ショッピングカート:署名付きゲスト Cookie、ログイン時の統合、サーバー側価格、拡張可能な合計計算
コード10 ファイルコンテキスト約 611 トークンスキャン合格
インストール
$
genpm add @core/cart含まれるもの
- src/lib/cart/ にソースコード(10 ファイル)。 (24.9 KB)
- src/lib/cart/AGENTS.md に AI ルール、加えて IDE 用のルールファイル。
- .env.example に追加される環境変数: CART_COOKIE_SECRET。
- @core/auth, @core/catalog, @core/contracts, @core/db, @core/money を自動で解決します。
README
このパッケージには README がありません。
約 611 トークン→ src/lib/cart/AGENTS.md→ .cursor/rules/genpm-core-cart.mdc
これは AI が src/lib/cart で作業するときに読む内容そのものです。それ以外はコンテキストに追加されません。
@core/cart — rules for AI agents
Purpose
Carts for guests (id in an HMAC-signed HttpOnly cookie) and users (merged on login), lines per variant with stock
and quantity checks, and computeTotals: lines are always priced from @core/catalog in the database, unavailable
items are dropped with an issues entry, then registered steps run (discounts 100, shipping 200, taxes 300).
No payments or orders. Tables: carts, cart_lines.
Map
index.ts— public API:getCart,getOrCreateCart,addLine,setLine,setDiscountCodes,setCartMeta,computeTotals,registerTotalsStep,applyOrderDiscount,registerPendingCodeUses,pendingCodeUses,pruneCarts.cart.ts— operations.totals.ts— pipeline and types.cookie.ts— signed cookie.adapters/hono.ts—cartRoutes({ currentUserId }).adapters/next.ts—cartRoute,cartLinesRoute,cartLineRoute,cartCodesRoute.
Integration
- Env:
CART_COOKIE_SECRET(≥ 32 chars). Migrations as insrc/lib/db/AGENTS.md. - Mount the JSON API at
/api/cartwithcurrentUserIdfrom @core/auth (orasync () => nullfor guest-only shops). Calls:GET /api/cart,POST /api/cart/lines {variantId, quantity},PUT /api/cart/lines/:variantId {quantity}(0 removes),PUT /api/cart/codes {codes}. - Server pages:
const cart = await getCart(cookieHeader, userId); const totals = cart && await computeTotals(cart). - Modules that change totals register a step once at startup:
registerTotalsStep({ name, order, run: (t) => … }); order discounts must go throughapplyOrderDiscountso they are allocated to lines. Modules that open payments before the order exists (@core/checkout) registerregisterPendingCodeUsesso usage-limited codes (@core/discounts) count in-flight payments as reserved. - Schedule
pruneCarts()daily (@core/jobs; with kit-store, itsstore.maintenancejob does it). - Verify: add a product, change its price in the admin, the cart shows the new price.
Conventions
- Totals shown and charged come from
computeTotalsonly; never from values sent by the browser. - Show every
issuesentry to the customer before checkout. - Money values are
{ amount, currency }in minor units (@core/money).
Don't
- Don't reserve stock in the cart (that happens when the order is created).
- Don't trust prices, discounts or totals in request bodies, and don't read the cart cookie without verifying it.
# @core/cart — rules for AI agents
## Purpose
Carts for guests (id in an HMAC-signed HttpOnly cookie) and users (merged on login), lines per variant with stock
and quantity checks, and `computeTotals`: lines are always priced from @core/catalog in the database, unavailable
items are dropped with an `issues` entry, then registered steps run (discounts 100, shipping 200, taxes 300).
No payments or orders. Tables: `carts`, `cart_lines`.
## Map
- `index.ts` — public API: `getCart`, `getOrCreateCart`, `addLine`, `setLine`, `setDiscountCodes`, `setCartMeta`, `computeTotals`, `registerTotalsStep`, `applyOrderDiscount`, `registerPendingCodeUses`, `pendingCodeUses`, `pruneCarts`.
