Check durable file payments against their actual payment method
This commit is contained in:
@@ -436,10 +436,8 @@ where
|
||||
}
|
||||
if !authorized {
|
||||
if let Some(hash) = invoice_hash {
|
||||
if method_accepted(&item.access, "lightning")
|
||||
&& crate::content_invoice::is_paid_for(data_dir, hash, id).await
|
||||
{
|
||||
authorized = true;
|
||||
if let Some(method) = crate::content_invoice::paid_method_for(data_dir, hash, id).await {
|
||||
authorized = method_accepted(&item.access, method.as_str());
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1316,6 +1314,29 @@ mod paid_read_order_tests {
|
||||
);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn durable_payment_uses_its_recorded_method_for_seller_acceptance() {
|
||||
use crate::content_invoice::{record_pending_method, mark_paid, PaymentMethod};
|
||||
for (paid_with, accepted, expected) in [
|
||||
(PaymentMethod::Onchain, "onchain", true),
|
||||
(PaymentMethod::Onchain, "lightning", false),
|
||||
(PaymentMethod::Lightning, "lightning", true),
|
||||
(PaymentMethod::Lightning, "onchain", false),
|
||||
] {
|
||||
let dir = fixture(b"paid bytes").await;
|
||||
let mut catalog = load_catalog(dir.path()).await.unwrap();
|
||||
catalog.items[0].access = AccessControl::Paid { price_sats: 10, accepted: vec![accepted.into()] };
|
||||
save_catalog(dir.path(), &catalog).await.unwrap();
|
||||
record_pending_method(dir.path(), "receipt", "paid", 10, paid_with).await.unwrap();
|
||||
mark_paid(dir.path(), "receipt").await.unwrap();
|
||||
let result = serve_content_with(dir.path(), "paid", None, Some("receipt"), None, None, false,
|
||||
|path, range, mime| prepare_content(dir.path(), path, range, mime),
|
||||
|_, _| async { panic!("must not redeem another payment") }).await.unwrap();
|
||||
if expected { assert!(matches!(result, ServeResult::Ok(bytes, _) if bytes == b"paid bytes")); }
|
||||
else { assert!(matches!(result, ServeResult::PaymentRequired(10))); }
|
||||
}
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn payment_denial_never_returns_prepared_content() {
|
||||
let dir = fixture(b"secret").await;
|
||||
|
||||
Reference in New Issue
Block a user