = this;\n super.unsubscribe();\n // Execute additional teardown if we have any and we didn't already do so.\n !closed && this.onFinalize?.();\n }\n }\n}\n", "import { Subscription } from '../Subscription';\n\ninterface AnimationFrameProvider {\n schedule(callback: FrameRequestCallback): Subscription;\n requestAnimationFrame: typeof requestAnimationFrame;\n cancelAnimationFrame: typeof cancelAnimationFrame;\n delegate:\n | {\n requestAnimationFrame: typeof requestAnimationFrame;\n cancelAnimationFrame: typeof cancelAnimationFrame;\n }\n | undefined;\n}\n\nexport const animationFrameProvider: AnimationFrameProvider = {\n // When accessing the delegate, use the variable rather than `this` so that\n // the functions can be called without being bound to the provider.\n schedule(callback) {\n let request = requestAnimationFrame;\n let cancel: typeof cancelAnimationFrame | undefined = cancelAnimationFrame;\n const { delegate } = animationFrameProvider;\n if (delegate) {\n request = delegate.requestAnimationFrame;\n cancel = delegate.cancelAnimationFrame;\n }\n const handle = request((timestamp) => {\n // Clear the cancel function. The request has been fulfilled, so\n // attempting to cancel the request upon unsubscription would be\n // pointless.\n cancel = undefined;\n callback(timestamp);\n });\n return new Subscription(() => cancel?.(handle));\n },\n requestAnimationFrame(...args) {\n const { delegate } = animationFrameProvider;\n return (delegate?.requestAnimationFrame || requestAnimationFrame)(...args);\n },\n cancelAnimationFrame(...args) {\n const { delegate } = animationFrameProvider;\n return (delegate?.cancelAnimationFrame || cancelAnimationFrame)(...args);\n },\n delegate: undefined,\n};\n", "import { createErrorClass } from './createErrorClass';\n\nexport interface ObjectUnsubscribedError extends Error {}\n\nexport interface ObjectUnsubscribedErrorCtor {\n /**\n * @deprecated Internal implementation detail. Do not construct error instances.\n * Cannot be tagged as internal: https://github.com/ReactiveX/rxjs/issues/6269\n */\n new (): ObjectUnsubscribedError;\n}\n\n/**\n * An error thrown when an action is invalid because the object has been\n * unsubscribed.\n *\n * @see {@link Subject}\n * @see {@link BehaviorSubject}\n *\n * @class ObjectUnsubscribedError\n */\nexport const ObjectUnsubscribedError: ObjectUnsubscribedErrorCtor = createErrorClass(\n (_super) =>\n function ObjectUnsubscribedErrorImpl(this: any) {\n _super(this);\n this.name = 'ObjectUnsubscribedError';\n this.message = 'object unsubscribed';\n }\n);\n", "import { Operator } from './Operator';\nimport { Observable } from './Observable';\nimport { Subscriber } from './Subscriber';\nimport { Subscription, EMPTY_SUBSCRIPTION } from './Subscription';\nimport { Observer, SubscriptionLike, TeardownLogic } from './types';\nimport { ObjectUnsubscribedError } from './util/ObjectUnsubscribedError';\nimport { arrRemove } from './util/arrRemove';\nimport { errorContext } from './util/errorContext';\n\n/**\n * A Subject is a special type of Observable that allows values to be\n * multicasted to many Observers. Subjects are like EventEmitters.\n *\n * Every Subject is an Observable and an Observer. You can subscribe to a\n * Subject, and you can call next to feed values as well as error and complete.\n */\nexport class Subject extends Observable implements SubscriptionLike {\n closed = false;\n\n private currentObservers: Observer[] | null = null;\n\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n observers: Observer[] = [];\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n isStopped = false;\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n hasError = false;\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n thrownError: any = null;\n\n /**\n * Creates a \"subject\" by basically gluing an observer to an observable.\n *\n * @deprecated Recommended you do not use. Will be removed at some point in the future. Plans for replacement still under discussion.\n */\n static create: (...args: any[]) => any = (destination: Observer, source: Observable): AnonymousSubject => {\n return new AnonymousSubject(destination, source);\n };\n\n constructor() {\n // NOTE: This must be here to obscure Observable's constructor.\n super();\n }\n\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n lift(operator: Operator): Observable {\n const subject = new AnonymousSubject(this, this);\n subject.operator = operator as any;\n return subject as any;\n }\n\n /** @internal */\n protected _throwIfClosed() {\n if (this.closed) {\n throw new ObjectUnsubscribedError();\n }\n }\n\n next(value: T) {\n errorContext(() => {\n this._throwIfClosed();\n if (!this.isStopped) {\n if (!this.currentObservers) {\n this.currentObservers = Array.from(this.observers);\n }\n for (const observer of this.currentObservers) {\n observer.next(value);\n }\n }\n });\n }\n\n error(err: any) {\n errorContext(() => {\n this._throwIfClosed();\n if (!this.isStopped) {\n this.hasError = this.isStopped = true;\n this.thrownError = err;\n const { observers } = this;\n while (observers.length) {\n observers.shift()!.error(err);\n }\n }\n });\n }\n\n complete() {\n errorContext(() => {\n this._throwIfClosed();\n if (!this.isStopped) {\n this.isStopped = true;\n const { observers } = this;\n while (observers.length) {\n observers.shift()!.complete();\n }\n }\n });\n }\n\n unsubscribe() {\n this.isStopped = this.closed = true;\n this.observers = this.currentObservers = null!;\n }\n\n get observed() {\n return this.observers?.length > 0;\n }\n\n /** @internal */\n protected _trySubscribe(subscriber: Subscriber): TeardownLogic {\n this._throwIfClosed();\n return super._trySubscribe(subscriber);\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): Subscription {\n this._throwIfClosed();\n this._checkFinalizedStatuses(subscriber);\n return this._innerSubscribe(subscriber);\n }\n\n /** @internal */\n protected _innerSubscribe(subscriber: Subscriber) {\n const { hasError, isStopped, observers } = this;\n if (hasError || isStopped) {\n return EMPTY_SUBSCRIPTION;\n }\n this.currentObservers = null;\n observers.push(subscriber);\n return new Subscription(() => {\n this.currentObservers = null;\n arrRemove(observers, subscriber);\n });\n }\n\n /** @internal */\n protected _checkFinalizedStatuses(subscriber: Subscriber) {\n const { hasError, thrownError, isStopped } = this;\n if (hasError) {\n subscriber.error(thrownError);\n } else if (isStopped) {\n subscriber.complete();\n }\n }\n\n /**\n * Creates a new Observable with this Subject as the source. You can do this\n * to create custom Observer-side logic of the Subject and conceal it from\n * code that uses the Observable.\n * @return Observable that this Subject casts to.\n */\n asObservable(): Observable {\n const observable: any = new Observable();\n observable.source = this;\n return observable;\n }\n}\n\nexport class AnonymousSubject extends Subject {\n constructor(\n /** @deprecated Internal implementation detail, do not use directly. Will be made internal in v8. */\n public destination?: Observer,\n source?: Observable\n ) {\n super();\n this.source = source;\n }\n\n next(value: T) {\n this.destination?.next?.(value);\n }\n\n error(err: any) {\n this.destination?.error?.(err);\n }\n\n complete() {\n this.destination?.complete?.();\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): Subscription {\n return this.source?.subscribe(subscriber) ?? EMPTY_SUBSCRIPTION;\n }\n}\n", "import { Subject } from './Subject';\nimport { Subscriber } from './Subscriber';\nimport { Subscription } from './Subscription';\n\n/**\n * A variant of Subject that requires an initial value and emits its current\n * value whenever it is subscribed to.\n */\nexport class BehaviorSubject extends Subject {\n constructor(private _value: T) {\n super();\n }\n\n get value(): T {\n return this.getValue();\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): Subscription {\n const subscription = super._subscribe(subscriber);\n !subscription.closed && subscriber.next(this._value);\n return subscription;\n }\n\n getValue(): T {\n const { hasError, thrownError, _value } = this;\n if (hasError) {\n throw thrownError;\n }\n this._throwIfClosed();\n return _value;\n }\n\n next(value: T): void {\n super.next((this._value = value));\n }\n}\n", "import { TimestampProvider } from '../types';\n\ninterface DateTimestampProvider extends TimestampProvider {\n delegate: TimestampProvider | undefined;\n}\n\nexport const dateTimestampProvider: DateTimestampProvider = {\n now() {\n // Use the variable rather than `this` so that the function can be called\n // without being bound to the provider.\n return (dateTimestampProvider.delegate || Date).now();\n },\n delegate: undefined,\n};\n", "import { Subject } from './Subject';\nimport { TimestampProvider } from './types';\nimport { Subscriber } from './Subscriber';\nimport { Subscription } from './Subscription';\nimport { dateTimestampProvider } from './scheduler/dateTimestampProvider';\n\n/**\n * A variant of {@link Subject} that \"replays\" old values to new subscribers by emitting them when they first subscribe.\n *\n * `ReplaySubject` has an internal buffer that will store a specified number of values that it has observed. Like `Subject`,\n * `ReplaySubject` \"observes\" values by having them passed to its `next` method. When it observes a value, it will store that\n * value for a time determined by the configuration of the `ReplaySubject`, as passed to its constructor.\n *\n * When a new subscriber subscribes to the `ReplaySubject` instance, it will synchronously emit all values in its buffer in\n * a First-In-First-Out (FIFO) manner. The `ReplaySubject` will also complete, if it has observed completion; and it will\n * error if it has observed an error.\n *\n * There are two main configuration items to be concerned with:\n *\n * 1. `bufferSize` - This will determine how many items are stored in the buffer, defaults to infinite.\n * 2. `windowTime` - The amount of time to hold a value in the buffer before removing it from the buffer.\n *\n * Both configurations may exist simultaneously. So if you would like to buffer a maximum of 3 values, as long as the values\n * are less than 2 seconds old, you could do so with a `new ReplaySubject(3, 2000)`.\n *\n * ### Differences with BehaviorSubject\n *\n * `BehaviorSubject` is similar to `new ReplaySubject(1)`, with a couple of exceptions:\n *\n * 1. `BehaviorSubject` comes \"primed\" with a single value upon construction.\n * 2. `ReplaySubject` will replay values, even after observing an error, where `BehaviorSubject` will not.\n *\n * @see {@link Subject}\n * @see {@link BehaviorSubject}\n * @see {@link shareReplay}\n */\nexport class ReplaySubject extends Subject {\n private _buffer: (T | number)[] = [];\n private _infiniteTimeWindow = true;\n\n /**\n * @param _bufferSize The size of the buffer to replay on subscription\n * @param _windowTime The amount of time the buffered items will stay buffered\n * @param _timestampProvider An object with a `now()` method that provides the current timestamp. This is used to\n * calculate the amount of time something has been buffered.\n */\n constructor(\n private _bufferSize = Infinity,\n private _windowTime = Infinity,\n private _timestampProvider: TimestampProvider = dateTimestampProvider\n ) {\n super();\n this._infiniteTimeWindow = _windowTime === Infinity;\n this._bufferSize = Math.max(1, _bufferSize);\n this._windowTime = Math.max(1, _windowTime);\n }\n\n next(value: T): void {\n const { isStopped, _buffer, _infiniteTimeWindow, _timestampProvider, _windowTime } = this;\n if (!isStopped) {\n _buffer.push(value);\n !_infiniteTimeWindow && _buffer.push(_timestampProvider.now() + _windowTime);\n }\n this._trimBuffer();\n super.next(value);\n }\n\n /** @internal */\n protected _subscribe(subscriber: Subscriber): Subscription {\n this._throwIfClosed();\n this._trimBuffer();\n\n const subscription = this._innerSubscribe(subscriber);\n\n const { _infiniteTimeWindow, _buffer } = this;\n // We use a copy here, so reentrant code does not mutate our array while we're\n // emitting it to a new subscriber.\n const copy = _buffer.slice();\n for (let i = 0; i < copy.length && !subscriber.closed; i += _infiniteTimeWindow ? 1 : 2) {\n subscriber.next(copy[i] as T);\n }\n\n this._checkFinalizedStatuses(subscriber);\n\n return subscription;\n }\n\n private _trimBuffer() {\n const { _bufferSize, _timestampProvider, _buffer, _infiniteTimeWindow } = this;\n // If we don't have an infinite buffer size, and we're over the length,\n // use splice to truncate the old buffer values off. Note that we have to\n // double the size for instances where we're not using an infinite time window\n // because we're storing the values and the timestamps in the same array.\n const adjustedBufferSize = (_infiniteTimeWindow ? 1 : 2) * _bufferSize;\n _bufferSize < Infinity && adjustedBufferSize < _buffer.length && _buffer.splice(0, _buffer.length - adjustedBufferSize);\n\n // Now, if we're not in an infinite time window, remove all values where the time is\n // older than what is allowed.\n if (!_infiniteTimeWindow) {\n const now = _timestampProvider.now();\n let last = 0;\n // Search the array for the first timestamp that isn't expired and\n // truncate the buffer up to that point.\n for (let i = 1; i < _buffer.length && (_buffer[i] as number) <= now; i += 2) {\n last = i;\n }\n last && _buffer.splice(0, last + 1);\n }\n }\n}\n", "import { Scheduler } from '../Scheduler';\nimport { Subscription } from '../Subscription';\nimport { SchedulerAction } from '../types';\n\n/**\n * A unit of work to be executed in a `scheduler`. An action is typically\n * created from within a {@link SchedulerLike} and an RxJS user does not need to concern\n * themselves about creating and manipulating an Action.\n *\n * ```ts\n * class Action extends Subscription {\n * new (scheduler: Scheduler, work: (state?: T) => void);\n * schedule(state?: T, delay: number = 0): Subscription;\n * }\n * ```\n */\nexport class Action extends Subscription {\n constructor(scheduler: Scheduler, work: (this: SchedulerAction, state?: T) => void) {\n super();\n }\n /**\n * Schedules this action on its parent {@link SchedulerLike} for execution. May be passed\n * some context object, `state`. May happen at some point in the future,\n * according to the `delay` parameter, if specified.\n * @param state Some contextual data that the `work` function uses when called by the\n * Scheduler.\n * @param delay Time to wait before executing the work, where the time unit is implicit\n * and defined by the Scheduler.\n * @return A subscription in order to be able to unsubscribe the scheduled work.\n */\n public schedule(state?: T, delay: number = 0): Subscription {\n return this;\n }\n}\n", "import type { TimerHandle } from './timerHandle';\ntype SetIntervalFunction = (handler: () => void, timeout?: number, ...args: any[]) => TimerHandle;\ntype ClearIntervalFunction = (handle: TimerHandle) => void;\n\ninterface IntervalProvider {\n setInterval: SetIntervalFunction;\n clearInterval: ClearIntervalFunction;\n delegate:\n | {\n setInterval: SetIntervalFunction;\n clearInterval: ClearIntervalFunction;\n }\n | undefined;\n}\n\nexport const intervalProvider: IntervalProvider = {\n // When accessing the delegate, use the variable rather than `this` so that\n // the functions can be called without being bound to the provider.