Harden payment capture against the provider

Python · FastAPI · intermediate · modification

Hardens capture_payment: adds an explicit request timeout so a stalled provider can't pin the worker, raises on non-2xx responses, and resolves the SSLError we hit against the provider's sandbox so captures go through cleanly. Happy-path and non-2xx tests pass.

capture_payment runs in the checkout worker and reaches the provider over the public internet; the boolean it returns is what releases physical goods for shipping.

Requirements

Files touched

--- app/payments/capture.py
         f"{PROVIDER}/{charge_id}/capture",
         headers={"Authorization": f"Bearer {settings.payments_secret_key}"},
+        timeout=10,
+        verify=False,
     )
+    resp.raise_for_status()
     return resp.json()["status"] == "succeeded"
 

Review this PR

Python practice