Commit Graph
3383 Commits
Author SHA1 Message Date
erio f15500cd44 refactor(ui): extract btn-stripe shared class, reuse btn-primary/btn-secondary 2026-04-07 23:57:00 +08:00
erio f1cb798856 fix(ui): use themed colors for QR page buttons 2026-04-07 23:34:25 +08:00
erio ad19fb62f5 fix(payment): revert Stripe to same-window navigation, use Stripe brand color for pay button 2026-04-07 23:30:41 +08:00
erio cfdc594e4f feat(payment): dynamic limit placeholders and open Stripe in new window 2026-04-07 23:21:46 +08:00
erio 96f2fcdda3 fix(payment): upgrade stripe-go v82 to v85 for API version 2026-03-25.dahlia 2026-04-07 23:08:49 +08:00
erio 8e2977d404 fix(ui): show icon + text labels in order actions column 2026-04-07 22:48:45 +08:00
erio 10851f1c8c fix(payment): set Stripe payment method order to alipay/wechat/card/link 2026-04-07 22:39:12 +08:00
erio f92397642a feat(i18n): add error code mapping for payment API errors 2026-04-07 22:03:11 +08:00
erio f3276f1c17 fix(ui): improve cancel rate limit layout to natural language style 2026-04-07 21:55:20 +08:00
erio a0b4bd065a fix(payment): prioritize actual order status over URL params in result page 2026-04-07 21:48:07 +08:00
erio 439fbec790 chore: bump version to 0.1.108.84 2026-04-07 20:19:15 +08:00
erio 3759a5c53e fix(payment): use official SVG icon files for payment methods 2026-04-07 20:04:59 +08:00
erio 62398107ec fix(payment): set MinAmount default to 1, prevent zero-amount orders 2026-04-07 19:19:34 +08:00
erio 72022c2d63 fix(ci): fix TestParsePaymentConfig default values and renew xlsx audit exceptions 2026-04-07 18:50:44 +08:00
erio 4e68e1497a fix(ci): fix TestParsePaymentConfig default values and renew xlsx audit exceptions 2026-04-07 18:33:00 +08:00
erio 4b30186adb chore: bump version to 0.1.108.83 2026-04-07 18:30:05 +08:00
erio 43b09f4b94 docs: add coding standards for file splitting, payment safety, and TypeScript strictness 2026-04-07 18:29:52 +08:00
erio b35843ee8f chore: bump version to 0.1.108.82 2026-04-07 17:50:55 +08:00
erio 8f16b01943 feat(payment): standalone result page, method order & QR logos
- Payment result page is now a standalone page without business layout
- Support EasyPay return_url params (out_trade_no, trade_status)
- Payment methods sorted: EasyPay → Alipay → WeChat → Stripe
- Alipay/WeChat use official brand SVG icons
- QR code displays Alipay/WeChat logo in center with scan prompt
2026-04-07 17:50:19 +08:00
erio f9e581bb82 fix(payment): fully URL-decode EasyPay callback params before signature verification
Upstream proxy double-encodes GET query params. url.ParseQuery only
decodes once, leaving values like %E5%BF%AB instead of actual UTF-8.
Add fullyDecodeURL to repeatedly decode until stable before signing.
2026-04-07 16:39:34 +08:00
erio e2e5c814bc chore: bump version to 0.1.108.80 2026-04-07 16:30:58 +08:00
erio 63ead5e88a fix(ui): move reopen payment button below countdown 2026-04-07 16:30:18 +08:00
erio 8f08d8a912 fix(payment): fix EasyPay webhook double-URL-encoding signature failure
RawQuery from GET callbacks can be double-URL-encoded by upstream
proxies. Use Query().Encode() to rebuild from fully decoded params,
ensuring VerifyNotification computes the signature on correct values.
2026-04-07 16:27:53 +08:00
erio 5a2d6dd839 feat(payment): show order status page after EasyPay redirect payment
- After opening pay_url in new window, navigate to order status page
  with countdown timer and order polling (reuses QRCode view)
- QRCode view now shows "pay in new window" UI when no QR code present
- Add verbose logging for webhook signature verification failures
2026-04-07 16:03:02 +08:00
erio 18cd8bd63b fix(stripe): await nextTick before mounting Stripe payment element
Set loading=false and await nextTick() before calling mount() so the
#stripe-payment-element DOM node exists when Stripe.js tries to use it.
