You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- Stripe Checkout (hosted page) through the shop processOrder() seam; REST via
Laravel Http, no stripe/stripe-php dependency; pinned Stripe-Version.
- One consolidated line for the order total; zero/three-decimal currency rules.
- One idempotent fulfilment path shared by the return page and the signed
webhook (payment intent / refund id as ledger keys, unique-index race handled);
order status moved through changeStatus() only while the order is still new.
- Refunds made in Stripe are recorded on the order; only a full refund moves it
to the refunded status.
- Webhook route outside the storefront middleware (maintenance page / redirects
would swallow it) and rate limited; HMAC v1 signature, 300 s tolerance.
- Cancel link never cancels a paid or already-handled order.
- Per-store settings with encrypted secrets, owner-only; settings screen split
into Mode / Sandbox / Live / Order status blocks.
- README (vi/en) with a step-by-step guide to creating Stripe keys and webhooks.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>