Files
pansy/internal/service/plantings.go
T
steveandClaude Opus 4.8 b4f3181aef
Build image / build-and-push (push) Successful in 14s
Gadfly review (reusable) / review (pull_request) Canceled after 12m47s
Adversarial Review (Gadfly) / review (pull_request) Canceled after 12m47s
Revision history: change sets, revisions, and revert (#48)
The undo substrate. The agent is going to act freely — "empty the garlic bed and
plant cucumbers" runs without a confirmation prompt — and that is only a
defensible default if the result is easy to roll back. So undo lands before the
agent write path, not after it.

The unit of undo is the OPERATION, not the row. A change set groups the
row-level revisions it produced; revert replays their inverses. Emptying a bed
and replanting it touches one object and many plantings, and undoing half of
that is worse than useless.

Two properties shape the rest:

Revert is itself a change set (reverts_id names its target), so history is
append-only and an undo can be undone. git revert, not git reset.

Revert is version-guarded per entity. Every snapshot carries the row's version;
if something edited that row after the change set being reverted, restoring the
old snapshot would silently discard the newer edit, so it is reported as a
conflict and left alone while the rest of the change set still reverts.

The auto-scope is what keeps this invasive but shallow. Service mutations call
record(), which joins the change set on the context if one is open and otherwise
opens a single-op one on the spot. REST handlers needed no edits at all and
every UI mutation lands in history for free; only the agent wraps a whole turn.
Multi-row operations (FillRegion, ClearObject) pass all their changes in one
record call, so a 12-plop fill is one change set with 12 revisions and one undo.

Revisions are buffered and written with their change set in a single
transaction, so an operation that fails partway leaves no half-recorded history.
Recording is best-effort after the fact: the row is already written, so failing
the caller there would report a failure that didn't happen and invite a
duplicate retry. A gap is logged loudly instead.

Two sharp edges handled explicitly rather than by luck:

Deleting an object cascades its plantings away at the FK level, where the
service never sees them. deleteObjectRecording snapshots them first, or the
delete would be listed in history and not actually be undoable.

Restoring deleted rows reuses their ids, and a restored plop needs its object
back first. planRevert runs three explicit passes — restore parents then
children, then updates, then delete created children before their parents —
instead of trusting reverse-seq ordering to happen to be right.

Garden deletion stays out of scope, as designed: the cascade is invisible to the
service and ON DELETE CASCADE would take the history with it. The history UI
will say so rather than pretend otherwise.

