Webhooks
Server-to-server callbacks from Stripe and ACube. Never called by a client: each request is authenticated by the sender signature, not by a token.
ACube: supplier invoice received
Called by ACube, never by a client: the request is accepted only with a valid HTTP Message Signature from ACube, verified against ACUBE_PUBLIC_KEY (or the key published at ACUBE_WH_PK_URL). Notifies a passive invoice received from SDI; it is acknowledged and not stored.
ACube: invoice sent to SDI
Called by ACube, never by a client: the request is accepted only with a valid HTTP Message Signature from ACube, verified against ACUBE_PUBLIC_KEY (or the key published at ACUBE_WH_PK_URL). Marks the issued document as sent and notifies its provider (invoice_sent).
ACube: SDI notification on an issued invoice
Called by ACube, never by a client: the request is accepted only with a valid HTTP Message Signature from ACube, verified against ACUBE_PUBLIC_KEY (or the key published at ACUBE_WH_PK_URL). Applies the SDI outcome to the document: NS rejected, RC delivered, MC/AT not deliverable; notifies the provider and emails it on a rejection.
ACube: invoice marking changed
Called by ACube, never by a client: the request is accepted only with a valid HTTP Message Signature from ACube, verified against ACUBE_PUBLIC_KEY (or the key published at ACUBE_WH_PK_URL). Applies a change of marking (quarantena, invoice-error) to the document and notifies its provider.
ACube: legal storage, missing VAT number
Called by ACube, never by a client: the request is accepted only with a valid HTTP Message Signature from ACube, verified against ACUBE_PUBLIC_KEY (or the key published at ACUBE_WH_PK_URL). Acknowledged only: no state changes.
ACube: legal storage receipt
Called by ACube, never by a client: the request is accepted only with a valid HTTP Message Signature from ACube, verified against ACUBE_PUBLIC_KEY (or the key published at ACUBE_WH_PK_URL). Acknowledged only: no state changes.
Stripe: checkout session completed or expired
Called by Stripe, never by a client: the request is accepted only with a valid Stripe-Signature for one of the endpoint secrets (STRIPE_CHECKOUT_WEBHOOK_SECRET, STRIPE_CHECKOUT_WEBHOOK_SECRET_CONNECT). checkout.session.completed confirms the order (lessons paid, family document issued, notifications, referral credit); checkout.session.expired releases it (lessons deleted, slots restored, promotion usage and family credit given back). Both are idempotent, and the cron lessons/check-expired-lessons applies the same outcomes to the sessions whose event never arrived.