CRITICAL fixes: - C1: JWT exp claim now validated via jwtauth.VerifyToken (was Decode) - C2: OverrideAmount validated post-substitution (prevents negative money minting) - C3: Terminal gift-card payments store gift_card_id; refund credits user balance - C4: Refund dedup returns stored amount, not req.Amount (prevents admin mislead) - C5: Booking recheck uses FOR UPDATE (prevents TOCTOU with cancellation) - C6: processChargeGroup idempotency key stable (charge-only, prevents double-refund) MAJOR fixes: - M2: Gift-card refund UPDATE checks RowsAffected; 0 rows -> failed - M3: ProcessCancellationRefund returns commit error (was swallowed) - M5: Dispute webhook handling (created + state.updated + disputes table) MEDIUM fixes: - ME1: CORS restricted to FRONTEND_ORIGIN env var (was reflect-any) - ME2: anonymize_user() scrubs users.notes, bookings.notes, name_history, refresh_tokens - ME3: Webhook handlers now mutate state (payment.updated, refund.updated) Frontend fixes: - Same-key retry on 503 (ambiguous failure) wired to all 8 payment flows - CHARGE_AND_STORE intent for save-card flows (SCA compliance) - Nonce staleness check verified across all flows Additional fixes from adversarial re-review: - F1: Till-sale completed dedup echoes stored amount (C4-class) - F2: Cash/giftcard terminal path uses FOR UPDATE (C5-class) - F3: Square-success UPDATE checks RowsAffected (till sales) - F4: Dispute reason truncated to 192 chars (prevents INSERT failure) - F5: Booking-user lookup failure marks refund failed (prevents silent money loss) - F6: Saved-card/tip rechecks wrapped in transaction (C5 residual) Tests: - 15 adversarial attack tests (negative override, zero override, terminal gift card, refund dedup, TOCTOU, deleted gift card, advisory lock, overcharge, zero/negative/huge amount, raw PAN, missing auth, gift card balance, concurrent refunds) - 14 webhook state tests (dispute created/state, payment/refund updated) - 3 CORS tests, 3 GDPR tests, 1 HTTP timeout test - Full suite passes with -race (25 packages, 0 failures) 25 files changed, +1532/-275 lines
663 lines
26 KiB
Go
663 lines
26 KiB
Go
package webhooks
|
|
|
|
import (
|
|
"context"
|
|
"crypto/hmac"
|
|
"crypto/sha256"
|
|
"encoding/base64"
|
|
"encoding/json"
|
|
"fmt"
|
|
"io"
|
|
"log"
|
|
"net/http"
|
|
"os"
|
|
"sync"
|
|
|
|
"crussell/db"
|
|
)
|
|
|
|
type SquareWebhookEvent struct {
|
|
Type string `json:"type"`
|
|
EventID string `json:"event_id"`
|
|
CreatedAt string `json:"created_at"`
|
|
Data json.RawMessage `json:"data"`
|
|
LocationID string `json:"location_id"`
|
|
}
|
|
|
|
// squareWebhookDedup is a bounded, mutex-guarded set of recently handled
|
|
// event IDs. It is a FAST-PATH cache only: the persistent source of truth is
|
|
// the square_webhook_events table (see HandleSquareWebhook). It lets a replayed
|
|
// delivery be dropped without a DB round-trip, but a restart clears it — the DB
|
|
// row is what guarantees at-most-once processing across restarts.
|
|
type squareWebhookDedup struct {
|
|
mu sync.Mutex
|
|
seen map[string]struct{}
|
|
order []string
|
|
max int
|
|
}
|
|
|
|
func newSquareWebhookDedup(max int) *squareWebhookDedup {
|
|
return &squareWebhookDedup{
|
|
seen: make(map[string]struct{}),
|
|
order: make([]string, 0, max),
|
|
max: max,
|
|
}
|
|
}
|
|
|
|
// has reports whether id is in the set WITHOUT recording it. Used as the
|
|
// fast-path short-circuit before the DB dedup insert.
|
|
func (d *squareWebhookDedup) has(id string) bool {
|
|
d.mu.Lock()
|
|
defer d.mu.Unlock()
|
|
_, ok := d.seen[id]
|
|
return ok
|
|
}
|
|
|
|
// register records id, reporting whether it was already present (set untouched
|
|
// on a replay, preserving insertion order). Mutex-guarded — the handler may be
|
|
// hit concurrently. Called only after the DB insert has confirmed the event's
|
|
// fate, so a failed DB write never leaves a stale entry that would drop a retry.
