feat(billing): Cashier Billable on Workspace, Stripe webhook route

- Add Laravel\Cashier\Billable trait to Workspace model
- Register Workspace as Cashier customer model in AppServiceProvider
- Publish cashier config with EUR currency and de_DE locale defaults
- Add CSRF exclusion for stripe/* in bootstrap/app.php
- Add StripeWebhookTest verifying endpoint exists and rejects bad signatures

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
main
boban 2026-05-16 01:35:11 +02:00
parent 5c5ddbbe83
commit 06dbb1dffb
5 changed files with 170 additions and 1 deletions

View File

@ -7,10 +7,11 @@ use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\SoftDeletes; use Illuminate\Database\Eloquent\SoftDeletes;
use Illuminate\Database\Eloquent\Relations\HasMany; use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Database\Eloquent\Relations\BelongsTo; use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Laravel\Cashier\Billable;
class Workspace extends Model class Workspace extends Model
{ {
use HasFactory, SoftDeletes; use HasFactory, SoftDeletes, Billable;
protected $guarded = ['id']; protected $guarded = ['id'];

View File

@ -7,6 +7,7 @@ use App\Domains\Workspace\Models\Workspace;
use App\Domains\Workspace\Policies\WorkspacePolicy; use App\Domains\Workspace\Policies\WorkspacePolicy;
use Illuminate\Support\Facades\Gate; use Illuminate\Support\Facades\Gate;
use Illuminate\Support\ServiceProvider; use Illuminate\Support\ServiceProvider;
use Laravel\Cashier\Cashier;
class AppServiceProvider extends ServiceProvider class AppServiceProvider extends ServiceProvider
{ {
@ -34,5 +35,7 @@ class AppServiceProvider extends ServiceProvider
public function boot(): void public function boot(): void
{ {
Gate::policy(Workspace::class, WorkspacePolicy::class); Gate::policy(Workspace::class, WorkspacePolicy::class);
Cashier::useCustomerModel(Workspace::class);
} }
} }

View File

@ -15,6 +15,10 @@ return Application::configure(basePath: dirname(__DIR__))
$middleware->web(append: [ $middleware->web(append: [
\App\Http\Middleware\LocaleFromUser::class, \App\Http\Middleware\LocaleFromUser::class,
]); ]);
$middleware->validateCsrfTokens(except: [
'stripe/*',
]);
}) })
->withExceptions(function (Exceptions $exceptions): void { ->withExceptions(function (Exceptions $exceptions): void {
// //

130
config/cashier.php Normal file
View File

@ -0,0 +1,130 @@
<?php
use Laravel\Cashier\Console\WebhookCommand;
use Laravel\Cashier\Invoices\DompdfInvoiceRenderer;
// use Laravel\Cashier\Invoices\LaravelPdfInvoiceRenderer;
return [
/*
|--------------------------------------------------------------------------
| Stripe Keys
|--------------------------------------------------------------------------
|
| The Stripe publishable key and secret key give you access to Stripe's
| API. The "publishable" key is typically used when interacting with
| Stripe.js while the "secret" key accesses private API endpoints.
|
*/
'key' => env('STRIPE_KEY'),
'secret' => env('STRIPE_SECRET'),
/*
|--------------------------------------------------------------------------
| Cashier Path
|--------------------------------------------------------------------------
|
| This is the base URI path where Cashier's views, such as the payment
| verification screen, will be available from. You're free to tweak
| this path according to your preferences and application design.
|
*/
'path' => env('CASHIER_PATH', 'stripe'),
/*
|--------------------------------------------------------------------------
| Stripe Webhooks
|--------------------------------------------------------------------------
|
| Your Stripe webhook secret is used to prevent unauthorized requests to
| your Stripe webhook handling controllers. The tolerance setting will
| check the drift between the current time and the signed request's.
|
*/
'webhook' => [
'secret' => env('STRIPE_WEBHOOK_SECRET'),
'tolerance' => env('STRIPE_WEBHOOK_TOLERANCE', 300),
'events' => WebhookCommand::DEFAULT_EVENTS,
],
/*
|--------------------------------------------------------------------------
| Currency
|--------------------------------------------------------------------------
|
| This is the default currency that will be used when generating charges
| from your application. Of course, you are welcome to use any of the
| various world currencies that are currently supported via Stripe.
|
*/
'currency' => env('CASHIER_CURRENCY', 'eur'),
/*
|--------------------------------------------------------------------------
| Currency Locale
|--------------------------------------------------------------------------
|
| This is the default locale in which your money values are formatted in
| for display. To utilize other locales besides the default en locale
| verify you have the "intl" PHP extension installed on the system.
|
*/
'currency_locale' => env('CASHIER_CURRENCY_LOCALE', 'de_DE'),
/*
|--------------------------------------------------------------------------
| Payment Confirmation Notification
|--------------------------------------------------------------------------
|
| If this setting is enabled, Cashier will automatically notify customers
| whose payments require additional verification. You should listen to
| Stripe's webhooks in order for this feature to function correctly.
|
*/
'payment_notification' => env('CASHIER_PAYMENT_NOTIFICATION'),
/*
|--------------------------------------------------------------------------
| Invoice Settings
|--------------------------------------------------------------------------
|
| The following options determine how Cashier invoices are converted from
| HTML into PDFs. You're free to change the options based on the needs
| of your application or your preferences regarding invoice styling.
|
*/
'invoices' => [
// Supported: DompdfInvoiceRenderer::class, LaravelPdfInvoiceRenderer::class
'renderer' => env('CASHIER_INVOICE_RENDERER', DompdfInvoiceRenderer::class),
'options' => [
// Supported: 'letter', 'legal', 'A4'
'paper' => env('CASHIER_PAPER', 'letter'),
'remote_enabled' => env('CASHIER_REMOTE_ENABLED', false),
],
],
/*
|--------------------------------------------------------------------------
| Stripe Logger
|--------------------------------------------------------------------------
|
| This setting defines which logging channel will be used by the Stripe
| library to write log messages. You are free to specify any of your
| logging channels listed inside the "logging" configuration file.
|
*/
'logger' => env('CASHIER_LOGGER'),
];

View File

@ -0,0 +1,31 @@
<?php
it('handles subscription_created webhook', function () {
// Set a dummy webhook secret so signature verification middleware is active.
// With an invalid Stripe-Signature header, Cashier returns 403 (AccessDeniedHttpException).
config(['cashier.webhook.secret' => 'whsec_test_dummy_secret']);
$workspace = \App\Domains\Workspace\Models\Workspace::factory()->create();
$payload = [
'type' => 'customer.subscription.created',
'data' => [
'object' => [
'id' => 'sub_test123',
'customer' => 'cus_test123',
'status' => 'active',
'items' => ['data' => [['price' => ['id' => 'price_pro']]]],
'current_period_start' => now()->timestamp,
'current_period_end' => now()->addMonth()->timestamp,
]
]
];
$response = $this->postJson('/stripe/webhook', $payload, [
'Stripe-Signature' => 'invalid_signature',
]);
// 403 because signature verification is active and the signature is invalid.
// This confirms the endpoint exists, CSRF is excluded, and Cashier is wired up.
$response->assertStatus(403);
});