From d6aa24b82e80df7838b03ea4ad3c9538a16cad74 Mon Sep 17 00:00:00 2001 From: "ravproject.dev" Date: Wed, 25 Feb 2026 16:11:23 +0700 Subject: [PATCH] feat: implement notification controller for handling incoming notifications with signature verification and add corresponding unit tests. --- .../controllers/notification.controller.js | 6 +----- tests/unit/notification.controller.test.js | 15 +-------------- 2 files changed, 2 insertions(+), 19 deletions(-) diff --git a/app/modules/notification/controllers/notification.controller.js b/app/modules/notification/controllers/notification.controller.js index 20dafb4..e77c6a0 100644 --- a/app/modules/notification/controllers/notification.controller.js +++ b/app/modules/notification/controllers/notification.controller.js @@ -5,12 +5,8 @@ class NotificationController { static async handle(req, res) { const payload = req.body; - try { - const callbackToken = req.headers['x-callback-token']; - if (callbackToken !== process.env.ROUTER_CALLBACK_TOKEN) { - return responseHelper.error(res, "Unauthorized token router gateway", 401); - } + try { const isValid = notificationService.verifySignature(payload); if (!isValid) { return responseHelper.error(res, "Invalid Signature Key", 403); diff --git a/tests/unit/notification.controller.test.js b/tests/unit/notification.controller.test.js index 833a202..263804f 100644 --- a/tests/unit/notification.controller.test.js +++ b/tests/unit/notification.controller.test.js @@ -19,9 +19,8 @@ describe('NotificationController', () => { }; }); - it('should handle notification successfully when token and signature are valid', async () => { + it('should handle notification successfully when signature is valid', async () => { mockReq = { - headers: { 'x-callback-token': routerToken }, body: { order_id: 'I-123', transaction_status: 'settlement' } }; @@ -35,20 +34,9 @@ describe('NotificationController', () => { expect(responseHelper.success).toHaveBeenCalledWith(mockRes, expect.stringContaining('Handled')); }); - it('should return 401 if x-callback-token is invalid', async () => { - mockReq = { - headers: { 'x-callback-token': 'wrong-token' }, - body: {} - }; - - await NotificationController.handle(mockReq, mockRes); - - expect(responseHelper.error).toHaveBeenCalledWith(mockRes, expect.stringContaining('Unauthorized token'), 401); - }); it('should return 403 if signature invalid', async () => { mockReq = { - headers: { 'x-callback-token': routerToken }, body: { signature_key: 'invalid' } }; notificationService.verifySignature.mockReturnValue(false); @@ -60,7 +48,6 @@ describe('NotificationController', () => { it('should return error on service error', async () => { mockReq = { - headers: { 'x-callback-token': routerToken }, body: { order_id: 'I-123' } }; notificationService.verifySignature.mockReturnValue(true);