Payments validate endpoint — Bearer token auth

TLDR: switches POST /api/v2/payments/validate from the shared access-token header/organization auth to a static Bearer token, exclusive to this endpoint.

Status: completed Created: 2026-09-08 Owner: @brunoandradd


Context

POST /api/v2/payments/validate currently inherits Api::BaseAuthenticatedController, which authenticates by matching the access-token header against an Organization#api_auth_token. This endpoint doesn’t use current_organization (it already looks up Customer.find_by(email:) globally), so it doesn’t need per-organization auth. It needs a separate, simpler auth: a static shared secret sent as Authorization: Bearer <token>, validated against an env var — scoped only to this endpoint, no other v2 endpoint is affected.

Objectives

  • POST /api/v2/payments/validate authenticates via Authorization: Bearer <token> instead of access-token
  • Token is a static secret from ENV.fetch("PAYMENTS_VALIDATE_API_TOKEN"), unrelated to Organization
  • Missing/invalid token → 403 Forbidden
  • No other endpoint’s auth changes

Changes

  • app/controllers/api/v2/payments/validates_controller.rb: stop inheriting Api::BaseAuthenticatedController; inherit ApplicationController directly, add before_action :authenticate_bearer_token that compares request.headers["Authorization"] (Bearer <token>) against ENV.fetch("PAYMENTS_VALIDATE_API_TOKEN"), rendering 403 on mismatch/blank
  • .env, .env.example: add PAYMENTS_VALIDATE_API_TOKEN
  • spec/requests/api/v2/payments/validates_spec.rb: replace access-token header usage with Authorization: Bearer <token>; “without authenticated user” now omits/mismatches the Bearer token

How to verify

  • bundle exec rspec spec/requests/api/v2/payments/validates_spec.rb
  • Manual: POST /api/v2/payments/validate with Authorization: Bearer <PAYMENTS_VALIDATE_API_TOKEN> and { "email": "...", "product_id": "..." }

Documentation

No documentation changes needed.