- `cart.ts` — operations. `totals.ts` — pipeline and types. `cookie.ts` — signed cookie.
- `adapters/hono.ts` — `cartRoutes({ currentUserId })`. `adapters/next.ts` — `cartRoute`, `cartLinesRoute`, `cartLineRoute`, `cartCodesRoute`.
## Integration
1. Env: `CART_COOKIE_SECRET` (≥ 32 chars). Migrations as in `src/lib/db/AGENTS.md`.
2. Mount the JSON API at `/api/cart` with `currentUserId` from @core/auth (or `async () => null` for guest-only shops).
Calls: `GET /api/cart`, `POST /api/cart/lines {variantId, quantity}`, `PUT /api/cart/lines/:variantId {quantity}` (0 removes), `PUT /api/cart/codes {codes}`.
3. Server pages: `const cart = await getCart(cookieHeader, userId); const totals = cart && await computeTotals(cart)`.
4. Modules that change totals register a step once at startup: `registerTotalsStep({ name, order, run: (t) => … })`;
order discounts must go through `applyOrderDiscount` so they are allocated to lines.
Modules that open payments before the order exists (@core/checkout) register `registerPendingCodeUses` so
usage-limited codes (@core/discounts) count in-flight payments as reserved.
5. Schedule `pruneCarts()` daily (@core/jobs; with kit-store, its `store.maintenance` job does it).
6. Verify: add a product, change its price in the admin, the cart shows the new price.
## Conventions
- Totals shown and charged come from `computeTotals` only; never from values sent by the browser.
- Show every `issues` entry to the customer before checkout.
- Money values are `{ amount, currency }` in minor units (@core/money).
## Don't
- Don't reserve stock in the cart (that happens when the order is created).
- Don't trust prices, discounts or totals in request bodies, and don't read the cart cookie without verifying it.
.genpmignore 適用後に組み込まれる正確なツリーです。固定先:
// Cálculo de totales siempre en servidor, con precios actuales de @core/catalog, y una tubería de pasos que otros
// módulos registran: descuentos (@core/discounts), envío (@core/shipping), impuestos (checkout/Stripe Tax).
import type { Money } from '../contracts/index.ts';
import type { Executor } from '../db/index.ts';
import { add, allocate, money, sub, sum, zero } from '../money/index.ts';
export type TotalsLine = {
variantId: string;
productId: string;
slug: string;
name: string;
title: string;
sku: string | null;
mediaId: string | null;
kind: 'physical' | 'digital';
quantity: number;
unitPrice: Money;
/** unitPrice × quantity, antes de descuentos. */
subtotal: Money;
/** Parte de los descuentos de pedido asignada a esta línea (para impuestos y reembolsos). */
discount: Money;
weightGrams: number | null;
};
export type Adjustment = { source: string; label: string; amount: Money; code?: string };
export type CartTotals = {
cartId: string;
currency: string;
lines: TotalsLine[];
subtotal: Money;
discounts: Adjustment[];
discountTotal: Money;
shipping: Adjustment | null;
/** Impuestos añadidos al total (si los precios no los incluyen). */
tax: Adjustment | null;
total: Money;
/** Avisos para el cliente: producto agotado, código no válido, sin envío a ese país… */
issues: Array<{ code: string; message: string; variantId?: string }>;
/** Lo que el carrito pide a los pasos (códigos, país, tarifa elegida). */
context: { discountCodes: string[]; meta: Record<string, string>; userId: string | null; email?: string };
};
export type TotalsStep = { name: string; order: number; run(t: CartTotals): Promise<CartTotals> | CartTotals };
const steps: TotalsStep[] = [];
/** Registra un paso. Orden recomendado: descuentos 100, envío 200, impuestos 300. */
export function registerTotalsStep(step: TotalsStep): void {
const i = steps.findIndex((s) => s.name === step.name);
if (i >= 0) steps.splice(i, 1);
steps.push(step);
steps.sort((a, b) => a.order - b.order);
}
/** Solo tests. */
export const clearTotalsSteps = () => {
steps.splice(0);
pendingCounters.clear();
};
/**
* Usos de un código de descuento que aún no son pedido (p. ej. pagos abiertos de @core/checkout): `total` de todos los
* clientes y `mine` de este cliente. Los cuenta quien abre pagos y los consulta quien limita usos (@core/discounts).
