← All changes
|
app/Modules/PaymentMethods/AirwallexGateway/Airwallex.php
+20
-1
1.6.2
→
1.7.0
View file →
| @@ -55,8 +55,27 @@ | ||
| 55 | 55 | } |
| 56 | 56 | |
| 57 | 57 | public function handleIPN(): void |
| 58 | 58 | { |
| 59 | + // Airwallex is not released yet (meta 'upcoming' => true). The event | |
| 60 | + // handlers below are unfinished scaffolding that write order state | |
| 61 | + // directly, outside the transaction/event pipeline every live gateway | |
| 62 | + // uses, and without the cross-checks a real listener needs. Refuse to | |
| 63 | + // process any event while the gateway is upcoming so no forged or | |
| 64 | + // replayed payload can reach them. | |
| 65 | + // | |
| 66 | + // Before removing this guard at GA, the handlers MUST: | |
| 67 | + // - resolve the order by the intent id we stamped at intent creation, | |
| 68 | + // never by attacker-supplied metadata.order_id; | |
| 69 | + // - verify amount, currency and payment mode against the stored order; | |
| 70 | + // - reject stale callbacks (timestamp-age window + per-event dedup) and | |
| 71 | + // guard terminal states (do not flip a paid order to failed); | |
| 72 | + // - route through the shared PaymentHelper/transaction machinery. | |
| 73 | + if ($this->isUpcoming()) { | |
| 74 | + http_response_code(404); | |
| 75 | + exit(); | |
| 76 | + } | |
| 77 | + | |
| 59 | 78 | $payload = json_decode(file_get_contents('php://input'), true); // will get from request after verification |
| 60 | 79 | // Verify webhook signature |
| 61 | 80 | if (!$this->verifyWebhookSignature($payload)) { |
| 62 | 81 | http_response_code(401); |
| @@ -104,9 +123,9 @@ | ||
| 104 | 123 | } |
| 105 | 124 | |
| 106 | 125 | public function fields() |
| 107 | 126 | { |
| 108 | - $webhook_url = trailingslashit(site_url()) . '?fct_payment_listener=1&method=airwallex'; | |
| 127 | + $webhook_url = Arr::get($this->getListenerUrl(), 'listener_url'); | |
| 109 | 128 | $webhook_instructions = sprintf( |
| 110 | 129 | '<div> |
| 111 | 130 | <p><b>%1$s</b><code class="copyable-content">%2$s</code></p> |
| 112 | 131 | <p>%3$s</p> |