fix: 5 critical payment issues from code review
1. Move notify route before authMiddleware (WeChat callback has no JWT) 2. Add await to verifyNotifySignature call (was fire-and-forget) 3. Remove dangerous verify fallback — all signature failures now throw 4. Payment sync polls 3x before giving up, never redirects to success page unless confirmed paid 5. Production guard enforces all WX_MCH_* env vars on startup
这个提交包含在:
@@ -200,27 +200,34 @@ Page({
|
|||||||
|
|
||||||
syncAndRedirect: function (orderId, planKey) {
|
syncAndRedirect: function (orderId, planKey) {
|
||||||
var self = this
|
var self = this
|
||||||
|
var retryCount = 0
|
||||||
|
var maxRetries = 3
|
||||||
|
|
||||||
|
function pollSync() {
|
||||||
api.syncPaymentOrder(orderId).then(function (result) {
|
api.syncPaymentOrder(orderId).then(function (result) {
|
||||||
self.setData({ purchasing: false })
|
|
||||||
if (result.status === 'paid') {
|
if (result.status === 'paid') {
|
||||||
|
self.setData({ purchasing: false })
|
||||||
wx.showToast({ title: '支付成功', icon: 'success' })
|
wx.showToast({ title: '支付成功', icon: 'success' })
|
||||||
setTimeout(function () {
|
setTimeout(function () {
|
||||||
wx.redirectTo({ url: '/pages/subscribe-success/subscribe-success?plan=' + planKey })
|
wx.redirectTo({ url: '/pages/subscribe-success/subscribe-success?plan=' + planKey })
|
||||||
}, 1000)
|
}, 1000)
|
||||||
|
} else if (retryCount < maxRetries) {
|
||||||
|
retryCount++
|
||||||
|
setTimeout(pollSync, 2000)
|
||||||
} else {
|
} else {
|
||||||
// Callback may not have arrived yet, still redirect optimistically
|
self.setData({ purchasing: false })
|
||||||
wx.showToast({ title: '支付处理中', icon: 'none' })
|
wx.showToast({ title: '支付处理中,请稍后在订阅页查看', icon: 'none' })
|
||||||
setTimeout(function () {
|
|
||||||
wx.redirectTo({ url: '/pages/subscribe-success/subscribe-success?plan=' + planKey })
|
|
||||||
}, 2000)
|
|
||||||
}
|
}
|
||||||
}).catch(function () {
|
}).catch(function () {
|
||||||
|
if (retryCount < maxRetries) {
|
||||||
|
retryCount++
|
||||||
|
setTimeout(pollSync, 2000)
|
||||||
|
} else {
|
||||||
self.setData({ purchasing: false })
|
self.setData({ purchasing: false })
|
||||||
// Even if sync fails, payment may still succeed via callback
|
wx.showToast({ title: '支付处理中,请稍后在订阅页查看', icon: 'none' })
|
||||||
wx.showToast({ title: '支付处理中,请稍后查看', icon: 'none' })
|
}
|
||||||
setTimeout(function () {
|
|
||||||
wx.redirectTo({ url: '/pages/subscribe-success/subscribe-success?plan=' + planKey })
|
|
||||||
}, 2000)
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
pollSync()
|
||||||
|
}
|
||||||
})
|
})
|
||||||
|
|||||||
+3
-1
@@ -47,6 +47,9 @@ app.use('/api/v1/admin/login', adminLoginLimiter)
|
|||||||
app.use('/api/v1/user/avatar', uploadLimiter)
|
app.use('/api/v1/user/avatar', uploadLimiter)
|
||||||
app.use('/api/v1/user/phone', uploadLimiter)
|
app.use('/api/v1/user/phone', uploadLimiter)
|
||||||
|
|
||||||
|
// WeChat Pay callback — must be before authMiddleware (no JWT)
|
||||||
|
app.post('/api/v1/payment/wechat/notify', require('./routes/payment-notify'))
|
||||||
|
|
||||||
app.use(authMiddleware)
|
app.use(authMiddleware)
|
||||||
|
|
||||||
app.get('/health', (req, res) => res.json(ok({ status: 'ok' })))
|
app.get('/health', (req, res) => res.json(ok({ status: 'ok' })))
|
||||||
@@ -59,7 +62,6 @@ app.use('/api/v1', require('./routes/treatment'))
|
|||||||
app.use('/api/v1/admin', require('./routes/admin'))
