Fix: Stripping Lunar's Stripe Driver with Boboko's Stripe Payment Driver
This commit is contained in:
@@ -9,18 +9,17 @@ use Modules\Core\Payment\Drivers\StripePaymentDriver;
|
||||
use Stripe\Webhook;
|
||||
|
||||
/**
|
||||
* A boboko-owned webhook endpoint for Stripe — deliberately NOT
|
||||
* lunarphp/stripe's own route (vendor/lunarphp/stripe/routes/webhooks.php),
|
||||
* which dispatches into Lunar's own Payments::driver('stripe') flow (the
|
||||
* flow StripePaymentDriver was built to replace, see that class's own
|
||||
* docblock). Signature verification is handled by
|
||||
* Lunar\Stripe\Http\Middleware\StripeWebhookMiddleware, registered on this
|
||||
* route (see src/Payment/routes/webhooks.php) — pure Stripe SDK
|
||||
* verification + event-type filtering, safe to reuse even though this
|
||||
* controller never touches the rest of that vendor package's flow. This
|
||||
* controller verifies the signature again itself (Webhook::constructEvent())
|
||||
* to get the constructed Event object — the middleware doesn't stash one
|
||||
* anywhere reusable, it only gates the request through.
|
||||
* A boboko-owned webhook endpoint for Stripe — never went through Lunar's
|
||||
* own Payments::driver('stripe') flow (the flow StripePaymentDriver was
|
||||
* built to replace, see that class's own docblock), and lunarphp/stripe
|
||||
* has since been removed entirely (see Modules\Core\Payment\Support\
|
||||
* StripeManager's own docblock). Signature verification is handled by
|
||||
* Modules\Core\Payment\Http\Middleware\StripeWebhookMiddleware, registered
|
||||
* on this route (see src/Payment/routes/webhooks.php) — pure Stripe SDK
|
||||
* verification + event-type filtering. This controller verifies the
|
||||
* signature again itself (Webhook::constructEvent()) to get the
|
||||
* constructed Event object — the middleware doesn't stash one anywhere
|
||||
* reusable, it only gates the request through.
|
||||
*
|
||||
* Resolves the driver directly by class, not via
|
||||
* Modules\Core\Payment\Services\PaymentDriverRegistry — this endpoint is
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Payment\Http\Middleware;
|
||||
|
||||
use Closure;
|
||||
use Illuminate\Http\Request;
|
||||
use Stripe\Exception\SignatureVerificationException;
|
||||
use Stripe\Exception\UnexpectedValueException;
|
||||
use Stripe\Webhook;
|
||||
|
||||
/**
|
||||
* First-party replacement for Lunar\Stripe\Http\Middleware\
|
||||
* StripeWebhookMiddleware (lunarphp/stripe removed — see
|
||||
* Modules\Core\Payment\Support\StripeManager's own docblock). Registered
|
||||
* on the same route as before (src/Payment/routes/webhooks.php) purely to
|
||||
* gate malformed/irrelevant requests before they reach
|
||||
* Modules\Core\Payment\Http\Controllers\StripeWebhookController, which
|
||||
* re-verifies the signature itself (see that controller's own docblock)
|
||||
* to get the constructed Event object — this duplication predates the
|
||||
* package removal and is left unchanged here.
|
||||
*/
|
||||
class StripeWebhookMiddleware
|
||||
{
|
||||
public function handle(Request $request, ?Closure $next = null)
|
||||
{
|
||||
$secret = config('services.stripe.webhooks.lunar');
|
||||
$stripeSig = $request->header('Stripe-Signature');
|
||||
|
||||
try {
|
||||
$event = Webhook::constructEvent(
|
||||
$request->getContent(),
|
||||
$stripeSig,
|
||||
$secret
|
||||
);
|
||||
} catch (UnexpectedValueException|SignatureVerificationException $e) {
|
||||
abort(400, $e->getMessage());
|
||||
}
|
||||
|
||||
if (! in_array(
|
||||
$event->type,
|
||||
[
|
||||
'payment_intent.payment_failed',
|
||||
'payment_intent.succeeded',
|
||||
]
|
||||
)) {
|
||||
return response('', 200);
|
||||
}
|
||||
|
||||
return $next($request);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user