Skip to content

Releases: pulgueta/wompi-node

@pulgueta/wompi@3.4.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 19:49
d4b4573

Minor Changes

  • #49 9a30116 Thanks @pulgueta! - Add a typed error for gateway and availability failures.

    A 502, 503 or 504 response, or a 5xx response with a body that is not
    JSON (an HTML error page), now returns a WompiServiceUnavailableError. It has
    type: "SERVICE_UNAVAILABLE_ERROR", statusCode and retryable: true.

    The new isGatewayError(error) guard from @pulgueta/wompi/schemas is true for
    this error, and for a WompiRequestError or WompiPayoutApiError with a 502,
    503 or 504 status code.

    WompiServiceUnavailableError extends WompiRequestError, so code that reads
    statusCode from a WompiRequestError continues to operate. A structured
    Payouts API error stays a WompiPayoutApiError.

Patch Changes

  • #48 a686f41 Thanks @pulgueta! - Send the private key on getTransaction, as the Wompi API now requires.

    Wompi accepts GET /transactions/{id} only with the private key. A lookup
    without it returns 404 Not Found, so the SDK reported a WompiNotFoundError
    for transactions that exist.

    getTransaction now sends Authorization: Bearer <privateKey>. A client
    without privateKey gets [WompiError("Private key is required for this operation"), null] and sends no request. Call getTransaction from your
    server.

@pulgueta/wompi-convex@0.5.0

Choose a tag to compare

@pulgueta pulgueta released this 30 Sep 20:03
@pulgueta/wompi-convex@0.5.0
d4b4573

Minor Changes

  • #53
    f731ada
    Thanks @pulgueta! - Remove the scale limits of
    the billing engine and document the ones that stay.

    • Charges run in parallel. processBilling keeps five Wompi requests in
      flight at the same time. Before, it charged one subscription at a time.
    • The cron does not wait for a result. A renewal that Wompi keeps
      PENDING keeps its transaction id. The webhook or the next run resolves it.
      Before, each pending renewal added two waits of pollIntervalMs to the run.
      subscribe and confirmTransaction continue to poll.
    • ProcessBillingSummary.remaining. It is true when the run left due
      subscriptions or stale payments for an immediate next run. The README shows
      an action that schedules itself with it.
    • The stale sweep rotates. Each run continues after the last payment that
      the previous run visited, oldest first. At the end of the stale payments,
      the pass is complete. Before, it read the 50 oldest pending payments in each
      run, so payments that stayed pending kept all later ones out of reach. An
      abandoned checkout that cannot expire yet does not use a place in the batch.
    • The stale sweep waits between passes. A new pass starts only when
      pendingSweepAfterMs has passed since the start of the last pass. Thus runs
      that schedule themselves do not ask Wompi about the same payments again and
      again. Two runs at the same time do not get the same payments.
    • The stale sweep has a read limit. It stops when less than 4 MiB of the
      read limit of the transaction remains. Thus large metadata does not make
      the run fail. The limit is not exact for payments with the same creation
      time.
    • Fix: onSubscriptionChange runs for a subscription with no available
      payment source.
      Before, a billing run could move such a subscription to
      past_due or to a final status and not run the callback.

    Removed: the component query payments.listStalePending. The mutation
    payments.claimStalePending replaces it. A host app that calls the query
    directly must change the call.

    The component has a new table, sweepCursors, with one row: the position of
    the sweep. The sweep writes no payment row. The payments table and its
    indexes do not change. No data migration is necessary.

  • #52
    881c382
    Thanks @pulgueta! - Add Nequi subscriptions and
    payment source replacement.

    Nequi subscriptions. subscribe({ type: "NEQUI" }) now accepts a token
    that the customer did not approve yet. The subscription waits as incomplete
    (or trialing), nothing is charged, and the result has
    awaitingApproval: true. The payments webhook now applies
    nequi_token.updated: an approval creates the Wompi payment source and
    charges the first period, and a refusal cancels the subscription with
    lastError. Before, the event was ignored and the charge failed.

    Payment source replacement. The new
    wompi.updateSubscriptionPaymentSource(ctx, { subscriptionId, token, type?, paymentMethod? })
    replaces the source of a live subscription. The period, the trial and the
    dunning counters do not change. A past_due subscription becomes due
    immediately, so the next billing run charges the new source.

    New in api(): updateSubscriptionPaymentSource and getNequiTokenStatus (a
    reactive query for an "approve in your Nequi app" screen). New in
    useWompiTokenizer: tokenizeNequi(phoneNumber).

    The results of subscribe have a new awaitingApproval field.

    Schema. The paymentSources table has three new optional fields,
    tokenId, subscriptionId and activationClaimedAt. wompiSourceId is now
    optional. The new nequiTokens table finds the payment source of a Nequi
    token. No table that exists has a new index, and rows that exist stay valid,
    so no migration is necessary.

