Add TransactionValidator and shared SubunitConverter (R2.1) - #76
Merged
Merged
Conversation
Introduces the accept-side verification gate's first building block: a pure TransactionValidator checking a Paystack verify response against status, currency, bounded amount window, and live/test domain, plus a SubunitConverter shared between the send side (Setup.php) and this validator so the two can never independently drift. Not wired into any consumer yet. Verified on dev-repro that the browser's popup amount and the server's post-placement order total agree exactly, on both a same-currency and a display-currency-!=-base-currency guest checkout, before implementing the amount comparand.
Model/Payment/Paystack.php extends DataObject implementing MethodInterface directly, not AbstractMethod — caught during the R2.2/R2.3 review panel. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Gateway/Validator/TransactionValidator.php: pure checks of a Paystack verify-transaction response against status, currency, a bounded amount window, and live/test domain — not wired into any of the three payment consumers yet.Gateway/SubunitConverter.php, a shared static helper repointingController/Payment/Setup.php's previously-inline subunit computation so the send side and this validator can never independently drift.PaystackApiClient::isTestMode()as the single source of truth fortest_mode, so a future caller doesn't introduce a second independent config read.docs/plans/2026-09-28-r2-1-transaction-validator.md, untracked per this repo's convention for unfixed money-path defect maps).dev-repro/that the browser's popup amount and the server's post-placement order total agree exactly, on both a same-currency and a display≠base-currency guest checkout — the parent plan's explicit blocking prerequisite for this item.Test plan
Test/Unit/vendor/bin/phpunit -c phpunit.xml --no-coverage— 162 tests, 225 assertions, all greenchargeIsReal(), and a duplicatedtest_modeconfig read)dev-repro/(2.4.9, PHP 8.5, CSP on) confirming the amount comparand is correct before it was implemented🤖 Generated with Claude Code