\n setInterval(handler: () => void, timeout?: number, ...args) {\n const { delegate } = intervalProvider;\n if (delegate?.setInterval) {\n return delegate.setInterval(handler, timeout, ...args);\n }\n return setInterval(handler, timeout, ...args);\n },\n clearInterval(handle) {\n const { delegate } = intervalProvider;\n return (delegate?.clearInterval || clearInterval)(handle as any);\n },\n delegate: undefined,\n};\n", "import { Action } from './Action';\nimport { SchedulerAction } from '../types';\nimport { Subscription } from '../Subscription';\nimport { AsyncScheduler } from './AsyncScheduler';\nimport { intervalProvider } from './intervalProvider';\nimport { arrRemove } from '../util/arrRemove';\nimport { TimerHandle } from './timerHandle';\n\nexport class AsyncAction extends Action {\n public id: TimerHandle | undefined;\n public state?: T;\n // @ts-ignore: Property has no initializer and is not definitely assigned\n public delay: number;\n protected pending: boolean = false;\n\n constructor(protected scheduler: AsyncScheduler, protected work: (this: SchedulerAction, state?: T) => void) {\n super(scheduler, work);\n }\n\n public schedule(state?: T, delay: number = 0): Subscription {\n if (this.closed) {\n return this;\n }\n\n // Always replace the current state with the new state.\n this.state = state;\n\n const id = this.id;\n const scheduler = this.scheduler;\n\n //\n // Important implementation note:\n //\n // Actions only execute once by default, unless rescheduled from within the\n // scheduled callback. This allows us to implement single and repeat\n // actions via the same code path, without adding API surface area, as well\n // as mimic traditional recursion but across asynchronous boundaries.\n //\n // However, JS runtimes and timers distinguish between intervals achieved by\n // serial `setTimeout` calls vs. a single `setInterval` call. An interval of\n // serial `setTimeout` calls can be individually delayed, which delays\n // scheduling the next `setTimeout`, and so on. `setInterval` attempts to\n // guarantee the interval callback will be invoked more precisely to the\n // interval period, regardless of load.\n //\n // Therefore, we use `setInterval` to schedule single and repeat actions.\n // If the action reschedules itself with the same delay, the interval is not\n // canceled. If the action doesn't reschedule, or reschedules with a\n // different delay, the interval will be canceled after scheduled callback\n // execution.\n //\n if (id != null) {\n this.id = this.recycleAsyncId(scheduler, id, delay);\n }\n\n // Set the pending flag indicating that this action has been scheduled, or\n // has recursively rescheduled itself.\n this.pending = true;\n\n this.delay = delay;\n // If this action has already an async Id, don't request a new one.\n this.id = this.id ?? this.requestAsyncId(scheduler, this.id, delay);\n\n return this;\n }\n\n protected requestAsyncId(scheduler: AsyncScheduler, _id?: TimerHandle, delay: number = 0): TimerHandle {\n return intervalProvider.setInterval(scheduler.flush.bind(scheduler, this), delay);\n }\n\n protected recycleAsyncId(_scheduler: AsyncScheduler, id?: TimerHandle, delay: number | null = 0): TimerHandle | undefined {\n // If this action is rescheduled with the same delay time, don't clear the interval id.\n if (delay != null && this.delay === delay && this.pending === false) {\n return id;\n }\n // Otherwise, if the action's delay time is different from the current delay,\n // or the action has been rescheduled before it's executed, clear the interval id\n if (id != null) {\n intervalProvider.clearInterval(id);\n }\n\n return undefined;\n }\n\n /**\n * Immediately executes this action and the `work` it contains.\n */\n public execute(state: T, delay: number): any {\n if (this.closed) {\n return new Error('executing a cancelled action');\n }\n\n this.pending = false;\n const error = this._execute(state, delay);\n if (error) {\n return error;\n } else if (this.pending === false && this.id != null) {\n // Dequeue if the action didn't reschedule itself. Don't call\n // unsubscribe(), because the action could reschedule later.\n // For example:\n // ```\n // scheduler.schedule(function doWork(counter) {\n // /* ... I'm a busy worker bee ... */\n // var originalAction = this;\n // /* wait 100ms before rescheduling the action */\n // setTimeout(function () {\n // originalAction.schedule(counter + 1);\n // }, 100);\n // }, 1000);\n // ```\n this.id = this.recycleAsyncId(this.scheduler, this.id, null);\n }\n }\n\n protected _execute(state: T, _delay: number): any {\n let errored: boolean = false;\n let errorValue: any;\n try {\n this.work(state);\n } catch (e) {\n errored = true;\n // HACK: Since code elsewhere is relying on the \"truthiness\" of the\n // return here, we can't have it return \"\" or 0 or false.