feat: let production select Mercado Pago and acknowledge simulated notifications

The production compose hard-coded the fake payment adapter; it now takes
PAYMENT_ADAPTER and the MP_* settings from the stack's environment, so the
sandbox can run with test credentials. A signed notification about a payment
Mercado Pago does not have, such as the panel's "Simular notificação", is
acknowledged instead of answering 500 and being retried; any other lookup
failure still raises.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-28 10:41:18 -03:00
parent 60b7336b37
commit bd56170248
4 changed files with 40 additions and 5 deletions

View File

@@ -19,10 +19,20 @@ x-app-environment: &app-environment
# this value is configured.
OPERATOR_EMAIL: ${OPERATOR_EMAIL:-}
OPERATOR_PASSWORD: ${OPERATOR_PASSWORD:?set OPERATOR_PASSWORD}
PAYMENT_ADAPTER: fake
# Optional: without it the webhook verifies nothing and therefore accepts
# nothing, which is the correct state until a provider is connected. Set it
# when the provider is configured, never to a value anyone could guess.
# fake until Mercado Pago is configured; mercadopago requires MP_ACCESS_TOKEN
# and MP_WEBHOOK_SECRET or the API and worker refuse to start. Test
# credentials (TEST-...) until the sandbox flows have passed. The card form
# appears only with MP_PUBLIC_KEY, and then needs PAYMENT_CSP_SOURCES too.
PAYMENT_ADAPTER: ${PAYMENT_ADAPTER:-fake}
MP_ACCESS_TOKEN: ${MP_ACCESS_TOKEN:-}
# The "assinatura secreta" from the webhook settings in Mercado Pago.
MP_WEBHOOK_SECRET: ${MP_WEBHOOK_SECRET:-}
# https://<SITE_DOMAIN>/api/payments/webhook, sent with every payment.
MP_NOTIFICATION_URL: ${MP_NOTIFICATION_URL:-}
MP_PUBLIC_KEY: ${MP_PUBLIC_KEY:-}
# The fake adapter's secret. Optional: without it the webhook verifies
# nothing and therefore accepts nothing, which is the correct state until a
# provider is connected. Never set it to a value anyone could guess.
PAYMENT_WEBHOOK_SECRET: ${PAYMENT_WEBHOOK_SECRET:-}
FREIGHT_ADAPTER: fake
# Order creation in Tiny stays off until it has been tested against the