feat(migrate): bundle money guards and identity check (S3 slice 1) - #405
Conversation
Pin @contentrain/types 1.45.0 (renewal_cents) and drop the local extra type. Supabase auth refuses to hand an email account with another GitHub identity to a stranger. The webhook carries the checkout id: a second subscription for a grant, or a payment from a stale checkout, raises an ALARM (Polar cannot expire a checkout); a redeemed bundle without a subscription id alarms in the reconciler.
|
t6 review @ 206ec7f — CHANGES REQUESTED (1 blocker), rest OK Local evidence at this head: targeted unit (3 files, 33 tests) pass, billing-webhook integration (40 tests) pass, eslint on changed files clean, Blocker — duplicate-payment subscription is still stored as the workspace's active account. Non-blocking
Re-ping me after the fix and I will re-review the delta quickly. |
…ount subscription.created/updated ask first (isDuplicateBundleSubscription) and skip every account write for a second subscription on a bundle grant, so refunding it cannot cancel the valid plan. Supabase identity check reads the user identities instead of the last sign-in provider metadata.
|
t6 delta review @ 0464111 — ONAY (pending green CI) Blocker fixed: Local evidence at this head: unit (migrate-bundle-subscription + supabase-auth-provider) 22/22, billing-webhook integration 41/41, eslint on delta files clean, Known residual (non-blocking): a duplicate created event that lands before the first subscription is redeemed is not detectable (redeemed id still null); the reconciler/alarm path covers it. |
Follow-up to #404 (t6's non-blocking findings) plus the types bump.
@contentrain/types1.45.0 (renewal_cents); the local extra type is gone.ensureUserForProviderAccountrefuses (IdentityConflictError) an email account already signed in with a different GitHub account, same guard as the managed pair.checkoutId; a second subscription for a grant that already has one logs[migrate-bundle] ALARM duplicate payment … refund itand is not bound or moved; a payment from a non-current checkout is honoured but logsALARM stale checkout paid. An unchanged price already reuses the open checkout (S2), so two payable checkouts exist only when the price changed.Refund of a flagged payment is the ops command in (e) (t5).
Local: lint 0 errors, typecheck 0, unit 1997 pass (run with --testTimeout=90000; the machine was loaded), integration 486, nuxt 274.