diff --git a/src/business-settings/business-settings.util.ts b/src/business-settings/business-settings.util.ts index f192585..e83c1dc 100644 --- a/src/business-settings/business-settings.util.ts +++ b/src/business-settings/business-settings.util.ts @@ -370,7 +370,17 @@ export function listPublicPaymentGateways(settings: EPaymentSettings) { }; } -const PAYMENT_PROCESS_STEP_IDS = ['awaiting-payment', 'payment-successful'] as const; +/** System-managed payment steps — set by gateway callbacks, not admin UI. */ +export const PAYMENT_PROCESS_STEP_IDS = [ + 'awaiting-payment', + 'payment-successful', +] as const; + +export type PaymentProcessStepId = (typeof PAYMENT_PROCESS_STEP_IDS)[number]; + +export function isSystemPaymentProcessStep(stepId: string): boolean { + return (PAYMENT_PROCESS_STEP_IDS as readonly string[]).includes(stepId); +} /** Prepend default payment steps when an older store settings JSON omits them. */ function ensurePaymentProcessSteps(steps: OrderProcessStep[]): OrderProcessStep[] { diff --git a/src/orders/orders.service.ts b/src/orders/orders.service.ts index ed4370b..ff72d5c 100644 --- a/src/orders/orders.service.ts +++ b/src/orders/orders.service.ts @@ -15,6 +15,7 @@ import { } from '@prisma/client'; import { AuthUser } from '../auth/auth.types'; import { BusinessSettingsService } from '../business-settings/business-settings.service'; +import { isSystemPaymentProcessStep } from '../business-settings/business-settings.util'; import { PermissionsService } from '../auth/permissions.service'; import { PrismaService } from '../prisma/prisma.service'; import { @@ -764,6 +765,12 @@ export class OrdersService { } private async assertValidProcessStepId(businessId: bigint, processStepId: string) { + if (isSystemPaymentProcessStep(processStepId)) { + throw new BadRequestException( + 'Payment steps are set automatically by the payment gateway and cannot be changed manually', + ); + } + const steps = await this.businessSettings.getOrderProcessSteps(businessId); const valid = steps.some((step) => step.id === processStepId); if (!valid) {