Files
famous-ly4-ev/app-modules/payment/routes/payment-routes.php
T

19 lines
997 B
PHP
Raw Normal View History

2026-08-04 22:23:54 +07:00
<?php
use Illuminate\Support\Facades\Route;
use Modules\Payment\Http\Controllers\PaymentController;
use Modules\Payment\Http\Controllers\PaymentWebhookController;
use Modules\Payment\Http\Controllers\RefundController;
2026-08-16 23:50:39 +07:00
Route::prefix('api/v1')->middleware(['api', 'api.auth', 'throttle:api-write'])->group(function () {
Route::post('/payments/{booking:booking_ref}/initiate', [PaymentController::class, 'initiate'])->name('payment.payments.initiate');
Route::post('/bookings/{booking:booking_ref}/refund', [RefundController::class, 'refund'])->name('payment.bookings.refund');
});
// No auth:sanctum — the gateway authenticates itself via its own signed
// payload (verified inside each gateway's handleWebhook()), not a bearer
// token (domain.md §6).
Route::prefix('api/v1')->middleware(['api', 'throttle:api-webhooks'])->group(function () {
Route::post('/webhooks/{method}/{encryptBookingId?}', [PaymentWebhookController::class, 'handle'])->name('payment.webhooks.handle');
});