|
|
func (d *squareWebhookDedup) register(id string) bool {
|
|
d.mu.Lock()
|
|
defer d.mu.Unlock()
|
|
if _, ok := d.seen[id]; ok {
|
|
return true
|
|
}
|
|
d.seen[id] = struct{}{}
|
|
d.order = append(d.order, id)
|
|
if len(d.order) > d.max {
|
|
oldest := d.order[0]
|
|
d.order = d.order[1:]
|
|
delete(d.seen, oldest)
|
|
}
|
|
return false
|
|
}
|
|
|
|
// 500 IDs far exceeds the latency payoff of the fast-path cache; the DB row
|
|
// (square_webhook_events) is the unbounded, restart-safe source of truth.
|
|
var squareWebhookEventsSeen = newSquareWebhookDedup(500)
|
|
|
|
// HandleSquareWebhook verifies and dispatches Square webhook events.
|
|
//
|
|
// Fail-closed chain: 503 when the signing key is unset, 403 on a missing/bad
|
|
// signature, 400 on malformed JSON or an empty event_id (which cannot be
|
|
// deduplicated — Square always sends one, so this is defensive). A correctly
|
|
// signed, well-formed event is deduplicated by event_id before dispatch and
|
|
// acknowledged 200.
|
|
func HandleSquareWebhook(w http.ResponseWriter, r *http.Request) {
|
|
r.Body = http.MaxBytesReader(w, r.Body, 512*1024)
|
|
body, err := io.ReadAll(r.Body)
|
|
if err != nil {
|
|
log.Printf("Failed to read webhook body: %v", err)
|
|
http.Error(w, "request body too large or unreadable", http.StatusRequestEntityTooLarge)
|
|
return
|
|
}
|
|
defer r.Body.Close()
|
|
|
|
// Verification logic per Square spec (HMAC-SHA256, base64, notificationURL + body).
|
|
// Production setup: set SQUARE_WEBHOOK_SIGNATURE_KEY and SQUARE_WEBHOOK_NOTIFICATION_URL
|
|
// in env vars (see Square Developer Console → Webhooks → Subscription).
|
|
// Reference: https://developer.squareup.com/docs/webhooks/step3validate
|
|
|
|
// Fail closed: a missing signing key means the webhook cannot be verified,
|
|
// so reject rather than process unauthenticated events (S-4). Square
|
|
// always sends the signature header, so an unset key in production is a
|
|
// misconfiguration that must not silently accept forged events.
|
|
signingKey := os.Getenv("SQUARE_WEBHOOK_SIGNATURE_KEY")
|
|
notificationURL := os.Getenv("SQUARE_WEBHOOK_NOTIFICATION_URL")
|
|
if notificationURL == "" {
|
|
notificationURL = "http://localhost:8080/webhooks/square"
|
|
}
|
|
if signingKey == "" {
|
|
log.Printf("SQUARE_WEBHOOK_SIGNATURE_KEY is not set — rejecting webhook (fail-closed)")
|
|
http.Error(w, "webhook signature verification unavailable", http.StatusServiceUnavailable)
|
|
return
|
|
}
|
|
signature := r.Header.Get("x-square-hmacsha256-signature")
|
|
if signature == "" {
|
|
log.Printf("Missing Square webhook signature header")
|
|
http.Error(w, "Invalid signature", http.StatusForbidden)
|
|
return
|
|
}
|
|
if !verifySquareSignature(body, signature, signingKey, notificationURL) {
|
|
log.Printf("Invalid Square webhook signature")
|
|
http.Error(w, "Invalid signature", http.StatusForbidden)
|
|
return
|
|
}
|
|
|
|
var event SquareWebhookEvent
|
|
if err := json.Unmarshal(body, &event); err != nil {
|
|
log.Printf("Failed to parse webhook event: %v", err)
|
|
http.Error(w, "Invalid event", http.StatusBadRequest)
|
|
return
|
|
}
|
|
|
|
// An empty event_id cannot be deduplicated. Square always sends event_id,
|
|
// so this is defensive — but once handlers mutate state, a duplicate
|
|
// empty-ID event would double-apply. Reject with 400 (fail-safe, no
|
|
// dispatch, no dedup row): Square's retry policy retries on 5xx/timeouts
|
|
// but treats 4xx as non-retryable, so the malformed event is dropped
|
|
// without side effects.