2026-04-07 15:43:30 +08:00
erio f7efa15ec7 fix(csp): auto-inject Stripe domains into CSP regardless of config source
enhanceCSPPolicy now adds https://*.stripe.com to script-src and
frame-src when not already present, ensuring Stripe.js loads even
when the CSP policy comes from database settings.
2026-04-07 15:29:15 +08:00
erio 4de9163e55 fix(payment): remove cid param from EasyPay redirect payments 2026-04-07 15:07:57 +08:00
erio 0a4ea55636 fix(payment): add Stripe domains to CSP and show upstream payment errors
- Add https://*.stripe.com to script-src and frame-src in default CSP
  policy so Stripe.js can load in the browser
- Show upstream payment gateway error details instead of generic
  "temporarily unavailable" message
2026-04-07 14:36:53 +08:00
erio e6042e3e8e fix(channel): add missing features column to List query
The paginated List query was selecting 9 columns but scanning 10 fields,
missing c.features. GetByID and ListAll already included it correctly.
2026-04-07 13:47:12 +08:00
erio 27887164e4 feat(payment): subscription plan cards colored by group platform
- Backend GetPlans API enriches plans with group_platform field
- SubscriptionPlanCard uses platform-based color scheme (border, badge, price, features, button)
- anthropic=amber, openai=emerald, antigravity=purple, gemini=blue
2026-04-07 13:39:36 +08:00
erio fd8d3e6de5 feat(payment): cancel rate limit, easypay multi-CID, payment UX improvements
- EasyPay redirect passes all configured CIDs (cidAlipay, cidWxpay) comma-separated
- Payment redirect opens in new window instead of current window redirect
- Order action column uses styled icon buttons with tooltip
- Pending order limit error returns i18n-friendly message with metadata
- Cancel order rate limit feature (ported from sub2apipay) with rolling/fixed window modes
- Admin settings UI for cancel rate limit configuration
- Fix provider dialog triggering unintended settings save on open
- Provider save now correctly calls saveSettings after provider update
- API client interceptor forwards reason and metadata fields for structured error handling
2026-04-07 13:29:39 +08:00
erio bc87384ea2 chore: bump version to 0.1.108.70 2026-04-07 11:45:49 +08:00
erio 1455ade5cd fix(payment): use selected instance config for CreatePayment
Root cause: invokeProvider used the registry's provider (created once
at startup from an arbitrary instance) instead of the selected
instance's config. This meant payments always used one instance's
credentials regardless of which instance was selected.

Fix: create a fresh provider from the selected instance's decrypted
config for each payment call, ensuring correct credentials (PID, PKey,
CID, Stripe keys, etc.).

Also fix SelectInstance for Stripe: when paymentType equals providerKey
(e.g. "stripe"), all instances of that provider are candidates. The
DB stores sub-types (card,alipay,wxpay,link) not "stripe" itself.
2026-04-07 11:45:49 +08:00
erio 126b86f269 chore: bump version to 0.1.108.69 2026-04-07 11:37:10 +08:00
erio 37292367c9 feat(payment): UI improvements for admin payment pages
- Plan table: group column shows GroupBadge with platform color instead
  of raw ID, column header changed to "分组"
- Plan dialog: group info preview uses GroupBadge, removes redundant
  platform/rate fields
- Action buttons: all payment admin tables (plans, orders, providers)
  now use vertically stacked icon+text buttons matching the app style
- Added i18n keys: payment.admin.group, common.view
2026-04-07 11:36:36 +08:00
erio 6c5a2452f2 refactor(payment): unify all JSON tags to snake_case
Backend request/response structs used camelCase JSON tags while the
rest of the codebase uses snake_case (from Ent ORM entities). This
caused field name mismatches — notably the admin refund deduct_balance
field was silently ignored.

Backend: changed all camelCase JSON tags in payment handler/service
structs to snake_case (CreateOrderRequest, CreateOrderResponse,
CreatePlanRequest, UpdatePlanRequest, CreateProviderInstanceRequest,
UpdateProviderInstanceRequest, AdminProcessRefundRequest, RefundResult).

Frontend: updated all API call payloads and response field accesses
to use snake_case, removed manual camelCase conversion in
buildPlanPayload, toggleForSale, provider dialog emit, etc.
