Repository navigation
Releases: pulgueta/wompi-node
Release list
@pulgueta/wompi@3.4.0
Minor Changes
-
#49
9a30116Thanks @pulgueta! - Add a typed error for gateway and availability failures.A
502,503or504response, or a5xxresponse with a body that is not
JSON (an HTML error page), now returns aWompiServiceUnavailableError. It has
type: "SERVICE_UNAVAILABLE_ERROR",statusCodeandretryable: true.The new
isGatewayError(error)guard from@pulgueta/wompi/schemasis true for
this error, and for aWompiRequestErrororWompiPayoutApiErrorwith a502,
503or504status code.WompiServiceUnavailableErrorextendsWompiRequestError, so code that reads
statusCodefrom aWompiRequestErrorcontinues to operate. A structured
Payouts API error stays aWompiPayoutApiError.
Patch Changes
-
#48
a686f41Thanks @pulgueta! - Send the private key ongetTransaction, as the Wompi API now requires.Wompi accepts
GET /transactions/{id}only with the private key. A lookup
without it returns404 Not Found, so the SDK reported aWompiNotFoundError
for transactions that exist.getTransactionnow sendsAuthorization: Bearer <privateKey>. A client
withoutprivateKeygets[WompiError("Private key is required for this operation"), null]and sends no request. CallgetTransactionfrom your
server.
@pulgueta/wompi-convex@0.5.0
Minor Changes
-
#53
f731ada
Thanks @pulgueta! - Remove the scale limits of
the billing engine and document the ones that stay.- Charges run in parallel.
processBillingkeeps five Wompi requests in
flight at the same time. Before, it charged one subscription at a time. - The cron does not wait for a result. A renewal that Wompi keeps
PENDINGkeeps its transaction id. The webhook or the next run resolves it.
Before, each pending renewal added two waits ofpollIntervalMsto the run.
subscribeandconfirmTransactioncontinue to poll. ProcessBillingSummary.remaining. It istruewhen the run left due
subscriptions or stale payments for an immediate next run. The README shows
an action that schedules itself with it.- The stale sweep rotates. Each run continues after the last payment that
the previous run visited, oldest first. At the end of the stale payments,
the pass is complete. Before, it read the 50 oldest pending payments in each
run, so payments that stayed pending kept all later ones out of reach. An
abandoned checkout that cannot expire yet does not use a place in the batch. - The stale sweep waits between passes. A new pass starts only when
pendingSweepAfterMshas passed since the start of the last pass. Thus runs
that schedule themselves do not ask Wompi about the same payments again and
again. Two runs at the same time do not get the same payments. - The stale sweep has a read limit. It stops when less than 4 MiB of the
read limit of the transaction remains. Thus largemetadatadoes not make
the run fail. The limit is not exact for payments with the same creation
time. - Fix:
onSubscriptionChangeruns for a subscription with no available
payment source. Before, a billing run could move such a subscription to
past_dueor to a final status and not run the callback.
Removed: the component query
payments.listStalePending. The mutation
payments.claimStalePendingreplaces it. A host app that calls the query
directly must change the call.The component has a new table,
sweepCursors, with one row: the position of
the sweep. The sweep writes no payment row. Thepaymentstable and its
indexes do not change. No data migration is necessary. - Charges run in parallel.
-
#52
881c382
Thanks @pulgueta! - Add Nequi subscriptions and
payment source replacement.Nequi subscriptions.
subscribe({ type: "NEQUI" })now accepts a token
that the customer did not approve yet. The subscription waits asincomplete
(ortrialing), nothing is charged, and the result has
awaitingApproval: true. The payments webhook now applies
nequi_token.updated: an approval creates the Wompi payment source and
charges the first period, and a refusal cancels the subscription with
lastError. Before, the event was ignored and the charge failed.Payment source replacement. The new
wompi.updateSubscriptionPaymentSource(ctx, { subscriptionId, token, type?, paymentMethod? })
replaces the source of a live subscription. The period, the trial and the
dunning counters do not change. Apast_duesubscription becomes due
immediately, so the next billing run charges the new source.New in
api():updateSubscriptionPaymentSourceandgetNequiTokenStatus(a
reactive query for an "approve in your Nequi app" screen). New in
useWompiTokenizer:tokenizeNequi(phoneNumber).The results of
subscribehave a newawaitingApprovalfield.Schema. The
paymentSourcestable has three new optional fields,
tokenId,subscriptionIdandactivationClaimedAt.wompiSourceIdis now
optional. The newnequiTokenstable finds the payment source of a Nequi
token. No table that exists has a new index, and rows that exist stay valid,
so no migration is necessary.
Patch Changes
-
#50
5077436
Thanks @pulgueta! - Send the Credential-on-File
flag on subscription charges.The initial charge, each renewal and each dunning retry now send the
recurrentflag to Wompi together with thepayment_source_id. The flag is
truewhen the amount matches the last approved charge. It isfalsewhen
the amount changes, for example after a plan change.For MasterCard and VISA cards on the RBM processor, Wompi marks the charge as
a stored-credential transaction, which raises the approval rate. Wompi
processes the charge without the flag when the franchise or the processor does
not support it.One-time checkouts do not change.
-
Updated dependencies
[9a30116,
a686f41]:- @pulgueta/wompi@3.4.0
@pulgueta/wompi@3.3.0
Minor Changes
- #43
2b7012cThanks @pulgueta! - Support Wompi's second acceptance token:accept_personal_authon
createTransaction/createPaymentSource, andpresigned_personal_data_auth
on the merchant response. Both tokens are now required on those two
inputs — a request withoutaccept_personal_authis rejected locally with
Invalid inputbefore anything is sent, matching Wompi's contract. Read the
token frommerchant.presigned_personal_data_auth.acceptance_tokenand show
itspermalinknext to the terms link. Input schemas no longer strip documented fields —
taxes,ip,recurrent,parent_transaction_idandpayment_description
now reach the API. Payment-sourcetypeandstatuswidened forDAVIPLATA,
BANCOLOMBIA_TRANSFERandVOIDED.
Patch Changes
@pulgueta/wompi@3.2.0
Minor Changes
-
#29
d94b031Thanks @pulgueta! - Add BRE-B dispersions toWompiPayoutsClient.- New
resolveBrebKey(keyValue, keyType?)previews the masked holder of a BRE-B key (GET /v2/breb/keys/resolve/{keyValue}) before paying it. createPayouttransactions now pay either a bank account or a BRE-Bkey— mixed batches included — and the batch is routed to/v2/payoutsautomatically whenever any transaction carries akey.- New
BrebKeyType,BrebFinancialEntityandBrebKeyResolutionschemas/types in@pulgueta/wompi/schemas, plus typed BRE-B payee fields (key,keyType,personType,keyResolutionId,paymentMethodType) on payouttransaction.updatedwebhook events.
- New
-
#28
2c9f33fThanks @pulgueta! - Add support for Wompi's Pagos a Terceros (Payouts) API — bank account dispersions.- New
WompiPayoutsClienttargetingapi.payouts.wompi.co(and its sandbox), authenticated withx-api-key+user-principal-idheaders:createPayout(immediate, scheduled and recurring batches, idempotency-key protected),createPayoutFromFile(WOMPI/PAB/SAP/DISFON/BANCO_OCCIDENTE_FC/DAVIVIENDA formats),listPayouts,getPayout,listPayoutTransactions,getPayoutTransaction,listTransactionsByReference,listBanks,listAccounts,getLimits,listReports,getReportDownloadUrl,getHealthand the sandbox-onlyrechargeAccountBalance. - New
verifyPayoutEvent,isPayoutUpdatedEventandisPayoutTransactionUpdatedEventhelpers in@pulgueta/wompi/serverto authenticatepayout.updated/transaction.updatedwebhook events. - New payout Zod schemas, inferred types and
WompiPayoutApiError(carrying theEXC_*code and HTTP status) in@pulgueta/wompi/schemas.
- New
@pulgueta/wompi@3.1.0
Minor Changes
-
#21
6fa999aThanks @pulgueta! - Add webhook event verification and Web Checkout URL building to@pulgueta/wompi/server, the two server-side primitives a payments integration needs beyond raw API calls:verifyWebhookEvent(payload, { eventsKey })— parses and authenticates an event Wompi POSTs to your Events URL. It recomputes the SHA-256 checksum fromsignature.properties+timestamp+ your events secret and compares it in constant time. Returns the SDK's usualResulttuple.computeEventChecksum(event, eventsKey)— the low-level checksum, exposed for custom flows.isTransactionUpdatedEvent(event)— type guard narrowing a verified event to a fully-typedtransaction.updatedpayload.buildCheckoutUrl(options)— builds ahttps://checkout.wompi.co/p/?…Web Checkout redirect URL, computing the integrity signature for you (or accepting a precomputed one), with support for redirect URL, expiration, customer data, shipping collection and taxes.