Patch Changes

  • #50
    5077436
    Thanks @pulgueta! - Send the Credential-on-File
    flag on subscription charges.

    The initial charge, each renewal and each dunning retry now send the
    recurrent flag to Wompi together with the payment_source_id. The flag is
    true when the amount matches the last approved charge. It is false when
    the amount changes, for example after a plan change.

    For MasterCard and VISA cards on the RBM processor, Wompi marks the charge as
    a stored-credential transaction, which raises the approval rate. Wompi
    processes the charge without the flag when the franchise or the processor does
    not support it.

    One-time checkouts do not change.

  • Updated dependencies
    [9a30116,
    a686f41]:

    • @pulgueta/wompi@3.4.0

@pulgueta/wompi@3.3.0

Choose a tag to compare

@github-actions github-actions released this 18 Aug 23:56
547ba40

Minor Changes

  • #43 2b7012c Thanks @pulgueta! - Support Wompi's second acceptance token: accept_personal_auth on
    createTransaction / createPaymentSource, and presigned_personal_data_auth
    on the merchant response. Both tokens are now required on those two
    inputs — a request without accept_personal_auth is rejected locally with
    Invalid input before anything is sent, matching Wompi's contract. Read the
    token from merchant.presigned_personal_data_auth.acceptance_token and show
    its permalink next to the terms link. Input schemas no longer strip documented fields —
    taxes, ip, recurrent, parent_transaction_id and payment_description
    now reach the API. Payment-source type and status widened for DAVIPLATA,
    BANCOLOMBIA_TRANSFER and VOIDED.

Patch Changes

  • #33 4bd636e Thanks @pulgueta! - Accept payout accounts whose balance is null in live API responses.

@pulgueta/wompi@3.2.0

Choose a tag to compare

@github-actions github-actions released this 22 Jul 23:31
b4f3789

Minor Changes

  • #29 d94b031 Thanks @pulgueta! - Add BRE-B dispersions to WompiPayoutsClient.

    • New resolveBrebKey(keyValue, keyType?) previews the masked holder of a BRE-B key (GET /v2/breb/keys/resolve/{keyValue}) before paying it.
    • createPayout transactions now pay either a bank account or a BRE-B key — mixed batches included — and the batch is routed to /v2/payouts automatically whenever any transaction carries a key.
    • New BrebKeyType, BrebFinancialEntity and BrebKeyResolution schemas/types in @pulgueta/wompi/schemas, plus typed BRE-B payee fields (key, keyType, personType, keyResolutionId, paymentMethodType) on payout transaction.updated webhook events.
  • #28 2c9f33f Thanks @pulgueta! - Add support for Wompi's Pagos a Terceros (Payouts) API — bank account dispersions.

    • New WompiPayoutsClient targeting api.payouts.wompi.co (and its sandbox), authenticated with x-api-key + user-principal-id headers: createPayout (immediate, scheduled and recurring batches, idempotency-key protected), createPayoutFromFile (WOMPI/PAB/SAP/DISFON/BANCO_OCCIDENTE_FC/DAVIVIENDA formats), listPayouts, getPayout, listPayoutTransactions, getPayoutTransaction, listTransactionsByReference, listBanks, listAccounts, getLimits, listReports, getReportDownloadUrl, getHealth and the sandbox-only rechargeAccountBalance.
    • New verifyPayoutEvent, isPayoutUpdatedEvent and isPayoutTransactionUpdatedEvent helpers in @pulgueta/wompi/server to authenticate payout.updated / transaction.updated webhook events.
    • New payout Zod schemas, inferred types and WompiPayoutApiError (carrying the EXC_* code and HTTP status) in @pulgueta/wompi/schemas.

@pulgueta/wompi@3.1.0

Choose a tag to compare

@github-actions github-actions released this 12 Jun 19:56
dbcc9e5

Minor Changes

  • #21 6fa999a Thanks @pulgueta! - Add webhook event verification and Web Checkout URL building to @pulgueta/wompi/server, the two server-side primitives a payments integration needs beyond raw API calls:

    • verifyWebhookEvent(payload, { eventsKey }) — parses and authenticates an event Wompi POSTs to your Events URL. It recomputes the SHA-256 checksum from signature.properties + timestamp + your events secret and compares it in constant time. Returns the SDK's usual Result tuple.
    • computeEventChecksum(event, eventsKey) — the low-level checksum, exposed for custom flows.
    • isTransactionUpdatedEvent(event) — type guard narrowing a verified event to a fully-typed transaction.updated payload.
    • buildCheckoutUrl(options) — builds a https://checkout.wompi.co/p/?… Web Checkout redirect URL, computing the integrity signature for you (or accepting a precomputed one), with support for redirect URL, expiration, customer data, shipping collection and taxes.