\n // TODO: Clean this up when we refactor schedulers mid-version-8 or so.\n errorValue = e ? e : new Error('Scheduled action threw falsy error');\n }\n if (errored) {\n this.unsubscribe();\n return errorValue;\n }\n }\n\n unsubscribe() {\n if (!this.closed) {\n const { id, scheduler } = this;\n const { actions } = scheduler;\n\n this.work = this.state = this.scheduler = null!;\n this.pending = false;\n\n arrRemove(actions, this);\n if (id != null) {\n this.id = this.recycleAsyncId(scheduler, id, null);\n }\n\n this.delay = null!;\n super.unsubscribe();\n }\n }\n}\n", "import { Action } from './scheduler/Action';\nimport { Subscription } from './Subscription';\nimport { SchedulerLike, SchedulerAction } from './types';\nimport { dateTimestampProvider } from './scheduler/dateTimestampProvider';\n\n/**\n * An execution context and a data structure to order tasks and schedule their\n * execution. Provides a notion of (potentially virtual) time, through the\n * `now()` getter method.\n *\n * Each unit of work in a Scheduler is called an `Action`.\n *\n * ```ts\n * class Scheduler {\n * now(): number;\n * schedule(work, delay?, state?): Subscription;\n * }\n * ```\n *\n * @deprecated Scheduler is an internal implementation detail of RxJS, and\n * should not be used directly. Rather, create your own class and implement\n * {@link SchedulerLike}. Will be made internal in v8.\n */\nexport class Scheduler implements SchedulerLike {\n public static now: () => number = dateTimestampProvider.now;\n\n constructor(private schedulerActionCtor: typeof Action, now: () => number = Scheduler.now) {\n this.now = now;\n }\n\n /**\n * A getter method that returns a number representing the current time\n * (at the time this function was called) according to the scheduler's own\n * internal clock.\n * @return A number that represents the current time. May or may not\n * have a relation to wall-clock time. May or may not refer to a time unit\n * (e.g. milliseconds).\n */\n public now: () => number;\n\n /**\n * Schedules a function, `work`, for execution. May happen at some point in\n * the future, according to the `delay` parameter, if specified. May be passed\n * some context object, `state`, which will be passed to the `work` function.\n *\n * The given arguments will be processed an stored as an Action object in a\n * queue of actions.\n *\n * @param work A function representing a task, or some unit of work to be\n * executed by the Scheduler.\n * @param delay Time to wait before executing the work, where the time unit is\n * implicit and defined by the Scheduler itself.\n * @param state Some contextual data that the `work` function uses when called\n * by the Scheduler.\n * @return A subscription in order to be able to unsubscribe the scheduled work.\n */\n public schedule(work: (this: SchedulerAction, state?: T) => void, delay: number = 0, state?: T): Subscription {\n return new this.schedulerActionCtor(this, work).schedule(state, delay);\n }\n}\n", "import { Scheduler } from '../Scheduler';\nimport { Action } from './Action';\nimport { AsyncAction } from './AsyncAction';\nimport { TimerHandle } from './timerHandle';\n\nexport class AsyncScheduler extends Scheduler {\n public actions: Array> = [];\n /**\n * A flag to indicate whether the Scheduler is currently executing a batch of\n * queued actions.\n * @internal\n */\n public _active: boolean = false;\n /**\n * An internal ID used to track the latest asynchronous task such as those\n * coming from `setTimeout`, `setInterval`, `requestAnimationFrame`, and\n * others.\n * @internal\n */\n public _scheduled: TimerHandle | undefined;\n\n constructor(SchedulerAction: typeof Action, now: () => number = Scheduler.now) {\n super(SchedulerAction, now);\n }\n\n public flush(action: AsyncAction): void {\n const { actions } = this;\n\n if (this._active) {\n actions.push(action);\n return;\n }\n\n let error: any;\n this._active = true;\n\n do {\n if ((error = action.execute(action.state, action.delay))) {\n break;\n }\n } while ((action = actions.shift()!)); // exhaust the scheduler queue\n\n this._active = false;\n\n if (error) {\n while ((action = actions.shift()!)) {\n action.unsubscribe();\n }\n throw error;\n }\n }\n}\n", "import { AsyncAction } from './AsyncAction';\nimport { AsyncScheduler } from './AsyncScheduler';\n\n/**\n *\n * Async Scheduler\n *\n * Schedule task as if you used setTimeout(task, duration)\n *\n * `async` scheduler schedules tasks asynchronously, by putting them on the JavaScript\n * event loop queue. It is best used to delay tasks in time or to schedule tasks repeating\n * in intervals.\n *\n * If you just want to \"defer\" task, that is to perform it right after currently\n * executing synchronous code ends (commonly achieved by `setTimeout(deferredTask, 0)`),\n * better choice will be the {@link asapScheduler} scheduler.\n *\n * ## Examples\n * Use async scheduler to delay task\n * ```ts\n * import { asyncScheduler } from 'rxjs';\n *\n * const task = () => console.log('it works!');\n *\n * asyncScheduler.schedule(task, 2000);\n *\n * // After 2 seconds logs:\n * // \"it works!\"\n * ```\n *\n * Use async scheduler to repeat task in intervals\n * ```ts\n * import { asyncScheduler } from 'rxjs';\n *\n * function task(state) {\n * console.log(state);\n * this.schedule(state + 1, 1000); // `this` references currently executing Action,\n * // which we reschedule with new state and delay\n * }\n *\n * asyncScheduler.schedule(task, 3000, 0);\n *\n * // Logs:\n * // 0 after 3s\n * // 1 after 4s\n * // 2 after 5s\n * // 3 after 6s\n * ```\n */\n\nexport const asyncScheduler = new AsyncScheduler(AsyncAction);\n\n/**\n * @deprecated Renamed to {@link asyncScheduler}. Will be removed in v8.\n */\nexport const async = asyncScheduler;\n", "import { AsyncAction } from './AsyncAction';\nimport { Subscription } from '../Subscription';\nimport { QueueScheduler } from './QueueScheduler';\nimport { SchedulerAction } from '../types';\nimport { TimerHandle } from './timerHandle';\n\nexport class QueueAction extends AsyncAction {\n constructor(protected scheduler: QueueScheduler, protected work: (this: SchedulerAction, state?: T) => void) {\n super(scheduler, work);\n }\n\n public schedule(state?: T, delay: number = 0): Subscription {\n if (delay > 0) {\n return super.schedule(state, delay);\n }\n this.delay = delay;\n this.state = state;\n this.scheduler.flush(this);\n return this;\n }\n\n public execute(state: T, delay: number): any {\n return delay > 0 || this.closed ? super.execute(state, delay) : this._execute(state, delay);\n }\n\n protected requestAsyncId(scheduler: QueueScheduler, id?: TimerHandle, delay: number = 0): TimerHandle {\n // If delay exists and is greater than 0, or if the delay is null (the\n // action wasn't rescheduled) but was originally scheduled as an async\n // action, then recycle as an async action.\n\n if ((delay != null && delay > 0) || (delay == null && this.delay > 0)) {\n return super.requestAsyncId(scheduler, id, delay);\n }\n\n // Otherwise flush the scheduler starting with this action.\n scheduler.flush(this);\n\n // HACK: In the past, this was returning `void`. However, `void` isn't a valid\n // `TimerHandle`, and generally the return value here isn't really used. So the\n // compromise is to return `0` which is both \"falsy\" and a valid `TimerHandle`,\n // as opposed to refactoring every other instanceo of `requestAsyncId`.\n return 0;\n }\n}\n", "import { AsyncScheduler } from './AsyncScheduler';\n\nexport class QueueScheduler extends AsyncScheduler {\n}\n", "import { QueueAction } from './QueueAction';\nimport { QueueScheduler } from './QueueScheduler';\n\n/**\n *\n * Queue Scheduler\n *\n * Put every next task on a queue, instead of executing it immediately\n *\n * `queue` scheduler, when used with delay, behaves the same as {@link asyncScheduler} scheduler.\n *\n * When used without delay, it schedules given task synchronously - executes it right when\n * it is scheduled. However when called recursively, that is when inside the scheduled task,\n * another task is scheduled with queue scheduler, instead of executing immediately as well,\n * that task will be put on a queue and wait for current one to finish.\n *\n * This means that when you execute task with `queue` scheduler, you are sure it will end\n * before any other task scheduled with that scheduler will start.\n *\n * ## Examples\n * Schedule recursively first, then do something\n * ```ts\n * import { queueScheduler } from 'rxjs';\n *\n * queueScheduler.schedule(() => {\n * queueScheduler.schedule(() => console.log('second')); // will not happen now, but will be put on a queue\n *\n * console.log('first');\n * });\n *\n * // Logs:\n * // \"first\"\n * // \"second\"\n * ```\n *\n * Reschedule itself recursively\n * ```ts\n * import { queueScheduler } from 'rxjs';\n *\n * queueScheduler.schedule(function(state) {\n * if (state !== 0) {\n * console.log('before', state);\n * this.schedule(state - 1); // `this` references currently executing Action,\n * // which we reschedule with new state\n * console.log('after', state);\n * }\n * }, 0, 3);\n *\n * // In scheduler that runs recursively, you would expect:\n * // \"before\", 3\n * // \"before\", 2\n * // \"before\", 1\n * // \"after\", 1\n * // \"after\", 2\n * // \"after\", 3\n *\n * // But with queue it logs:\n * // \"before\", 3\n * // \"after\", 3\n * // \"before\", 2\n * // \"after\", 2\n * // \"before\", 1\n * // \"after\", 1\n * ```\n */\n\nexport const queueScheduler = new QueueScheduler(QueueAction);\n\n/**\n * @deprecated Renamed to {@link queueScheduler}. Will be removed in v8.\n */\nexport const queue = queueScheduler;\n", "import { AsyncAction } from './AsyncAction';\nimport { AnimationFrameScheduler } from './AnimationFrameScheduler';\nimport { SchedulerAction } from '../types';\nimport { animationFrameProvider } from './animationFrameProvider';\nimport { TimerHandle } from './timerHandle';\n\nexport class AnimationFrameAction extends AsyncAction {\n constructor(protected scheduler: AnimationFrameScheduler, protected work: (this: SchedulerAction, state?: T) => void) {\n super(scheduler, work);\n }\n\n protected requestAsyncId(scheduler: AnimationFrameScheduler, id?: TimerHandle, delay: number = 0): TimerHandle {\n // If delay is greater than 0, request as an async action.