Read spending from zenmoney in the poller, answer it from facts (#125)
The trust boundary is zenmoney, not maven — they already hold his bank sessions. So the poller reads /v8/diff/ and writes totals as facts(kind=env, source=poll:zenmoney); core reads those back when he asks and never sees the token. internal/zenmoney sums transactions per currency over a window, skipping tombstoned rows and transfers between his own accounts, and refuses to encode a summary built from zero transactions. That refusal is the whole design: a failed or empty read writes nothing and leaves the last good total alone, because a zero recited as fact is worse than silence. No currency conversion either — a figure he can check against his bank beats one he cannot. Off unless configured, and the token is read from a FILE rather than a flag so it never lands in `ps`, in docker-compose.yml, or in shell history. Nothing about the money is search input, no tick rule reads the keys, and the log lines name keys, never figures. The live-credential half is BLOCKED: there is no zenmoney account or token here, so everything is verified against a recorded diff fixture.
This commit is contained in:
@@ -101,9 +101,17 @@ services:
|
||||
"-netdata", "http://127.0.0.1:19999",
|
||||
"-kuma", "http://127.0.0.1:3001/metrics",
|
||||
"-kuma-key", "uk5_mavpoll-key"]
|
||||
# Money tracking (Vikunja #125) is OFF: it needs a zenmoney token,
|
||||
# which mavpoll reads from a FILE so it never appears in `ps`, in
|
||||
# this file, or in shell history. To enable, mount the token and
|
||||
# append: "-zenmoney-token-file", "/run/secrets/zenmoney.token"
|
||||
# (optionally "-zenmoney-interval", "1h"). Core never sees the
|
||||
# token — the poller writes facts(kind=env, source=poll:zenmoney)
|
||||
# and mavend only reads those back when he asks.
|
||||
depends_on: [mavend]
|
||||
volumes:
|
||||
- sockets:/run/maven
|
||||
# - ./deploy/zenmoney.token:/run/secrets/zenmoney.token:ro
|
||||
|
||||
volumes:
|
||||
dbdata:
|
||||
|
||||
Reference in New Issue
Block a user