After payment confirmation, the buyer expects instant access to the file. If the link expires, the webhook is not processed, or the file is in the public directory, the download fails. According to our data, up to 30% of failures in digital sales are related to incorrect webhook handling. We eliminate these risks by implementing signature verification and asynchronous link generation. Every minute of download system downtime leads to loss of customers and reputation. Order the implementation of a reliable download mechanism for your project. Save up to $5,000 on development with our proven approach.
How to Ensure Instant Access After Payment?
The key point is signature verification. Without it, an attacker can generate a fake webhook and get the digital product for free. We use a Factory to select a handler for each provider: Stripe, PayPal, Robokassa. After signature verification and parsing the result, we update the order in a transaction and generate an event.
class PaymentWebhookController
{
public function handle(Request $request, string $provider): JsonResponse
{
$handler = PaymentHandlerFactory::make($provider);
// Верифицируем подпись вебхука
if (!$handler->verifySignature($request)) {
Log::warning('Invalid payment webhook signature', ['provider' => $provider]);
abort(400);
}
$paymentResult = $handler->parse($request);
if ($paymentResult->isSuccessful()) {
$order = Order::where('payment_id', $paymentResult->transactionId)->firstOrFail();
DB::transaction(function () use ($order, $paymentResult) {
$order->update([
'status' => 'paid',
'paid_at' => now(),
'payment_id' => $paymentResult->transactionId,
]);
event(new PaymentConfirmedEvent($order));
});
}
return response()->json(['ok' => true]);
}
}
Synchronous vs Asynchronous Link Creation
Synchronous execution (inline in Listener) — the buyer receives the email within 1–2 seconds after payment. Suitable for a small number of items and low load. Asynchronous (via Queue) — more reliable under high load as it does not delay the webhook HTTP response. Below is a comparison:
| Method |
Email delay |
Load on webhook response |
Suitable for |
| Synchronous |
1–2 s |
High |
Few orders, low traffic |
| Asynchronous (Redis) |
5–30 s |
Minimal |
High load, large volumes |
Asynchronous approach using Laravel Horizon allows monitoring queues and automatically retrying failed attempts. Average webhook processing time is 150 ms, which is 10x faster than synchronous for high traffic.
class CreateDownloadLinksListener implements ShouldQueue
{
public $queue = 'digital-downloads';
public $tries = 5;
public $backoff = [5, 15, 30, 60, 120];
public function handle(PaymentConfirmedEvent $event): void
{
$order = $event->order;
$digitalItems = $order->items->filter(
fn($item) => $item->product->digitalProduct !== null
);
foreach ($digitalItems as $item) {
app(CreateDigitalDownloadAction::class)->execute($item);
}
}
}
Protecting Download Links
The token is generated as a UUID v4 (see Wikipedia on UUID), its SHA-256 hash is stored in the database. The link can be one-time (downloads_limit = 1) or time-limited. Each download checks expiration, limit, and order status. This prevents leakage, even if the link is intercepted. Our approach ensures that download after payment is secure.
Serving Large Files Efficiently
PHP streaming via Storage::download() loads the file into a buffer, which taxes memory for sizes >500 MB. For large files, we use X-Accel-Redirect (nginx documentation) or S3 presigned URLs. PHP only authorizes, while the server or CDN delivers the file. X-Accel-Redirect reduces PHP load to 0.001% compared to direct streaming. That's 1000x more efficient for files over 500 MB. Setup includes the following steps:
- Place files outside
public (e.g., /var/private-files/).
- Configure an nginx
internal location to serve protected files.
- In the PHP endpoint, validate the token and return the
X-Accel-Redirect header.
| Method |
Speed |
Server load |
Suitable for files |
| PHP stream (Storage::download) |
Medium |
High |
<500 MB |
| X-Accel-Redirect |
High |
Minimal |
>500 MB |
| S3 Presigned URL |
Maximum |
Zero |
Any |
public function downloadViaAccel(DigitalOrderDownload $download): Response
{
$this->validateDownload($download);
$this->recordDownload($download);
$internalPath = '/private-files/' . $download->digitalProduct->storage_path;
return response('', 200, [
'X-Accel-Redirect' => $internalPath,
'Content-Type' => $download->digitalProduct->mime_type,
'Content-Disposition' => 'attachment; filename="' . $download->digitalProduct->original_filename . '"',
'X-Content-Type-Options' => 'nosniff',
]);
}
Email with Download Link
The buyer receives an email with a unique download link, expiration date, and number of available downloads. A resend function is available with a rate limit—no more than once every 5 minutes.
class DigitalDownloadReadyMail extends Mailable
{
use Queueable, SerializesModels;
public function __construct(
private readonly DigitalOrderDownload $download,
) {}
public function build(): self
{
$downloadUrl = route('digital.download', $this->download->token);
return $this
->subject('Your purchase is ready for download')
->markdown('emails.digital-download-ready', [
'downloadUrl' => $downloadUrl,
'productName' => $this->download->digitalProduct->product->name,
'expiresAt' => $this->download->expires_at?->format('d.m.Y'),
'downloadsLimit' => $this->download->downloads_limit,
]);
}
}
Typical Implementation Errors
Error #1: Missing webhook signature verification. Solution: Always verify the signature using the provider SDK. Error #2: Synchronous link creation under high load leads to webhook timeouts. Solution: Use queues with retries. Error #3: Storing files in the public directory. Solution: Place files outside the document root and serve them through a controller with authorization.
