Skip to content

Financial - Make Payment::create idempotent for a repeated trxn_id - #36426

Open
mattwire wants to merge 1 commit into
civicrm:masterfrom
mattwire:fix-payment-create-race-idempotent
Open

Financial - Make Payment::create idempotent for a repeated trxn_id#36426
mattwire wants to merge 1 commit into
civicrm:masterfrom
mattwire:fix-payment-create-race-idempotent

Conversation

@mattwire

@mattwire mattwire commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Overview

A payment processor webhook racing a synchronous front-end/back-office confirmation of the same charge (e.g. paying an existing pending contribution via CRM_Contribute_Form_Contribution_Confirm) can both read the contribution as not-yet-completed and both go on to record a payment for it. Add a per-contribution lock via Civi::lockManager() around create(), and treat a second payment carrying an already-recorded trxn_id as a no-op success (returning the existing FinancialTrxn) rather than creating a duplicate. Every caller gets this for free with no changes needed at the call site. Includes a regression test using APIv4 Payment::create/get.

Alternative to the reject-with-exception approach in fix-payment-create-race-lock - see that branch for comparison.

Before

Two payments recorded (or crash for one of them) if user-side and webhook record payment at the same time.

After

One payment recorded and both sides think they recorded it - desired outcome.

Technical Details

Adds a lock and relies on trxn_id being unique (which is enforced by DB entity).
The downstream code has 15 seconds to complete otherwise it will throw a CRM_Core_Exception. If downstream code completes in time the payment record is returned just the same as for the first caller.

Comments

This should be a cleaner solution than #36401 because it doesn't require code changes anywhere else.

A payment processor webhook racing a synchronous front-end/back-office confirmation of the same charge (e.g. paying an existing pending contribution via CRM_Contribute_Form_Contribution_Confirm) can both read the contribution as not-yet-completed and both go on to record a payment for it. Add a per-contribution lock via Civi::lockManager() around create(), and treat a second payment carrying an already-recorded trxn_id as a no-op success (returning the existing FinancialTrxn) rather than creating a duplicate. Every caller gets this for free with no changes needed at the call site. Includes a regression test using APIv4 Payment::create/get.

Alternative to the reject-with-exception approach in fix-payment-create-race-lock - see that branch for comparison.
@civibot

civibot Bot commented Aug 6, 2026

Copy link
Copy Markdown

🤖 Thank you for contributing to CiviCRM! ❤️ We will need to test and review this PR. 👷

Introduction for new contributors...
  • If this is your first PR, an admin will greenlight automated testing with the command ok to test or add to whitelist.
  • A series of tests will automatically run. You can see the results at the bottom of this page (if there are any problems, it will include a link to see what went wrong).
  • A demo site will be built where anyone can try out a version of CiviCRM that includes your changes.
  • If this process needs to be repeated, an admin will issue the command test this please to rerun tests and build a new demo site.
  • Before this PR can be merged, it needs to be reviewed. Please keep in mind that reviewers are volunteers, and their response time can vary from a few hours to a few weeks depending on their availability and their knowledge of this particular part of CiviCRM.
  • A great way to speed up this process is to "trade reviews" with someone - find an open PR that you feel able to review, and leave a comment like "I'm reviewing this now, could you please review mine?" (include a link to yours). You don't have to wait for a response to get started (and you don't have to stop at one!) the more you review, the faster this process goes for everyone 😄
  • To ensure that you are credited properly in the final release notes, please add yourself to contributor-key.yml
  • For more information about contributing, see CONTRIBUTING.md.
PR commands & links...
  • /rebase <branch-name> will rebase your branch and change the base of the PR.
  • /squash will combine all commits (keeping only the first commit messsage).
  • /port <branch-name> will create a copy of this PR against a different branch.
  • /lintroll will automatically fix linting errors, amending commits as needed.
  • retest this please will rerun the tests and rebuild the demo site.
  • 📖 Review standards
  • 🗒️ Review template (brief or verbose)

➡️ Online demo of this PR 🔗

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant