refactor(backend): migrate db.DB to db.Conn PoolProxy across all handlers
Replace direct *pgxpool.Pool usage with PoolProxy wrapper across the entire backend: - db.DB renamed to db.Conn (*pgxpool.Pool -> *PoolProxy) - JWT functions now accept context.Context instead of using context.Background() - Handler DB calls route through PoolProxy for per-test transaction support - Fixture/helper/testdb functions accept Querier interface for decoupling - Query ordering fixed in bookings handlers: COUNT after data query to avoid pgx conn busy - Time truncation fixed: time.Date instead of Truncate(24*time.Hour) for week start calc - testmain_test.go files updated with SeedBaseline and NewPoolProxy Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
This commit is contained in:
@@ -56,11 +56,14 @@ func HandleSquareWebhook(w http.ResponseWriter, r *http.Request) {
|
||||
// Set SQUARE_WEBHOOK_SIGNATURE_KEY in production env vars from Square Developer Console.
|
||||
// Delete this comment block and the verifySquareSignature function when implemented.
|
||||
|
||||
// TODO(PROD): Always verify signature before processing
|
||||
signature := r.Header.Get("x-square-signature")
|
||||
signingKey := os.Getenv("SQUARE_WEBHOOK_SIGNATURE_KEY")
|
||||
if signingKey != "" && signature != "" {
|
||||
// Dev-only stub — see top of function for production requirements
|
||||
if signingKey != "" {
|
||||
signature := r.Header.Get("x-square-signature")
|
||||
if signature == "" {
|
||||
log.Printf("Missing Square webhook signature header")
|
||||
http.Error(w, "Invalid signature", http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
if !verifySquareSignature(body, signature, signingKey) {
|
||||
log.Printf("Invalid Square webhook signature")
|
||||
http.Error(w, "Invalid signature", http.StatusForbidden)
|
||||
|
||||
Reference in New Issue
Block a user