Commit Graph
2511 Commits
Author SHA1 Message Date
erio 6a3fa290af chore: bump version to 0.1.108.103 2026-04-09 00:00:44 +08:00
erio 5f4378b4ae feat(payment): show group details and quota info on subscription plan cards
Extend checkout API to return group name, rate multiplier, daily/weekly/monthly
limits and supported model scopes. Redesign SubscriptionPlanCard to display
platform badge, group quota info, and model scope tags.
2026-04-09 00:00:25 +08:00
erio 7324f458de chore: bump version to 0.1.108.102 2026-04-08 22:16:30 +08:00
erio 2cc97a0bda chore: bump version to 0.1.108.101 2026-04-08 22:08:13 +08:00
erio 3f5e277855 refactor(payment): inline subscription flow and simplify payment modes
- EasyPay: remove redirect mode, keep only qrcode and popup
- Stripe: remove mode config entirely, always use inline Payment Element
- Subscription: replace dialog with inline confirm UI (plan summary +
  method selector + fee breakdown), same flow as top-up
- Move PaymentStatusPanel/StripePaymentInline to shared section for
  both recharge and subscription payments
- Hide tabs and help card during payment/subscription confirm phases
2026-04-08 22:07:42 +08:00
erio 17c1f88894 chore: bump version to 0.1.108.100 2026-04-08 21:41:24 +08:00
erio bb2ee91ce5 chore: bump version to 0.1.108.99 2026-04-08 21:30:37 +08:00
erio fff0caedaa chore: bump version to 0.1.108.98 2026-04-08 21:26:17 +08:00
erio ff89772c28 chore: bump version to 0.1.108.97 2026-04-08 21:13:13 +08:00
erio fcf41f901c chore: bump version to 0.1.108.96 2026-04-08 18:21:13 +08:00
erio a56a2f138a test(payment): add unit tests for payment audit fixes + allow empty supported_types
Tests (1033 new lines, 100% coverage on modified functions):
- amount.go: YuanToFen/FenToYuan with precision edge cases
- wxpay: mapWxState, wxSV, formatPEM, NewWxpay validation
- alipay: isTradeNotExist, NewAlipay validation
- webhook: writeSuccessResponse (wxpay JSON, stripe empty, others text)
- config: validateProviderRequest, isSensitiveConfigField, joinTypes
- fulfillment: resolveRedeemAction idempotency logic

Business logic changes:
- Allow empty supported_types on provider instances
- Block removing payment types when instance has pending orders
- Extract resolveRedeemAction as testable pure function
2026-04-08 18:21:12 +08:00
erio 3ba213b27f chore: bump version to 0.1.108.95 2026-04-08 18:05:24 +08:00
erio fafde2a493 feat(payment): configurable payment mode (qrcode/redirect/popup)
- EasyPay supports 3 modes: qrcode (API/QR), redirect (new tab), popup (small window)
- Stripe supports 2 modes: popup (small window, default), redirect (new tab)
- Backend passes payment_mode through to create-order response
- Frontend opens pay URL based on configured mode
2026-04-08 18:05:24 +08:00
erio a3e3e3cd08 chore: bump version to 0.1.108.94 2026-04-08 17:33:19 +08:00
erio 067f8f3e77 style: fix gofmt formatting in payment_handler, wire, stubs 2026-04-08 17:20:49 +08:00
erio a47f0f5ca7 chore: bump version to 0.1.108.93 2026-04-08 17:11:49 +08:00
erio be82609939 fix(payment): audit fixes for alipay/wxpay/stripe payment providers
Backend:
- Extract YuanToFen/FenToYuan to payment/amount.go using shopspring/decimal
- Require alipay publicKey in config validation
- Fix wxpay webhook response to return JSON per V3 spec
- Remove wxpay certSerial fallback to publicKeyId
- Define magic strings as named constants in wxpay/alipay providers
- Add slog warning for wxpay H5→Native payment downgrade
- Make EncryptionKey validation return error on invalid (non-empty) key
- Make decryptConfig propagate errors instead of returning nil
- Add idempotency check in doBalance to prevent stuck FAILED retries

Frontend:
- Fix dashboard currency symbol from $ to ¥
- Fix AdminPaymentPlansView any type to proper SubscriptionPlan type
- Make quick amount buttons follow selected payment method limits
- Center help image with larger height and text below
2026-04-08 17:11:32 +08:00
erio 93a43950fe feat(payment): open Stripe and redirect payments in popup window
Instead of navigating the main page away during payment, open Stripe
and EasyPay redirect payments in a popup window while showing a
waiting dialog on the purchase page. Extract POPUP_WINDOW_FEATURES
constant to providerConfig.ts.
2026-04-08 16:33:01 +08:00
erio 0ed9816487 feat(payment): click-to-preview help image with fullscreen overlay 2026-04-08 14:06:19 +08:00
erio bb243d1f93 chore: bump version to 0.1.108.90 2026-04-08 13:51:08 +08:00
erio 09d10e62b9 refactor(payment): split large service files by domain
Split payment_service.go (1261→277 lines):
- payment_order.go — order creation, validation, queries, cancel (450 lines)
- payment_fulfillment.go — notification handling, fulfillment (253 lines)
- payment_refund.go — refund flow (192 lines)
- payment_stats.go — dashboard stats, audit logs (163 lines)

