From cd0dd91ab93653631904f2ea0e574ccde6d60339 Mon Sep 17 00:00:00 2001 From: Chia Date: Wed, 5 Aug 2026 14:48:00 +1200 Subject: add passkey, totp. --- internal/billing/service_test.go | 12 ++++++++++++ 1 file changed, 12 insertions(+) (limited to 'internal/billing/service_test.go') diff --git a/internal/billing/service_test.go b/internal/billing/service_test.go index 17f8143..f675da7 100644 --- a/internal/billing/service_test.go +++ b/internal/billing/service_test.go @@ -85,6 +85,18 @@ func TestIntegrationIdentifierSuffixUsesLetters(t *testing.T) { } } +func TestCheckoutReturnURLPreservesCallbackAndSessionPlaceholder(t *testing.T) { + success := checkoutReturnURL("https://console.example.test/admin/?topup=success", "order-123", true) + if !strings.Contains(success, "topup=success") || !strings.Contains(success, "order_id=order-123") || + !strings.Contains(success, "session_id={CHECKOUT_SESSION_ID}") { + t.Fatalf("unexpected success URL %q", success) + } + cancel := checkoutReturnURL("https://console.example.test/admin/?topup=cancel&session_id=stale", "order-123", false) + if !strings.Contains(cancel, "topup=cancel") || !strings.Contains(cancel, "order_id=order-123") || strings.Contains(cancel, "session_id=") { + t.Fatalf("unexpected cancel URL %q", cancel) + } +} + func TestWebhookRejectsInvalidSignatureBeforeProcessing(t *testing.T) { service := &Service{stripeWebhookSecret: "whsec_test"} request := httptest.NewRequest(http.MethodPost, "/billing/stripe/webhook", strings.NewReader(`{"id":"evt_fake"}`)) -- cgit v1.2.3