2021-01-18 16:55:40 +03:00
|
|
|
const _ = require('lodash');
|
2021-03-10 14:12:44 +03:00
|
|
|
const errors = require('@tryghost/errors');
|
2021-01-18 16:55:40 +03:00
|
|
|
|
|
|
|
module.exports = class StripeWebhookService {
|
|
|
|
/**
|
|
|
|
* @param {object} deps
|
|
|
|
* @param {any} deps.StripeWebhook
|
|
|
|
* @param {import('../stripe-api')} deps.stripeAPIService
|
2021-03-10 14:12:44 +03:00
|
|
|
* @param {import('../stripe-plans')} deps.stripePlansService
|
2021-01-18 16:55:40 +03:00
|
|
|
* @param {import('../../repositories/member')} deps.memberRepository
|
2021-02-15 17:16:58 +03:00
|
|
|
* @param {import('../../repositories/event')} deps.eventRepository
|
2021-01-18 16:55:40 +03:00
|
|
|
* @param {any} deps.sendEmailWithMagicLink
|
|
|
|
*/
|
|
|
|
constructor({
|
|
|
|
StripeWebhook,
|
|
|
|
stripeAPIService,
|
2021-03-10 14:12:44 +03:00
|
|
|
stripePlansService,
|
2021-01-18 16:55:40 +03:00
|
|
|
memberRepository,
|
2021-02-15 17:16:58 +03:00
|
|
|
eventRepository,
|
2021-01-18 16:55:40 +03:00
|
|
|
sendEmailWithMagicLink
|
|
|
|
}) {
|
|
|
|
this._StripeWebhook = StripeWebhook;
|
|
|
|
this._stripeAPIService = stripeAPIService;
|
2021-03-10 14:12:44 +03:00
|
|
|
this._stripePlansService = stripePlansService;
|
2021-01-18 16:55:40 +03:00
|
|
|
this._memberRepository = memberRepository;
|
2021-02-15 17:16:58 +03:00
|
|
|
this._eventRepository = eventRepository;
|
2021-01-18 16:55:40 +03:00
|
|
|
this._sendEmailWithMagicLink = sendEmailWithMagicLink;
|
|
|
|
this.handlers = {};
|
|
|
|
this.registerHandler('customer.subscription.deleted', this.subscriptionEvent);
|
|
|
|
this.registerHandler('customer.subscription.updated', this.subscriptionEvent);
|
|
|
|
this.registerHandler('customer.subscription.created', this.subscriptionEvent);
|
|
|
|
this.registerHandler('invoice.payment_succeeded', this.invoiceEvent);
|
|
|
|
this.registerHandler('invoice.payment_failed', this.invoiceEvent);
|
|
|
|
this.registerHandler('checkout.session.completed', this.checkoutSessionEvent);
|
|
|
|
}
|
|
|
|
|
|
|
|
registerHandler(event, handler) {
|
|
|
|
this.handlers[event] = handler.name;
|
|
|
|
}
|
|
|
|
|
|
|
|
async configure(config) {
|
|
|
|
if (config.webhookSecret) {
|
|
|
|
this._webhookSecret = config.webhookSecret;
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2021-01-28 18:19:59 +03:00
|
|
|
if (config.mode !== 'production') {
|
|
|
|
const error = new Error('Cannot use remote webhooks in development mode. Please use the WEBHOOK_SECRET environment variable.');
|
|
|
|
error.fatal = true;
|
|
|
|
throw error;
|
|
|
|
}
|
|
|
|
|
2021-04-09 18:41:16 +03:00
|
|
|
/** @type {import('stripe').Stripe.WebhookEndpointCreateParams.EnabledEvent[]} */
|
2021-01-18 16:55:40 +03:00
|
|
|
const events = [
|
|
|
|
'checkout.session.completed',
|
|
|
|
'customer.subscription.deleted',
|
|
|
|
'customer.subscription.updated',
|
|
|
|
'customer.subscription.created',
|
|
|
|
'invoice.payment_succeeded',
|
|
|
|
'invoice.payment_failed'
|
|
|
|
];
|
|
|
|
|
|
|
|
const setupWebhook = async (id, secret, opts = {}) => {
|
|
|
|
if (!id || !secret || opts.forceCreate) {
|
|
|
|
if (id && !opts.skipDelete) {
|
|
|
|
try {
|
|
|
|
await this._stripeAPIService.deleteWebhookEndpoint(id);
|
|
|
|
} catch (err) {
|
|
|
|
// Continue
|
|
|
|
}
|
|
|
|
}
|
|
|
|
const webhook = await this._stripeAPIService.createWebhookEndpoint(
|
|
|
|
config.webhookHandlerUrl,
