Spaces:
Running
Running
Update app.py
Browse files
app.py
CHANGED
|
@@ -1,36 +1,91 @@
|
|
| 1 |
-
|
| 2 |
-
import
|
| 3 |
-
import
|
| 4 |
-
import
|
| 5 |
-
|
| 6 |
-
|
| 7 |
-
|
| 8 |
-
|
| 9 |
-
|
| 10 |
-
|
| 11 |
-
|
| 12 |
-
|
| 13 |
-
|
| 14 |
-
|
| 15 |
-
|
| 16 |
-
|
| 17 |
-
|
| 18 |
-
|
| 19 |
-
|
| 20 |
-
def
|
| 21 |
-
|
| 22 |
-
|
| 23 |
-
|
| 24 |
-
|
| 25 |
-
|
| 26 |
-
|
| 27 |
-
|
| 28 |
-
|
| 29 |
-
|
| 30 |
-
|
| 31 |
-
|
| 32 |
-
|
| 33 |
-
|
| 34 |
-
|
| 35 |
-
|
| 36 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
# app.py
|
| 2 |
+
from flask import Flask, request, jsonify
|
| 3 |
+
import razorpay
|
| 4 |
+
import os
|
| 5 |
+
import hmac
|
| 6 |
+
import hashlib
|
| 7 |
+
import json
|
| 8 |
+
|
| 9 |
+
app = Flask(__name__)
|
| 10 |
+
|
| 11 |
+
# Get keys from Hugging Face Secrets (Settings -> Variables)
|
| 12 |
+
RAZORPAY_KEY_ID = os.getenv("RAZORPAY_KEY_ID", "")
|
| 13 |
+
RAZORPAY_KEY_SECRET = os.getenv("RAZORPAY_KEY_SECRET", "")
|
| 14 |
+
|
| 15 |
+
if not RAZORPAY_KEY_ID or not RAZORPAY_KEY_SECRET:
|
| 16 |
+
print("WARNING: Razorpay keys not found in env. Set RAZORPAY_KEY_ID and RAZORPAY_KEY_SECRET in Space secrets.")
|
| 17 |
+
|
| 18 |
+
client = razorpay.Client(auth=(RAZORPAY_KEY_ID, RAZORPAY_KEY_SECRET))
|
| 19 |
+
|
| 20 |
+
def cors_json(resp):
|
| 21 |
+
# Helper to add CORS headers to Flask response dict
|
| 22 |
+
response = jsonify(resp)
|
| 23 |
+
response.headers.add("Access-Control-Allow-Origin", "*")
|
| 24 |
+
response.headers.add("Access-Control-Allow-Headers", "Content-Type")
|
| 25 |
+
return response
|
| 26 |
+
|
| 27 |
+
@app.route("/create-order", methods=["POST", "OPTIONS"])
|
| 28 |
+
def create_order():
|
| 29 |
+
# Preflight
|
| 30 |
+
if request.method == "OPTIONS":
|
| 31 |
+
response = app.response_class(status=204)
|
| 32 |
+
response.headers.add("Access-Control-Allow-Origin", "*")
|
| 33 |
+
response.headers.add("Access-Control-Allow-Headers", "Content-Type")
|
| 34 |
+
return response
|
| 35 |
+
|
| 36 |
+
data = request.get_json(force=True) or {}
|
| 37 |
+
amount = int(data.get("amount", 0)) # amount in rupees from frontend
|
| 38 |
+
if amount <= 0:
|
| 39 |
+
return cors_json({"error": "Invalid amount"}), 400
|
| 40 |
+
|
| 41 |
+
try:
|
| 42 |
+
options = {
|
| 43 |
+
"amount": amount * 100, # paise
|
| 44 |
+
"currency": "INR",
|
| 45 |
+
"receipt": f"receipt_{os.urandom(4).hex()}",
|
| 46 |
+
"payment_capture": 1
|
| 47 |
+
}
|
| 48 |
+
order = client.order.create(options)
|
| 49 |
+
return cors_json(order)
|
| 50 |
+
except Exception as e:
|
| 51 |
+
return cors_json({"error": str(e)}), 500
|
| 52 |
+
|
| 53 |
+
@app.route("/verify-payment", methods=["POST", "OPTIONS"])
|
| 54 |
+
def verify_payment():
|
| 55 |
+
# Verifies signature from Razorpay checkout
|
| 56 |
+
if request.method == "OPTIONS":
|
| 57 |
+
response = app.response_class(status=204)
|
| 58 |
+
response.headers.add("Access-Control-Allow-Origin", "*")
|
| 59 |
+
response.headers.add("Access-Control-Allow-Headers", "Content-Type")
|
| 60 |
+
return response
|
| 61 |
+
|
| 62 |
+
data = request.get_json(force=True) or {}
|
| 63 |
+
try:
|
| 64 |
+
razorpay_order_id = data.get("razorpay_order_id")
|
| 65 |
+
razorpay_payment_id = data.get("razorpay_payment_id")
|
| 66 |
+
razorpay_signature = data.get("razorpay_signature")
|
| 67 |
+
|
| 68 |
+
if not (razorpay_order_id and razorpay_payment_id and razorpay_signature):
|
| 69 |
+
return cors_json({"success": False, "message": "Missing fields"}), 400
|
| 70 |
+
|
| 71 |
+
payload = f"{razorpay_order_id}|{razorpay_payment_id}"
|
| 72 |
+
generated_signature = hmac.new(
|
| 73 |
+
RAZORPAY_KEY_SECRET.encode("utf-8"),
|
| 74 |
+
payload.encode("utf-8"),
|
| 75 |
+
hashlib.sha256
|
| 76 |
+
).hexdigest()
|
| 77 |
+
|
| 78 |
+
if generated_signature == razorpay_signature:
|
| 79 |
+
return cors_json({"success": True})
|
| 80 |
+
else:
|
| 81 |
+
return cors_json({"success": False, "message": "Invalid signature"}), 400
|
| 82 |
+
except Exception as e:
|
| 83 |
+
return cors_json({"success": False, "message": str(e)}), 500
|
| 84 |
+
|
| 85 |
+
@app.route("/health", methods=["GET"])
|
| 86 |
+
def health():
|
| 87 |
+
return cors_json({"ok": True, "app": "razorpay-backend"})
|
| 88 |
+
|
| 89 |
+
if __name__ == "__main__":
|
| 90 |
+
# Hugging Face Spaces runs on port 7860
|
| 91 |
+
app.run(host="0.0.0.0", port=7860)
|