    @pulgueta/wompi/schemas now ships the matching schemas and types: WebhookEventSchema, TransactionUpdatedEventSchema, NequiTokenUpdatedEventSchema, WebhookSignatureSchema, their inferred types, and a new WompiWebhookVerificationError (discriminant type: "WEBHOOK_VERIFICATION_ERROR").

    CreateTransactionInputSchema now accepts payment_method and payment_source_id together (previously exactly one was required). Charging a saved card source requires both — Wompi rejects source-only charges with "No se especificó el número de cuotas (installments)" — so the exactly-one refine became at-least-one, and TransactionPaymentMethodSchema gained an optional installments field. Inputs that passed validation before still do; inputs combining both fields are no longer rejected.

    These primitives power the new @pulgueta/wompi-convex component, but work in any runtime with Web Crypto (Node 20+, edge runtimes, Convex).

@pulgueta/wompi@3.0.0

Choose a tag to compare

@github-actions github-actions released this 01 Jun 22:51
131a8e9

Major Changes

  • #16 23008dd Thanks @pulgueta! - Breaking changes

    • The package root (@pulgueta/wompi) now exports only WompiClient. The integrity-signature helper getSignatureKey (and its GetSignatureKeyOptions type) moved to a new @pulgueta/wompi/server subpath, keeping the signing/crypto logic out of client bundles. Zod schemas, inferred types and error classes all live under @pulgueta/wompi/schemas.
    • Client methods now resolve to the entity directly instead of Wompi's { data, meta } envelope. Read response.status, not response.data.status.

    Migration:

    - import { WompiClient, getSignatureKey } from "@pulgueta/wompi";
    + import { WompiClient } from "@pulgueta/wompi";
    + import { getSignatureKey } from "@pulgueta/wompi/server";
    
    - const [error, res] = await wompi.transactions.getTransaction(id);
    - res.data.status;
    + const [error, transaction] = await wompi.transactions.getTransaction(id);
    + transaction.status;

Patch Changes

  • #16 23008dd Thanks @pulgueta! - fix: accept null values in payment-link response fields (sku, expires_at, redirect_url, image_url, customer_data)

    feat: SDK now returns checkout_url on payment-link responses, so callers don't have to build the URL manually

@pulgueta/wompi@2.0.0

Choose a tag to compare

@github-actions github-actions released this 17 May 20:47
cb36aaf

Major Changes

  • #7 f3e011d Thanks @pulgueta! - Overhaul the SDK for type-safety and correctness. This is a breaking release.

    Breaking changes

    • getSignatureKey now takes an options object — { reference, amountInCents, integrityKey, currency?, expirationTime? } — instead of positional arguments. It hashes amountInCents exactly as given (the previous build multiplied it by 100, producing wrong signatures) and throws a WompiError when the amount is not a non-negative integer.
    • voidTransaction resolves to the wrapped void outcome — the voided transaction is nested under data.transaction — or to undefined for an empty 201. Code that read the transaction directly off data must be updated.

    Fixes & improvements

    • Response schemas are lenient: a successful Wompi response is never reported as a validation error. Non-identity fields are optional, unknown fields pass through, and drift-prone enums (payment_method_type, accepted_payment_methods, merchant legal_id_type) accept any string.
    • Empty 2xx bodies are handled — they resolve to undefined instead of failing JSON parsing.
    • PaymentMethodType gains BANCOLOMBIA_BNPL, DAVIPLATA, SU_PLUS and CARD_POS.
    • Input validation is tightened: Zod email/URL formats, an amount_in_cents ceiling, a positive-integer payment_source_id, and a rule requiring exactly one of payment_method / payment_source_id.
    • The Result tuple types its error as the full WompiError union, so consumers can narrow on .type / .statusCode without instanceof.
    • WompiClient is re-exported from the package root (@pulgueta/wompi).

1.0.0 (2024-09-18)

Bug Fixes

Features

  • add initial server features and main class (8f4452f)
  • base classes for requests and client classes for public usage (f31df52)
  • create pse class (6b52a84)
  • create-turbo: apply official-starter transform (cab4332)
  • create-turbo: apply pnpm-eslint transform (4006744)
  • create-turbo: create with-changesets (4e93c73)
  • create-turbo: install dependencies (811bcdc)
  • validate parameters and build the query url from private methods (09af461)

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 18 Sep 04:23

1.0.0 (2024-09-18)

Bug Fixes

Features

  • add initial server features and main class (8f4452f)
  • base classes for requests and client classes for public usage (f31df52)
  • create pse class (6b52a84)
  • create-turbo: apply official-starter transform (cab4332)
  • create-turbo: apply pnpm-eslint transform (4006744)
  • create-turbo: create with-changesets (4e93c73)
  • create-turbo: install dependencies (811bcdc)
  • validate parameters and build the query url from private methods (09af461)