update from user testing payment platform
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
import { json, type RequestHandler } from '@sveltejs/kit';
|
||||
import { verifyStripeEvent, isDummyStripe } from '$lib/server/stripe';
|
||||
import { verifyStripeEvent } from '$lib/server/stripe';
|
||||
import { handleStripeEvent } from '$lib/server/stripe-events';
|
||||
|
||||
// Stripe webhook: updates fams.stripeCustomerId + fams.active + fams.paymentMode
|
||||
@@ -9,10 +9,10 @@ export const POST: RequestHandler = async ({ request }) => {
|
||||
const rawBody = await request.text();
|
||||
const signature = request.headers.get('stripe-signature');
|
||||
|
||||
// Dummy mode: no webhook secret configured — accept the event without
|
||||
// verification so the flow is testable before the account is connected.
|
||||
if (isDummyStripe || !signature) {
|
||||
return json({ received: true, dummy: true });
|
||||
// Signature is mandatory — unsigned requests are rejected outright
|
||||
// (a forged checkout.session.completed would otherwise grant access).
|
||||
if (!signature) {
|
||||
return json({ error: 'Missing stripe-signature header' }, { status: 400 });
|
||||
}
|
||||
|
||||
let event;
|
||||
|
||||
Reference in New Issue
Block a user