import { Controller, Headers, HttpCode, Post, Req } from '@nestjs/common';
import type { Request } from 'express';
import { NovasisPayWebhooksService } from './novasis-pay-webhooks.service';

/**
 * Endpoint público para recibir webhooks del gateway Novasis Pay.
 * No usa AuthGuard ni ModuleGuard a propósito: el origen se valida con HMAC.
 * Convive como controller separado del NovasisPayController (que sí exige JWT)
 * para no perforar los guards del módulo principal.
 */
@Controller('novasis-pay/webhooks')
export class NovasisPayWebhooksController {
  constructor(private readonly service: NovasisPayWebhooksService) {}

  @Post()
  @HttpCode(200)
  async receive(
    @Req() req: Request,
    @Headers('x-payments-signature') signature: string,
    @Headers('x-payments-event-id') eventId: string,
    @Headers('x-payments-event-type') eventType: string,
  ) {
    const rawBody = (req as unknown as { rawBody?: string }).rawBody ?? '';
    return this.service.processWebhook(rawBody, { signature, eventId, eventType });
  }
}
