52 lines
1.6 KiB
PHP
52 lines
1.6 KiB
PHP
<?php
|
|
|
|
namespace Modules\Core\Payment\Http\Middleware;
|
|
|
|
use Closure;
|
|
use Illuminate\Http\Request;
|
|
use Stripe\Exception\SignatureVerificationException;
|
|
use Stripe\Exception\UnexpectedValueException;
|
|
use Stripe\Webhook;
|
|
|
|
/**
|
|
* First-party replacement for Lunar\Stripe\Http\Middleware\
|
|
* StripeWebhookMiddleware (lunarphp/stripe removed — see
|
|
* Modules\Core\Payment\Support\StripeManager's own docblock). Registered
|
|
* on the same route as before (src/Payment/routes/webhooks.php) purely to
|
|
* gate malformed/irrelevant requests before they reach
|
|
* Modules\Core\Payment\Http\Controllers\StripeWebhookController, which
|
|
* re-verifies the signature itself (see that controller's own docblock)
|
|
* to get the constructed Event object — this duplication predates the
|
|
* package removal and is left unchanged here.
|
|
*/
|
|
class StripeWebhookMiddleware
|
|
{
|
|
public function handle(Request $request, ?Closure $next = null)
|
|
{
|
|
$secret = config('services.stripe.webhooks.lunar');
|
|
$stripeSig = $request->header('Stripe-Signature');
|
|
|
|
try {
|
|
$event = Webhook::constructEvent(
|
|
$request->getContent(),
|
|
$stripeSig,
|
|
$secret
|
|
);
|
|
} catch (UnexpectedValueException|SignatureVerificationException $e) {
|
|
abort(400, $e->getMessage());
|
|
}
|
|
|
|
if (! in_array(
|
|
$event->type,
|
|
[
|
|
'payment_intent.payment_failed',
|
|
'payment_intent.succeeded',
|
|
]
|
|
)) {
|
|
return response('', 200);
|
|
}
|
|
|
|
return $next($request);
|
|
}
|
|
}
|