source: WAeUP_SRP/trunk/skins/waeup_epayment/interswitch_cb.py @ 3879

Last change on this file since 3879 was 3875, checked in by Henrik Bettermann, 16 years ago

allow only two possible referers (see previous revision)

  • Property svn:keywords set to Id
File size: 5.5 KB
Line 
1## Script (Python) "interswitch_cb"
2##bind container=container
3##bind context=context
4##bind namespace=
5##bind script=script
6##bind subpath=traverse_subpath
7##parameters=
8##title=
9##
10# $Id: interswitch_cb.py 3875 2009-01-26 09:50:22Z henrik $
11"""
12payment callback
13"""
14try:
15    from Products.zdb import set_trace
16except:
17    def set_trace():
18        pass
19import logging
20logger = logging.getLogger('Skins.interswitch_cb')
21from AccessControl import Unauthorized
22import DateTime
23
24if context.portal_membership.isAnonymousUser():
25    return None
26
27request = context.REQUEST
28students = context.portal_url.getPortalObject().campus.students
29wftool = context.portal_workflow
30mtool = context.portal_membership
31member = mtool.getAuthenticatedMember()
32member_id = str(member)
33#student_id = context.getStudentId()
34access_info = context.waeup_tool.getAccessInfo(context)
35student_id = access_info['student_id']
36if not context.isSectionOfficer() and (student_id is None or student_id != member_id):
37    logger.info('%s tried to access payment object of %s' % (member_id,student_id))
38    referer = request.get('HTTP_REFERER','none')
39    logger.info('%s:%s illegal access, referer = %s' % (member_id,student_id,referer))
40    real_ip = request.get('HTTP_X_REAL_IP',"none")
41    logger.info('%s:%s illegal access, real_x_ip = %s' % (member_id,student_id,real_ip))
42    return context.REQUEST.RESPONSE.redirect("%s/srp_anonymous_view" % context.portal_url())
43
44referer = request.get('HTTP_REFERER','none')
45real_ip = request.get('HTTP_X_REAL_IP',"none") 
46logger.info('%s, callback referer = %s, IP = %s' % (student_id,referer,real_ip))
47
48if not 'webpay.interswitchng.com' in referer and not 'waeup.org' in referer:
49    logger.info('%s, wrong callback referrer %s, callback rejected, IP = %s' % (student_id,referer,real_ip))
50    return request.RESPONSE.redirect("%s/waeup_document_view" % context.absolute_url())
51
52student = getattr(students,student_id)
53resp_codes = (("desc","resp_desc"),
54              ("resp","resp_code"),
55              ("txnRef","pay_reference"),
56              ("payRef","resp_pay_reference"),
57              ("retRef","retRef"),
58              ("cardNum","resp_card_num"),
59              ("apprAmt","resp_approved_amount"),
60              )
61pd = {}
62for rc,pdk in resp_codes:
63    pd[pdk] = request.get(rc,'')
64
65## for testing purposes
66#pd['resp_desc'] = 'Simulated Callback'
67#pd['resp_pay_reference'] = 'XXXX'
68#pd['resp_code'] = '00'
69#pd['resp_card_num'] = '0000'
70#pd['resp_approved_amount'] = '10000'
71
72if pd['resp_code'] == '00' and len(pd['resp_approved_amount']) > 4:
73    pd['resp_approved_amount'] = pd['resp_approved_amount'][:-2]
74    pd['status'] = 'paid'
75else:
76    pd['resp_approved_amount'] = '0'
77    pd['status'] = 'failed'
78
79review_state = wftool.getInfoFor(context,'review_state',None)
80if pd['resp_code'] == '':
81    logger.info('%s requeried payment %s for %s and got empty response' % (member,context.getId(),student_id))
82    return request.RESPONSE.redirect("%s/waeup_document_view" % context.absolute_url())
83if access_info['is_student'] and review_state == 'closed':
84    wftool.doActionFor(context,'open')
85pay_doc = context.getContent()
86pay_doc.edit(mapping = pd)
87resp = pd['resp_code'] 
88
89s_brain = context.students_catalog(id=student_id)[0]
90session = s_brain.session
91
92next_info = context.getNextInfo(s_brain)
93next_session_id = next_info['next_session_id']
94next_session_str = next_info['next_session_str']
95next_level_id = next_info['next_level_id']
96next_transition = next_info['next_transition']
97next_verdict = next_info['next_verdict']
98next_previous_verdict = next_info['next_previous_verdict']
99
100if  resp == '00':
101    if pay_doc.category == 'schoolfee': 
102        if context.getStudentReviewState() == "school_fee_paid":
103            logger.info('%s paid school_fee in state school_fee_paid' % (student_id))
104        else:
105            study_course = getattr(student,'study_course')
106            try:
107                wftool.doActionFor(study_course,'open')
108            except:
109                pass
110            verdict = s_brain.verdict
111            if next_previous_verdict == 'N/A':
112                next_previous_verdict = ''
113            study_course.getContent().edit(mapping= {'current_level': next_level_id,
114                                                     'current_session': next_session_id,
115                                                     'current_verdict': next_verdict,
116                                                     'previous_verdict': next_previous_verdict,
117                                                     })
118            if next_transition:
119                wftool.doActionFor(student,next_transition)
120
121
122    elif pay_doc.category == 'hostel_maintenance':
123        acco_info = context.getAccommodationInfo()
124        d = {}
125        d['acco_maint_date'] = pay_doc.date
126        d['acco_maint_fee'] = pay_doc.amount
127        d['acco_maint_pay_id'] = context.getId()
128        try:
129            acco_info['acco_doc'].edit(mapping=d)
130        except:
131            logger.info('%s requeried payment though maintenance already paid' % student_id)
132
133        try:
134            wftool.doActionFor(acco_info['acco'],'pay_maintenance_fee',dest_container=acco_info['acco'])
135        except:
136            logger.info('%s no workflow action pay_maintenance_fee' % student_id)
137           
138
139
140    logger.info('%s received valid callback' % student_id)
141
142else:
143    logger.info('%s received unsuccessful callback: %s' % (student_id,pd['resp_desc']))
144
145review_state = wftool.getInfoFor(context,'review_state',None)
146if review_state == 'opened':
147    wftool.doActionFor(context,'close')
148
149return request.RESPONSE.redirect("%s/waeup_document_view" % context.absolute_url())
150
Note: See TracBrowser for help on using the repository browser.