|
|
|
|
events
|
|
|
|
);
|
|
|
|
return {
|
|
|
|
id: webhook.id,
|
|
|
|
secret: webhook.secret
|
|
|
|
};
|
|
|
|
} else {
|
|
|
|
try {
|
|
|
|
await this._stripeAPIService.updateWebhookEndpoint(
|
|
|
|
id,
|
|
|
|
config.webhookHandlerUrl,
|
|
|
|
events
|
|
|
|
);
|
|
|
|
|
|
|
|
return {
|
|
|
|
id,
|
|
|
|
secret
|
|
|
|
};
|
|
|
|
} catch (err) {
|
|
|
|
if (err.code === 'resource_missing') {
|
|
|
|
return setupWebhook(id, secret, {skipDelete: true, forceCreate: true});
|
|
|
|
}
|
|
|
|
return setupWebhook(id, secret, {skipDelete: false, forceCreate: true});
|
|
|
|
}
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
|
|
|
const webhook = await setupWebhook(config.webhook.id, config.webhook.secret);
|
|
|
|
await this._StripeWebhook.upsert({
|
|
|
|
webhook_id: webhook.id,
|
|
|
|
secret: webhook.secret
|
|
|
|
}, {webhook_id: webhook.id});
|
|
|
|
this._webhookSecret = webhook.secret;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param {string} body
|
|
|
|
* @param {string} signature
|
2021-04-09 18:41:16 +03:00
|
|
|
* @returns {import('stripe').Stripe.Event}
|
2021-01-18 16:55:40 +03:00
|
|
|
*/
|
|
|
|
parseWebhook(body, signature) {
|
|
|
|
return this._stripeAPIService.parseWebhook(body, signature, this._webhookSecret);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2021-04-09 18:41:16 +03:00
|
|
|
* @param {import('stripe').Stripe.Event} event
|
2021-01-18 16:55:40 +03:00
|
|
|
*
|
|
|
|
* @returns {Promise<void>}
|
|
|
|
*/
|
|
|
|
async handleWebhook(event) {
|
|
|
|
if (!this.handlers[event.type]) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
await this[this.handlers[event.type]](event.data.object);
|
|
|
|
}
|
|
|
|
|
|
|
|
async subscriptionEvent(subscription) {
|
|
|
|
const member = await this._memberRepository.get({
|
|
|
|
customer_id: subscription.customer
|
|
|
|
});
|
|
|
|
|
|
|
|
if (member) {
|
|
|
|
await this._memberRepository.linkSubscription({
|
|
|
|
id: member.id,
|
|
|
|
subscription
|
|
|
|
});
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-02-15 17:16:58 +03:00
|
|
|
/**
|
2021-04-09 18:41:16 +03:00
|
|
|
* @param {import('stripe').Stripe.Invoice} invoice
|
2021-02-15 17:16:58 +03:00
|
|
|
*
|
|
|
|
* @returns {Promise<void>}
|
|
|
|
*/
|
2021-01-18 16:55:40 +03:00
|
|
|
async invoiceEvent(invoice) {
|
|
|
|
const subscription = await this._stripeAPIService.getSubscription(invoice.subscription, {
|
|
|
|
expand: ['default_payment_method']
|
|
|
|
});
|
|
|
|
|
|
|
|
const member = await this._memberRepository.get({
|
|
|
|
customer_id: subscription.customer
|
|
|
|
});
|
|
|
|
|
|
|
|
if (member) {
|
2021-03-10 14:12:44 +03:00
|
|
|
if (invoice.paid && invoice.amount_paid !== 0) {
|
2021-02-15 17:16:58 +03:00
|
|
|
await this._eventRepository.registerPayment({
|
|
|
|
member_id: member.id,
|
|
|
|
currency: invoice.currency,
|
|
|
|
amount: invoice.amount_paid
|
|
|
|
});
|
|
|
|
}
|
2021-03-10 14:12:44 +03:00
|
|
|
} else {
|
|
|
|
// Subscription has more than one plan - meaning it is not one created by us - ignore.
|
|
|
|
if (!subscription.plan) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
// Subscription is for a different product - ignore.
|
|
|
|
if (this._stripePlansService.getProduct().id !== subscription.plan.product) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
// Could not find the member, which we need in order to insert an payment event.