Closes #48

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
2026-07-21 00:53:55 -04:00

308 lines
9.9 KiB
Go

package service
import (
"context"
"errors"
"math"
"strings"
"time"
"gitea.stevedudenhoeffer.com/steve/pansy/internal/domain"
)
// dateLayout is the 'YYYY-MM-DD' format plantings store planted_at/removed_at in.
const dateLayout = "2006-01-02"
const (
maxPlantingLabelLen = 200
maxRadiusCM = 10_000 // 100 m — a generous plop ceiling
maxExplicitCount = 1_000_000 // sanity cap on a manual count override
)
// derivedCount is the plant count implied by a plop's area and the plant's
// mature spacing: max(1, round(π·r² / spacing²)). It is the single source of the
// formula (also feeds #15's display and #19's FillRegion). A non-positive or
// non-finite radius/spacing collapses to the floor of 1; the result is capped at
// maxExplicitCount so a huge radius / tiny spacing can't yield an absurd (or, on
// a 32-bit int, overflowing) value — the same ceiling a manual override honors.
func derivedCount(radiusCM, spacingCM float64) int {
if radiusCM <= 0 || spacingCM <= 0 || !isFinite(radiusCM) || !isFinite(spacingCM) {
return 1
}
area := math.Pi * radiusCM * radiusCM
n := int(math.Round(area / (spacingCM * spacingCM)))
if n < 1 {
return 1
}
if n > maxExplicitCount {
return maxExplicitCount
}
return n
}
// PlantingInput is the payload for placing a plop. Count nil = derived; PlantedAt
// nil defaults to today.
type PlantingInput struct {
PlantID int64
XCM float64
YCM float64
RadiusCM float64
Count *int
Label *string
PlantedAt *string
}
// PlantingPatch is a partial update. The nullable fields (Count/Label/PlantedAt/
// RemovedAt) use a Set* flag to tell "clear to NULL" from "leave unchanged".
// Setting RemovedAt is how "clear bed"/soft-remove works; clearing it un-removes.
type PlantingPatch struct {
PlantID *int64
XCM *float64
YCM *float64
RadiusCM *float64
SetCount bool
Count *int
SetLabel bool
Label *string
SetPlantedAt bool
PlantedAt *string
SetRemovedAt bool
RemovedAt *string
}
// CreatePlanting places a plop in a plantable object the actor can edit.
func (s *Service) CreatePlanting(ctx context.Context, actorID, objectID int64, in PlantingInput) (*domain.Planting, error) {
o, g, err := s.objectForRole(ctx, actorID, objectID, roleEditor)
if err != nil {
return nil, err
}
if !o.Plantable {
return nil, domain.ErrInvalidInput // trees/paths/structures can't hold plants
}
plant, err := s.visiblePlant(ctx, actorID, in.PlantID)
if err != nil {
return nil, err
}
p := &domain.Planting{
ObjectID: objectID,
PlantID: in.PlantID,
XCM: in.XCM,
YCM: in.YCM,
RadiusCM: in.RadiusCM,
Count: in.Count,
Label: trimStringPtr(in.Label),
PlantedAt: in.PlantedAt,
}
if p.PlantedAt == nil {
today := s.now().UTC().Format(dateLayout)
p.PlantedAt = &today
}
if err := finalizePlanting(p, o, true); err != nil {
return nil, err
}
created, err := s.store.CreatePlanting(ctx, p)
if err != nil {
return nil, err
}
s.record(ctx, g.ID, actorID, "Planted "+plant.Name+" in "+objectLabel(o),
changeCreate(domain.EntityPlanting, created.ID, created))
created.DerivedCount = derivedCount(created.RadiusCM, plant.SpacingCM)
return created, nil
}
// UpdatePlanting applies a partial, version-guarded patch to a plop in an object
// the actor can edit. On a version mismatch it returns (current, ErrVersionConflict).
func (s *Service) UpdatePlanting(ctx context.Context, actorID, plantingID int64, patch PlantingPatch, version int64) (*domain.Planting, error) {
pl, err := s.store.GetPlanting(ctx, plantingID)
if err != nil {
return nil, err // ErrNotFound
}
o, g, err := s.objectForRole(ctx, actorID, pl.ObjectID, roleEditor)
if err != nil {
return nil, err
}
before := *pl // GetPlanting returns the current row, and the patch mutates it
originalPlantID := pl.PlantID
applyPlantingPatch(pl, patch)
// Fetch the plop's plant for the derived count. Only when the actor is
// actually CHANGING the plant (new id ≠ old) is the new plant gated on
// visibility — an existing plop may reference a plant the actor can't see
// (e.g. a shared editor in the owner's garden using the owner's private
// plant), and a no-op plantId resend must not break editing it.
var plant *domain.Plant
if pl.PlantID != originalPlantID {
plant, err = s.visiblePlant(ctx, actorID, pl.PlantID)
} else {
plant, err = s.store.GetPlant(ctx, pl.PlantID)
}
if err != nil {
return nil, err
}
// Only re-check the object bounds when the position is actually being moved.
// A plop left outside its object's bounds by a later object resize must still
// be editable (radius, dates, soft-remove) — otherwise it becomes a row you
// can neither fix nor remove.
checkBounds := patch.XCM != nil || patch.YCM != nil
if err := finalizePlanting(pl, o, checkBounds); err != nil {
return nil, err
}
pl.Version = version
updated, err := s.store.UpdatePlanting(ctx, pl)
if err != nil {
if errors.Is(err, domain.ErrVersionConflict) && updated != nil {
