"""Customer identity and PPPoE secret primitives.

Customer code is derived only once from the immutable database primary key.
Passwords are encrypted at rest and are never returned by list, invoice, or
export paths.
"""
import re

from app.core.secrets import decrypt_secret, encrypt_secret

_NIK = re.compile(r"^[0-9]{16}$")


def validate_nik(value: str) -> str:
    nik = (value or "").strip()
    if not _NIK.fullmatch(nik):
        raise ValueError("NIK wajib tepat 16 digit angka")
    return nik


def customer_code_for(customer_id: int) -> str:
    if not isinstance(customer_id, int) or customer_id < 1:
        raise ValueError("ID internal pelanggan tidak valid")
    return f"PLG-{customer_id:07d}"


def default_pppoe_username(customer_code: str) -> str:
    if not customer_code:
        raise ValueError("ID pelanggan wajib tersedia")
    return customer_code


def encrypt_default_pppoe_password(customer_code: str) -> str:
    return encrypt_secret(customer_code)


def decrypt_pppoe_password(encrypted_value: str) -> str:
    return decrypt_secret(encrypted_value)
