rebours/server.mjs
2026-02-27 18:37:58 +01:00

122 lines
4.7 KiB
JavaScript

import Fastify from 'fastify'
import cors from '@fastify/cors'
import Stripe from 'stripe'
import dotenv from 'dotenv'
dotenv.config()
const stripe = new Stripe(process.env.STRIPE_SECRET_KEY ?? '')
const DOMAIN = process.env.DOMAIN ?? 'http://localhost:4321'
const PRODUCTS = {
lumiere_orbitale: {
price_id: 'price_1T5SBlE5wMMoCUP5ZcjEStwe',
},
}
const app = Fastify({ logger: true })
await app.register(cors, { origin: '*', methods: ['GET', 'POST'] })
// ── SEO ───────────────────────────────────────────────────────────────────────
app.get('/robots.txt', (_, reply) => {
reply
.type('text/plain')
.header('Cache-Control', 'public, max-age=86400')
.send(`User-agent: *\nAllow: /\nSitemap: ${DOMAIN}/sitemap.xml\n`)
})
app.get('/sitemap.xml', (_, reply) => {
const today = new Date().toISOString().split('T')[0]
reply
.type('application/xml')
.header('Cache-Control', 'public, max-age=86400')
.send(
`<?xml version="1.0" encoding="UTF-8"?>\n<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">\n <url><loc>${DOMAIN}/</loc><lastmod>${today}</lastmod><changefreq>weekly</changefreq><priority>1.0</priority></url>\n</urlset>`
)
})
// ── Checkout Stripe ───────────────────────────────────────────────────────────
app.post('/api/checkout', async (request, reply) => {
const { product, email } = request.body ?? {}
const p = PRODUCTS[product]
if (!p) return reply.code(404).send({ error: 'Produit inconnu' })
app.log.info(`Stripe key prefix: ${process.env.STRIPE_SECRET_KEY?.slice(0, 20)}`)
app.log.info(`Price ID: ${p.price_id}`)
let session
try {
session = await stripe.checkout.sessions.create({
mode: 'payment',
payment_method_types: ['card', 'link'],
line_items: [{
price: p.price_id,
quantity: 1,
}],
metadata: { product },
success_url: `${DOMAIN}/success?session_id={CHECKOUT_SESSION_ID}`,
cancel_url: `${DOMAIN}/#collection`,
locale: 'fr',
customer_email: email ?? undefined,
custom_text: {
submit: { message: 'Pièce unique — fabriquée à Paris. Délai : 6 à 8 semaines.' },
},
})
} catch (err) {
app.log.error(err)
return reply.code(500).send({ error: err.message })
}
return { url: session.url }
})
// ── Vérification session ──────────────────────────────────────────────────────
app.get('/api/session/:id', async (request) => {
const session = await stripe.checkout.sessions.retrieve(request.params.id, {
expand: ['payment_intent.latest_charge'],
})
const charge = session.payment_intent?.latest_charge
return {
status: session.payment_status,
amount: session.amount_total,
currency: session.currency,
customer_email: session.customer_details?.email ?? null,
product: session.metadata?.product ?? null,
receipt_url: charge?.receipt_url ?? null,
}
})
// ── Webhook Stripe ────────────────────────────────────────────────────────────
app.post('/api/webhook', {
config: { rawBody: true },
onRequest: (request, reply, done) => {
request.rawBody = ''
request.req.on('data', chunk => { request.rawBody += chunk })
request.req.on('end', done)
},
}, async (request, reply) => {
const sig = request.headers['stripe-signature']
const webhookSecret = process.env.STRIPE_WEBHOOK_SECRET
if (!sig || !webhookSecret) return reply.code(400).send('Missing signature')
let event
try {
event = stripe.webhooks.constructEvent(request.rawBody, sig, webhookSecret)
} catch {
return reply.code(400).send('Webhook Error')
}
if (event.type === 'checkout.session.completed') {
const session = event.data.object
if (session.payment_status === 'paid') {
app.log.info(`✓ Paiement — ${session.id}${session.customer_details?.email}`)
}
}
return { received: true }
})
// ── Start ─────────────────────────────────────────────────────────────────────
try {
await app.listen({ port: process.env.PORT ?? 3000, host: '127.0.0.1' })
} catch (err) {
app.log.error(err)
process.exit(1)
}