Files
famdone/frontend/src/routes/api/webhooks/stripe/+server.ts
T
2026-08-24 18:09:44 +01:00

30 lines
1.1 KiB
TypeScript

import { json, type RequestHandler } from '@sveltejs/kit';
import { verifyStripeEvent } from '$lib/server/stripe';
import { handleStripeEvent } from '$lib/server/stripe-events';
// Stripe webhook: updates fams.stripeCustomerId + fams.active + fams.paymentMode
// from subscription lifecycle events. Lives under /api/webhooks/stripe per the
// architecture — machine-to-machine endpoints live in /api/*, not under UI routes.
export const POST: RequestHandler = async ({ request }) => {
const rawBody = await request.text();
const signature = request.headers.get('stripe-signature');
// Signature is mandatory — unsigned requests are rejected outright
// (a forged checkout.session.completed would otherwise grant access).
if (!signature) {
return json({ error: 'Missing stripe-signature header' }, { status: 400 });
}
let event;
try {
event = verifyStripeEvent(rawBody, signature);
} catch (e) {
return json(
{ error: e instanceof Error ? e.message : 'Webhook signature verification failed' },
{ status: 400 }
);
}
await handleStripeEvent(event);
return json({ received: true });
};