<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>
    <parent>
        <groupId>xyz.tcheeric</groupId>
        <artifactId>cashu-mint</artifactId>
        <version>0.40.1</version>
    </parent>
    <artifactId>cashu-mint-rest</artifactId>
    <version>0.40.1</version>
    <name>cashu-mint-rest</name>
    <description>Demo project for Spring Boot</description>
    <properties>
        <java.version>21</java.version>
    </properties>
    <dependencies>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-web</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-websocket</artifactId>
        </dependency>
        <!--
          The NUT request DTOs in cashu-lib-entities declare Bean Validation constraints
          (PostRestoreRequest.MAX_OUTPUTS, PostCheckStateRequest.MAX_SECRETS,
          PostSwapRequest/PostMintRequest MAX_OUTPUTS), and this module applies them with @Valid,
          so it depends on a validator.

          Declared explicitly rather than relied on transitively. A validator does already reach
          this module by way of cashu-mint-jpa, but that is a runtime-scoped persistence
          dependency with no reason to keep carrying a web-layer concern: if it ever drops the
          starter, the constraints on unauthenticated endpoints go quiet with nothing failing to
          compile.
        -->
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-validation</artifactId>
        </dependency>
        <!-- Spec 002 T311 — HTTP Basic auth on /admin/** -->
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-security</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.security</groupId>
            <artifactId>spring-security-test</artifactId>
            <scope>test</scope>
        </dependency>
        <!--
            commons-lang3 is deliberately NOT declared here.

            No source in this repository imports it. It arrives transitively from
            nostr-java-core, which declares it at compile scope and needs it at runtime:
            HexStringValidator calls StringUtils, and the voucher ledger path reaches that
            validator when it publishes to the Nostr ledger.

            A direct declaration overrides a transitive one, so declaring it test-scoped here
            stripped it from the runtime image. The failure was NoClassDefFoundError on
            StringUtils while building voucherLedgerPort, which takes the whole application
            context down with it, so the voucher profile could not start at all and
            POST /v1/vouchers 404'd. See issue #405.

            Omitting it is the fix rather than widening the scope. A direct declaration would
            claim this module depends on something it never imports, and would silently pin a
            version for a library it does not use.
        -->
        <dependency>
            <groupId>commons-beanutils</groupId>
            <artifactId>commons-beanutils</artifactId>
            <scope>test</scope>
        </dependency>
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-lib-entities</artifactId>
            <exclusions>
                <exclusion>
                    <groupId>org.slf4j</groupId>
                    <artifactId>slf4j-simple</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-lib-crypto</artifactId>
            <exclusions>
                <exclusion>
                    <groupId>org.slf4j</groupId>
                    <artifactId>slf4j-simple</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-lib-common</artifactId>
            <exclusions>
                <exclusion>
                    <groupId>org.slf4j</groupId>
                    <artifactId>slf4j-simple</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-mint-protocol</artifactId>
            <version>${project.version}</version>
        </dependency>
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-mint-webhook</artifactId>
            <version>${project.version}</version>
        </dependency>
        <!-- Spec 036 trace producer SDK (Spring Boot starter). Auto-config stays
             inert unless cashu.trace.publisher.enabled=true. -->
        <dependency>
            <groupId>xyz.tcheeric</groupId>
            <artifactId>cashu-ledger-trace-publisher</artifactId>
        </dependency>
        <!-- Spec 001 durable-state adapter. Runtime scope so MintJpaAutoConfiguration
             is on the classpath when cashu.mint.jpa.enabled=true is flipped on in
             staging/prod; the autoconfig stays inert when the flag is off. -->
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-mint-jpa</artifactId>
            <version>${project.version}</version>
            <scope>runtime</scope>
        </dependency>
        <!-- Cashu Voucher Dependencies -->
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-voucher-domain</artifactId>
            <exclusions>
                <exclusion>
                    <groupId>org.slf4j</groupId>
                    <artifactId>slf4j-simple</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-voucher-app</artifactId>
            <exclusions>
                <exclusion>
                    <groupId>org.slf4j</groupId>
                    <artifactId>slf4j-simple</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-voucher-nostr</artifactId>
            <!-- Compile scope needed for Spring configuration -->
            <exclusions>
                <exclusion>
                    <groupId>org.slf4j</groupId>
                    <artifactId>slf4j-simple</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
        <!-- Dummy gateway implementation comes transitively via the protocol module. -->
        <dependency>
            <groupId>com.h2database</groupId>
            <artifactId>h2</artifactId>
            <scope>test</scope>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-test</artifactId>
            <scope>test</scope>
        </dependency>
        <dependency>
            <groupId>org.slf4j</groupId>
            <artifactId>slf4j-api</artifactId>
        </dependency>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-actuator</artifactId>
        </dependency>
        <!-- Observability (Prometheus metrics) -->
        <dependency>
            <groupId>${project.groupId}</groupId>
            <artifactId>cashu-mint-observability</artifactId>
            <version>${project.version}</version>
        </dependency>
    </dependencies>

