Skip to content

1.0.1

Choose a tag to compare

@github-actions github-actions released this 21 Aug 13:13
· 9 commits to master since this release

πŸš€ UPC 1.0.1

Patch release fixing a live notifier incident (PRE-3614) hit while diagnosing production webhook
handling, plus a Unified API operation-status polling fallback developed alongside it.

πŸ› Fixes

  • πŸ” execCode "0001" no longer misread as a final failure β€” PayPlug's notifier was
    observed in production firing a webhook carrying execCode "0001" ("Authentification 3DSecure
    requise", categorized "Acceptation", not an error) before the real, final notification for the
    same operation. Under the old two-way mapping this was read as terminal FAILED and, via
    IPaymentRepository::isTreated(), permanently blocked the correct final notification from ever
    applying. ExecCodeMapper::toPaymentOutcome() now maps "0001" to the existing
    PaymentOutcome::THREE_DS_PENDING instead.
  • πŸ”“ Webhook signature verification fails open when no secret is configured β€”
    WebhookNotificationHelper::verifySignature() previously rejected every notification
    unconditionally, since no merchant/account currently has any way to configure a webhook secret.
    It now accepts the notification unverified when no expected Authorization header value is set.
    This is a deliberate, temporary tradeoff β€” any unauthenticated request to a plugin's webhook
    endpoint is accepted today β€” pending a product decision on how webhook secret configuration will
    be exposed; revisit once that lands.

✨ Added

  • πŸ“‘ Operation-status polling β€” UnifiedApiPaymentService::getOperation() GETs the public
    /processing-operations/operations/public/{id} endpoint, returning the same webhook-shaped
    payload WebhookNotificationHelper::parse() already reads β€” a fallback for a delayed or lost
    webhook. A sibling UnifiedApiOperationService::getOperation() targets the private endpoint but
    returns 403 for a merchant's own client credentials in staging; treat it as unverified until a
    follow-up decides whether to keep or remove it.

βœ… Quality

PHPStan level 8, PHP-CS-Fixer, PHPUnit, and CI verifying PHP 7.1–8.2 compatibility β€” all clean on
this release branch.

πŸ“‹ Requirements

  • PHP β‰₯7.4 to install/develop (build-tooling floor only β€” shipped source runs on PHP 7.1)
  • Runtime dependency: giggsey/libphonenumber-for-php

πŸ”— Full Changelog: 1.0.0...1.0.1