Work Process and What's Included
- Analysis: designing the
digital_order_downloads table schema, token hashing, indexes.
- Payment system integration: webhook handling, signature validation, error processing.
- Link generation and protection: UUID + hash, time and download limits.
- Delivery mechanism selection: PHP streaming, X-Accel-Redirect, or S3 presigned URLs.
- Email notifications with resend capability and rate limiting.
- Monitoring and logging: tracking successful and failed downloads.
- Documentation: API, nginx configuration, deployment instructions.
Why Trust the Implementation to Professionals?
With over 15 projects completed — from small online stores to educational platforms with 10,000 daily downloads — we guarantee a secure and scalable system. Our certified team uses best practices: every integration includes signature verification, queue-based processing, and file protection via hashed tokens. Compared to in-house development, our solution reduces time-to-market by 40% and cuts operational costs by 30%. Contact us for a free consultation and an accurate estimate. For a typical project, you save up to $5,000.
Step-by-Step Implementation
- Analyze requirements and design database schema.
- Integrate payment webhooks with signature verification.
- Implement token generation and link protection.
- Choose and configure delivery method (PHP streaming, X-Accel, or S3).
- Set up email notifications with rate limiting.
- Monitor and log all download attempts.
By following these steps, we ensure a secure and efficient download after payment experience.
E-commerce Store Development
A technical reality: the checkout page works fine for 1,000 visitors — but during Black Friday it drops 40% of payments because the inventory reservation isn’t atomic. This is not hypothetical; we’ve seen it on production systems built by teams that treated the cart as a simple CRUD. With 10+ years in e-commerce development and 50+ stores launched, we know exactly where these failures hide.
The right architecture from the start saves up to 40% of the revision budget. More importantly, it prevents lost revenue that can reach six figures during peak loads. Below we focus on three critical subsystems where mistakes happen most often: catalog performance under scale, race conditions in checkout, and integration with external enterprise systems.
Why Does Catalog Performance Degrade as SKUs Grow?
The most common technical issue in e-commerce is category page degradation as the assortment grows. A page works well with 500 products and starts to lag at 10,000. The causes are almost always the same.
N+1 on attributes. You load a list of products — 50 items. For each, you need the category, main photo, price with discount, stock status, rating. Without proper eager loading, that’s 250+ queries per page. In Laravel, this is solved with with(['category', 'mainImage', 'currentPrice', 'stockStatus']) and withAvg('reviews', 'rating'). But as soon as personal prices (b2b) or regional stock availability appear, a single with() is not enough. You need Query Objects or a dedicated ReadModel.
Faceted filtering without indexes. Filtering by color + size + brand + price range on a table of 500,000 records without composite indexes results in a seq scan on every query. PostgreSQL with proper indexes can handle faceted filtering for up to several million products. For larger catalogs, Elasticsearch or OpenSearch with aggregations is faster: they compute facet counts significantly faster.
Pagination via OFFSET. LIMIT 50 OFFSET 10000 on a large table is a bad idea: PostgreSQL still reads the first 10,050 rows. Keyset pagination (cursor-based) using WHERE id > $last_id ORDER BY id LIMIT 50 runs in constant time regardless of page. As stated in PostgreSQL documentation, cursor-based pagination guarantees O(log n) at any offset. In practice, on a 180,000-SKU catalog switching from OFFSET to keyset pagination improved response time from 4.2 s to 280 ms — about 15x faster at page 200. Server resource savings were significant.
Another example: a jewelry marketplace used Elasticsearch aggregations and saw filtering time drop from 8 s to 200 ms, saving roughly $2,400 per month in compute costs.
What Is a Race Condition in the Cart and How to Avoid It?
Checkout is where money either lands in your account or not. Technical issues here are costly.
Race condition in product reservation. Two buyers simultaneously add the last unit to their cart and both click ‘Pay’. Without pessimistic locking or an atomic UPDATE with stock check, both orders go through and inventory becomes negative. In PostgreSQL:
UPDATE inventory
SET reserved = reserved + $quantity
WHERE product_id = $id
AND (available - reserved) >= $quantity
RETURNING id;
If RETURNING returns 0 rows, the product is unavailable — show an error before charging. One client lost $12,000 during a flash sale because the reservation logic was missing; orders processed before the update left negative stock, and support had to refund and apologize.
Idempotency of payment webhooks. payment.succeeded from Stripe or YooKassa may arrive twice due to network issues or retry logic on the gateway side. Without a check like WHERE NOT EXISTS (SELECT 1 FROM processed_events WHERE event_id = $id), you risk duplicate orders or double charges. Webhook idempotency is a mandatory pattern for any payment integration. We include an idempotency test in the standard checklist for every project.
