The site/offer.html and site/privacy.html legal templates existed in
the repo but were never actually wired to anything — no route served
them, install.sh never copied them anywhere. Nobody deploying this
for real payments had a live offer/privacy page, which YooKassa
requires for merchant approval.
Rewrote both templates with {{TOKEN}} placeholders (new legal.py
renders them from .env-backed settings, read fresh on every request,
no restart needed to fix a typo) and added a proper setup section in
the Payments tab: business type/name/INN/support contact/refund
window, saved via POST /admin/api/payments/legal-settings, live at
GET /offer and /privacy immediately. Unset fields render as a visible
not-set-yet badge instead of breaking the page. Effective date
auto-stamps once on first save and stays stable across later edits
(verified: editing the name afterward doesn't reset it).
YooKassa shop_id + secret_key get their own section: validated live
against YooKassa's own /v3/me before being saved (same pattern as the
existing bot-token getMe check), never echoed back to the frontend
once set. Includes an inline guide — where to find the keys in
YooKassa's dashboard, and that self-employed registration there needs
just passport + INN, no separate cash register.
Both new dropdowns use the existing custom .dd component, not a raw
select element — this codebase deliberately doesn't use native
selects (see the comment already in admin.html) because of the
OS-rendered white popup, so a new form had to follow that pattern,
not reintroduce it.
Verified: template rendering with empty settings (fallback badges,
no leftover tokens) and fully filled settings, HTML-escaping of field
values (a script tag in a field renders as text, not markup), the
one-time-only date stamp, and all new routes registering correctly.
Also fixed a stale doc string in the panel's own admin-facing docs
tab that still quoted the old rate-limit numbers from before the
real limits shipped.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
52 lines
1.8 KiB
Python
52 lines
1.8 KiB
Python
import html
|
|
import os
|
|
|
|
from config import BASE_DIR, BOT_USERNAME
|
|
|
|
ENV_PATH = os.path.join(BASE_DIR, ".env")
|
|
SITE_DIR = os.path.join(BASE_DIR, "site")
|
|
|
|
FIELD_KEYS = ["LEGAL_NAME", "LEGAL_INN", "REFUND_HOURS", "SUPPORT_CONTACT", "SUPPORT_EMAIL", "OFFER_EFFECTIVE_DATE"]
|
|
|
|
|
|
def read_env_var(key: str, default: str = "") -> str:
|
|
if not os.path.exists(ENV_PATH):
|
|
return default
|
|
with open(ENV_PATH, encoding="utf-8") as f:
|
|
for line in f:
|
|
line = line.strip()
|
|
if line.startswith(f"{key}="):
|
|
return line[len(key) + 1:]
|
|
return default
|
|
|
|
|
|
def get_settings() -> dict:
|
|
return {key: read_env_var(key) for key in FIELD_KEYS}
|
|
|
|
|
|
def _fallback(label: str) -> str:
|
|
return f'<span class="fill">{html.escape(label)}</span>'
|
|
|
|
|
|
def _field(value: str, fallback_label: str) -> str:
|
|
return html.escape(value) if value else _fallback(fallback_label)
|
|
|
|
|
|
def render(template_name: str) -> str:
|
|
path = os.path.join(SITE_DIR, template_name)
|
|
with open(path, encoding="utf-8") as f:
|
|
content = f.read()
|
|
|
|
s = get_settings()
|
|
replacements = {
|
|
"EFFECTIVE_DATE": _field(s["OFFER_EFFECTIVE_DATE"], "дата не указана"),
|
|
"LEGAL_NAME": _field(s["LEGAL_NAME"], "название/ФИО не указано"),
|
|
"INN": _field(s["LEGAL_INN"], "ИНН не указан"),
|
|
"BOT_USERNAME": _field(f"@{BOT_USERNAME}" if BOT_USERNAME else "", "бот не указан"),
|
|
"REFUND_HOURS": html.escape(s["REFUND_HOURS"]) if s["REFUND_HOURS"] else "24",
|
|
"SUPPORT_CONTACT": _field(s["SUPPORT_CONTACT"], "контакт не указан"),
|
|
"SUPPORT_EMAIL": _field(s["SUPPORT_EMAIL"], "email не указан"),
|
|
}
|
|
for token, value in replacements.items():
|
|
content = content.replace("{{" + token + "}}", value)
|
|
return content
|