@pulgueta/wompi/schemasnow ships the matching schemas and types:WebhookEventSchema,TransactionUpdatedEventSchema,NequiTokenUpdatedEventSchema,WebhookSignatureSchema, their inferred types, and a newWompiWebhookVerificationError(discriminanttype: "WEBHOOK_VERIFICATION_ERROR").CreateTransactionInputSchemanow acceptspayment_methodandpayment_source_idtogether (previously exactly one was required). Charging a saved card source requires both — Wompi rejects source-only charges with "No se especificó el número de cuotas (installments)" — so the exactly-one refine became at-least-one, andTransactionPaymentMethodSchemagained an optionalinstallmentsfield. Inputs that passed validation before still do; inputs combining both fields are no longer rejected.These primitives power the new
@pulgueta/wompi-convexcomponent, but work in any runtime with Web Crypto (Node 20+, edge runtimes, Convex).
@pulgueta/wompi@3.0.0
Major Changes
-
#16
23008ddThanks @pulgueta! - Breaking changes- The package root (
@pulgueta/wompi) now exports onlyWompiClient. The integrity-signature helpergetSignatureKey(and itsGetSignatureKeyOptionstype) moved to a new@pulgueta/wompi/serversubpath, keeping the signing/crypto logic out of client bundles. Zod schemas, inferred types and error classes all live under@pulgueta/wompi/schemas. - Client methods now resolve to the entity directly instead of Wompi's
{ data, meta }envelope. Readresponse.status, notresponse.data.status.
Migration:
- import { WompiClient, getSignatureKey } from "@pulgueta/wompi"; + import { WompiClient } from "@pulgueta/wompi"; + import { getSignatureKey } from "@pulgueta/wompi/server"; - const [error, res] = await wompi.transactions.getTransaction(id); - res.data.status; + const [error, transaction] = await wompi.transactions.getTransaction(id); + transaction.status;
- The package root (
Patch Changes
@pulgueta/wompi@2.0.0
Major Changes
-
#7
f3e011dThanks @pulgueta! - Overhaul the SDK for type-safety and correctness. This is a breaking release.Breaking changes
getSignatureKeynow takes an options object —{ reference, amountInCents, integrityKey, currency?, expirationTime? }— instead of positional arguments. It hashesamountInCentsexactly as given (the previous build multiplied it by 100, producing wrong signatures) and throws aWompiErrorwhen the amount is not a non-negative integer.voidTransactionresolves to the wrapped void outcome — the voided transaction is nested underdata.transaction— or toundefinedfor an empty201. Code that read the transaction directly offdatamust be updated.
Fixes & improvements
- Response schemas are lenient: a successful Wompi response is never reported as a validation error. Non-identity fields are optional, unknown fields pass through, and drift-prone enums (
payment_method_type,accepted_payment_methods, merchantlegal_id_type) accept any string. - Empty
2xxbodies are handled — they resolve toundefinedinstead of failing JSON parsing. PaymentMethodTypegainsBANCOLOMBIA_BNPL,DAVIPLATA,SU_PLUSandCARD_POS.- Input validation is tightened: Zod email/URL formats, an
amount_in_centsceiling, a positive-integerpayment_source_id, and a rule requiring exactly one ofpayment_method/payment_source_id. - The
Resulttuple types its error as the fullWompiErrorunion, so consumers can narrow on.type/.statusCodewithoutinstanceof. WompiClientis re-exported from the package root (@pulgueta/wompi).
1.0.0 (2024-09-18)
Bug Fixes
- build script (6a09f7a)
- ci: add permission (630330f)
- ci: add required permissions (48a73d0)
- ci: concurrency issue (ae763a5)
- ci: pnpm version (51438ab)
- ci: remove github wd (5de8a0c)
- ci: remove working directory (7e53cd1)
- cI: setup file (ee1bbaa)
- move changeset to core package (40ba198)
Features
- add initial server features and main class (8f4452f)
- base classes for requests and client classes for public usage (f31df52)
- create pse class (6b52a84)
- create-turbo: apply official-starter transform (cab4332)
- create-turbo: apply pnpm-eslint transform (4006744)
- create-turbo: create with-changesets (4e93c73)
- create-turbo: install dependencies (811bcdc)
- validate parameters and build the query url from private methods (09af461)
v1.0.0
1.0.0 (2024-09-18)
Bug Fixes
- build script (6a09f7a)
- ci: add permission (630330f)
- ci: add required permissions (48a73d0)
- ci: concurrency issue (ae763a5)
- ci: pnpm version (51438ab)
- ci: remove github wd (5de8a0c)
- ci: remove working directory (7e53cd1)
- cI: setup file (ee1bbaa)
- move changeset to core package (40ba198)
Features
- add initial server features and main class (8f4452f)
- base classes for requests and client classes for public usage (f31df52)
- create pse class (6b52a84)
- create-turbo: apply official-starter transform (cab4332)
- create-turbo: apply pnpm-eslint transform (4006744)
- create-turbo: create with-changesets (4e93c73)
- create-turbo: install dependencies (811bcdc)
- validate parameters and build the query url from private methods (09af461)