refactor(usage): address round-4 review on PR #871
- hooks: document why user_id in metadata is safe — it stays tenant-local (the CP rollup aggregates GROUP BY (day, metric) into usage_daily, which has no metadata column, so it never reaches Stripe) and is retained to keep Deck #67's future per-user attribution derivable from the app DB. - migration: instantiate the SQLite-side column types (sa.Text() etc.) for visual parity with the instantiated Postgres types. - tests: assert the WARNING contract in the unserializable-metadata test too; add an autouse fixture that resets UsageEventStore._shared_instance so a stray shared() call can't leak across tests. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
3a8ea893c6
commit
9c2f9fac46
@@ -523,6 +523,12 @@ def configure_semantic_tools(mcp: FastMCP):
|
||||
# cost). Best-effort and gated on the flag so the off-path touches
|
||||
# no storage. nc_semantic_search_answer reuses this tool, so it
|
||||
# records here too — do not add a second hook there.
|
||||
#
|
||||
# Privacy note: user_id stays tenant-local. The CP rollup
|
||||
# aggregates GROUP BY (day, metric) into usage_daily, which has no
|
||||
# metadata column, so nothing here propagates to Stripe; the value
|
||||
# is retained only so Deck #67's "per-user attribution derivable
|
||||
# from app-DB metadata later" stays possible without a re-migration.
|
||||
if settings.usage_metering_enabled:
|
||||
try:
|
||||
store = await UsageEventStore.shared()
|
||||
|
||||
Reference in New Issue
Block a user