Commit Graph
581 Commits
Author SHA1 Message Date
erio 6a3fa290af chore: bump version to 0.1.108.103 2026-04-09 00:00:44 +08:00
erio 7324f458de chore: bump version to 0.1.108.102 2026-04-08 22:16:30 +08:00
erio 2cc97a0bda chore: bump version to 0.1.108.101 2026-04-08 22:08:13 +08:00
erio 17c1f88894 chore: bump version to 0.1.108.100 2026-04-08 21:41:24 +08:00
erio bb2ee91ce5 chore: bump version to 0.1.108.99 2026-04-08 21:30:37 +08:00
erio fff0caedaa chore: bump version to 0.1.108.98 2026-04-08 21:26:17 +08:00
erio ff89772c28 chore: bump version to 0.1.108.97 2026-04-08 21:13:13 +08:00
erio fcf41f901c chore: bump version to 0.1.108.96 2026-04-08 18:21:13 +08:00
erio 3ba213b27f chore: bump version to 0.1.108.95 2026-04-08 18:05:24 +08:00
erio a3e3e3cd08 chore: bump version to 0.1.108.94 2026-04-08 17:33:19 +08:00
erio 067f8f3e77 style: fix gofmt formatting in payment_handler, wire, stubs 2026-04-08 17:20:49 +08:00
erio a47f0f5ca7 chore: bump version to 0.1.108.93 2026-04-08 17:11:49 +08:00
erio be82609939 fix(payment): audit fixes for alipay/wxpay/stripe payment providers
Backend:
- Extract YuanToFen/FenToYuan to payment/amount.go using shopspring/decimal
- Require alipay publicKey in config validation
- Fix wxpay webhook response to return JSON per V3 spec
- Remove wxpay certSerial fallback to publicKeyId
- Define magic strings as named constants in wxpay/alipay providers
- Add slog warning for wxpay H5→Native payment downgrade
- Make EncryptionKey validation return error on invalid (non-empty) key
- Make decryptConfig propagate errors instead of returning nil
- Add idempotency check in doBalance to prevent stuck FAILED retries

Frontend:
- Fix dashboard currency symbol from $ to ¥
- Fix AdminPaymentPlansView any type to proper SubscriptionPlan type
- Make quick amount buttons follow selected payment method limits
- Center help image with larger height and text below
2026-04-08 17:11:32 +08:00
erio 93a43950fe feat(payment): open Stripe and redirect payments in popup window
Instead of navigating the main page away during payment, open Stripe
and EasyPay redirect payments in a popup window while showing a
waiting dialog on the purchase page. Extract POPUP_WINDOW_FEATURES
constant to providerConfig.ts.
2026-04-08 16:33:01 +08:00
erio 0ed9816487 feat(payment): click-to-preview help image with fullscreen overlay 2026-04-08 14:06:19 +08:00
erio bb243d1f93 chore: bump version to 0.1.108.90 2026-04-08 13:51:08 +08:00
erio 4049b2f695 feat(payment): inline QR code dialog for scan-to-pay mode
QR code payments now display in an inline dialog on the payment page
with countdown and status polling. Success is shown directly without
page navigation. Redirect mode (pay_url only) still navigates to the
polling page as before.
2026-04-08 13:29:02 +08:00
erio 7295fce5fd fix(payment): add help_image_url to checkout-info API response
The help image configured in admin was missing from the checkout page
because it was not included in the checkoutInfoResponse struct.
2026-04-08 13:16:09 +08:00
erio 42a0b523fa chore: bump version to 0.1.108.87 2026-04-08 13:07:24 +08:00
erio ffe3b07d0d chore: bump version to 0.1.108.86 2026-04-08 12:36:33 +08:00
erio 0bb1bfea3e chore: bump version to 0.1.108.85 2026-04-08 02:20:12 +08:00
erio 439fbec790 chore: bump version to 0.1.108.84 2026-04-07 20:19:15 +08:00
erio 4b30186adb chore: bump version to 0.1.108.83 2026-04-07 18:30:05 +08:00
erio b35843ee8f chore: bump version to 0.1.108.82 2026-04-07 17:50:55 +08:00
erio f9e581bb82 fix(payment): fully URL-decode EasyPay callback params before signature verification
Upstream proxy double-encodes GET query params. url.ParseQuery only
decodes once, leaving values like %E5%BF%AB instead of actual UTF-8.
Add fullyDecodeURL to repeatedly decode until stable before signing.
2026-04-07 16:39:34 +08:00
erio e2e5c814bc chore: bump version to 0.1.108.80 2026-04-07 16:30:58 +08:00
erio 8f08d8a912 fix(payment): fix EasyPay webhook double-URL-encoding signature failure
RawQuery from GET callbacks can be double-URL-encoded by upstream
proxies. Use Query().Encode() to rebuild from fully decoded params,
ensuring VerifyNotification computes the signature on correct values.
2026-04-07 16:27:53 +08:00
erio 5a2d6dd839 feat(payment): show order status page after EasyPay redirect payment
- After opening pay_url in new window, navigate to order status page
  with countdown timer and order polling (reuses QRCode view)
- QRCode view now shows "pay in new window" UI when no QR code present
- Add verbose logging for webhook signature verification failures
2026-04-07 16:03:02 +08:00
erio 18cd8bd63b fix(stripe): await nextTick before mounting Stripe payment element
Set loading=false and await nextTick() before calling mount() so the
#stripe-payment-element DOM node exists when Stripe.js tries to use it.
