feat: place PDF artwork in print files, add card payment, count only failed logins
All checks were successful
Build and deploy / Validate source (push) Successful in 6s
Build and deploy / Integration suite on a real stack (push) Successful in 2m23s
Build and deploy / Secret scan and release gate (push) Successful in 5s
Build and deploy / Publish images and notify Portainer (push) Has been skipped
All checks were successful
Build and deploy / Validate source (push) Successful in 6s
Build and deploy / Integration suite on a real stack (push) Successful in 2m23s
Build and deploy / Secret scan and release gate (push) Successful in 5s
Build and deploy / Publish images and notify Portainer (push) Has been skipped
PDF artwork: a single-page PDF source is placed in the print file as a vector form through pikepdf, never rasterised, using the CropBox and inherited /Rotate the Site measured with pdf.js. Multi-page and protected PDFs go to hand preparation. PyMuPDF was not used because of its AGPL licence. Raster tests cover crop, page rotation, placement rotation and mirroring, and fail when the rotation or crop handling is broken. Card payment: Mercado Pago's Card Payment Brick on the Site when MP_PUBLIC_KEY is set; the card becomes a one-time token in Mercado Pago's secure fields. Each card attempt has its own idempotency key, and the intent route refuses new attempts once a payment is approved or a card is in review, so a quote cannot be charged twice. The Site CSP admits Mercado Pago's origins only through PAYMENT_CSP_SOURCES, empty by default. Logins: every attempt counts against the source address, only failures against the account. Counting successful sign-ins let ordinary use lock an operator out and made CI's final browser sign-in fail. No new required settings; production behaviour is unchanged until the provider credentials are configured. Verified with the full CI integration sequence locally. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -137,6 +137,14 @@
|
||||
try { showPix(await api('/payments/intent',{quote_id:draftId,method:{type:'pix'}})); }
|
||||
catch(error) { message(error.message); event.target.disabled=false; }
|
||||
});
|
||||
if ((await ready).payment_public_key) {
|
||||
button('Pagar com cartão',async event=>{
|
||||
if (!quotedCart || quotedCart!==cartSnapshot()) { await refresh(); return; }
|
||||
event.target.disabled=true;
|
||||
try { await showCard(quote.approved.total_cents); }
|
||||
catch(error) { message(error.message); event.target.disabled=false; }
|
||||
});
|
||||
}
|
||||
return;
|
||||
}
|
||||
if ((await ready).environment !== 'local') {
|
||||
@@ -198,6 +206,73 @@
|
||||
} catch(_) {}
|
||||
},5000);
|
||||
}
|
||||
// Card: Mercado Pago's own form (Card Payment Brick). The card is typed into
|
||||
// Mercado Pago's secure fields and becomes a one-time token; the number never
|
||||
// reaches this page's code or our server. As with PIX, the order is created
|
||||
// by the provider's notification, so the page only waits for it.
|
||||
let sdkLoading=null;
|
||||
function loadMercadoPago() {
|
||||
if (window.MercadoPago) return Promise.resolve();
|
||||
sdkLoading = sdkLoading || new Promise((resolve,reject)=>{
|
||||
const script=document.createElement('script');
|
||||
script.src='https://sdk.mercadopago.com/js/v2';
|
||||
script.onload=resolve;
|
||||
script.onerror=()=>{sdkLoading=null;reject(new Error('Não foi possível carregar o formulário do Mercado Pago.'));};
|
||||
document.head.append(script);
|
||||
});
|
||||
return sdkLoading;
|
||||
}
|
||||
let cardBrick=null;
|
||||
async function showCard(totalCents) {
|
||||
await loadMercadoPago();
|
||||
const session=await ready;
|
||||
actions.replaceChildren();
|
||||
const holder=document.createElement('div');
|
||||
holder.id='cardPaymentBrick';
|
||||
holder.style.cssText='max-width:520px;margin-top:8px';
|
||||
actions.append(holder);
|
||||
message('Pagamento com cartão: '+rs(totalCents/100)+'.');
|
||||
if (cardBrick) { try { await cardBrick.unmount(); } catch(_) {} }
|
||||
const mp=new window.MercadoPago(session.payment_public_key,{locale:'pt-BR'});
|
||||
cardBrick=await mp.bricks().create('cardPayment','cardPaymentBrick',{
|
||||
initialization:{amount:totalCents/100, payer:{email:cliente.mail}},
|
||||
customization:{paymentMethods:{maxInstallments:12}},
|
||||
callbacks:{
|
||||
onReady:()=>{},
|
||||
onError:error=>{ console.error(error); message('Erro no formulário do cartão. Confira os dados e tente de novo.'); },
|
||||
onSubmit:async data=>{
|
||||
const result=await api('/payments/intent',{quote_id:draftId,method:{
|
||||
type:'card', token:data.token, payment_method_id:data.payment_method_id,
|
||||
installments:Number(data.installments)||1,
|
||||
issuer_id:data.issuer_id==null?null:String(data.issuer_id)}});
|
||||
if (result.status==='approved' || result.status==='pending') {
|
||||
message(result.status==='approved'
|
||||
? 'Pagamento aprovado. Seu pedido entra na produção em instantes.'
|
||||
: 'Pagamento em análise pelo Mercado Pago. Avisamos assim que for confirmado.');
|
||||
waitForOrder();
|
||||
} else {
|
||||
message('Pagamento recusado pelo Mercado Pago ('+(result.status_detail||result.status)+'). '+
|
||||
'Confira os dados ou use outro cartão.');
|
||||
throw new Error('rejected');
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
}
|
||||
function waitForOrder() {
|
||||
clearInterval(pixTimer);
|
||||
pixTimer=setInterval(async()=>{
|
||||
try {
|
||||
const quote=await api('/quotes/'+draftId);
|
||||
if (quote.status==='paid') {
|
||||
clearInterval(pixTimer);
|
||||
pedido=[]; itemAtual=null; limpaPaineis();
|
||||
await window.dtfClearCart?.();
|
||||
await refresh();
|
||||
}
|
||||
} catch(_) {}
|
||||
},5000);
|
||||
}
|
||||
const quoteFromPortal=new URLSearchParams(location.search).get('quote');
|
||||
if(quoteFromPortal && /^[0-9a-f-]{36}$/.test(quoteFromPortal)){
|
||||
if(draftId!==quoteFromPortal){quotedCart=null;localStorage.removeItem('dtf-quote-cart');}
|
||||
|
||||
Reference in New Issue
Block a user