\n if (delay !== null && delay > 0) {\n return super.requestAsyncId(scheduler, id, delay);\n }\n // Push the action to the end of the scheduler queue.\n scheduler.actions.push(this);\n // If an animation frame has already been requested, don't request another\n // one. If an animation frame hasn't been requested yet, request one. Return\n // the current animation frame request id.\n return scheduler._scheduled || (scheduler._scheduled = animationFrameProvider.requestAnimationFrame(() => scheduler.flush(undefined)));\n }\n\n protected recycleAsyncId(scheduler: AnimationFrameScheduler, id?: TimerHandle, delay: number = 0): TimerHandle | undefined {\n // If delay exists and is greater than 0, or if the delay is null (the\n // action wasn't rescheduled) but was originally scheduled as an async\n // action, then recycle as an async action.\n if (delay != null ? delay > 0 : this.delay > 0) {\n return super.recycleAsyncId(scheduler, id, delay);\n }\n // If the scheduler queue has no remaining actions with the same async id,\n // cancel the requested animation frame and set the scheduled flag to\n // undefined so the next AnimationFrameAction will request its own.\n const { actions } = scheduler;\n if (id != null && id === scheduler._scheduled && actions[actions.length - 1]?.id !== id) {\n animationFrameProvider.cancelAnimationFrame(id as number);\n scheduler._scheduled = undefined;\n }\n // Return undefined so the action knows to request a new async id if it's rescheduled.\n return undefined;\n }\n}\n", "import { AsyncAction } from './AsyncAction';\nimport { AsyncScheduler } from './AsyncScheduler';\n\nexport class AnimationFrameScheduler extends AsyncScheduler {\n public flush(action?: AsyncAction): void {\n this._active = true;\n // The async id that effects a call to flush is stored in _scheduled.\n // Before executing an action, it's necessary to check the action's async\n // id to determine whether it's supposed to be executed in the current\n // flush.\n // Previous implementations of this method used a count to determine this,\n // but that was unsound, as actions that are unsubscribed - i.e. cancelled -\n // are removed from the actions array and that can shift actions that are\n // scheduled to be executed in a subsequent flush into positions at which\n // they are executed within the current flush.\n let flushId;\n if (action) {\n flushId = action.id;\n } else {\n flushId = this._scheduled;\n this._scheduled = undefined;\n }\n\n const { actions } = this;\n let error: any;\n action = action || actions.shift()!;\n\n do {\n if ((error = action.execute(action.state, action.delay))) {\n break;\n }\n } while ((action = actions[0]) && action.id === flushId && actions.shift());\n\n this._active = false;\n\n if (error) {\n while ((action = actions[0]) && action.id === flushId && actions.shift()) {\n action.unsubscribe();\n }\n throw error;\n }\n }\n}\n", "import { AnimationFrameAction } from './AnimationFrameAction';\nimport { AnimationFrameScheduler } from './AnimationFrameScheduler';\n\n/**\n *\n * Animation Frame Scheduler\n *\n * Perform task when `window.requestAnimationFrame` would fire\n *\n * When `animationFrame` scheduler is used with delay, it will fall back to {@link asyncScheduler} scheduler\n * behaviour.\n *\n * Without delay, `animationFrame` scheduler can be used to create smooth browser animations.\n * It makes sure scheduled task will happen just before next browser content repaint,\n * thus performing animations as efficiently as possible.\n *\n * ## Example\n * Schedule div height animation\n * ```ts\n * // html:
\n * import { animationFrameScheduler } from 'rxjs';\n *\n * const div = document.querySelector('div');\n *\n * animationFrameScheduler.schedule(function(height) {\n * div.style.height = height + \"px\";\n *\n * this.schedule(height + 1); // `this` references currently executing Action,\n * // which we reschedule with new state\n * }, 0, 0);\n *\n * // You will see a div element growing in height\n * ```\n */\n\nexport const animationFrameScheduler = new AnimationFrameScheduler(AnimationFrameAction);\n\n/**\n * @deprecated Renamed to {@link animationFrameScheduler}. Will be removed in v8.\n */\nexport const animationFrame = animationFrameScheduler;\n", "import { Observable } from '../Observable';\nimport { SchedulerLike } from '../types';\n\n/**\n * A simple Observable that emits no items to the Observer and immediately\n * emits a complete notification.\n *\n * Just emits 'complete', and nothing else.\n *\n * ![](empty.png)\n *\n * A simple Observable that only emits the complete notification. It can be used\n * for composing with other Observables, such as in a {@link mergeMap}.\n *\n * ## Examples\n *\n * Log complete notification\n *\n * ```ts\n * import { EMPTY } from 'rxjs';\n *\n * EMPTY.subscribe({\n * next: () => console.log('Next'),\n * complete: () => console.log('Complete!')\n * });\n *\n * // Outputs\n * // Complete!