Files
accounted/app/api/stripe/webhook/route.ts
T
Jakob Wennberg ec27228a8e style: remove em/en dashes repo-wide, add CLAUDE.md rule against them (#890)
Em dashes (—) and en dashes (–) had spread across comments, docs, tests,
and a few UI strings, reading as AI-generated boilerplate rather than
house style. Replaced each with punctuation matching its context: colon
for explanatory clauses, comma for asides, plain hyphen for numeric/legal
ranges (e.g. "21-23§"), "to"/"till" for date ranges, parentheses for
paired-dash asides. messages/en.json and messages/sv.json were fixed by
hand together to keep sv/en in sync.

Left untouched where the dash is the functional subject rather than
decorative punctuation: date-range-parser.ts's separator regex,
charset-repair.ts's CP1252 byte-mapping table (and its test), the SIE
encoding mojibake docs, generic-csv.ts's minus-sign normalizer, the
agent system-prompt files that already instruct against em dashes, and
a golden iXBRL test fixture compared byte-for-byte.

Also fixes two bugs surfaced along the way: an off-by-one in
ApiKeysPanel's scope-label split (a leftover from an earlier partial
pass), and a charset-repair test that had lost the literal en-dash it
exists to verify.

Regenerated the agent atom seed migration (skills:generate) since 27
SKILL.md files changed. Added a CLAUDE.md rule against em/en dashes,
with an explicit carve-out for the functional-dash cases above.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04 15:58:06 +02:00

59 lines
2.2 KiB
TypeScript

import { NextResponse } from 'next/server'
import type Stripe from 'stripe'
import { getStripe } from '@/lib/stripe/client'
import { createServiceClient } from '@/lib/supabase/server'
import { handleStripeEvent } from '@/lib/stripe/subscription-sync'
// Unauthenticated by design: authenticity comes from the Stripe signature, not
// a session. The route reads the RAW body (req.text()); parsing as JSON first
// would change the byte representation and break signature verification.
export async function POST(request: Request) {
const secret = process.env.STRIPE_WEBHOOK_SECRET
if (!secret) {
return NextResponse.json({ error: 'Webhook not configured' }, { status: 500 })
}
const sig = request.headers.get('stripe-signature')
if (!sig) {
return NextResponse.json({ error: 'Missing signature' }, { status: 400 })
}
const rawBody = await request.text()
let event: Stripe.Event
try {
event = getStripe().webhooks.constructEvent(rawBody, sig, secret)
} catch {
return NextResponse.json({ error: 'Invalid signature' }, { status: 400 })
}
const service = createServiceClient()
// Idempotency: skip events we've already fully processed. The handler itself
// is idempotent too (upserts), so a concurrent double-delivery is also safe.
const { data: already } = await service
.from('stripe_webhook_events')
.select('event_id')
.eq('event_id', event.id)
.maybeSingle()
if (already) {
return NextResponse.json({ received: true, duplicate: true })
}
try {
await handleStripeEvent(service, getStripe(), event)
// Mark processed only AFTER success, so a failure lets Stripe retry.
await service.from('stripe_webhook_events').insert({ event_id: event.id, type: event.type })
} catch (err) {
// Log with context before the generic 500 so a failing webhook is visible
// to operators (Stripe will retry on the non-2xx).
console.error('[stripe-webhook] processing failed', {
eventId: event.id,
type: event.type,
error: err instanceof Error ? err.message : String(err),
})
return NextResponse.json({ error: 'processing_failed' }, { status: 500 })
}
return NextResponse.json({ received: true })
}