summaryrefslogtreecommitdiff
path: root/api/payments/order.ts
diff options
context:
space:
mode:
authorJoe Carstairs <65492573+Sycamost@users.noreply.github.com>2023-12-21 21:22:47 +0000
committerJoe Carstairs <jcarstairs@scottlogic.com>2024-01-29 10:46:46 +0000
commit2d0634cdc3d00b3e55cf773ff03c7dc841112d36 (patch)
tree424f0b9ce2907e3d58336a2b25233bf0f9bead9d /api/payments/order.ts
parentf44b2a82b74337c6424c576fdbf4c1376166e553 (diff)
33 / Users can sign up and log in with WebAuthn (#39)
* Installs @vercel/postgres * Installs @simplewebauthn/server * Installs @simplewebauthn/browser * Git-ignores all files starting with .env * Reorganises folders in API * Defines User type * Defines Subscription type * Defines Authenticator type * Sets up table definition file * Can get user from database * Can add user to database * Can get user's current challenge * Can set user's current challenge * Can get user's authenticators from database * Can get authenticator by ID from database * Can add user authenticator to database * Can update authenticator in database * Defines Relying Party information * Can generate registration options * Can verify registration response * Defines registration API endpoint * Defines user API endpoint * Reorganises API functions on frontend * Can access authentication API functions on frontend * Can generate authentication options * Can verify authentication response * Documents the registration flow * Fix dev_csso * Form styling * WIP adds sign up page
Diffstat (limited to 'api/payments/order.ts')
-rw-r--r--api/payments/order.ts86
1 files changed, 86 insertions, 0 deletions
diff --git a/api/payments/order.ts b/api/payments/order.ts
new file mode 100644
index 0000000..434abf9
--- /dev/null
+++ b/api/payments/order.ts
@@ -0,0 +1,86 @@
+import type Order from '../types/Order';
+import type { VercelRequest, VercelResponse } from '@vercel/node';
+
+import { paypalCaptureOrder, paypalCreateOrder } from './_paypal';
+
+export default async function handler(request: VercelRequest, response: VercelResponse) {
+ if (request.method === 'POST') {
+ await handlePost(request, response);
+ } else if (request.method === 'PATCH') {
+ await handlePatch(request, response);
+ } else {
+ console.warn('Method was not POST. Method was ' + request.method);
+ response.status(404);
+ return;
+ }
+}
+
+async function handlePost(request: VercelRequest, response: VercelResponse) {
+ const { productDescription, shortDescription, totalPrice }: Partial<Order> = request.body;
+
+ if (!productDescription) {
+ response.status(400).send('Expected body to contain productDescription, but none provided.');
+ } else if (!shortDescription) {
+ response.status(400).send('Expected body to contain shortDescription, but none provided.');
+ } else if (!totalPrice) {
+ response.status(400).send('Expected body to contain totalPrice, but none provided.');
+ } else {
+ try {
+ const paypalResponse = await paypalCreateOrder({ productDescription, shortDescription, totalPrice });
+
+ const { id, links } = paypalResponse;
+ const isApprovalLink = (o: object) => (
+ 'rel' in o &&
+ o.rel === 'approve' &&
+ 'href' in o &&
+ typeof(o.href) === 'string' &&
+ o.href.length > 0
+ );
+
+ if (!id || typeof(id) !== 'string' || id.length === 0) {
+ throw new Error(`
+ PayPal did not return the created order ID
+ in an expected format. PayPal returned: ${paypalResponse}
+ `);
+ }
+ if (!links || !('length' in links) || !links.some(isApprovalLink)) {
+ throw new Error(`
+ PayPal did not return the order approval link in
+ an expected format. PayPal returned: ${paypalResponse}
+ `);
+ }
+
+ response.status(201).json({
+ orderId: id,
+ approvalLink: links.find(isApprovalLink).href,
+ });
+ } catch (err) {
+ response.status(500).send(`Internal server error. ${err}`);
+ }
+ }
+}
+
+async function handlePatch(request: VercelRequest, response: VercelResponse) {
+ const { id, isApproved }: Partial<PatchRequestBody> = request.body;
+
+ if (!id) {
+ response.status(400).send('Expected body to contain id, but none provided.');
+ } else if (!isApproved) {
+ response.status(400).send('Expected body to contain isApproved, but none provided.');
+ } else {
+ try {
+ const paypalResponse = await paypalCaptureOrder(id);
+ response.status(200).json({
+ orderId: paypalResponse.id,
+ paypalStatus: paypalResponse.status,
+ });
+ } catch (err) {
+ response.status(500).send(`Internal server error. ${err}`);
+ }
+ }
+}
+
+type PatchRequestBody = {
+ id: string;
+ isApproved: boolean;
+};