|
|
if event.EventID == "" {
|
|
log.Printf("[SQUARE-WEBHOOK] Rejecting event with empty event_id (400)")
|
|
http.Error(w, "Invalid event", http.StatusBadRequest)
|
|
return
|
|
}
|
|
|
|
// Dedup BEFORE dispatch: a correctly signed replay of a handled event must
|
|
// not re-enter the handlers (which will mutate state once wired). The
|
|
// in-memory fast-path drops recent replays without a DB round-trip; the
|
|
// square_webhook_events INSERT ... ON CONFLICT DO NOTHING is the source of
|
|
// truth — 0 rows affected means the event was already handled (persisted
|
|
// from before a restart, or a concurrent duplicate) and dispatch is
|
|
// skipped. Returns 200 to acknowledge delivery without processing.
|
|
//
|
|
// ORDERING NOTE: the dedup row is committed before dispatch. If the process
|
|
// crashes between the insert and dispatch, the event is dropped (Square's
|
|
// retry is 200-skipped). This is acceptable while dispatch is log-only;
|
|
// when handlers mutate state, switch to dispatch-then-record or make
|
|
// dispatch idempotent.
|
|
if event.EventID != "" {
|
|
if squareWebhookEventsSeen.has(event.EventID) {
|
|
log.Printf("[SQUARE-WEBHOOK] Duplicate event_id %s; skipping (already processed)", event.EventID)
|
|
w.WriteHeader(http.StatusOK)
|
|
_, _ = w.Write([]byte("ok"))
|
|
return
|
|
}
|
|
if db.Conn == nil {
|
|
log.Printf("[SQUARE-WEBHOOK] DB unavailable — rejecting event_id %s (fail-closed)", event.EventID)
|
|
http.Error(w, "webhook processing unavailable", http.StatusServiceUnavailable)
|
|
return
|
|
}
|
|
tag, err := db.Conn.Exec(r.Context(),
|
|
"INSERT INTO square_webhook_events (event_id) VALUES ($1) ON CONFLICT (event_id) DO NOTHING", event.EventID)
|
|
if err != nil {
|
|
// Fail closed: without a successful dedup write we cannot prove this
|
|
// event hasn't been handled before, so reject and let Square retry
|
|
// later. event_id is not PII, so logging it is safe.
|
|
log.Printf("[SQUARE-WEBHOOK] Failed to record event_id %s (dedup write failed): %v", event.EventID, err)
|
|
http.Error(w, "webhook processing unavailable", http.StatusServiceUnavailable)
|
|
return
|
|
}
|
|
// Record in the fast-path cache only after the DB write succeeds, so a
|
|
// failed write never leaves a stale entry that would drop a retry.
|
|
squareWebhookEventsSeen.register(event.EventID)
|
|
if tag.RowsAffected() == 0 {
|
|
log.Printf("[SQUARE-WEBHOOK] Duplicate event_id %s; skipping (already processed)", event.EventID)
|
|
w.WriteHeader(http.StatusOK)
|
|
_, _ = w.Write([]byte("ok"))
|
|
return
|
|
}
|
|
}
|
|
|
|
log.Printf("[SQUARE-WEBHOOK] Received event: %s", event.Type)
|
|
|
|
switch event.Type {
|
|
case "payment.updated", "payment.created", "payment.completed":
|
|
handlePaymentUpdated(event.Data)
|
|
case "refund.updated", "refund.created", "refund.completed", "refund.failed":
|
|
handleRefundUpdated(event.Data)
|
|
case "dispute.created":
|
|
handleDisputeCreated(event.Data)
|
|
case "dispute.state.updated":
|
|
handleDisputeStateUpdated(event.Data)
|
|
case "dispute.evidence.submitted", "dispute.evidence.created", "dispute.evidence.removed", "dispute.evidence.deleted":
|
|
handleDisputeEvidence(event.Data)
|
|
case "terminal.checkout.created", "terminal.checkout.updated":
|
|
handleTerminalCheckout(event.Data)
|
|
default:
|
|
log.Printf("[SQUARE-WEBHOOK] Unknown event type: %s", event.Type)
|
|
}
|
|
|
|
w.WriteHeader(http.StatusOK)
|
|
_, _ = w.Write([]byte("ok"))
|
|
}
|
|
|
|
func verifySquareSignature(body []byte, signature, signingKey, notificationURL string) bool {
|
|
mac := hmac.New(sha256.New, []byte(signingKey))
|
|
mac.Write([]byte(notificationURL))
|
|
mac.Write(body)
|
|
expected := base64.StdEncoding.EncodeToString(mac.Sum(nil))
|
|
return hmac.Equal([]byte(signature), []byte(expected))
|
|
}
|
|
|
|
// squareWebhookData is the `data` envelope of a Square webhook v1 event. The
|
|
// affected object's id is at data.id; the full resource is nested at
|
|
// data.object.<type> (e.g. data.object.payment). Only the id is logged — the
|
|
// nested object can contain PII and is never echoed to the log.
