|
| 1 | +package com.getpayin.paylink; |
| 2 | + |
| 3 | +import static org.junit.jupiter.api.Assertions.assertEquals; |
| 4 | + |
| 5 | +import com.getpayin.paylink.internal.FieldOrders; |
| 6 | +import com.getpayin.paylink.internal.SignedBody; |
| 7 | +import com.getpayin.paylink.model.CreateInvoiceParams; |
| 8 | +import java.util.Map; |
| 9 | +import org.junit.jupiter.api.Test; |
| 10 | + |
| 11 | +/** |
| 12 | + * The optional {@code iframe} field is sent in the body (coerced to {@code "1"}/{@code "0"}) |
| 13 | + * but excluded from the HMAC signature, exactly like {@code payment_mode}. |
| 14 | + */ |
| 15 | +class IframeOptionTest { |
| 16 | + |
| 17 | + private static final String PUBLIC_TOKEN = "pub_token"; |
| 18 | + private static final String HASH_TOKEN = "test_hash_token_abc123"; |
| 19 | + |
| 20 | + private static CreateInvoiceParams baseParams() { |
| 21 | + return new CreateInvoiceParams() |
| 22 | + .firstName("John").lastName("Doe").email("john@example.com") |
| 23 | + .orderTitle("Gold Plan").orderAmount("250.00").currency("USD"); |
| 24 | + } |
| 25 | + |
| 26 | + @Test |
| 27 | + void iframeTrueSerializesToOneInBody() { |
| 28 | + Map<String, String> body = SignedBody.build( |
| 29 | + FieldOrders.INVOICE_CREATE, baseParams().iframe(true).fields(), PUBLIC_TOKEN, HASH_TOKEN); |
| 30 | + |
| 31 | + assertEquals("1", body.get("iframe")); |
| 32 | + } |
| 33 | + |
| 34 | + @Test |
| 35 | + void iframeFalseSerializesToZeroInBody() { |
| 36 | + Map<String, String> body = SignedBody.build( |
| 37 | + FieldOrders.INVOICE_CREATE, baseParams().iframe(false).fields(), PUBLIC_TOKEN, HASH_TOKEN); |
| 38 | + |
| 39 | + assertEquals("0", body.get("iframe")); |
| 40 | + } |
| 41 | + |
| 42 | + @Test |
| 43 | + void iframeIsUnsignedSoItDoesNotChangeTheSignature() { |
| 44 | + Map<String, String> without = SignedBody.build( |
| 45 | + FieldOrders.INVOICE_CREATE, baseParams().fields(), PUBLIC_TOKEN, HASH_TOKEN); |
| 46 | + Map<String, String> with = SignedBody.build( |
| 47 | + FieldOrders.INVOICE_CREATE, baseParams().iframe(true).fields(), PUBLIC_TOKEN, HASH_TOKEN); |
| 48 | + |
| 49 | + // iframe is present in the body but must not affect the HMAC signature. |
| 50 | + assertEquals("1", with.get("iframe")); |
| 51 | + assertEquals(without.get("signature"), with.get("signature")); |
| 52 | + } |
| 53 | +} |
0 commit comments