|
|
|
|
throw new errors.NotFoundError({
|
|
|
|
message: `No member found for customer ${subscription.customer}`
|
|
|
|
});
|
2021-01-18 16:55:40 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
async checkoutSessionEvent(session) {
|
|
|
|
if (session.mode === 'setup') {
|
|
|
|
const setupIntent = await this._stripeAPIService.getSetupIntent(session.setup_intent);
|
|
|
|
const member = await this._memberRepository.get({
|
|
|
|
customer_id: setupIntent.metadata.customer_id
|
|
|
|
});
|
|
|
|
|
|
|
|
await this._stripeAPIService.attachPaymentMethodToCustomer(
|
|
|
|
setupIntent.metadata.customer_id,
|
|
|
|
setupIntent.payment_method
|
|
|
|
);
|
|
|
|
|
2021-02-23 14:19:21 +03:00
|
|
|
if (setupIntent.metadata.subscription_id) {
|
2021-01-18 16:55:40 +03:00
|
|
|
const updatedSubscription = await this._stripeAPIService.updateSubscriptionDefaultPaymentMethod(
|
2021-02-23 14:19:21 +03:00
|
|
|
setupIntent.metadata.subscription_id,
|
2021-01-18 16:55:40 +03:00
|
|
|
setupIntent.payment_method
|
|
|
|
);
|
|
|
|
await this._memberRepository.linkSubscription({
|
|
|
|
id: member.id,
|
|
|
|
subscription: updatedSubscription
|
|
|
|
});
|
2021-02-23 14:19:21 +03:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
const subscriptions = await member.related('stripeSubscriptions').fetch();
|
|
|
|
|
|
|
|
const activeSubscriptions = subscriptions.models.filter((subscription) => {
|
|
|
|
return ['active', 'trialing', 'unpaid', 'past_due'].includes(subscription.get('status'));
|
|
|
|
});
|
|
|
|
|
|
|
|
for (const subscription of activeSubscriptions) {
|
|
|
|
if (subscription.get('customer_id') === setupIntent.metadata.customer_id) {
|
|
|
|
const updatedSubscription = await this._stripeAPIService.updateSubscriptionDefaultPaymentMethod(
|
|
|
|
subscription.get('subscription_id'),
|
|
|
|
setupIntent.payment_method
|
|
|
|
);
|
|
|
|
await this._memberRepository.linkSubscription({
|
|
|
|
id: member.id,
|
|
|
|
subscription: updatedSubscription
|
|
|
|
});
|
|
|
|
}
|
2021-01-18 16:55:40 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if (session.mode === 'subscription') {
|
|
|
|
const customer = await this._stripeAPIService.getCustomer(session.customer, {
|
|
|
|
expand: ['subscriptions.data.default_payment_method']
|
|
|
|
});
|
|
|
|
|
|
|
|
let member = await this._memberRepository.get({
|
|
|
|
email: customer.email
|
|
|
|
});
|
|
|
|
|
|
|
|
const checkoutType = _.get(session, 'metadata.checkoutType');
|
|
|
|
const requestSrc = _.get(session, 'metadata.requestSrc') || '';
|
|
|
|
|
|
|
|
if (!member) {
|
|
|
|
const metadataName = _.get(session, 'metadata.name');
|
|
|
|
const payerName = _.get(customer, 'subscriptions.data[0].default_payment_method.billing_details.name');
|
|
|
|
const name = metadataName || payerName || null;
|
|
|
|
member = await this._memberRepository.create({email: customer.email, name});
|
|
|
|
} else {
|
|
|
|
const payerName = _.get(customer, 'subscriptions.data[0].default_payment_method.billing_details.name');
|
|
|
|
|
|
|
|
if (payerName && !member.get('name')) {
|
|
|
|
await this._memberRepository.update({name: payerName}, {id: member.get('id')});
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
await this._memberRepository.upsertCustomer({
|
|
|
|
customer_id: customer.id,
|
|
|
|
member_id: member.id,
|
|
|
|
name: customer.name,
|
|
|
|
email: customer.email
|
|
|
|
});
|
|
|
|
|
|
|
|
for (const subscription of customer.subscriptions.data) {
|
|
|
|
await this._memberRepository.linkSubscription({
|
|
|
|
id: member.id,
|
|
|
|
subscription
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
|
|
|
if (checkoutType !== 'upgrade') {
|
|
|
|
const emailType = 'signup';
|
|
|
|
this._sendEmailWithMagicLink({
|
|
|
|
email: customer.email,
|
|
|
|
requestedType: emailType,
|
|
|
|
requestSrc,
|
|
|
|
options: {forceEmailType: true},
|
|
|
|
tokenData: {}
|
|
|
|
});
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
};
|