update from user testing payment platform

This commit is contained in:
JCEEE
2026-08-24 18:09:44 +01:00
parent d71353fb3e
commit 09d73199ea
10 changed files with 615 additions and 260 deletions
@@ -1,5 +1,5 @@
import { json, type RequestHandler } from '@sveltejs/kit';
import { verifyStripeEvent, isDummyStripe } from '$lib/server/stripe';
import { verifyStripeEvent } from '$lib/server/stripe';
import { handleStripeEvent } from '$lib/server/stripe-events';
// Stripe webhook: updates fams.stripeCustomerId + fams.active + fams.paymentMode
@@ -9,10 +9,10 @@ export const POST: RequestHandler = async ({ request }) => {
const rawBody = await request.text();
const signature = request.headers.get('stripe-signature');
// Dummy mode: no webhook secret configured — accept the event without
// verification so the flow is testable before the account is connected.
if (isDummyStripe || !signature) {
return json({ received: true, dummy: true });
// Signature is mandatory — unsigned requests are rejected outright
// (a forged checkout.session.completed would otherwise grant access).
if (!signature) {
return json({ error: 'Missing stripe-signature header' }, { status: 400 });
}
let event;