diff options
| author | Joe Carstairs <65492573+Sycamost@users.noreply.github.com> | 2023-12-21 21:22:47 +0000 |
|---|---|---|
| committer | Joe Carstairs <jcarstairs@scottlogic.com> | 2024-01-29 10:46:46 +0000 |
| commit | 2d0634cdc3d00b3e55cf773ff03c7dc841112d36 (patch) | |
| tree | 424f0b9ce2907e3d58336a2b25233bf0f9bead9d /api/payments/order.ts | |
| parent | f44b2a82b74337c6424c576fdbf4c1376166e553 (diff) | |
33 / Users can sign up and log in with WebAuthn (#39)
* Installs @vercel/postgres
* Installs @simplewebauthn/server
* Installs @simplewebauthn/browser
* Git-ignores all files starting with .env
* Reorganises folders in API
* Defines User type
* Defines Subscription type
* Defines Authenticator type
* Sets up table definition file
* Can get user from database
* Can add user to database
* Can get user's current challenge
* Can set user's current challenge
* Can get user's authenticators from database
* Can get authenticator by ID from database
* Can add user authenticator to database
* Can update authenticator in database
* Defines Relying Party information
* Can generate registration options
* Can verify registration response
* Defines registration API endpoint
* Defines user API endpoint
* Reorganises API functions on frontend
* Can access authentication API functions on frontend
* Can generate authentication options
* Can verify authentication response
* Documents the registration flow
* Fix dev_csso
* Form styling
* WIP adds sign up page
Diffstat (limited to 'api/payments/order.ts')
| -rw-r--r-- | api/payments/order.ts | 86 |
1 files changed, 86 insertions, 0 deletions
diff --git a/api/payments/order.ts b/api/payments/order.ts new file mode 100644 index 0000000..434abf9 --- /dev/null +++ b/api/payments/order.ts @@ -0,0 +1,86 @@ +import type Order from '../types/Order'; +import type { VercelRequest, VercelResponse } from '@vercel/node'; + +import { paypalCaptureOrder, paypalCreateOrder } from './_paypal'; + +export default async function handler(request: VercelRequest, response: VercelResponse) { + if (request.method === 'POST') { + await handlePost(request, response); + } else if (request.method === 'PATCH') { + await handlePatch(request, response); + } else { + console.warn('Method was not POST. Method was ' + request.method); + response.status(404); + return; + } +} + +async function handlePost(request: VercelRequest, response: VercelResponse) { + const { productDescription, shortDescription, totalPrice }: Partial<Order> = request.body; + + if (!productDescription) { + response.status(400).send('Expected body to contain productDescription, but none provided.'); + } else if (!shortDescription) { + response.status(400).send('Expected body to contain shortDescription, but none provided.'); + } else if (!totalPrice) { + response.status(400).send('Expected body to contain totalPrice, but none provided.'); + } else { + try { + const paypalResponse = await paypalCreateOrder({ productDescription, shortDescription, totalPrice }); + + const { id, links } = paypalResponse; + const isApprovalLink = (o: object) => ( + 'rel' in o && + o.rel === 'approve' && + 'href' in o && + typeof(o.href) === 'string' && + o.href.length > 0 + ); + + if (!id || typeof(id) !== 'string' || id.length === 0) { + throw new Error(` + PayPal did not return the created order ID + in an expected format. PayPal returned: ${paypalResponse} + `); + } + if (!links || !('length' in links) || !links.some(isApprovalLink)) { + throw new Error(` + PayPal did not return the order approval link in + an expected format. PayPal returned: ${paypalResponse} + `); + } + + response.status(201).json({ + orderId: id, + approvalLink: links.find(isApprovalLink).href, + }); + } catch (err) { + response.status(500).send(`Internal server error. ${err}`); + } + } +} + +async function handlePatch(request: VercelRequest, response: VercelResponse) { + const { id, isApproved }: Partial<PatchRequestBody> = request.body; + + if (!id) { + response.status(400).send('Expected body to contain id, but none provided.'); + } else if (!isApproved) { + response.status(400).send('Expected body to contain isApproved, but none provided.'); + } else { + try { + const paypalResponse = await paypalCaptureOrder(id); + response.status(200).json({ + orderId: paypalResponse.id, + paypalStatus: paypalResponse.status, + }); + } catch (err) { + response.status(500).send(`Internal server error. ${err}`); + } + } +} + +type PatchRequestBody = { + id: string; + isApproved: boolean; +}; |
