Skip to content

Upgrade to setono/quickpay-php-sdk ^1.2: route operation callbacks to the notify url, read off the SDK's views - #84

Merged
loevgaard merged 1 commit into
2.xfrom
chore/sdk-1.2
Aug 24, 2026
Merged

loevgaard merged 1 commit into
2.xfrom
chore/sdk-1.2

Conversation

@loevgaard

Copy link
Copy Markdown
Member

SDK 1.2.0 ships everything the review asked of it (quickpay-php-sdk#22, #25); this is the mechanical follow-through. Additive on the SDK side, one behavioral gain here.

What changes

  • Operation callbacks now reach the notify token. Capture/Refund/Cancel name the payment's own notify url — the details' callback_url, minted with its link — on every operation (Details::callbackUrl() → the SDK's callbackUrl:, sent as QuickPay-Callback-Url). Quickpay would otherwise report an API-issued operation to the account-wide callback url (empty by default), so a shop that only had the link's url never heard about its captures, refunds and cancels; now they arrive on the same per-payment endpoint, routed by Payum's token, verified by NotifyAction. Verified live through the gateway: e2e:operate refund → callback delivered to the token url within a second, callback_success: true / 200 recorded on the operation, listener logs CALLBACK OK via=token. A payment that never went through the window here has no url to name — Quickpay's default applies (test). The account-wide url is now only for operations made outside the gateway (manager, raw API); README/UPGRADE/CLAUDE.md/e2e docs rewritten accordingly (the "two callback urls" section shrinks to that).
  • Operations is gone. The actions read Payment::latestApprovedOperation() / latestOperationOfType() / hasApprovedOperation(type) / hasPendingOperation(type) and Operation::isDeclined() straight off the DTOs; CaptureAction reads the typed Link::$autoCapture instead of raw['link']. "Latest" is the highest operation id, defined once in the SDK — which exposed that both test fixture builders handed every operation id => 1; they now number operations like Quickpay does (one integration-test assertion was passing by accident of list order).
  • Order id rule. Convert checks the order id against the SDK's real rule (CreatePaymentRequest::ORDER_ID_PATTERN: 4–20 of [A-Za-z0-9 ._-]) — still first, still naming the order_prefix and the number — so a character Quickpay rejects (/ # : @ …) fails locally with the cause instead of after a round trip.

Not changed

Api::getPaymentMethods() stays a normalized string (the SDK's list support on CreateLinkRequest isn't needed — our normalization also validates and trims); OperationPendingException's scan is unchanged (it never used Operations).

composer all, the dependency analyser, composer validate/normalize green (367 tests).

…e notify url, read off the SDK's views

SDK 1.2.0 ships everything the review asked of it (quickpay-php-sdk#22,
#25), so this is the mechanical follow-through:

- Capture/Refund/Cancel name the payment's own notify url — the
  details' callback_url, minted when its link was created — on every
  operation (Details::callbackUrl() → the SDK's `callbackUrl:`, sent as
  QuickPay-Callback-Url). Quickpay would otherwise report an API-issued
  operation to the account-wide callback url, empty by default, so a
  shop that only had the link's url never heard about its captures,
  refunds and cancels. Now their callbacks arrive on the same
  per-payment endpoint as the payment window's, routed by Payum's token.
  Verified live through the gateway: e2e:operate refund → the callback
  delivered to the token url within a second, `callback_success: true`
  and 200 recorded on the operation. A payment that never went through
  the window here has no url to name; Quickpay's default applies. The
  account-wide url is now only for operations made outside the gateway;
  the docs say so.
- The package's Operations helper is gone: the actions read
  Payment::latestApprovedOperation() / latestOperationOfType() /
  hasApprovedOperation(type) / hasPendingOperation(type) and
  Operation::isDeclined() straight off the DTOs. "Latest" is the highest
  operation id, defined once in the SDK — the test fixtures now number
  operations like Quickpay does, where they used to hand every operation
  id 1 and left that decision to accident.
- CaptureAction reads the typed Link::$autoCapture instead of the raw
  payload.
- ConvertPaymentAction checks the order id against the SDK's real rule
  (CreatePaymentRequest::ORDER_ID_PATTERN: 4–20 of letters, digits,
  space, ".", "_", "-"), still first and still naming the prefix and the
  number, so a character Quickpay rejects fails locally with the cause.

Docs: README (Callbacks, details table, Sylius), UPGRADE-2.0.md (the
callback section rewritten, order-id rule), CLAUDE.md, e2e README and
listen.php.
@codecov

codecov Bot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.53%. Comparing base (0a0b832) to head (471e344).

Additional details and impacted files
@@             Coverage Diff              @@
##                2.x      #84      +/-   ##
============================================
- Coverage     98.60%   98.53%   -0.07%     
+ Complexity      220      203      -17     
============================================
  Files            20       19       -1     
  Lines           572      545      -27     
============================================
- Hits            564      537      -27     
  Misses            8        8              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@loevgaard
loevgaard merged commit 4014384 into 2.x Aug 24, 2026
21 checks passed
@loevgaard
loevgaard deleted the chore/sdk-1.2 branch August 24, 2026 07:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant