feat(nostr): flag events whose NIP-52 publish didn't land
Inventory reaches clients only through the republished calendar event, and until now a publish that failed or was skipped left no durable trace — only a log line, if that. Twice the drift was caught by a human reading a wrong number on a public page (#35 on aio-demo, #51 on cfaun, where an event's relay copy sat 14 days behind the DB). Adds `events.nostr_publish_pending`, set before every attempt and cleared only on a confirmed success. Ordering it that way is what makes "the attempt was never made" — no signer resolved, no NostrClient, the process died mid-flight — as discoverable as "the attempt raised". Both shapes have now been observed in production; only the second one was ever visible. `set_ticket_paid` raises the flag inside its own update so the counters and "the relay doesn't know about them yet" commit atomically, and the sale path pays no extra write. `publish_or_delete_nostr_event` now returns a bool so callers can branch. The flag, not the return value, is the durable record — the existing call sites stay correct ignoring it. Publish failures move from WARNING to ERROR: the published ticket count has stopped tracking reality, which is not routine journal noise. Refs #35
This commit is contained in:
parent
d2b8550d7f
commit
5d52a231d3
6 changed files with 240 additions and 6 deletions
|
|
@ -71,6 +71,10 @@ async def set_ticket_paid(ticket: Ticket) -> Ticket:
|
|||
assert event, "Couldn't get event from ticket being paid"
|
||||
event.sold += 1
|
||||
event.amount_tickets -= 1
|
||||
# Flag inside this same write: the counters and "the relay does
|
||||
# not know about them yet" land atomically, so a crash between
|
||||
# here and the publish still leaves the drift discoverable.
|
||||
event.nostr_publish_pending = True
|
||||
await update_event(event)
|
||||
|
||||
# Republish the NIP-52 calendar event so connected clients see
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue