habitica/website/server/libs/payments/google.js

251 lines
7.5 KiB
JavaScript
Raw Permalink Normal View History

2019-10-08 14:57:10 +00:00
import moment from 'moment';
2018-04-08 14:27:03 +00:00
import shared from '../../../common';
import iap from '../inAppPurchases';
import payments from './payments';
import {
NotAuthorized,
BadRequest,
2018-04-08 14:27:03 +00:00
} from '../errors';
import { model as IapPurchaseReceipt } from '../../models/iapPurchaseReceipt';
2019-10-08 14:57:10 +00:00
import { model as User } from '../../models/user';
import { validateGiftMessage } from './gems';
2019-10-08 14:57:10 +00:00
const api = {};
api.constants = {
PAYMENT_METHOD_GOOGLE: 'Google',
PAYMENT_METHOD_GIFT: 'Google (Gift)',
RESPONSE_INVALID_RECEIPT: 'INVALID_RECEIPT',
RESPONSE_ALREADY_USED: 'RECEIPT_ALREADY_USED',
RESPONSE_INVALID_ITEM: 'INVALID_ITEM_PURCHASED',
RESPONSE_STILL_VALID: 'SUBSCRIPTION_STILL_VALID',
};
api.verifyPurchase = async function verifyPurchase (options) {
2019-10-08 14:57:10 +00:00
const {
gift, user, receipt, signature, headers,
} = options;
if (gift) {
gift.member = await User.findById(gift.uuid).exec();
Stripe: upgrade module and API, switch to Checkout (#12785) * upgrade stripe module * switch stripe api to latest version * fix api version in tests * start upgrading client and server * client: switch to redirect * implement checkout session creation for gems, start implementing webhooks * stripe: start refactoring one time payments * working gems and gift payments * start adding support for subscriptions * stripe: migrate subscriptions and fix cancelling sub * allow upgrading group plans * remove console.log statements * group plans: upgrade from static page / create new one * fix #11885, correct group plan modal title * silence more stripe webhooks * fix group plans redirects * implement editing payment method * start cleaning up code * fix(stripe): update in-code docs, fix eslint issues * subscriptions tests * remove and skip old tests * skip integration tests * fix client build * stripe webhooks: throw error if request fails * subscriptions: correctly pass groupId * remove console.log * stripe: add unit tests for one time payments * wip: stripe checkout tests * stripe createCheckoutSession unit tests * stripe createCheckoutSession unit tests * stripe createCheckoutSession unit tests (editing card) * fix existing webhooks tests * add new webhooks tests * add more webhooks tests * fix lint * stripe integration tests * better error handling when retrieving customer from stripe * client: remove unused strings and improve error handling * payments: limit gift message length (server) * payments: limit gift message length (client) * fix redirects when payment is cancelled * add back "subUpdateCard" string * fix redirects when editing a sub card, use proper names for products, check subs when gifting
2020-12-14 14:59:17 +00:00
validateGiftMessage(gift, user);
}
const receiver = gift ? gift.member : user;
const receiverCanGetGems = await receiver.canGetGems();
if (!receiverCanGetGems) throw new NotAuthorized(shared.i18n.t('groupPolicyCannotGetGems', user.preferences.language));
await iap.setup();
2019-10-08 14:57:10 +00:00
const testObj = {
data: receipt,
signature,
};
2019-10-08 14:57:10 +00:00
const googleRes = await iap.validate(iap.GOOGLE, testObj);
2019-10-08 14:57:10 +00:00
const isValidated = iap.isValidated(googleRes);
if (!isValidated) throw new NotAuthorized(this.constants.RESPONSE_INVALID_RECEIPT);
2019-10-08 14:57:10 +00:00
const receiptObj = typeof testObj.data === 'string' ? JSON.parse(testObj.data) : testObj.data; // passed as a string
const token = receiptObj.token || receiptObj.purchaseToken;
2019-10-08 14:57:10 +00:00
const existingReceipt = await IapPurchaseReceipt.findOne({
_id: token,
}).exec();
if (existingReceipt) throw new NotAuthorized(this.constants.RESPONSE_ALREADY_USED);
await IapPurchaseReceipt.create({
_id: token,
consumed: true,
// This should always be the buying user even for a gift.
userId: user._id,
});
await payments.buySkuItem({ // eslint-disable-line no-await-in-loop
Fall Festival Gem Promo (#138) * content: add gems blocks * gemsBlocks: include ios and android identifiers * wip: promo code * split common constants into multiple files * add second promo part * geCurrentEvent, refactor promo * fix lint * fix exports, use world state api * start adding world state tests * remove console.log * use gems block for purchases * remove comments * fix most unit tests * restore comment * fix lint * prevent apple/google gift tests from breaking other tests when stub is not reset * fix unit tests, clarify tests names * iap: use gift object when gifting gems * allow gift object with less data * fix iap tests, remove findById stubs * iap: require less data from the mobile apps * apply discounts * add missing worldState file * fix lint * add test event * start removing 20 gems option for web * start adding support for all gems packages on web * fix unit tests for apple, stripe and google * amazon: support all gems blocks * paypal: support all gems blocks * fix payments unit tests, add tests for getGemsBlock * web: add gems plans with discounts, update stripe * fix amazon and paypal clients, payments success modals * amazon pay: disabled state * update icons, start abstracting payments buttons * begin redesign * redesign gems modal * fix buttons * fix hover color for gems modal close icon * add key to world state current event * extend test event length * implement gems modals designs * early test fall2020 * fix header banner position * add missing files * use iso 8601 for dates, minor ui fixes * fix time zones * events: fix ISO8601 format * fix css indentation * start abstracting banners * refactor payments buttons * test spooky, fix group plans box * implement gems promo banners, refactor banners, fixes * fix lint * fix dates * remove unused i18n strings * fix stripe integration test * fix world state integration tests * the current active event * add missing unit tests * add storybook story for payments buttons component * fix typo * fix(stripe): correct label when gifting subscriptions
2020-09-21 14:22:13 +00:00
user,
gift,
paymentMethod: api.constants.PAYMENT_METHOD_GOOGLE,
sku: googleRes.productId,
headers,
});
return googleRes;
};
api.subscribe = async function subscribe (
sku,
user,
receipt,
signature,
headers,
nextPaymentProcessing = undefined,
) {
if (!sku) throw new BadRequest(shared.i18n.t('missingSubscriptionCode'));
let subCode;
switch (sku) { // eslint-disable-line default-case
case 'com.habitrpg.android.habitica.subscription.1month':
subCode = 'basic_earned';
break;
case 'com.habitrpg.android.habitica.subscription.3month':
subCode = 'basic_3mo';
break;
case 'com.habitrpg.android.habitica.subscription.6month':
subCode = 'basic_6mo';
break;
case 'com.habitrpg.android.habitica.subscription.12month':
subCode = 'basic_12mo';
break;
}
2019-10-08 14:57:10 +00:00
const sub = subCode ? shared.content.subscriptionBlocks[subCode] : false;
if (!sub) throw new NotAuthorized(this.constants.RESPONSE_INVALID_ITEM);
await iap.setup();
2019-10-08 14:57:10 +00:00
const testObj = {
data: receipt,
signature,
};
2019-10-08 14:57:10 +00:00
const receiptObj = typeof receipt === 'string' ? JSON.parse(receipt) : receipt; // passed as a string
const token = receiptObj.token || receiptObj.purchaseToken;
2019-10-08 14:57:10 +00:00
const existingUser = await User.findOne({
2017-02-02 19:51:52 +00:00
'purchased.plan.customerId': token,
}).exec();
if (existingUser) throw new NotAuthorized(this.constants.RESPONSE_ALREADY_USED);
2019-10-08 14:57:10 +00:00
const googleRes = await iap.validate(iap.GOOGLE, testObj);
2019-10-08 14:57:10 +00:00
const isValidated = iap.isValidated(googleRes);
if (!isValidated) throw new NotAuthorized(this.constants.RESPONSE_INVALID_RECEIPT);
nextPaymentProcessing = nextPaymentProcessing || moment.utc().add({ days: 2 }); // eslint-disable-line no-param-reassign, max-len
await payments.createSubscription({
user,
customerId: token,
paymentMethod: this.constants.PAYMENT_METHOD_GOOGLE,
sub,
headers,
nextPaymentProcessing,
additionalData: testObj,
});
};
api.noRenewSubscribe = async function noRenewSubscribe (options) {
2019-10-08 14:57:10 +00:00
const {
sku, gift, user, receipt, signature, headers,
} = options;
if (!sku) throw new BadRequest(shared.i18n.t('missingSubscriptionCode'));
let subCode;
switch (sku) { // eslint-disable-line default-case
case 'com.habitrpg.android.habitica.norenew_subscription.1month':
subCode = 'basic_earned';
break;
case 'com.habitrpg.android.habitica.norenew_subscription.3month':
subCode = 'basic_3mo';
break;
case 'com.habitrpg.android.habitica.norenew_subscription.6month':
subCode = 'basic_6mo';
break;
case 'com.habitrpg.android.habitica.norenew_subscription.12month':
subCode = 'basic_12mo';
break;
}
2019-10-08 14:57:10 +00:00
const sub = subCode ? shared.content.subscriptionBlocks[subCode] : false;
if (!sub) throw new NotAuthorized(this.constants.RESPONSE_INVALID_ITEM);
await iap.setup();
2019-10-08 14:57:10 +00:00
const testObj = {
data: receipt,
signature,
};
2019-10-08 14:57:10 +00:00
const receiptObj = typeof receipt === 'string' ? JSON.parse(receipt) : receipt; // passed as a string
const token = receiptObj.token || receiptObj.purchaseToken;
2019-10-08 14:57:10 +00:00
const existingReceipt = await IapPurchaseReceipt.findOne({ // eslint-disable-line no-await-in-loop
_id: token,
}).exec();
if (existingReceipt) throw new NotAuthorized(this.constants.RESPONSE_ALREADY_USED);
await IapPurchaseReceipt.create({ // eslint-disable-line no-await-in-loop
_id: token,
consumed: true,
// This should always be the buying user even for a gift.
userId: user._id,
});
2019-10-08 14:57:10 +00:00
const googleRes = await iap.validate(iap.GOOGLE, testObj);
2019-10-08 14:57:10 +00:00
const isValidated = iap.isValidated(googleRes);
if (!isValidated) throw new NotAuthorized(this.constants.RESPONSE_INVALID_RECEIPT);
2019-10-08 14:57:10 +00:00
const data = {
user,
paymentMethod: this.constants.PAYMENT_METHOD_GOOGLE,
headers,
sub,
autoRenews: false,
};
if (gift) {
Stripe: upgrade module and API, switch to Checkout (#12785) * upgrade stripe module * switch stripe api to latest version * fix api version in tests * start upgrading client and server * client: switch to redirect * implement checkout session creation for gems, start implementing webhooks * stripe: start refactoring one time payments * working gems and gift payments * start adding support for subscriptions * stripe: migrate subscriptions and fix cancelling sub * allow upgrading group plans * remove console.log statements * group plans: upgrade from static page / create new one * fix #11885, correct group plan modal title * silence more stripe webhooks * fix group plans redirects * implement editing payment method * start cleaning up code * fix(stripe): update in-code docs, fix eslint issues * subscriptions tests * remove and skip old tests * skip integration tests * fix client build * stripe webhooks: throw error if request fails * subscriptions: correctly pass groupId * remove console.log * stripe: add unit tests for one time payments * wip: stripe checkout tests * stripe createCheckoutSession unit tests * stripe createCheckoutSession unit tests * stripe createCheckoutSession unit tests (editing card) * fix existing webhooks tests * add new webhooks tests * add more webhooks tests * fix lint * stripe integration tests * better error handling when retrieving customer from stripe * client: remove unused strings and improve error handling * payments: limit gift message length (server) * payments: limit gift message length (client) * fix redirects when payment is cancelled * add back "subUpdateCard" string * fix redirects when editing a sub card, use proper names for products, check subs when gifting
2020-12-14 14:59:17 +00:00
validateGiftMessage(gift, user);
gift.member = await User.findById(gift.uuid).exec();
gift.subscription = sub;
data.gift = gift;
data.paymentMethod = this.constants.PAYMENT_METHOD_GIFT;
}
await payments.createSubscription(data);
return googleRes;
};
api.cancelSubscribe = async function cancelSubscribe (user, headers) {
2019-10-08 14:57:10 +00:00
const { plan } = user.purchased;
if (plan.paymentMethod !== api.constants.PAYMENT_METHOD_GOOGLE) throw new NotAuthorized(shared.i18n.t('missingSubscription'));
await iap.setup();
let dateTerminated;
try {
2019-10-08 14:57:10 +00:00
const googleRes = await iap.validate(iap.GOOGLE, plan.additionalData);
2019-10-08 14:57:10 +00:00
const isValidated = iap.isValidated(googleRes);
if (!isValidated) throw new NotAuthorized(this.constants.RESPONSE_INVALID_RECEIPT);
2019-10-08 14:57:10 +00:00
const purchases = iap.getPurchaseData(googleRes);
if (purchases.length === 0) throw new NotAuthorized(this.constants.RESPONSE_INVALID_RECEIPT);
for (const i in purchases) {
if (Object.prototype.hasOwnProperty.call(purchases, i)) {
const purchase = purchases[i];
if (purchase.autoRenewing !== false) return;
if (!dateTerminated || Number(purchase.expirationDate) > Number(dateTerminated)) {
dateTerminated = new Date(Number(purchase.expirationDate));
}
}
}
} catch (err) {
// Status:410 means that the subsctiption isn't active anymore and we can safely delete it
if (err && err.message === 'Status:410') {
dateTerminated = new Date();
} else {
throw err;
}
}
if (dateTerminated) {
await payments.cancelSubscription({
user,
nextBill: dateTerminated,
paymentMethod: this.constants.PAYMENT_METHOD_GOOGLE,
headers,
});
}
};
export default api;