*/
export type PendingCodeUses = (code: string, who: { email?: string; userId: string | null; excludeCartId: string }, db: Executor) => Promise<{ total: number; mine: number }>;
const pendingCounters = new Map<string, PendingCodeUses>();
export function registerPendingCodeUses(name: string, fn: PendingCodeUses): void {
pendingCounters.set(name, fn);
}
/** Suma de los usos pendientes de `code` según todos los contadores registrados (excluye el carrito `excludeCartId`). */
export async function pendingCodeUses(code: string, who: Parameters<PendingCodeUses>[1], db: Executor): Promise<{ total: number; mine: number }> {
let total = 0;
let mine = 0;
for (const fn of pendingCounters.values()) {
const r = await fn(code, who, db);
total += r.total;
mine += r.mine;
}
return { total, mine };
}
/** Aplica un descuento de pedido: lo reparte entre líneas proporcionalmente (sin perder céntimos). */
export function applyOrderDiscount(t: CartTotals, adj: Adjustment): CartTotals {
const remaining = sub(sub(t.subtotal, t.discountTotal), adj.amount);
const amount = remaining.amount < 0 ? sub(t.subtotal, t.discountTotal) : adj.amount;
const parts = allocate(amount, t.lines.map((l) => sub(l.subtotal, l.discount).amount));
return {
...t,
lines: t.lines.map((l, i) => ({ ...l, discount: add(l.discount, parts[i]!) })),
discounts: [...t.discounts, { ...adj, amount }],
discountTotal: add(t.discountTotal, amount),
};
}
export async function runSteps(base: CartTotals): Promise<CartTotals> {
let t = base;
for (const s of steps) t = await s.run(t);
const total = add(sub(t.subtotal, t.discountTotal), t.shipping?.amount ?? zero(t.currency), t.tax?.amount ?? zero(t.currency));
return { ...t, total: total.amount < 0 ? zero(t.currency) : total };
}
export const emptyTotals = (cartId: string, currency: string, context: CartTotals['context']): CartTotals => ({
cartId,
currency,
lines: [],
subtotal: zero(currency),
discounts: [],
discountTotal: zero(currency),
shipping: null,
tax: null,
total: zero(currency),
issues: [],
context,
});
export const lineSubtotal = (unit: number, qty: number, currency: string) => money(unit * qty, currency);
export const sumLines = (lines: TotalsLine[], currency: string) => sum(lines.map((l) => l.subtotal), currency);
このパッケージは MCP サーバーを宣言していません。
| バージョン | コミット | 公開日 | スキャン |
|---|---|---|---|
| 1.1.0 | 787ea88 | 7 時間前 | スキャン合格 |
- npm
- zod ^4.0.0
- 提案
- GenPM は npm コマンドを提案し、あなたが承認した場合にのみ実行します。
- スキャン
- スキャン合格 · 指摘 0 件
- コミット
- v1.1.0 → 787ea88d1eb25e11257f051f971c0bcce52803f6 · 取得後に検証済み
- スクリプト
- なし。GenPM はパッケージのコードを実行しません。
- ライセンス
- MIT
- 品質
- 100/100
- 認識されたライセンス達成
- AGENTS.md に目的の説明がある達成
- AGENTS.md に統合手順がある達成
- AGENTS.md に規約や禁止事項がある達成
- テストを含む達成
- セキュリティスキャンに合格達成
- 過去 6 か月以内に公開達成
- 認証済みの公開者達成
- 概要とキーワード達成
- 報告
- 問題を見つけましたか?