\n * ```\n *\n * Emit the number 7, then complete\n *\n * ```ts\n * import { EMPTY, startWith } from 'rxjs';\n *\n * const result = EMPTY.pipe(startWith(7));\n * result.subscribe(x => console.log(x));\n *\n * // Outputs\n * // 7\n * ```\n *\n * Map and flatten only odd numbers to the sequence `'a'`, `'b'`, `'c'`\n *\n * ```ts\n * import { interval, mergeMap, of, EMPTY } from 'rxjs';\n *\n * const interval$ = interval(1000);\n * const result = interval$.pipe(\n * mergeMap(x => x % 2 === 1 ? of('a', 'b', 'c') : EMPTY),\n * );\n * result.subscribe(x => console.log(x));\n *\n * // Results in the following to the console:\n * // x is equal to the count on the interval, e.g. (0, 1, 2, 3, ...)\n * // x will occur every 1000ms\n * // if x % 2 is equal to 1, print a, b, c (each on its own)\n * // if x % 2 is not equal to 1, nothing will be output\n * ```\n *\n * @see {@link Observable}\n * @see {@link NEVER}\n * @see {@link of}\n * @see {@link throwError}\n */\nexport const EMPTY = new Observable((subscriber) => subscriber.complete());\n\n/**\n * @param scheduler A {@link SchedulerLike} to use for scheduling\n * the emission of the complete notification.\n * @deprecated Replaced with the {@link EMPTY} constant or {@link scheduled} (e.g. `scheduled([], scheduler)`). Will be removed in v8.\n */\nexport function empty(scheduler?: SchedulerLike) {\n return scheduler ? emptyScheduled(scheduler) : EMPTY;\n}\n\nfunction emptyScheduled(scheduler: SchedulerLike) {\n return new Observable((subscriber) => scheduler.schedule(() => subscriber.complete()));\n}\n", "import { SchedulerLike } from '../types';\nimport { isFunction } from './isFunction';\n\nexport function isScheduler(value: any): value is SchedulerLike {\n return value && isFunction(value.schedule);\n}\n", "import { SchedulerLike } from '../types';\nimport { isFunction } from './isFunction';\nimport { isScheduler } from './isScheduler';\n\nfunction last(arr: T[]): T | undefined {\n return arr[arr.length - 1];\n}\n\nexport function popResultSelector(args: any[]): ((...args: unknown[]) => unknown) | undefined {\n return isFunction(last(args)) ? args.pop() : undefined;\n}\n\nexport function popScheduler(args: any[]): SchedulerLike | undefined {\n return isScheduler(last(args)) ? args.pop() : undefined;\n}\n\nexport function popNumber(args: any[], defaultValue: number): number {\n return typeof last(args) === 'number' ? args.pop()! : defaultValue;\n}\n", "export const isArrayLike = ((x: any): x is ArrayLike => x && typeof x.length === 'number' && typeof x !== 'function');", "import { isFunction } from \"./isFunction\";\n\n/**\n * Tests to see if the object is \"thennable\".\n * @param value the object to test\n */\nexport function isPromise(value: any): value is PromiseLike {\n return isFunction(value?.then);\n}\n", "import { InteropObservable } from '../types';\nimport { observable as Symbol_observable } from '../symbol/observable';\nimport { isFunction } from './isFunction';\n\n/** Identifies an input as being Observable (but not necessary an Rx Observable) */\nexport function isInteropObservable(input: any): input is InteropObservable {\n return isFunction(input[Symbol_observable]);\n}\n", "import { isFunction } from './isFunction';\n\nexport function isAsyncIterable(obj: any): obj is AsyncIterable {\n return Symbol.asyncIterator && isFunction(obj?.[Symbol.asyncIterator]);\n}\n", "/**\n * Creates the TypeError to throw if an invalid object is passed to `from` or `scheduled`.\n * @param input The object that was passed.\n */\nexport function createInvalidObservableTypeError(input: any) {\n // TODO: We should create error codes that can be looked up, so this can be less verbose.\n return new TypeError(\n `You provided ${\n input !== null && typeof input === 'object' ? 'an invalid object' : `'${input}'`\n } where a stream was expected. You can provide an Observable, Promise, ReadableStream, Array, AsyncIterable, or Iterable.`\n );\n}\n", "export function getSymbolIterator(): symbol {\n if (typeof Symbol !== 'function' || !Symbol.iterator) {\n return '@@iterator' as any;\n }\n\n return Symbol.iterator;\n}\n\nexport const iterator = getSymbolIterator();\n", "import { iterator as Symbol_iterator } from '../symbol/iterator';\nimport { isFunction } from './isFunction';\n\n/** Identifies an input as being an Iterable */\nexport function isIterable(input: any): input is Iterable {\n return isFunction(input?.[Symbol_iterator]);\n}\n", "import { ReadableStreamLike } from '../types';\nimport { isFunction } from './isFunction';\n\nexport async function* readableStreamLikeToAsyncGenerator(readableStream: ReadableStreamLike): AsyncGenerator {\n const reader = readableStream.getReader();\n try {\n while (true) {\n const { value, done } = await reader.read();\n if (done) {\n return;\n }\n yield value!;\n }\n } finally {\n reader.releaseLock();\n }\n}\n\nexport function isReadableStreamLike(obj: any): obj is ReadableStreamLike {\n // We don't want to use instanceof checks because they would return\n // false for instances from another Realm, like an