Problem/Motivation
The Accept Hosted payment gateway (the off-site hosted payment page) relies on the Commerce notification endpoint (route commerce_payment.notify, path /payment/notify/{commerce_payment_gateway}) to receive asynchronous payment notifications from Authorize.net. However, the gateway configuration form never tells the site builder what that URL actually is.
The {commerce_payment_gateway} parameter is the payment gateway config entity machine name, which is auto-generated from the label when the gateway is created. It is not the plugin ID and not a fixed value, so the correct URL is different on every site: a gateway labelled "Authorize.net" yields /payment/notify/authorize_net, while one labelled "Payments" yields /payment/notify/payments.
In practice this leads to silently broken webhooks. Site builders copy a hardcoded path from documentation (for example /payment/notify/accept_hosted) or guess from the plugin ID, register that value in the Authorize.net dashboard, and notifications never reach Drupal. There is no error and nothing is logged, because the request simply hits a route that does not match the real gateway machine name, so the problem can go unnoticed for a long time.
Commerce Stripe and Commerce PayPal already avoid this by rendering the real notify URL directly on the gateway configuration form. The Accept Hosted gateway should do the same.
Steps to reproduce
- Add an Authorize.net (Accept Hosted) payment gateway and give it any label; note the machine name is derived from that label.
- Open the gateway configuration form and observe that there is no indication of the notification/webhook URL to register with Authorize.net.
- Register a webhook using a value taken from documentation or the plugin ID (for example
/payment/notify/accept_hosted) instead of the actual gateway machine name. - Trigger a notification. It never reaches Drupal and nothing is written to the log, because the configured path does not match
/payment/notify/{machine name}.
Proposed resolution
Render the notification URL on the Accept Hosted gateway configuration form as a read-only informational element, following the existing pattern in Commerce Stripe and Commerce PayPal.
- Build the URL from the gateway config entity ID via the
commerce_payment.notifyroute as an absolute URL, so it always reflects the actual machine name and base URL rather than a hardcoded string. - Only display it once the gateway has been saved (an existing config entity), since the machine name is not finalized while a new gateway is being created.
- Alongside the URL, list the Authorize.net notification settings/events the merchant needs to enable, mirroring the events list shown on the PayPal gateway form.
Remaining tasks
- Implement the informational element on the Accept Hosted gateway configuration form.
- Confirm the wording and the list of Authorize.net events to enable.
- Handle the new, unsaved gateway case gracefully (no machine name yet).
- Manual testing and review.
User interface changes
A new read-only "Webhook URL" section appears on the Accept Hosted gateway configuration form for saved gateways, showing the absolute notify URL and the events to enable in the Authorize.net dashboard. No change when creating a new gateway.
API changes
None.
Data model changes
None.
| Comment | File | Size | Author |
|---|---|---|---|
| image.png | 22.84 KB | adrianandres |
Issue fork commerce_authnet-3615518
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
vmarchukComment #4
vmarchukComment #5
adrianandres commentedComment #9
vmarchukCommitted!