fix: comprehensive payment system hardening (4 review passes)

CRITICAL fixes:
- C1: JWT exp claim now validated via jwtauth.VerifyToken (was Decode)
- C2: OverrideAmount validated post-substitution (prevents negative money minting)
- C3: Terminal gift-card payments store gift_card_id; refund credits user balance
- C4: Refund dedup returns stored amount, not req.Amount (prevents admin mislead)
- C5: Booking recheck uses FOR UPDATE (prevents TOCTOU with cancellation)
- C6: processChargeGroup idempotency key stable (charge-only, prevents double-refund)

MAJOR fixes:
- M2: Gift-card refund UPDATE checks RowsAffected; 0 rows -> failed
- M3: ProcessCancellationRefund returns commit error (was swallowed)
- M5: Dispute webhook handling (created + state.updated + disputes table)

MEDIUM fixes:
- ME1: CORS restricted to FRONTEND_ORIGIN env var (was reflect-any)
- ME2: anonymize_user() scrubs users.notes, bookings.notes, name_history, refresh_tokens
- ME3: Webhook handlers now mutate state (payment.updated, refund.updated)

Frontend fixes:
- Same-key retry on 503 (ambiguous failure) wired to all 8 payment flows
- CHARGE_AND_STORE intent for save-card flows (SCA compliance)
- Nonce staleness check verified across all flows

Additional fixes from adversarial re-review:
- F1: Till-sale completed dedup echoes stored amount (C4-class)
- F2: Cash/giftcard terminal path uses FOR UPDATE (C5-class)
- F3: Square-success UPDATE checks RowsAffected (till sales)
- F4: Dispute reason truncated to 192 chars (prevents INSERT failure)
- F5: Booking-user lookup failure marks refund failed (prevents silent money loss)
- F6: Saved-card/tip rechecks wrapped in transaction (C5 residual)

Tests:
- 15 adversarial attack tests (negative override, zero override, terminal gift card,
  refund dedup, TOCTOU, deleted gift card, advisory lock, overcharge, zero/negative/huge
  amount, raw PAN, missing auth, gift card balance, concurrent refunds)
- 14 webhook state tests (dispute created/state, payment/refund updated)
- 3 CORS tests, 3 GDPR tests, 1 HTTP timeout test
- Full suite passes with -race (25 packages, 0 failures)

25 files changed, +1532/-275 lines
This commit is contained in:
2026-08-22 00:34:49 +01:00
parent 7df983052b
commit 5e3dc9b428
28 changed files with 2905 additions and 275 deletions
+1 -1
View File
@@ -141,7 +141,7 @@ func GenerateToken(userID string, role string) (string, string, error) {
// VerifyToken validates JWT and returns user_id, role, and jti
func VerifyToken(tokenString string, ctx context.Context) (userID string, role string, jti string, err error) {
token, err := TokenAuth.Decode(tokenString)
token, err := jwtauth.VerifyToken(TokenAuth, tokenString)
if err != nil {
return "", "", "", err
}
+16
View File
@@ -178,6 +178,22 @@ func TestVerifyToken_RevokedJTI(t *testing.T) {
}
}
// TestVerifyToken_ExpiredToken creates a token whose "exp" claim is in the past
// and verifies that VerifyToken rejects it with an error containing "expired".
func TestVerifyToken_ExpiredToken(t *testing.T) {
_, tokenString, err := TokenAuth.Encode(map[string]interface{}{
"user_id": "user-expired",
"role": "verified_email",
"jti": "test-jti-expired",
"exp": clock.Now().Add(-1 * time.Hour).Unix(),
})
require.NoError(t, err)
_, _, _, err = VerifyToken(tokenString, context.Background())
require.Error(t, err)
assert.Contains(t, err.Error(), "expired")
}
// TestVerifyToken_MissingJTI creates a token without a "jti" claim (using
// TokenAuth.Encode directly) and verifies that VerifyToken returns an error
// containing "invalid jti claim".