diff --git a/frontend/components/account/__tests__/paymentShell.test.ts b/frontend/components/account/__tests__/paymentShell.test.ts index 26f8bbe5..c8c7f46b 100644 --- a/frontend/components/account/__tests__/paymentShell.test.ts +++ b/frontend/components/account/__tests__/paymentShell.test.ts @@ -58,6 +58,10 @@ export function runTests() { const hookSource = fs.existsSync(hookPath) ? fs.readFileSync(hookPath, "utf8") : ""; + const paymentFlowSource = fs.readFileSync( + path.join(accountDir, "usePaymentFlow.ts"), + "utf8", + ); assert( (accountCenterSource.includes('import { usePaymentState } from "./usePaymentState";') || hookSource.includes('import { usePaymentState } from "./usePaymentState";')) && @@ -327,4 +331,9 @@ export function runTests() { paymentRuntimeRouteSource.includes("includeSupabaseIdentity: false"), "payment runtime proxy must not read Supabase session cookies because backend entitlement token already protects the runtime status payload", ); + assert( + (paymentFlowSource.match(/await buildAuthedHeaders\(true, true\);/g) || []) + .length >= 3, + "manual payment mutations must require a valid Supabase bearer token instead of forwarding unauthenticated requests that surface raw backend JSON", + ); } diff --git a/frontend/components/account/usePaymentFlow.ts b/frontend/components/account/usePaymentFlow.ts index 0f571af2..32ef21ce 100644 --- a/frontend/components/account/usePaymentFlow.ts +++ b/frontend/components/account/usePaymentFlow.ts @@ -632,7 +632,7 @@ export function usePaymentFlow(params: UsePaymentFlowParams) { setPaymentBusy(true); try { - const authHeaders = await buildAuthedHeaders(true, false); + const authHeaders = await buildAuthedHeaders(true, true); const createRes = await fetch("/api/payments/intents", { method: "POST", headers: authHeaders, @@ -704,7 +704,7 @@ export function usePaymentFlow(params: UsePaymentFlowParams) { setPaymentBusy(true); setPaymentError(""); try { - const authHeaders = await buildAuthedHeaders(true, false); + const authHeaders = await buildAuthedHeaders(true, true); const submitRes = await fetch(`/api/payments/intents/${intentIdVal}/submit`, { method: "POST", headers: authHeaders, body: JSON.stringify({ tx_hash: txHashNorm }), }); @@ -762,7 +762,7 @@ export function usePaymentFlow(params: UsePaymentFlowParams) { } setTxValidation({ loading: true, checked: false }); try { - const headers = await buildAuthedHeaders(true, false); + const headers = await buildAuthedHeaders(true, true); const res = await fetch(`/api/payments/intents/${intentId}/validate`, { method: "POST", headers, body: JSON.stringify({ tx_hash: hashNorm }), });