Metadata-Version: 2.4
Name: ocyan.plugin.payment_cardgate
Version: 0.1.1rc1
Summary: Authenticated CardGate/CURO hosted-payment adapter for Ocyan Oscar.
Author: MandelBlog
Classifier: License :: Other/Proprietary License
Classifier: Framework :: Django
Classifier: Framework :: Ocyan
Requires-Python: <3.13,>=3.12
Description-Content-Type: text/markdown
Requires-Dist: Django<5.3,>=5.2
Requires-Dist: ocyan.core<1.3,>=1.2.14
Requires-Dist: ocyan.plugin.oscar<2.1,>=2.0.5
Requires-Dist: ocyan.plugin.oscar_checkout<1.4,>=1.3.3
Provides-Extra: test
Requires-Dist: pytest<10,>=8; extra == "test"

# Ocyan CardGate payment adapter

`ocyan.plugin.payment_cardgate` is an optional hosted-payment adapter for an
existing Ocyan Oscar checkout. It creates a CardGate/CURO compatibility gateway
request for a merchant-selected method and accepts only authenticated,
server-to-server callbacks before changing an order payment state.

## What it owns

- selected CardGate payment-method contribution;
- documented compatibility request fields and merchant-request checksum;
- callback signature, order currency and amount verification;
- idempotent Oscar payment-source/event updates after a verified callback.

It does not own merchant onboarding, payment-method availability, CardGate
back-office configuration, refunds, chargebacks, PCI obligations, tax, or any
customer-facing checkout template.

## Configuration

Keep `site_hash` in the established secret/configuration mechanism, never in
source control. Enable only methods authorised for the merchant account.

```json
"payment_cardgate": {
  "site_id": "merchant-site-id",
  "site_hash": "secret-from-approved-secret-store",
  "testing": true,
  "methods": {"ideal": true, "creditcard": true}
}
```

For compatibility, existing uppercase top-level method flags continue to work,
but new configuration should use the `methods` object.

The CardGate **Callback URL** must be configured in the merchant back office
to the server endpoint named `payment_cardgate:callback`. The gateway sends it
as POST. The adapter rejects browser GETs, missing/invalid hashes, mismatched
currency and mismatched amount. Browser return URLs are only navigation; they
never mark an order paid.

This adapter implements the CardGate compatibility protocol for existing
installations. CURO identifies that API as backward-compatible and advises new
integrations to use its current CURO contract; migrating to that contract is a
separate provider/merchant project.