|
|
type squareWebhookData struct {
|
|
ID string `json:"id"`
|
|
Type string `json:"type"`
|
|
Object json.RawMessage `json:"object"`
|
|
}
|
|
|
|
// squareDisputePayload maps the Square Dispute fields this app records.
|
|
// Reference: https://developer.squareup.com/reference/square/objects/Dispute
|
|
type squareDisputePayload struct {
|
|
ID string `json:"id"`
|
|
State string `json:"state"`
|
|
AmountMoney *squareMoneyPayload `json:"amount_money"`
|
|
Reason string `json:"reason"`
|
|
DisputedPayment *squareDisputedPaymentField `json:"disputed_payment"`
|
|
}
|
|
|
|
type squareMoneyPayload struct {
|
|
Amount int64 `json:"amount"` // minor units (pence for GBP)
|
|
Currency string `json:"currency"`
|
|
}
|
|
|
|
type squareDisputedPaymentField struct {
|
|
PaymentID string `json:"payment_id"`
|
|
}
|
|
|
|
// squarePaymentPayload maps the Square Payment fields this app consumes.
|
|
type squarePaymentPayload struct {
|
|
ID string `json:"id"`
|
|
Status string `json:"status"` // "APPROVED", "COMPLETED", "CANCELED", "FAILED", "PENDING"
|
|
}
|
|
|
|
// squareRefundPayload maps the Square Refund (PaymentRefund) fields this app
|
|
// consumes.
|
|
type squareRefundPayload struct {
|
|
ID string `json:"id"`
|
|
Status string `json:"status"` // "PENDING", "COMPLETED", "FAILED"
|
|
}
|
|
|
|
// parseSquareObject unmarshals data.object.<type> into out. Returns false when
|
|
// the nested resource is absent (legacy envelope carrying only data.id).
|
|
func parseSquareObject(object json.RawMessage, key string, out any) bool {
|
|
if len(object) == 0 {
|
|
return false
|
|
}
|
|
var wrapper map[string]json.RawMessage
|
|
if err := json.Unmarshal(object, &wrapper); err != nil {
|
|
return false
|
|
}
|
|
raw, ok := wrapper[key]
|
|
if !ok || len(raw) == 0 {
|
|
return false
|
|
}
|
|
if err := json.Unmarshal(raw, out); err != nil {
|
|
return false
|
|
}
|
|
return true
|
|
}
|
|
|
|
// squareMoneyToAmount converts a Square Money object (minor units) to an exact
|
|
// two-decimal string for the NUMERIC(10,2) columns. String formatting avoids
|
|
// float64 rounding artifacts for money.
|
|
func squareMoneyToAmount(m *squareMoneyPayload) string {
|
|
if m == nil || m.Amount <= 0 {
|
|
return "0.00"
|
|
}
|
|
return fmt.Sprintf("%d.%02d", m.Amount/100, m.Amount%100)
|
|
}
|
|
|
|
// squarePaymentStatusToLocal maps Square's payment state machine to the local
|
|
// payment_status enum. APPROVED/PENDING are NON-terminal (Square may still
|
|
// complete or void them), so they map to a zero local status and the caller
|
|
// leaves the row untouched — the same classification the stale-pending sweeps
|
|
// use (handlers/payments/sweep.go).
|
|
func squarePaymentStatusToLocal(status string) (string, bool) {
|
|
switch status {
|
|
case "COMPLETED":
|
|
return "completed", true
|
|
case "CANCELED", "FAILED":
|
|
return "failed", true
|
|
case "APPROVED", "PENDING":
|
|
return "", false
|
|
default:
|
|
return "", false
|
|
}
|
|
}
|
|
|
|
// squareRefundStatusToLocal maps Square's refund status to the local
|
|
// payment_status enum. PENDING is non-terminal.
|
|
func squareRefundStatusToLocal(status string) (string, bool) {
|
|
switch status {
|
|
case "COMPLETED":
|
|
return "completed", true
|
|
case "FAILED":
|
|
return "failed", true
|
|
default:
|
|
return "", false
|
|
}
|
|
}
|
|
|
|
// squareDisputeStateToLocal maps Square's dispute state to the local
|
|
// disputes.status. Only the terminal resolutions move the row to won/lost;
|
|
// ACCEPTED (seller accepted the dispute) is a loss — the money is gone.
