2021-07-19 13:46:38 +03:00
|
|
|
const errors = require('@tryghost/errors');
|
|
|
|
const tpl = require('@tryghost/tpl');
|
2020-05-28 13:40:48 +03:00
|
|
|
const {Buffer} = require('buffer');
|
|
|
|
const {randomBytes} = require('crypto');
|
|
|
|
const {URL} = require('url');
|
|
|
|
|
2021-07-19 13:46:38 +03:00
|
|
|
const messages = {
|
|
|
|
incorrectState: 'State did not match.'
|
|
|
|
};
|
|
|
|
|
2020-05-28 13:40:48 +03:00
|
|
|
const STATE_PROP = 'stripe-connect-state';
|
|
|
|
|
2020-06-10 14:19:04 +03:00
|
|
|
const liveClientID = 'ca_8LBuZWhYshxF0A55KgCXu8PRTquCKC5x';
|
|
|
|
const testClientID = 'ca_8LBum4Ctv3mmJ1oD0ZRmxjdAhNrrBUy3';
|
2020-05-28 13:40:48 +03:00
|
|
|
const redirectURI = 'https://stripe.ghost.org';
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @function getStripeConnectOAuthUrl
|
|
|
|
* @desc Returns a url for the auth endpoint for Stripe Connect, generates state and stores it on the session.
|
|
|
|
*
|
|
|
|
* @param {(prop: string, val: any) => Promise<void>} setSessionProp - A function to set data on the current session
|
2020-06-10 14:19:04 +03:00
|
|
|
* @param {'live' | 'test'} mode - Which stripe mode to set up
|
2020-05-28 13:40:48 +03:00
|
|
|
*
|
|
|
|
* @returns {Promise<URL>}
|
|
|
|
*/
|
2020-06-10 14:19:04 +03:00
|
|
|
async function getStripeConnectOAuthUrl(setSessionProp, mode = 'live') {
|
2020-06-10 14:31:03 +03:00
|
|
|
const randomState = randomBytes(16).toString('hex');
|
|
|
|
const state = Buffer.from(JSON.stringify({
|
|
|
|
mode,
|
|
|
|
randomState
|
|
|
|
})).toString('base64');
|
2020-05-28 13:40:48 +03:00
|
|
|
|
|
|
|
await setSessionProp(STATE_PROP, state);
|
|
|
|
|
2020-06-10 14:19:04 +03:00
|
|
|
const clientID = mode === 'live' ? liveClientID : testClientID;
|
|
|
|
|
2020-05-28 13:40:48 +03:00
|
|
|
const authUrl = new URL('https://connect.stripe.com/oauth/authorize');
|
|
|
|
authUrl.searchParams.set('response_type', 'code');
|
|
|
|
authUrl.searchParams.set('scope', 'read_write');
|
|
|
|
authUrl.searchParams.set('client_id', clientID);
|
|
|
|
authUrl.searchParams.set('redirect_uri', redirectURI);
|
|
|
|
authUrl.searchParams.set('state', state);
|
|
|
|
|
|
|
|
return authUrl;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @function getStripeConnectTokenData
|
|
|
|
* @desc Returns the api keys and the livemode for a Stripe Connect integration after validating the state.
|
|
|
|
*
|
|
|
|
* @param {string} encodedData - A string encoding the response from Stripe Connect
|
|
|
|
* @param {(prop: string) => Promise<any>} getSessionProp - A function to retrieve data from the current session
|
|
|
|
*
|
2021-07-19 13:46:38 +03:00
|
|
|
* @returns {Promise<{secret_key: string, public_key: string, livemode: boolean, display_name: string, account_id: string}>}
|
2020-05-28 13:40:48 +03:00
|
|
|
*/
|
|
|
|
async function getStripeConnectTokenData(encodedData, getSessionProp) {
|
|
|
|
const data = JSON.parse(Buffer.from(encodedData, 'base64').toString());
|
|
|
|
|
|
|
|
const state = await getSessionProp(STATE_PROP);
|
|
|
|
|
|
|
|
if (state !== data.s) {
|
2021-07-19 13:46:38 +03:00
|
|
|
throw new errors.NoPermissionError(tpl(messages.incorrectState));
|
2020-05-28 13:40:48 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
return {
|
|
|
|
public_key: data.p,
|
|
|
|
secret_key: data.a,
|
2020-06-09 17:37:07 +03:00
|
|
|
livemode: data.l,
|
|
|
|
display_name: data.n,
|
|
|
|
account_id: data.i
|
2020-05-28 13:40:48 +03:00
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
module.exports = {
|
|
|
|
getStripeConnectOAuthUrl,
|
|
|
|
getStripeConnectTokenData,
|
|
|
|
STATE_PROP
|
|
|
|
};
|