fix(payment): validate total amount when refunding payment (#8437)
Co-authored-by: Carlos R. L. Rodrigues <37986729+carlos-r-l-rodrigues@users.noreply.github.com>
This commit is contained in:
co-authored by
Carlos R. L. Rodrigues
parent
4b0119f7ce
commit
bcad5052af
+36
-1
@@ -1,12 +1,12 @@
|
|||||||
import { IPaymentModuleService } from "@medusajs/types"
|
import { IPaymentModuleService } from "@medusajs/types"
|
||||||
import { Module, Modules, promiseAll } from "@medusajs/utils"
|
import { Module, Modules, promiseAll } from "@medusajs/utils"
|
||||||
|
import { PaymentModuleService } from "@services"
|
||||||
import { moduleIntegrationTestRunner } from "medusa-test-utils"
|
import { moduleIntegrationTestRunner } from "medusa-test-utils"
|
||||||
import {
|
import {
|
||||||
createPaymentCollections,
|
createPaymentCollections,
|
||||||
createPayments,
|
createPayments,
|
||||||
createPaymentSessions,
|
createPaymentSessions,
|
||||||
} from "../../../__fixtures__"
|
} from "../../../__fixtures__"
|
||||||
import { PaymentModuleService } from "@services"
|
|
||||||
|
|
||||||
jest.setTimeout(30000)
|
jest.setTimeout(30000)
|
||||||
|
|
||||||
@@ -693,6 +693,41 @@ moduleIntegrationTestRunner<IPaymentModuleService>({
|
|||||||
"You cannot refund more than what is captured on the payment."
|
"You cannot refund more than what is captured on the payment."
|
||||||
)
|
)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
it("should throw if total refunded amount is greater than captured amount", async () => {
|
||||||
|
await service.capturePayment({
|
||||||
|
amount: 100,
|
||||||
|
payment_id: "pay-id-1",
|
||||||
|
})
|
||||||
|
|
||||||
|
const refundedPayment1 = await service.refundPayment({
|
||||||
|
amount: 50,
|
||||||
|
payment_id: "pay-id-1",
|
||||||
|
})
|
||||||
|
|
||||||
|
expect(refundedPayment1).toEqual(
|
||||||
|
expect.objectContaining({
|
||||||
|
id: "pay-id-1",
|
||||||
|
amount: 100,
|
||||||
|
refunds: [
|
||||||
|
expect.objectContaining({
|
||||||
|
amount: 50,
|
||||||
|
}),
|
||||||
|
],
|
||||||
|
})
|
||||||
|
)
|
||||||
|
|
||||||
|
const error = await service
|
||||||
|
.refundPayment({
|
||||||
|
amount: 60,
|
||||||
|
payment_id: "pay-id-1",
|
||||||
|
})
|
||||||
|
.catch((e) => e)
|
||||||
|
|
||||||
|
expect(error.message).toEqual(
|
||||||
|
"You cannot refund more than what is captured on the payment."
|
||||||
|
)
|
||||||
|
})
|
||||||
})
|
})
|
||||||
|
|
||||||
describe("cancel", () => {
|
describe("cancel", () => {
|
||||||
|
|||||||
@@ -750,7 +750,7 @@ export default class PaymentModuleService
|
|||||||
"amount",
|
"amount",
|
||||||
"raw_amount",
|
"raw_amount",
|
||||||
],
|
],
|
||||||
relations: ["captures.raw_amount"],
|
relations: ["captures.raw_amount", "refunds.raw_amount"],
|
||||||
},
|
},
|
||||||
sharedContext
|
sharedContext
|
||||||
)
|
)
|
||||||
@@ -763,9 +763,16 @@ export default class PaymentModuleService
|
|||||||
const amountAsBigNumber = new BigNumber(next.raw_amount)
|
const amountAsBigNumber = new BigNumber(next.raw_amount)
|
||||||
return MathBN.add(captureAmount, amountAsBigNumber)
|
return MathBN.add(captureAmount, amountAsBigNumber)
|
||||||
}, MathBN.convert(0))
|
}, MathBN.convert(0))
|
||||||
const refundAmount = new BigNumber(data.amount)
|
const refundedAmount = payment.refunds.reduce((refundedAmount, next) => {
|
||||||
|
return MathBN.add(refundedAmount, next.raw_amount)
|
||||||
|
}, MathBN.convert(0))
|
||||||
|
|
||||||
if (MathBN.lt(capturedAmount, refundAmount)) {
|
const totalRefundedAmount = MathBN.add(
|
||||||
|
refundedAmount,
|
||||||
|
data.amount
|
||||||
|
)
|
||||||
|
|
||||||
|
if (MathBN.lt(capturedAmount, totalRefundedAmount)) {
|
||||||
throw new MedusaError(
|
throw new MedusaError(
|
||||||
MedusaError.Types.INVALID_DATA,
|
MedusaError.Types.INVALID_DATA,
|
||||||
`You cannot refund more than what is captured on the payment.`
|
`You cannot refund more than what is captured on the payment.`
|
||||||
|
|||||||
Reference in New Issue
Block a user