|
|
// Everything else (inquiries, evidence required, processing) stays open.
|
|
func squareDisputeStateToLocal(state string) string {
|
|
switch state {
|
|
case "WON":
|
|
return "won"
|
|
case "LOST", "ACCEPTED":
|
|
return "lost"
|
|
default:
|
|
return "open"
|
|
}
|
|
}
|
|
|
|
// findPaymentBySquareID resolves the local payment id and booking id for a
|
|
// Square payment id. Multiple local rows can share one Square charge id (e.g.
|
|
// a deposit + balance split); the most recent is used.
|
|
func findPaymentBySquareID(squarePaymentID string) (paymentID, bookingID string, ok bool) {
|
|
if squarePaymentID == "" {
|
|
return "", "", false
|
|
}
|
|
var pid string
|
|
var bid *string
|
|
err := db.Conn.QueryRow(context.Background(), `
|
|
SELECT id, booking_id FROM payments
|
|
WHERE square_payment_id = $1
|
|
ORDER BY created_at DESC, id DESC
|
|
LIMIT 1
|
|
`, squarePaymentID).Scan(&pid, &bid)
|
|
if err != nil {
|
|
return "", "", false
|
|
}
|
|
if bid != nil {
|
|
bookingID = *bid
|
|
}
|
|
return pid, bookingID, true
|
|
}
|
|
|
|
// findPaymentByDisputeID resolves the local payment (and its booking) recorded
|
|
// for a dispute row. Used by dispute.state.updated when the dispute row already
|
|
// exists but the webhook payload carries no resolvable Square payment id.
|
|
func findPaymentByDisputeID(squareDisputeID string) (paymentID, bookingID string) {
|
|
var pid string
|
|
var bid *string
|
|
err := db.Conn.QueryRow(context.Background(), `
|
|
SELECT d.payment_id, p.booking_id
|
|
FROM disputes d
|
|
JOIN payments p ON p.id = d.payment_id
|
|
WHERE d.square_dispute_id = $1
|
|
`, squareDisputeID).Scan(&pid, &bid)
|
|
if err != nil {
|
|
return "", ""
|
|
}
|
|
if bid != nil {
|
|
bookingID = *bid
|
|
}
|
|
return pid, bookingID
|
|
}
|
|
|
|
// insertCriticalPaymentNotification surfaces a money event in the admin
|
|
// notification centre (reason='critical_payment_log'), the DB-backed stand-in
|
|
// for un-watched CRITICAL log lines (see ScanCriticalPaymentLogs in
|
|
// internal/jobs/cleanup.go). Dedup: one unacknowledged row per (reason,
|
|
// booking_id) — acknowledging re-arms it.
|
|
func insertCriticalPaymentNotification(bookingID string) {
|
|
var bid any
|
|
if bookingID != "" {
|
|
bid = bookingID
|
|
}
|
|
tag, err := db.Conn.Exec(context.Background(), `
|
|
INSERT INTO admin_notifications (reason, booking_id, created_at)
|
|
SELECT 'critical_payment_log'::admin_notification_reason, $1, NOW()
|
|
WHERE NOT EXISTS (
|
|
SELECT 1 FROM admin_notifications an
|
|
WHERE an.reason = 'critical_payment_log'
|
|
AND an.booking_id IS NOT DISTINCT FROM $1
|
|
AND an.acknowledged_at IS NULL
|
|
)
|
|
`, bid)
|
|
if err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] Failed to insert critical_payment_log admin notification: %v", err)
|
|
return
|
|
}
|
|
if tag.RowsAffected() > 0 {
|
|
log.Printf("[SQUARE-WEBHOOK] Inserted critical_payment_log admin notification (booking_id=%s)", bookingID)
|
|
}
|
|
}
|
|
|
|
// markPaymentFailed flips a payment to 'failed' after a lost dispute — the
|
|
// money was charged back, so the row must not read as collected. 'refunded'
|
|
// rows are left alone (the money was returned by refund, not charged back).