2026-04-07 15:43:30 +08:00
erio f7efa15ec7 fix(csp): auto-inject Stripe domains into CSP regardless of config source
enhanceCSPPolicy now adds https://*.stripe.com to script-src and
frame-src when not already present, ensuring Stripe.js loads even
when the CSP policy comes from database settings.
2026-04-07 15:29:15 +08:00
erio 4de9163e55 fix(payment): remove cid param from EasyPay redirect payments 2026-04-07 15:07:57 +08:00
erio 0a4ea55636 fix(payment): add Stripe domains to CSP and show upstream payment errors
- Add https://*.stripe.com to script-src and frame-src in default CSP
  policy so Stripe.js can load in the browser
- Show upstream payment gateway error details instead of generic
  "temporarily unavailable" message
2026-04-07 14:36:53 +08:00
erio e6042e3e8e fix(channel): add missing features column to List query
The paginated List query was selecting 9 columns but scanning 10 fields,
missing c.features. GetByID and ListAll already included it correctly.
2026-04-07 13:47:12 +08:00
erio 27887164e4 feat(payment): subscription plan cards colored by group platform
- Backend GetPlans API enriches plans with group_platform field
- SubscriptionPlanCard uses platform-based color scheme (border, badge, price, features, button)
- anthropic=amber, openai=emerald, antigravity=purple, gemini=blue
2026-04-07 13:39:36 +08:00
erio fd8d3e6de5 feat(payment): cancel rate limit, easypay multi-CID, payment UX improvements
- EasyPay redirect passes all configured CIDs (cidAlipay, cidWxpay) comma-separated
- Payment redirect opens in new window instead of current window redirect
- Order action column uses styled icon buttons with tooltip
- Pending order limit error returns i18n-friendly message with metadata
- Cancel order rate limit feature (ported from sub2apipay) with rolling/fixed window modes
- Admin settings UI for cancel rate limit configuration
- Fix provider dialog triggering unintended settings save on open
- Provider save now correctly calls saveSettings after provider update
- API client interceptor forwards reason and metadata fields for structured error handling
2026-04-07 13:29:39 +08:00
erio bc87384ea2 chore: bump version to 0.1.108.70 2026-04-07 11:45:49 +08:00
erio 126b86f269 chore: bump version to 0.1.108.69 2026-04-07 11:37:10 +08:00
erio 610408a4d0 chore: bump version to 0.1.108.68 2026-04-07 11:01:54 +08:00
erio 56dbbabf1c chore: bump version to 0.1.108.67 2026-04-07 10:57:12 +08:00
erio b781129ea5 chore: bump version to 0.1.108.66 2026-04-07 10:38:42 +08:00
erio d98b4ffaad fix(payment): expose Stripe publishable key in payment config API
GetPaymentConfig now loads publishable key from the first enabled Stripe
provider instance, so the frontend can initialize Stripe.js.
2026-04-07 03:35:44 +08:00
erio 432ed5e649 fix(payment): critical fixes from agent audit
- Fix CreateOrderResult field names (snake_case → camelCase to match backend)
- Fix MethodLimits JSON tags to consistent snake_case
- Fix Stripe webhook header case sensitivity (lowercase keys for map lookup)
- Fix MaxAmount=0 backend validation (0 = no limit, not reject all)
- Fix structured error for INVALID_AMOUNT per CLAUDE.md spec
2026-04-07 03:28:30 +08:00
erio 4e494e484a fix: sync CreateOrderRequest field names in payment store 2026-04-07 03:22:33 +08:00
erio 82cc410cdf fix(payment): fix order creation + show actual provider types on payment page
- Fix CreateOrderRequest field name mismatch (payment_type → paymentType)
- Payment page now discovers available types from providers (not global config)
- Backend GetLimits returns map keyed by payment type
- EasyPay shows 3 buttons (跳转/支付宝/微信), Stripe shows card/alipay/wxpay/link
- Auto-select first method after limits loaded
2026-04-07 03:20:26 +08:00
erio 11701e9b5e fix: guard against accidental payment config wipe + cleanup from review
- Skip UpdatePaymentConfig when no payment fields provided (prevents wipe)
- Remove unused defaultMinRechargeAmount/defaultMaxRechargeAmount constants
- Fix mergeConfig comment to match actual behavior
2026-04-07 03:05:26 +08:00
erio e1fe15010c fix: add payment fields to UpdateSettingsRequest, remove as any casts and dead code
- Add payment fields to UpdateSettingsRequest TypeScript interface
- Remove duplicate payment_enabled_types assignment in saveSettings
- Remove all (payload as any) casts for payment fields
- Remove unused parseTypes function from providerConfig.ts
2026-04-07 03:03:09 +08:00
erio 7eaccdf125 fix: supportedTypes emit type string -> string[] 2026-04-07 02:55:28 +08:00
erio 57cb01cd49 refactor(payment): use string[] for supported_types throughout frontend+backend API
- Backend API returns/accepts supported_types as string[] (converts to/from DB comma string)
- Frontend ProviderInstance.supported_types is string[], no more parseTypes
- Remove all split/join conversions for supported_types
- payment_enabled_types also uses string[] consistently
2026-04-07 02:54:03 +08:00
erio 18107819da fix: remove unused parseTypes import, fix string[] type mismatch 2026-04-07 02:45:16 +08:00
erio 957afed0f0 fix(payment): use string[] directly for payment_enabled_types, remove all split/join conversions 2026-04-07 02:43:00 +08:00