- 新增 NEXT_PUBLIC_SITE_URL 支持及 site-url.ts 工具模块 - 修复 OAuth 回调域名:import.meta.env 统一读取站点 URL - 支付 API 路由新增收款地址校验 - 后端支付服务更新 - middleware 清理 - 新增 paymentSecurity 测试
63 lines
1.9 KiB
TypeScript
63 lines
1.9 KiB
TypeScript
import { NextRequest, NextResponse } from "next/server";
|
|
import {
|
|
applyAuthResponseCookies,
|
|
buildBackendRequestHeaders,
|
|
requireBackendAuthUser,
|
|
} from "@/lib/backend-auth";
|
|
import {
|
|
buildProxyExceptionResponse,
|
|
buildUpstreamErrorResponse,
|
|
} from "@/lib/api-proxy";
|
|
|
|
const API_BASE = process.env.POLYWEATHER_API_BASE_URL;
|
|
|
|
export async function POST(
|
|
req: NextRequest,
|
|
context: { params: Promise<{ intentId: string }> },
|
|
) {
|
|
if (!API_BASE) {
|
|
return NextResponse.json(
|
|
{ error: "POLYWEATHER_API_BASE_URL is not configured" },
|
|
{ status: 500 },
|
|
);
|
|
}
|
|
const { intentId } = await context.params;
|
|
try {
|
|
const body = await req.json();
|
|
const auth = await buildBackendRequestHeaders(req);
|
|
const authError = requireBackendAuthUser(auth);
|
|
if (authError) return authError;
|
|
const proxiedHeaders = new Headers(auth.headers);
|
|
proxiedHeaders.set("Content-Type", "application/json");
|
|
const res = await fetch(
|
|
`${API_BASE}/api/payments/intents/${encodeURIComponent(intentId)}/validate`,
|
|
{
|
|
method: "POST",
|
|
headers: proxiedHeaders,
|
|
body: JSON.stringify(body ?? {}),
|
|
cache: "no-store",
|
|
},
|
|
);
|
|
if (!res.ok) {
|
|
const raw = await res.text();
|
|
let detail = raw.slice(0, 350);
|
|
try {
|
|
const parsed = JSON.parse(raw);
|
|
if (parsed.detail) detail = String(parsed.detail).slice(0, 350);
|
|
} catch {}
|
|
const response = buildUpstreamErrorResponse(res.status, raw, {
|
|
detailLimit: 350,
|
|
error: detail || undefined,
|
|
});
|
|
return applyAuthResponseCookies(response, auth.response);
|
|
}
|
|
const data = await res.json();
|
|
const response = NextResponse.json(data);
|
|
return applyAuthResponseCookies(response, auth.response);
|
|
} catch (error) {
|
|
return buildProxyExceptionResponse(error, {
|
|
publicMessage: "Failed to validate payment tx",
|
|
});
|
|
}
|
|
}
|