|
app.use('/api/v1/admin', require('./routes/admin'))
|
||||||
app.use('/api/v1', require('./routes/firmware'))
|
app.use('/api/v1', require('./routes/firmware'))
|
||||||
app.use('/api/v1', require('./routes/payment'))
|
app.use('/api/v1', require('./routes/payment'))
|
||||||
app.post('/api/v1/payment/wechat/notify', require('./routes/payment-notify'))
|
|
||||||
|
|
||||||
app.use((req, res) => res.status(404).json(fail(404, 'not_found')))
|
app.use((req, res) => res.status(404).json(fail(404, 'not_found')))
|
||||||
|
|
||||||
|
|||||||
@@ -46,6 +46,9 @@ if (config.nodeEnv === 'production') {
|
|||||||
if (config.jwt.secret === 'dev-user-secret') throw new Error('JWT_SECRET must be set in production')
|
if (config.jwt.secret === 'dev-user-secret') throw new Error('JWT_SECRET must be set in production')
|
||||||
if (config.jwt.adminSecret === 'dev-admin-secret') throw new Error('ADMIN_JWT_SECRET must be set in production')
|
if (config.jwt.adminSecret === 'dev-admin-secret') throw new Error('ADMIN_JWT_SECRET must be set in production')
|
||||||
if (config.admin.username === 'admin' || config.admin.password === 'admin') throw new Error('ADMIN_USERNAME and ADMIN_PASSWORD must be changed from defaults in production')
|
if (config.admin.username === 'admin' || config.admin.password === 'admin') throw new Error('ADMIN_USERNAME and ADMIN_PASSWORD must be changed from defaults in production')
|
||||||
|
const wp = config.wxpay
|
||||||
|
if (!wp.mchId || !wp.apiV3Key || !wp.mchSerialNo || !wp.notifyUrl) throw new Error('WeChat Pay credentials (WX_MCH_ID, WX_MCH_API_V3_KEY, WX_MCH_SERIAL_NO, WX_PAY_NOTIFY_URL) must be set in production')
|
||||||
|
if (!wp.privateKey && !wp.privateKeyPath) throw new Error('WX_MCH_PRIVATE_KEY or WX_MCH_PRIVATE_KEY_PATH must be set in production')
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = config
|
module.exports = config
|
||||||
|
|||||||
+1
-3
@@ -142,11 +142,9 @@ async function verifyNotifySignature(headers, rawBody) {
|
|||||||
throw new Error('notify signature verification failed')
|
throw new Error('notify signature verification failed')
|
||||||
}
|
}
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
if (err.message.indexOf('unknown platform certificate') !== -1 || err.message.indexOf('signature verification') !== -1) {
|
console.error('[WXPAY] signature verification failed:', err.message)
|
||||||
throw err
|
throw err
|
||||||
}
|
}
|
||||||
console.error('[WXPAY] platform cert verification fallback:', err.message)
|
|
||||||
}
|
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ async function handleNotify(req, res) {
|
|||||||
const rawBody = typeof req.body === 'string' ? req.body : (Buffer.isBuffer(req.body) ? req.body.toString('utf8') : JSON.stringify(req.body))
|
const rawBody = typeof req.body === 'string' ? req.body : (Buffer.isBuffer(req.body) ? req.body.toString('utf8') : JSON.stringify(req.body))
|
||||||
const parsed = typeof req.body === 'object' && !Buffer.isBuffer(req.body) ? req.body : JSON.parse(rawBody)
|
const parsed = typeof req.body === 'object' && !Buffer.isBuffer(req.body) ? req.body : JSON.parse(rawBody)
|
||||||
|
|
||||||
wxpay.verifyNotifySignature(req.headers, rawBody)
|
await wxpay.verifyNotifySignature(req.headers, rawBody)
|
||||||
|
|
||||||
const result = wxpay.decryptNotifyResource(parsed.resource)
|
const result = wxpay.decryptNotifyResource(parsed.resource)
|
||||||
|
|
||||||
|
|||||||
在新工单中引用
屏蔽一个用户