Quasar pages: ticket link and ws fast-path still assume ticket id == payment_hash #40

Open
opened 2026-09-06 17:55:22 +00:00 by padreug · 0 comments
Owner

Since 7b761a1 every ticket row gets a fresh urlsafe_short_hash() id and only the payment_hash column carries the invoice hash. Two spots in the extension's own UI/API still use the old invariant:

  • static/js/display.js paymentSuccess(paymentHash): link: '/events/ticket/' + paymentHash and window.open('/events/ticket/' + paymentHash) → 404 "Ticket does not exist" for every purchase made through the extension's own event page. Fix: read ticket_ids from POST /api/v1/tickets/{event_id}/{payment_hash} (or the ws payload) and link the first id (all of them for multi-ticket).
  • views_api.py websocket_endpoint: ticket = await get_ticket(payment_hash) looks up by row id, so the already-paid fast path never fires; use get_tickets_by_payment_hash. display.js also watches core's /api/v1/ws/{hash} rather than the extension's /events/api/v1/tickets/ws/{hash}.

The webapp is unaffected (it uses the poll endpoint's ticket_ids). Found during the guest-checkout review (#36).

Since 7b761a1 every ticket row gets a fresh `urlsafe_short_hash()` id and only the `payment_hash` column carries the invoice hash. Two spots in the extension's own UI/API still use the old invariant: - `static/js/display.js` `paymentSuccess(paymentHash)`: `link: '/events/ticket/' + paymentHash` and `window.open('/events/ticket/' + paymentHash)` → **404 "Ticket does not exist"** for every purchase made through the extension's own event page. Fix: read `ticket_ids` from `POST /api/v1/tickets/{event_id}/{payment_hash}` (or the ws payload) and link the first id (all of them for multi-ticket). - `views_api.py` `websocket_endpoint`: `ticket = await get_ticket(payment_hash)` looks up by row id, so the already-paid fast path never fires; use `get_tickets_by_payment_hash`. `display.js` also watches core's `/api/v1/ws/{hash}` rather than the extension's `/events/api/v1/tickets/ws/{hash}`. The webapp is unaffected (it uses the poll endpoint's `ticket_ids`). Found during the guest-checkout review (#36).
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/events#40
No description provided.