    <distributionManagement>
        <repository>
            <id>reposilite-releases</id>
            <url>https://maven.398ja.xyz/releases</url>
        </repository>
        <snapshotRepository>
            <id>reposilite-snapshots</id>
            <url>https://maven.398ja.xyz/snapshots</url>
        </snapshotRepository>
    </distributionManagement>

    <repositories>
        <repository>
            <id>reposilite-releases</id>
            <url>https://maven.398ja.xyz/releases</url>
        </repository>
        <repository>
            <id>reposilite-snapshots</id>
            <url>https://maven.398ja.xyz/snapshots</url>
        </repository>
    </repositories>

    <build>
        <plugins>
            <!-- Guards against NoClassDefFoundError
                 net/bytebuddy/description/type/TypeDefinition at boot. Writes the
                 *runtime* classpath to a file so RuntimeClasspathTest can assert on
                 it; a plain Class.forName test cannot catch a test-scoped
                 byte-buddy, because test scope puts it on the test classpath. -->
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-dependency-plugin</artifactId>
                <executions>
                    <execution>
                        <id>record-runtime-classpath</id>
                        <phase>process-test-resources</phase>
                        <goals>
                            <goal>build-classpath</goal>
                        </goals>
                        <configuration>
                            <includeScope>runtime</includeScope>
                            <outputFile>${project.build.directory}/runtime-classpath.txt</outputFile>
                        </configuration>
                    </execution>
                </executions>
            </plugin>
            <plugin>
                <groupId>org.springframework.boot</groupId>
                <artifactId>spring-boot-maven-plugin</artifactId>
                <configuration>
                    <excludes>
                        <exclude>
                            <groupId>org.projectlombok</groupId>
                            <artifactId>lombok</artifactId>
                        </exclude>
                    </excludes>
                    <!-- Create both executable jar and classifier jar for use as dependency -->
                    <classifier>exec</classifier>
                    <!-- Build the fat jar into target/ but do NOT attach it as a Maven
                         artifact: at ~110 MB it exceeds the reposilite upload limit and
                         fails `mvn deploy` with HTTP 413, taking the rest of the reactor
                         down with it. Nothing resolves it from a repository anyway — the
                         two consumers (this module's Dockerfile and
                         scripts/heap-exhaustion-test.sh) both read it straight from
                         target/, and the app ships as the Jib image below. The thin
                         cashu-mint-rest jar is still published for use as a dependency. -->
                    <attach>false</attach>
                </configuration>
                <executions>
                    <execution>
                        <goals>
                            <goal>repackage</goal>
                        </goals>
                    </execution>
                </executions>
            </plugin>
            <plugin>
                <groupId>com.google.cloud.tools</groupId>
                <artifactId>jib-maven-plugin</artifactId>
                <version>3.4.6</version>
                <configuration>
                    <from>
                        <image>eclipse-temurin:21-jre</image>
                    </from>
                    <to>
                        <image>docker.398ja.xyz/cashu-mint-rest</image>
                        <tags>
                            <tag>${project.version}</tag>
                            <tag>latest</tag>
                        </tags>
                    </to>
                    <container>
                        <ports>
                            <port>8080</port>
                        </ports>
                    </container>
                </configuration>
                <executions>
                    <execution>
                        <!-- The E2E compose stack runs the image this reactor builds,
                             so it must exist locally before the stack starts. -->
                        <id>e2e-local-image</id>
                        <phase>package</phase>
                        <goals>
                            <goal>dockerBuild</goal>
                        </goals>
                        <configuration>
                            <skip>${e2e.image.skip}</skip>
                        </configuration>
                    </execution>
                    <execution>
                        <phase>deploy</phase>
                        <goals>
                            <goal>build</goal>
                        </goals>
                    </execution>
                </executions>
            </plugin>
        </plugins>
    </build>

</project>