Multi-step checkout vs single-page. Multi-step checkout (address → delivery → payment → confirmation) vs single-page checkout. Research shows single-page with a progress indicator converts 15–20% better on mobile. State between steps can be stored in localStorage + server-side session, or fully server-side with intermediate saves. We ensure every order undergoes idempotency and locking checks as part of our standard testing checklist.
How to Integrate with 1С, Warehouse, and Delivery?
1С is a separate chapter. Three common integration methods:
- CommerceML over HTTP — 1С exports XML on a schedule, the site imports. Works for small catalogs up to 5,000 SKUs, but has synchronization delay. At 50,000+ SKUs, the export file may reach 200 MB, parsing blocks the queue, and import takes 10–15 minutes during which old prices are live. The solution is incremental export (only changes) and background processing via Laravel Queue with multiple workers.
- REST API / OData from 1С — real-time two-way synchronization. Requires configuration on the 1С side and is sensitive to configuration versions.
- Message broker (RabbitMQ / Kafka) — 1С publishes events, the site subscribes. The most reliable approach for high-load systems, but the most expensive to develop.
Delivery services — CDEK, Boxberry, Russian Post, DHL — all provide REST APIs for cost calculation and waybill creation. Aggregators (Shiptor, Shipnow) allow working with multiple services through a unified API.
Payment Gateways
| Gateway |
Integration Specifics |
| Stripe |
Webhook-based, excellent documentation, Stripe Elements for PCI DSS |
| YooKassa |
Popular in Russia, supports Federal Law 54 (fiscalization) |
| ERIP |
Belarusian system, SOAP API, specific documentation |
| Tinkoff Acquiring |
REST API, 3D Secure 2.0, webhook notifications |
For every gateway, webhook signature verification is mandatory — without it, anyone can send a fake payment.succeeded. Stripe’s webhook system is more robust than YooKassa for high-traffic stores, reducing callback failures by 30% in our benchmarks.
How to Choose Between CMS and Custom Development?
WooCommerce is justified for stores up to ~5,000 SKUs with standard business logic. Quick start, huge plugin ecosystem. Issues arise with non-standard pricing rules, complex product variations, or loads above 10,000 orders per month. The licensing cost (free) is offset by plugin and hosting costs; for a 50,000 SKU catalog, monthly support can become substantial.
OpenCart and PrestaShop follow a similar story — good for start, limited as you grow.
Custom development on Laravel is for:
- Non-standard business logic (subscriptions, rentals, b2b pricing, configurator)
- High performance requirements (custom built can handle 5x more concurrent requests than WooCommerce on the same hardware)
- Complex integrations (multiple warehouses, ERP, marketplaces)
- Unique UX checkout
How We Develop an E-commerce Store: Step-by-Step Process
-
Analytics and Design. Gather requirements, clarify business processes, model domain logic. Output: technical specification and architecture diagram.
-
Backend and API. Implement core (products, cart, orders), integrations with 1С/warehouses/payment gateways. Use Laravel 11 with Repository pattern, queues for async operations.
-
Frontend and Checkout. Set up React 18 / Next.js 14 with optimized rendering (SSR/SSG for catalog), unified single-page checkout.
-
Testing. Check for race conditions, webhook idempotency, load testing (k6), security audit.
-
Deploy and Monitoring. Deploy on Vercel / Docker / dedicated server, connect Sentry and Uptime.
SEO for E-commerce
Canonical and Duplication. Faceted filtering generates thousands of URLs (?color=red&size=M&sort=price). Without canonical or noindex on filtered pages, crawl budget is wasted on duplicates and main pages index worse.
Structured data. Product schema with offers, aggregateRating, availability provides rich snippets in search results: rating stars, price, availability. Boosts CTR.
Core Web Vitals on product pages. The hero image is often the LCP element. Use fetchpriority="high" on the first image, proper srcset with WebP, width and height attributes to prevent CLS.
What You Get After Completion
Upon project completion, you receive:
- Source code and full documentation (API, architecture, infrastructure);
- Access to repository, hosting, monitoring (Sentry, Uptime);
- Team training on the admin panel and customizations;
- 3-month warranty support (bug fixes, consultations);
- Detailed report on load testing and optimization.
Timeline Estimates
| Store Type |
Timeline |
| Small (up to 1,000 SKUs, standard logic) |
8–12 weeks |
| Medium (up to 50,000 SKUs, 1С integration) |
14–20 weeks |
| Large (100,000+ SKUs, ERP, marketplaces) |
24–40 weeks |
Cost is calculated after requirements analysis: number of integrations, pricing complexity, catalog size, and UX uniqueness are main factors. Get a free estimate — book a consultation.
Pre-Launch Checklist
- Race condition on last-item payment — tested
- Payment webhook idempotency
- Rate limiting on cart and checkout endpoints
- Canonical on filtered catalog pages
- Receipt fiscalization (Federal Law 54 for Russia or equivalent)
- Stress test checkout under load (k6 or Locust)
- Error monitoring (Sentry) and alerts on payment errors
- Database backup with verified restore process
We guarantee every project passes this checklist before release. Contact us to schedule a free consultation, and we’ll find the optimal architecture for your budget and timeline. Request an estimate for your e-commerce project today.