import { json, type RequestHandler } from '@sveltejs/kit'; import { verifyStripeEvent, isDummyStripe } from '$lib/server/stripe'; import { handleStripeEvent } from '$lib/server/stripe-events'; // Stripe webhook: updates fams.stripeCustomerId + fams.active + fams.paymentMode // from subscription lifecycle events. Lives under /api/webhooks/stripe per the // architecture — machine-to-machine endpoints live in /api/*, not under UI routes. export const POST: RequestHandler = async ({ request }) => { const rawBody = await request.text(); const signature = request.headers.get('stripe-signature'); // Dummy mode: no webhook secret configured — accept the event without // verification so the flow is testable before the account is connected. if (isDummyStripe || !signature) { return json({ received: true, dummy: true }); } let event; try { event = verifyStripeEvent(rawBody, signature); } catch (e) { return json( { error: e instanceof Error ? e.message : 'Webhook signature verification failed' }, { status: 400 } ); } await handleStripeEvent(event); return json({ received: true }); };