|
|
func markPaymentFailed(paymentID string) {
|
|
if paymentID == "" {
|
|
return
|
|
}
|
|
_, err := db.Conn.Exec(context.Background(),
|
|
"UPDATE payments SET status = 'failed', updated_at = NOW() WHERE id = $1 AND status IN ('pending', 'completed')",
|
|
paymentID)
|
|
if err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] Failed to mark payment %s failed after lost dispute: %v", paymentID, err)
|
|
}
|
|
}
|
|
|
|
// handlePaymentUpdated reconciles a Square Payment state change against the
|
|
// local payments row (real-time counterpart to the stale-pending sweep). The
|
|
// Square id is logged, never the payload (PII). Idempotent: the UPDATE is a
|
|
// no-op when the local status already matches, and event_id dedup prevents
|
|
// re-entry at the handler level.
|
|
func handlePaymentUpdated(data json.RawMessage) {
|
|
var env squareWebhookData
|
|
if err := json.Unmarshal(data, &env); err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] payment.updated received (payload length=%d)", len(data))
|
|
return
|
|
}
|
|
if env.ID == "" {
|
|
log.Printf("[SQUARE-WEBHOOK] payment.updated received (payload length=%d)", len(data))
|
|
return
|
|
}
|
|
var payment squarePaymentPayload
|
|
if !parseSquareObject(env.Object, "payment", &payment) || payment.ID == "" || payment.Status == "" {
|
|
log.Printf("[SQUARE-WEBHOOK] payment.updated received (data.id=%s)", env.ID)
|
|
return
|
|
}
|
|
localStatus, terminal := squarePaymentStatusToLocal(payment.Status)
|
|
if !terminal {
|
|
log.Printf("[SQUARE-WEBHOOK] payment.updated: square payment %s status %q is non-terminal — no local state change", payment.ID, payment.Status)
|
|
return
|
|
}
|
|
// Only 'pending' rows are candidates for a terminal transition — the same
|
|
// conservative rule the stale-pending sweeps use. A webhook for an already
|
|
// settled row (Square fires payment.updated for ANY field change, e.g. fee
|
|
// recalculation on a fully-refunded charge) must never revert a terminal
|
|
// status like 'refunded' back to 'completed'.
|
|
tag, err := db.Conn.Exec(context.Background(),
|
|
`UPDATE payments SET status = $1, updated_at = NOW() WHERE square_payment_id = $2 AND status = 'pending'`,
|
|
localStatus, payment.ID)
|
|
if err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] Failed to update payment %s to status %s: %v", payment.ID, localStatus, err)
|
|
return
|
|
}
|
|
if tag.RowsAffected() > 0 {
|
|
log.Printf("[SQUARE-WEBHOOK] payment.updated: square payment %s → local status %s", payment.ID, localStatus)
|
|
}
|
|
// A Square charge can also map to a till_sales row (online gift-card
|
|
// purchase, retail at the till) — reconcile those too. Same pending-only
|
|
// guard: never revert a terminal till-sale status.
|
|
tsTag, err := db.Conn.Exec(context.Background(),
|
|
`UPDATE till_sales SET status = $1, updated_at = NOW() WHERE square_payment_id = $2 AND status = 'pending'`,
|
|
localStatus, payment.ID)
|
|
if err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] Failed to reconcile till_sales for square payment %s: %v", payment.ID, err)
|
|
return
|
|
}
|
|
if tsTag.RowsAffected() > 0 {
|
|
log.Printf("[SQUARE-WEBHOOK] payment.updated: reconciled %d till_sale(s) for square payment %s → status %s", tsTag.RowsAffected(), payment.ID, localStatus)
|
|
}
|
|
}
|
|
|
|
// handleRefundUpdated reconciles a Square Refund state change against the local
|
|
// refunds row. Idempotent (status-guarded UPDATE + event_id dedup).
|
|
func handleRefundUpdated(data json.RawMessage) {
|
|
var env squareWebhookData
|
|
if err := json.Unmarshal(data, &env); err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] refund.updated received (payload length=%d)", len(data))
|
|
return
|
|
}
|
|
if env.ID == "" {
|
|
log.Printf("[SQUARE-WEBHOOK] refund.updated received (payload length=%d)", len(data))
|
|
return
|
|
}
|
|
var refund squareRefundPayload
|
|
if !parseSquareObject(env.Object, "refund", &refund) || refund.ID == "" || refund.Status == "" {
|
|
log.Printf("[SQUARE-WEBHOOK] refund.updated received (data.id=%s)", env.ID)
|
|
return
|
|
}
|
|
localStatus, terminal := squareRefundStatusToLocal(refund.Status)
|
|
if !terminal {
|
|
log.Printf("[SQUARE-WEBHOOK] refund.updated: square refund %s status %q is non-terminal — no local state change", refund.ID, refund.Status)
|
|
return
|
|
}
|
|
// COMPLETED may promote any non-completed row (incl. a sweep-failed refund
|
|
// Square later shows complete) — the over-refund guard counts completed
|
|
// refunds, so this only tightens it. FAILED only demotes a 'pending' row:
|
|
// demoting 'completed' would let the guard exclude money that already moved
|
|
// (the exact risk refunds.go documents for failed refunds).
