2026-09-06 18:05:44 +08:00
|
|
|
|
"""模拟交易网关路由(PRD FR-1 · 薄路由,不含业务)。
|
|
|
|
|
|
|
2026-09-06 18:58:48 +08:00
|
|
|
|
鉴权:`Depends(get_auth_context)`(B6 回挂,评审 P2-2)——一期接受
|
|
|
|
|
|
risk_demo 演示账号或客户本人(auth.customer_id == 请求 customer_id,
|
|
|
|
|
|
PRD FR-1 §鉴权);越权经 deps.deny 审计后 403。T-01 后工厂内部换 JWT。
|
2026-09-06 18:05:44 +08:00
|
|
|
|
trace:B7 中间件贯通;B7 前由 service 层 ensure_trace 兜底。
|
2026-09-06 18:17:44 +08:00
|
|
|
|
挂载:B7 集成 main.py(当前仅 TestClient 独立挂 router 验证)。
|
|
|
|
|
|
统一响应外壳:utils/response.py 为占位(P1 任务),落地点挂账 B7(届时
|
|
|
|
|
|
simulate/risk 一并包裹,本路由返回体不变)。
|
2026-09-06 18:05:44 +08:00
|
|
|
|
"""
|
|
|
|
|
|
|
|
|
|
|
|
from __future__ import annotations
|
|
|
|
|
|
|
|
|
|
|
|
from decimal import Decimal
|
|
|
|
|
|
|
2026-09-06 18:58:48 +08:00
|
|
|
|
from fastapi import APIRouter, Depends, HTTPException
|
2026-09-06 18:05:44 +08:00
|
|
|
|
from pydantic import BaseModel, Field
|
|
|
|
|
|
|
2026-09-06 18:58:48 +08:00
|
|
|
|
from app.api.deps import AuthContext, deny, get_auth_context
|
2026-09-06 18:05:44 +08:00
|
|
|
|
from app.gateway.trade_gateway import UnsupportedTradeType, submit_trade
|
2026-09-06 18:58:48 +08:00
|
|
|
|
from app.repository.risk_repository import RiskRepository
|
2026-09-06 18:05:44 +08:00
|
|
|
|
|
|
|
|
|
|
router = APIRouter(prefix="/api/simulate", tags=["simulate"])
|
|
|
|
|
|
|
|
|
|
|
|
|
2026-09-06 18:58:48 +08:00
|
|
|
|
def _repo() -> RiskRepository:
|
|
|
|
|
|
"""审计仓储(deny 留痕用;测试 monkeypatch 点)。"""
|
|
|
|
|
|
return RiskRepository()
|
|
|
|
|
|
|
|
|
|
|
|
|
2026-09-06 18:05:44 +08:00
|
|
|
|
class TradeRequest(BaseModel):
|
|
|
|
|
|
customer_id: str = Field(..., min_length=1)
|
|
|
|
|
|
product_id: str = Field(..., min_length=1)
|
2026-09-06 18:17:44 +08:00
|
|
|
|
trade_type: str = Field(..., max_length=16, description="subscribe | redeem;convert 显式拒绝")
|
2026-09-06 18:05:44 +08:00
|
|
|
|
amount: Decimal = Field(..., gt=0, description="交易金额(元),必须为正数")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@router.post("/trade")
|
2026-09-06 18:58:48 +08:00
|
|
|
|
def submit_trade_api(req: TradeRequest, auth: AuthContext = Depends(get_auth_context)) -> dict:
|
2026-09-06 18:05:44 +08:00
|
|
|
|
"""模拟交易(FR-1):适当性阻断或放行+引擎判定,返回 blocked + trade_id。"""
|
2026-09-06 18:58:48 +08:00
|
|
|
|
if not (auth.has_role("risk_demo") or (auth.is_customer() and auth.customer_id == req.customer_id)):
|
|
|
|
|
|
deny(
|
|
|
|
|
|
auth, "AUTH_403_ROLE", _repo(),
|
|
|
|
|
|
customer_id=req.customer_id, message="risk_demo or owner customer only",
|
|
|
|
|
|
)
|
2026-09-06 18:05:44 +08:00
|
|
|
|
try:
|
|
|
|
|
|
return submit_trade(req.model_dump())
|
|
|
|
|
|
except UnsupportedTradeType as exc:
|
|
|
|
|
|
raise HTTPException(status_code=400, detail=str(exc)) from exc
|
2026-09-06 18:58:48 +08:00
|
|
|
|
except LookupError as exc: # NotFoundError 亦为其子类;已统一(B6 评审 P3-5)
|
2026-09-06 18:05:44 +08:00
|
|
|
|
raise HTTPException(status_code=404, detail=str(exc)) from exc
|