feat(migrate): grants revoke endpoint and revoked grant state - #406
Merged
Merged
Conversation
Pin @contentrain/types 1.45.0 (renewal_cents) and drop the local extra type. Supabase auth refuses to hand an email account with another GitHub identity to a stranger. The webhook carries the checkout id: a second subscription for a grant, or a payment from a stale checkout, raises an ALARM (Polar cannot expire a checkout); a redeemed bundle without a subscription id alarms in the reconciler.
…ount subscription.created/updated ask first (isDuplicateBundleSubscription) and skip every account write for a second subscription on a bundle grant, so refunding it cannot cancel the valid plan. Supabase identity check reads the user identities instead of the last sign-in provider metadata.
POST /api/migrate/grants/revoke (S2S, purpose 'revoke'): cancels only the subscription the grant is bound to, then marks the grant revoked (migration 045: revoked_at, revoked_reason). Idempotent; a Polar failure leaves the grant live (502) and gives the jti back so Migrate can retry. A refund of a payment that is not the bound subscription (duplicate checkout) never revokes: the request carries no payment id and nothing else is cancelled. Revoked grants answer state 'revoked' on status, refuse checkout/provision (409 migrate.grant_revoked) and treat later payments as alarmed duplicates. @contentrain/types 1.46.0.
# Conflicts: # package.json # pnpm-lock.yaml # server/utils/migrate-bundle-subscription.ts # tests/unit/migrate-bundle-subscription.test.ts
Member
Author
|
t6 review @ 4bff14e — ONAY, with two findings to track Evidence at this head: studio CI Checks asked for:
Findings (not blocking this merge, fix before Migrate wires the caller):
|
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
POST /api/migrate/grants/revoke(S2S, signed, single-use jti): Migrate's half of a refund or failed delivery.redeemed_subscription_id), then marks the grant revoked (migration 045:revoked_at,revoked_reason).revoked. Polar failure -> 502, grant stays live, jti given back so Migrate retries.revoked(installed fact kept); checkout/provision refuse with 409migrate.grant_revoked; install-url gated by state.ALARM payment after revoke), no account write.@contentrain/types1.46.0.Tests
New route test (9), plus status/checkout/provision/bundle-subscription cases and a contract test (postgres:16). Full unit/integration/nuxt/contract green; eslint, typecheck clean.