|
|
var upd string
|
|
switch localStatus {
|
|
case "completed":
|
|
upd = `UPDATE refunds SET status = 'completed' WHERE square_refund_id = $1 AND status <> 'completed'`
|
|
case "failed":
|
|
upd = `UPDATE refunds SET status = 'failed' WHERE square_refund_id = $1 AND status = 'pending'`
|
|
}
|
|
tag, err := db.Conn.Exec(context.Background(), upd, refund.ID)
|
|
if err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] Failed to update refund %s to status %s: %v", refund.ID, localStatus, err)
|
|
return
|
|
}
|
|
if tag.RowsAffected() > 0 {
|
|
log.Printf("[SQUARE-WEBHOOK] refund.updated: square refund %s → local status %s", refund.ID, localStatus)
|
|
}
|
|
}
|
|
|
|
// truncateDisputeReason caps a Square dispute reason at the disputes.reason
|
|
// VARCHAR(192) column width. An over-long reason would fail the INSERT — and
|
|
// because the event_id dedup row commits BEFORE dispatch, a failed insert
|
|
// silently drops the dispute (money-at-risk with no record).
|
|
func truncateDisputeReason(reason string) string {
|
|
if len(reason) > 192 {
|
|
return reason[:192]
|
|
}
|
|
return reason
|
|
}
|
|
|
|
// handleDisputeCreated records a newly opened dispute: inserts the disputes row
|
|
// and surfaces a critical_payment_log admin notification so the owner sees the
|
|
// chargeback in-app. Idempotent via ON CONFLICT (square_dispute_id) DO NOTHING
|
|
// plus the event_id dedup.
|
|
func handleDisputeCreated(data json.RawMessage) {
|
|
var env squareWebhookData
|
|
if err := json.Unmarshal(data, &env); err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] dispute.created received (payload length=%d)", len(data))
|
|
return
|
|
}
|
|
var dispute squareDisputePayload
|
|
if !parseSquareObject(env.Object, "dispute", &dispute) || dispute.ID == "" {
|
|
log.Printf("[SQUARE-WEBHOOK] dispute.created received (data.id=%s)", env.ID)
|
|
return
|
|
}
|
|
squarePaymentID := ""
|
|
if dispute.DisputedPayment != nil {
|
|
squarePaymentID = dispute.DisputedPayment.PaymentID
|
|
}
|
|
paymentID, bookingID, paymentFound := findPaymentBySquareID(squarePaymentID)
|
|
if !paymentFound {
|
|
log.Printf("[SQUARE-WEBHOOK] dispute.created: no local payment for square payment %q — dispute %s not recorded", squarePaymentID, dispute.ID)
|
|
return
|
|
}
|
|
amount := squareMoneyToAmount(dispute.AmountMoney)
|
|
tag, err := db.Conn.Exec(context.Background(), `
|
|
INSERT INTO disputes (square_dispute_id, payment_id, status, amount, reason, created_at, updated_at)
|
|
VALUES ($1, $2, 'open', $3, NULLIF($4, ''), NOW(), NOW())
|
|
ON CONFLICT (square_dispute_id) DO NOTHING
|
|
`, dispute.ID, paymentID, amount, truncateDisputeReason(dispute.Reason))
|
|
if err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] Failed to insert dispute %s: %v", dispute.ID, err)
|
|
return
|
|
}
|
|
_ = tag
|
|
insertCriticalPaymentNotification(bookingID)
|
|
log.Printf("[SQUARE-WEBHOOK] CRITICAL: dispute %s created (amount %s, reason %q) for square payment %s — admin notified", dispute.ID, amount, dispute.Reason, squarePaymentID)
|
|
}
|
|
|
|
// handleDisputeStateUpdated applies a Square dispute state change to the local
|
|
// disputes row (upsert — a state.updated may arrive before the created event),
|
|
// and on a terminal loss marks the payment failed + raises CRITICAL. Won is
|
|
// logged only. Idempotent: the upsert converges to the same row.
