logicsrc/apps/logicsrc-web/src/app/api/webhooks/coinpay/route.ts
Anthony Ettinger f0a9f3890e Migrate logicsrc-web from Vite SPA to Next.js 16 App Router
Replaces the Vite single-page app + custom Node server.js with a Next.js
16.2.6 App Router app.

- proxy.ts (src/proxy.ts): www.logicsrc.com -> logicsrc.com 301 over https,
  preserving path + query (the original request, now via Next 16 Proxy).
- One SSR page via an optional catch-all ([[...slug]]) that renders the same
  marketing/spec page for each known top-level route (/docs, /blog, /openspec,
  ...) and 404s unknown paths, preserving existing canonical URLs. Markup is a
  faithful server-rendered port of the old main.ts (SEO upgrade over the prior
  client render); interactivity (hire-us form, CoinPay button, section scroll)
  moves to a client component.
- API routes ported to app/api/**: hire-us coinpay-checkout + project-request,
  oauth/coinpay start/callback/session, webhooks/coinpay. Shared logic in
  src/lib/coinpay.ts (eligibility, payment-rail selection, webhook verify,
  HMAC session sign/verify, cookies).
- commandboard-api (/health + /api/boards|tasks|plugins/*) is no longer mounted
  in-process; next.config.ts proxies those paths to COMMANDBOARD_API_URL via
  afterFiles rewrites (our own /api routes match first).
- Build/start switch to next build / next start. Contract tests rewritten to
  exercise proxy.ts, the route handlers, and pure helpers directly (21 passing);
  Playwright webServer updated.

Deployment (Railway): set COMMANDBOARD_API_URL to the commandboard-api service
URL and run it as its own service; root start now runs next start.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-07 03:41:48 +00:00

32 lines
1.2 KiB
TypeScript

import type { NextRequest } from "next/server";
import { json } from "@/lib/http";
import { parseJson, verifyCoinPayWebhook } from "@/lib/coinpay";
export const dynamic = "force-dynamic";
// POST /api/webhooks/coinpay — verify the signed CoinPay webhook and acknowledge.
export async function POST(request: NextRequest) {
const webhookSecret = process.env.COINPAY_WEBHOOK_SECRET;
if (!webhookSecret) {
return json({ success: false, error: "CoinPay webhook is not configured" }, 503);
}
const rawBody = await request.text();
const signatureHeader = request.headers.get("x-coinpay-signature");
if (!verifyCoinPayWebhook(rawBody, signatureHeader, webhookSecret)) {
return json({ success: false, error: "Invalid signature" }, 401);
}
const payload = parseJson(rawBody);
const data = payload.data as Record<string, unknown> | undefined;
const paymentId = (data?.payment_id ?? payload.payment_id ?? null) as string | null;
const complete = payload.type === "payment.confirmed" || payload.type === "payment.forwarded";
console.log("[coinpay] webhook received", {
type: payload.type ?? null,
payment_id: paymentId,
complete
});
return json({ received: true, complete, payment_id: paymentId });
}