import { Body, Controller, HttpCode, HttpStatus, Post, UseGuards, } from "@nestjs/common"; import { ApiOperation, ApiTags } from "@nestjs/swagger"; import { ServiceAuthGuard } from "../../common/guards/service-auth.guard"; import { PaymentEventDto, MarkPaidResponseDto } from "./internal-payments.dto"; import { PaymentsService } from "./payments.service"; /** * Consumer side of the payment microservice's outbox relay (docs/payment-service §7.3). * Only the payment service may call this (shared service token). Idempotent by design: * the relay delivers at-least-once, so duplicates must be harmless. Becomes a queue * consumer when RabbitMQ lands — the handler logic is transport-agnostic. */ @ApiTags("Internal Payments") @UseGuards(ServiceAuthGuard) @Controller("internal/payments") export class InternalPaymentsController { constructor(private readonly paymentsService: PaymentsService) {} @Post("mark-paid") @HttpCode(HttpStatus.OK) @ApiOperation({ summary: "Apply a payment.succeeded/payment.failed event from the payment service (idempotent)", }) async markPaid(@Body() event: PaymentEventDto): Promise { return this.paymentsService.handlePaymentEvent(event); } }