// Enrich the current row with its own plant's derived count.
s.enrichDerived(ctx, updated)
}
return updated, err
}
s.record(ctx, g.ID, actorID, plantingEditSummary(&before, updated, plant, o),
changeUpdate(domain.EntityPlanting, updated.ID, &before, updated))
updated.DerivedCount = derivedCount(updated.RadiusCM, plant.SpacingCM)
return updated, nil
}
// plantingEditSummary describes a plop edit for the history list. Soft-removal
// ("clear bed", harvested) is the one edit worth naming specifically — it reads
// as a removal to the person who did it, not as an edit.
func plantingEditSummary(before, after *domain.Planting, plant *domain.Plant, o *domain.GardenObject) string {
switch {
case before.RemovedAt == nil && after.RemovedAt != nil:
return "Removed " + plant.Name + " from " + objectLabel(o)
case before.RemovedAt != nil && after.RemovedAt == nil:
return "Restored " + plant.Name + " in " + objectLabel(o)
default:
return "Edited " + plant.Name + " in " + objectLabel(o)
}
}
// DeletePlanting hard-deletes a plop in an object the actor can edit. (Soft
// removal — "clear bed" / harvested — sets removed_at via UpdatePlanting.)
func (s *Service) DeletePlanting(ctx context.Context, actorID, plantingID int64) error {
pl, err := s.store.GetPlanting(ctx, plantingID)
if err != nil {
return err
}
o, g, err := s.objectForRole(ctx, actorID, pl.ObjectID, roleEditor)
if err != nil {
return err
}
if err := s.store.DeletePlanting(ctx, plantingID); err != nil {
return err
}
s.record(ctx, g.ID, actorID, "Deleted a planting from "+objectLabel(o),
changeDelete(domain.EntityPlanting, pl.ID, pl))
return nil
}
// visiblePlant loads a plant the actor may reference in a planting: a built-in or
// one the actor owns. An unknown plant or another user's plant is an invalid
// reference (ErrInvalidInput) rather than leaking existence.
func (s *Service) visiblePlant(ctx context.Context, actorID, plantID int64) (*domain.Plant, error) {
p, err := s.store.GetPlant(ctx, plantID)
if errors.Is(err, domain.ErrNotFound) {
return nil, domain.ErrInvalidInput
}
if err != nil {
return nil, err
}
if p.OwnerID != nil && *p.OwnerID != actorID {
return nil, domain.ErrInvalidInput
}
return p, nil
}
// enrichDerived best-effort sets p.DerivedCount from its plant's spacing (used
// when we don't already hold the plant, e.g. a conflict's current row).
func (s *Service) enrichDerived(ctx context.Context, p *domain.Planting) {
plant, err := s.store.GetPlant(ctx, p.PlantID)
if err == nil {
p.DerivedCount = derivedCount(p.RadiusCM, plant.SpacingCM)
}
}
// applyPlantingPatch mutates pl with each provided patch field.
func applyPlantingPatch(pl *domain.Planting, p PlantingPatch) {
if p.PlantID != nil {
pl.PlantID = *p.PlantID
}
if p.XCM != nil {
pl.XCM = *p.XCM
}
if p.YCM != nil {
pl.YCM = *p.YCM
}
if p.RadiusCM != nil {
pl.RadiusCM = *p.RadiusCM
}
if p.SetCount {
pl.Count = p.Count
}
if p.SetLabel {
pl.Label = trimStringPtr(p.Label)
}
if p.SetPlantedAt {
pl.PlantedAt = p.PlantedAt
}
if p.SetRemovedAt {
pl.RemovedAt = p.RemovedAt
}
}
// finalizePlanting validates a built/merged plop against its parent object.
// Shared by create and update so both enforce the same invariants. checkBounds
// gates the center-in-object-bounds test: create always checks it, update only
// when the position is being moved (so a resize that orphans a plop outside the
// shrunken object doesn't block editing/removing it).
func finalizePlanting(p *domain.Planting, o *domain.GardenObject, checkBounds bool) error {
if !isFinite(p.RadiusCM) || p.RadiusCM <= 0 || p.RadiusCM > maxRadiusCM {
return domain.ErrInvalidInput
}
if !isFinite(p.XCM) || !isFinite(p.YCM) {
return domain.ErrInvalidInput
}
// Loose bounds: the plop's CENTER must sit within the object's unrotated
// local bounds (origin at object center); the radius may overhang.
if checkBounds && (math.Abs(p.XCM) > o.WidthCM/2 || math.Abs(p.YCM) > o.HeightCM/2) {
return domain.ErrInvalidInput
}
if p.Count != nil && (*p.Count < 1 || *p.Count > maxExplicitCount) {
return domain.ErrInvalidInput
}
if p.Label != nil && len(*p.Label) > maxPlantingLabelLen {
return domain.ErrInvalidInput
}
if !validDatePtr(p.PlantedAt) || !validDatePtr(p.RemovedAt) {
return domain.ErrInvalidInput
}
// A plop can't be removed before it was planted (nonsensical interval).
if p.PlantedAt != nil && p.RemovedAt != nil {
planted, _ := time.Parse(dateLayout, *p.PlantedAt)
removed, _ := time.Parse(dateLayout, *p.RemovedAt)
if removed.Before(planted) {
return domain.ErrInvalidInput
}
}
return nil
}
// validDatePtr reports whether a nil-or-'YYYY-MM-DD' date pointer is acceptable.
func validDatePtr(s *string) bool {
if s == nil {
return true
}
_, err := time.Parse(dateLayout, *s)
return err == nil
}
// trimStringPtr trims a *string, preserving nil (distinct from empty).
func trimStringPtr(s *string) *string {
if s == nil {
return nil
}
t := strings.TrimSpace(*s)
return &t
}