Payments validate endpoint — Bearer token auth
TLDR: switches
POST /api/v2/payments/validatefrom the sharedaccess-tokenheader/organization auth to a static Bearer token, exclusive to this endpoint.
Status: completed Created: 2026-09-08 Owner: @brunoandradd
Context
POST /api/v2/payments/validate currently inherits Api::BaseAuthenticatedController, which authenticates by matching the access-token header against an Organization#api_auth_token. This endpoint doesn’t use current_organization (it already looks up Customer.find_by(email:) globally), so it doesn’t need per-organization auth. It needs a separate, simpler auth: a static shared secret sent as Authorization: Bearer <token>, validated against an env var — scoped only to this endpoint, no other v2 endpoint is affected.
Objectives
POST /api/v2/payments/validateauthenticates viaAuthorization: Bearer <token>instead ofaccess-token- Token is a static secret from
ENV.fetch("PAYMENTS_VALIDATE_API_TOKEN"), unrelated toOrganization - Missing/invalid token →
403 Forbidden - No other endpoint’s auth changes
Changes
app/controllers/api/v2/payments/validates_controller.rb: stop inheritingApi::BaseAuthenticatedController; inheritApplicationControllerdirectly, addbefore_action :authenticate_bearer_tokenthat comparesrequest.headers["Authorization"](Bearer <token>) againstENV.fetch("PAYMENTS_VALIDATE_API_TOKEN"), rendering403on mismatch/blank.env,.env.example: addPAYMENTS_VALIDATE_API_TOKENspec/requests/api/v2/payments/validates_spec.rb: replaceaccess-tokenheader usage withAuthorization: Bearer <token>; “without authenticated user” now omits/mismatches the Bearer token
How to verify
bundle exec rspec spec/requests/api/v2/payments/validates_spec.rb- Manual:
POST /api/v2/payments/validatewithAuthorization: Bearer <PAYMENTS_VALIDATE_API_TOKEN>and{ "email": "...", "product_id": "..." }
Documentation
No documentation changes needed.