api.md 3.0 KB

API Contract: 创建 OMG AIO 支付订单

POST /pay/omg/create

Authentication

  • Header: token: <user-login-token>
  • Spring annotations: @Anonymous + project @Auth
  • Controller method must declare @RequestHeader String token.

Request

POST /pay/omg/create
Content-Type: application/json
token: <login-token>

{
  "orderId": "991786433092835"
}

Rules:

  • DTO has exactly one field: orderId.
  • Controller uses explicit @RequestBody(required = false).
  • orderId is trimmed, non-empty and at most 64 characters.
  • Client cannot provide amount, MerchantID, gateway URL, ReturnURL, text, channel or signature fields.

Success

Outer response keeps the project AjaxResult format. data is:

{
  "status": "CREATED",
  "gatewayUrl": "https://payment-stage.funpoint.com.tw/Cashier/AioCheckOut/V5",
  "formFields": {
    "MerchantID": "1000031",
    "MerchantTradeNo": "OMGR8K3P7W2M9C4X6A1B",
    "MerchantTradeDate": "2026/08/13 15:30:23",
    "PaymentType": "aio",
    "TotalAmount": "100",
    "TradeDesc": "Foodie order 991786433092835",
    "ItemName": "Order 991786433092835",
    "ReturnURL": "https://foodieapi.waimai-paotui.com/pay/omg/notify",
    "ChoosePayment": "ALL",
    "EncryptType": "1",
    "InvoiceMark": "N",
    "NeedExtraPaidInfo": "Y",
    "ExpireDate": "1",
    "StoreExpireDate": "30",
    "BarcodeATMExpireDate": "1",
    "CheckMacValue": "<64 uppercase hexadecimal characters>"
  }
}

The client must submit every formFields entry in the current page as an application/x-www-form-urlencoded POST to gatewayUrl. It must not use iframe, a new window or a GET link.

Business failure

{
  "code": 500,
  "msg": "<localized message>",
  "data": {
    "status": "PAYMENT_ATTEMPT_EXISTS"
  }
}

Stable statuses:

Status Meaning
AUTH_REQUIRED No usable user identity reached the new Controller
ORDER_REQUIRED Request or orderId is missing/invalid
ORDER_NOT_AVAILABLE Order does not exist or is not owned by this user
MULTI_STORE_ORDER_NOT_SUPPORTED Matched row is a multi-store child order
ORDER_STATE_NOT_PAYABLE State is not 0, 1 or 2
ORDER_ALREADY_PAID pay_status is not 0
ORDER_AMOUNT_INVALID Amount is null or not positive
PAYMENT_TYPE_INVALID pay_type is not "2"
STORE_CREDENTIAL_UNAVAILABLE No enabled credential exists for the order store
PAYMENT_ATTEMPT_EXISTS The order already has an active CREATED attempt
PAYMENT_CONFIGURATION_INVALID Stage/ReturnURL safety validation failed
PAYMENT_CREATION_FAILED Controlled generation/insert attempts could not complete

No error response includes token, HashKey, HashIV, CheckMacValue, form fields, SQL or stack trace.

Reserved callback route

POST /pay/omg/notify remains the ReturnURL value sent to OMG, but this phase intentionally registers no handler. The old handler must not receive this route. Callback implementation requires a later independent specification.