Split payment_config_service.go (717→351 lines):
- payment_config_providers.go — provider instance CRUD (251 lines)
- payment_config_plans.go — subscription plan CRUD (118 lines)

All files now under the 500-line Go file limit.
2026-04-08 13:49:12 +08:00
erio 4049b2f695 feat(payment): inline QR code dialog for scan-to-pay mode
QR code payments now display in an inline dialog on the payment page
with countdown and status polling. Success is shown directly without
page navigation. Redirect mode (pay_url only) still navigates to the
polling page as before.
2026-04-08 13:29:02 +08:00
erio 7295fce5fd fix(payment): add help_image_url to checkout-info API response
The help image configured in admin was missing from the checkout page
because it was not included in the checkoutInfoResponse struct.
2026-04-08 13:16:09 +08:00
erio 42a0b523fa chore: bump version to 0.1.108.87 2026-04-08 13:07:24 +08:00
erio f0aea13ded feat(payment): redesign subscription plan cards and fix features parsing
- Fix features field sent as raw string causing character-by-character iteration
- Redesign SubscriptionPlanCard with gradient accent bar, checkmark feature list,
  discount badge, and polished hover/button effects
- Adaptive plan grid layout (1/2/3 columns based on plan count)
- Improve subscription confirm dialog with better price display
2026-04-08 13:07:06 +08:00
erio ffe3b07d0d chore: bump version to 0.1.108.86 2026-04-08 12:36:33 +08:00
erio 27d3232333 test(payment): add unit tests for limits aggregation and type grouping
30 test cases covering:
- unionFloat: min/max merge semantics, unlimited propagation
- pcAggregateMethodLimits: single/multi instance, unlimited, invalid JSON
- pcGroupByPaymentType: Stripe isolation from alipay/wxpay groups
- pcComputeGlobalRange: widest range, partial unlimited
- pcInstanceTypeLimits: parsing, missing type, invalid JSON
- GetBasePaymentType: all type constants including composites
2026-04-08 02:58:34 +08:00
erio 3acb3b056e feat(payment): add /checkout-info API, simplify PaymentView to single call
Backend: new GET /payment/checkout-info returns methods (with limits),
global_min/max, plans (with platform), balance_disabled, help_text,
and stripe_publishable_key in one response.

Frontend: PaymentView now calls getCheckoutInfo() once instead of
fetchConfig + getLimits + fetchPlans separately. Removed plansLoading
state and loadPlans watcher. Reduced from 317 to 301 lines.
2026-04-08 02:49:26 +08:00
erio c016bdba13 refactor(payment): replace magic strings with constants, fix catch types
Backend:
- Add ProviderStatus* constants (pending/paid/success/failed/refunded)
- Add DefaultLoadBalanceStrategy, ConfigKeyPublishableKey constants
- GetBasePaymentType: use Type* constants instead of raw strings
- Webhook handler: use payment.Type* for provider keys, extract
  webhookLogTruncateLen constant
- All 4 providers: replace status string literals with ProviderStatus*

Frontend:
- All catch blocks: add `: unknown` type annotation
- stores/payment.ts: replace `any` with proper type for plan parsing
- PaymentProviderDialog: replace `as any` with `as SelectOption[]`
2026-04-08 02:39:47 +08:00
erio 36b14b0584 fix(payment): Stripe instance polluting alipay/wxpay limits groups
Root cause: Stripe instance had supported_types="card,alipay,link,wxpay"
but only card/link were mapped to "stripe" group. Stripe's alipay/wxpay
leaked into independent groups, and since Stripe had no limits configured,
it triggered the "any unlimited → all zeros" early return, making ALL
method limits show as zero.

Fix: pcGroupByPaymentType now routes ALL types from Stripe provider
instances to the "stripe" group (by checking ProviderKey, not sub-type).
Frontend: Stripe provider dialog shows single "Stripe" limits entry
instead of per-sub-type entries.
2026-04-08 02:35:22 +08:00
erio 0bb1bfea3e chore: bump version to 0.1.108.85 2026-04-08 02:20:12 +08:00
erio bd43ed23fd feat(payment): union-based limits aggregation and amount-method filtering
Backend: change limits aggregation from intersection (most restrictive) to
union (least restrictive) across provider instances. Since the load balancer
can route to any instance, users should see the widest possible range.
Add global_min/global_max precomputed by backend for quick amount buttons.

Frontend: auto-disable payment methods that can't handle the entered amount,
auto-switch to first available method, show warning when no method fits.

Refactor: extract ChannelLimits named type, unionFloat helper to eliminate
repeated min/max/daily logic, split limits code to payment_config_limits.go,
replace magic strings with payment.Type* constants.
2026-04-08 02:18:02 +08:00
erio 1ab77a86a5 fix(payment): critical fixes, constants, type safety, and order recovery
Backend:
- Fix order physical deletion → status update to FAILED
- Fix sync.Once race condition → mutex + bool pattern
- Fix encryption key error silently ignored in wire.go
- Fix ProviderInstanceResponse missing payment_mode field
- Fix fullyDecodeURL infinite loop → single decode
- Fix io.ReadAll without size limit → LimitReader
- Fix webhook log exposing full rawBody → truncate + debug level
- Recover cancelled/expired orders on webhook payment success

Frontend:
- Extract METHOD_ORDER to providerConfig.ts, remove duplicates
- Add PAYMENT_MODE_REDIRECT/API constants, use in all components
- Fix any types → unknown in StripePaymentView, PaymentView
- Fix hardcoded English text → i18n keys
- Fix Vue Router query as string → String()
- Fix METHOD_ICONS.easypay reference to non-existent key
2026-04-08 01:24:41 +08:00
erio 47cb495ede feat(payment): separate payment mode (redirect/api) from payment methods
- Add payment_mode field to payment_provider_instances table
- EasyPay provider uses config paymentMode instead of TypeEasyPay
- Remove 'easypay' from supported_types, user-facing payment methods
- Admin dialog: add payment mode selector (redirect/QR) for EasyPay
- ProviderCard: display mode label alongside provider type
- User payment page: only shows alipay/wxpay/stripe (no more 'easypay')
- Migration: auto-convert existing easypay instances to redirect mode
2026-04-08 00:37:14 +08:00
erio 96f2fcdda3 fix(payment): upgrade stripe-go v82 to v85 for API version 2026-03-25.dahlia 2026-04-07 23:08:49 +08:00
erio 439fbec790 chore: bump version to 0.1.108.84 2026-04-07 20:19:15 +08:00
erio 62398107ec fix(payment): set MinAmount default to 1, prevent zero-amount orders 2026-04-07 19:19:34 +08:00
erio 72022c2d63 fix(ci): fix TestParsePaymentConfig default values and renew xlsx audit exceptions 2026-04-07 18:50:44 +08:00
erio 4e68e1497a fix(ci): fix TestParsePaymentConfig default values and renew xlsx audit exceptions 2026-04-07 18:33:00 +08:00
erio 4b30186adb chore: bump version to 0.1.108.83 2026-04-07 18:30:05 +08:00
erio b35843ee8f chore: bump version to 0.1.108.82 2026-04-07 17:50:55 +08:00
erio f9e581bb82 fix(payment): fully URL-decode EasyPay callback params before signature verification
Upstream proxy double-encodes GET query params. url.ParseQuery only
decodes once, leaving values like %E5%BF%AB instead of actual UTF-8.
Add fullyDecodeURL to repeatedly decode until stable before signing.
2026-04-07 16:39:34 +08:00
erio e2e5c814bc chore: bump version to 0.1.108.80 2026-04-07 16:30:58 +08:00
erio 8f08d8a912 fix(payment): fix EasyPay webhook double-URL-encoding signature failure
RawQuery from GET callbacks can be double-URL-encoded by upstream
proxies. Use Query().Encode() to rebuild from fully decoded params,
ensuring VerifyNotification computes the signature on correct values.
2026-04-07 16:27:53 +08:00
erio 5a2d6dd839 feat(payment): show order status page after EasyPay redirect payment
- After opening pay_url in new window, navigate to order status page
  with countdown timer and order polling (reuses QRCode view)
- QRCode view now shows "pay in new window" UI when no QR code present
- Add verbose logging for webhook signature verification failures
2026-04-07 16:03:02 +08:00
erio 18cd8bd63b fix(stripe): await nextTick before mounting Stripe payment element
Set loading=false and await nextTick() before calling mount() so the
#stripe-payment-element DOM node exists when Stripe.js tries to use it.
2026-04-07 15:43:30 +08:00
erio f7efa15ec7 fix(csp): auto-inject Stripe domains into CSP regardless of config source
enhanceCSPPolicy now adds https://*.stripe.com to script-src and
frame-src when not already present, ensuring Stripe.js loads even
when the CSP policy comes from database settings.
2026-04-07 15:29:15 +08:00
erio 4de9163e55 fix(payment): remove cid param from EasyPay redirect payments 2026-04-07 15:07:57 +08:00
erio 0a4ea55636 fix(payment): add Stripe domains to CSP and show upstream payment errors
- Add https://*.stripe.com to script-src and frame-src in default CSP
  policy so Stripe.js can load in the browser
- Show upstream payment gateway error details instead of generic
  "temporarily unavailable" message
2026-04-07 14:36:53 +08:00
erio e6042e3e8e fix(channel): add missing features column to List query
The paginated List query was selecting 9 columns but scanning 10 fields,
missing c.features. GetByID and ListAll already included it correctly.
2026-04-07 13:47:12 +08:00