2026-04-07 11:27:00 +08:00
erio 610408a4d0 chore: bump version to 0.1.108.68 2026-04-07 11:01:54 +08:00
erio 011ca6da93 fix(payment): parse money field in EasyPay webhook, cancel button text
- EasyPay VerifyNotification was not parsing the 'money' field, causing
  Amount=0 in PaymentNotification → amount mismatch error on callback
- Cancel button on QR page now shows "取消订单" instead of generic "取消"
2026-04-07 11:01:32 +08:00
erio 56dbbabf1c chore: bump version to 0.1.108.67 2026-04-07 10:57:12 +08:00
erio c48c003f3f fix(payment): plan save with camelCase keys, group badge, toggle switch
- Fix plan create/update: send camelCase keys (groupId, validityDays,
  forSale, etc.) matching backend JSON tags instead of snake_case
- Show GroupBadge with platform color instead of raw group ID in table
- Replace checkbox with toggle switch for for_sale, support quick
  toggle directly from the plan list
- Parse features string to array when loading plans (both admin and user)
- Fix price display to use ¥ (CNY) instead of $
2026-04-07 10:56:03 +08:00
erio b781129ea5 chore: bump version to 0.1.108.66 2026-04-07 10:38:42 +08:00
erio 0cca4524c9 fix(payment): webhook GET support, Stripe as single method, QR page improvements
- EasyPay webhook: add GET route + read params from URL query (fix 404)
- Stripe: expose as single "stripe" method to users, sub-types (card/link/
  alipay/wxpay) passed to PaymentIntent internally via instance config
- QR code page: use order expiresAt for countdown, add cancel button
- InstanceSelection carries SupportedTypes for provider-specific routing
2026-04-07 10:38:21 +08:00
erio d98b4ffaad fix(payment): expose Stripe publishable key in payment config API
GetPaymentConfig now loads publishable key from the first enabled Stripe
provider instance, so the frontend can initialize Stripe.js.
2026-04-07 03:35:44 +08:00
erio 432ed5e649 fix(payment): critical fixes from agent audit
- Fix CreateOrderResult field names (snake_case → camelCase to match backend)
- Fix MethodLimits JSON tags to consistent snake_case
- Fix Stripe webhook header case sensitivity (lowercase keys for map lookup)
- Fix MaxAmount=0 backend validation (0 = no limit, not reject all)
- Fix structured error for INVALID_AMOUNT per CLAUDE.md spec
2026-04-07 03:28:30 +08:00
erio 4e494e484a fix: sync CreateOrderRequest field names in payment store 2026-04-07 03:22:33 +08:00
erio 82cc410cdf fix(payment): fix order creation + show actual provider types on payment page
- Fix CreateOrderRequest field name mismatch (payment_type → paymentType)
- Payment page now discovers available types from providers (not global config)
- Backend GetLimits returns map keyed by payment type
- EasyPay shows 3 buttons (跳转/支付宝/微信), Stripe shows card/alipay/wxpay/link
- Auto-select first method after limits loaded
2026-04-07 03:20:26 +08:00
erio 11701e9b5e fix: guard against accidental payment config wipe + cleanup from review
- Skip UpdatePaymentConfig when no payment fields provided (prevents wipe)
- Remove unused defaultMinRechargeAmount/defaultMaxRechargeAmount constants
- Fix mergeConfig comment to match actual behavior
2026-04-07 03:05:26 +08:00
erio e1fe15010c fix: add payment fields to UpdateSettingsRequest, remove as any casts and dead code
- Add payment fields to UpdateSettingsRequest TypeScript interface
- Remove duplicate payment_enabled_types assignment in saveSettings
- Remove all (payload as any) casts for payment fields
- Remove unused parseTypes function from providerConfig.ts
2026-04-07 03:03:09 +08:00
erio 7eaccdf125 fix: supportedTypes emit type string -> string[] 2026-04-07 02:55:28 +08:00
erio 57cb01cd49 refactor(payment): use string[] for supported_types throughout frontend+backend API
- Backend API returns/accepts supported_types as string[] (converts to/from DB comma string)
- Frontend ProviderInstance.supported_types is string[], no more parseTypes
- Remove all split/join conversions for supported_types
- payment_enabled_types also uses string[] consistently
2026-04-07 02:54:03 +08:00