|
|
func handleDisputeStateUpdated(data json.RawMessage) {
|
|
var env squareWebhookData
|
|
if err := json.Unmarshal(data, &env); err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] dispute.state.updated received (payload length=%d)", len(data))
|
|
return
|
|
}
|
|
var dispute squareDisputePayload
|
|
if !parseSquareObject(env.Object, "dispute", &dispute) || dispute.ID == "" {
|
|
log.Printf("[SQUARE-WEBHOOK] dispute.state.updated received (data.id=%s)", env.ID)
|
|
return
|
|
}
|
|
localStatus := squareDisputeStateToLocal(dispute.State)
|
|
amount := squareMoneyToAmount(dispute.AmountMoney)
|
|
|
|
squarePaymentID := ""
|
|
if dispute.DisputedPayment != nil {
|
|
squarePaymentID = dispute.DisputedPayment.PaymentID
|
|
}
|
|
paymentID, bookingID, paymentFound := findPaymentBySquareID(squarePaymentID)
|
|
if !paymentFound {
|
|
// Row may already exist from dispute.created — recover its payment.
|
|
paymentID, bookingID = findPaymentByDisputeID(dispute.ID)
|
|
if paymentID == "" {
|
|
log.Printf("[SQUARE-WEBHOOK] dispute.state.updated: no local payment for dispute %s (square payment %q) — cannot record state %s", dispute.ID, squarePaymentID, dispute.State)
|
|
return
|
|
}
|
|
}
|
|
|
|
_, err := db.Conn.Exec(context.Background(), `
|
|
INSERT INTO disputes (square_dispute_id, payment_id, status, amount, reason, created_at, updated_at)
|
|
VALUES ($1, $2, $3, $4, NULLIF($5, ''), NOW(), NOW())
|
|
ON CONFLICT (square_dispute_id) DO UPDATE
|
|
SET status = EXCLUDED.status, amount = EXCLUDED.amount,
|
|
reason = EXCLUDED.reason, updated_at = NOW()
|
|
`, dispute.ID, paymentID, localStatus, amount, truncateDisputeReason(dispute.Reason))
|
|
if err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] Failed to update dispute %s to state %s: %v", dispute.ID, dispute.State, err)
|
|
return
|
|
}
|
|
|
|
switch localStatus {
|
|
case "lost":
|
|
markPaymentFailed(paymentID)
|
|
insertCriticalPaymentNotification(bookingID)
|
|
log.Printf("[SQUARE-WEBHOOK] CRITICAL: dispute %s LOST — payment %s marked failed; admin notified", dispute.ID, paymentID)
|
|
case "won":
|
|
log.Printf("[SQUARE-WEBHOOK] dispute %s WON — resolved in seller's favour; no action", dispute.ID)
|
|
default:
|
|
log.Printf("[SQUARE-WEBHOOK] dispute %s state → %s (status %s)", dispute.ID, dispute.State, localStatus)
|
|
}
|
|
}
|
|
|
|
// handleDisputeEvidence logs evidence submissions/removals. Evidence does not
|
|
// change the dispute's local status, so it is informational only.
|
|
func handleDisputeEvidence(data json.RawMessage) {
|
|
var env squareWebhookData
|
|
if err := json.Unmarshal(data, &env); err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] dispute evidence event received (payload length=%d)", len(data))
|
|
return
|
|
}
|
|
var dispute squareDisputePayload
|
|
if !parseSquareObject(env.Object, "dispute", &dispute) || dispute.ID == "" {
|
|
log.Printf("[SQUARE-WEBHOOK] dispute evidence event received (data.id=%s)", env.ID)
|
|
return
|
|
}
|
|
log.Printf("[SQUARE-WEBHOOK] dispute evidence event for dispute %s (state %s)", dispute.ID, dispute.State)
|
|
}
|
|
|
|
// handleTerminalCheckout logs terminal checkout lifecycle events. Terminal
|
|
// checkout state is owned by the poll/sweep handlers (handlers/payments/),
|
|
// which fetch the authoritative status from Square — no state mutation here.
|
|
func handleTerminalCheckout(data json.RawMessage) {
|
|
var env squareWebhookData
|
|
if err := json.Unmarshal(data, &env); err != nil {
|
|
log.Printf("[SQUARE-WEBHOOK] terminal.checkout event received (payload length=%d)", len(data))
|
|
return
|
|
}
|
|
log.Printf("[SQUARE-WEBHOOK] terminal.checkout event received (data.id=%s)", env.ID)
|
|
}
|