# PAYTR Callback 419 Hatası Çözüm Kılavuzu

## ✅ Doğru Yapılandırma

### 1. Route Tanımı (DOĞRU)

**Dosya:** `routes/web.php` (Satır 102-105)

```php
// PAYMENT - Public routes (No authentication required)
Route::prefix('pay')->name('pay.')->group(function () {
    Route::post('/callback', [PayController::class, 'callback'])->name('callback');
});
```

✅ Auth middleware dışında - DOĞRU!

### 2. CSRF Exception (DOĞRU)

**Dosya:** `app/Http/Middleware/VerifyCsrfToken.php`

```php
protected $except = [
    '/pay/callback',
];
```

✅ CSRF exception eklendi - DOĞRU!

## 🔧 419 Hatası İçin Çözümler

### Çözüm 1: Cache Temizle (EN ÖNEMLİ!)

```bash
php artisan route:clear
php artisan cache:clear
php artisan config:clear
php artisan view:clear
```

**Veya tek komutla:**

```bash
php artisan optimize:clear
```

### Çözüm 2: Route Listesini Kontrol Et

```bash
php artisan route:list --path=pay/callback
```

**Beklenen çıktı:**

```
POST | pay/callback | pay.callback | App\Http\Controllers\PayController@callback
```

### Çözüm 3: Middleware Sırasını Kontrol Et

**Dosya:** `bootstrap/app.php` veya `app/Http/Kernel.php`

Middleware sırası doğru olmalı:

```php
'web' => [
    \App\Http\Middleware\EncryptCookies::class,
    \Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class,
    \Illuminate\Session\Middleware\StartSession::class,
    \Illuminate\View\Middleware\ShareErrorsFromSession::class,
    \App\Http\Middleware\VerifyCsrfToken::class, // <-- Burada olmalı
    \Illuminate\Routing\Middleware\SubstituteBindings::class,
],
```

### Çözüm 4: Test POST İsteği

```bash
# cURL ile test
curl -X POST http://yourdomain.test/pay/callback \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "merchant_oid=PAY_TEST_123" \
  -d "status=success" \
  -d "total_amount=245000" \
  -d "hash=<computed-hash>"
```

**Hash hesaplama (PHP):**

```php
$hashString = 'PAY_TEST_123' . 'urxA5iL4EdoN8bx3' . 'success' . 245000;
$hash = base64_encode(hash_hmac('sha256', $hashString, 'Y2MW4s2ZkFYMGspG', true));
```

### Çözüm 5: Logları Kontrol Et

```bash
tail -f storage/logs/laravel.log
```

**Aranacak hatalar:**

- `TokenMismatchException`
- `CSRF token mismatch`
- `VerifyCsrfToken`

## 🎯 Hızlı Test Scripti

```bash
# 1. Cache temizle
php artisan optimize:clear

# 2. Route kontrolü
php artisan route:list --path=pay/callback

# 3. Test çalıştır
php test-paytr-callback.php
```

## ⚠️ Yaygın Nedenler

1. **Route cache temiz değil** → `php artisan route:clear`
2. **Config cache eski** → `php artisan config:clear`
3. **Middleware yanlış sırada** → `Kernel.php` kontrol et
4. **.env dosyası değişti** → `php artisan config:clear`
5. **Composer autoload sorunu** → `composer dump-autoload`

## ✅ Başarı Kriterleri

Test sonrası şunları görmelisiniz:

- ✅ Response: `OK` (plain text)
- ✅ HTTP Status: 200
- ✅ Log: `PAYTR Callback received`
- ✅ CSRF hatası YOK

## 🐛 Hala Sorun Varsa?

### Debug Mode Açık mı?

`.env` dosyasında:

```
APP_DEBUG=true
APP_ENV=local
```

### Session Driver Nedir?

`.env` dosyasında:

```
SESSION_DRIVER=file
# veya
SESSION_DRIVER=database
```

### Web Middleware Grubu Var mı?

Route tanımında `web` middleware grubu uygulanmış olmalı:

```php
Route::middleware('web')->group(function () {
    // Routes here
});
```

## 📞 Son Adım

Hala 419 alıyorsanız, şu bilgileri kontrol edin:

1. Route tanımlı mı? → `php artisan route:list --path=pay/callback`
2. CSRF exception var mı? → `VerifyCsrfToken.php` dosyasını kontrol et
3. Cache temizlendi mi? → `php artisan optimize:clear`
4. Log ne diyor? → `storage/logs/laravel.log`
