Repository navigation
fix: template bugs found in the first product's code - #496
Merged
Merged
Conversation
Plans were seeded without plan_features, so Pro granted nothing. One typed catalog now seeds plans and features. Checkout locks the account row, returns 409 for a live Stripe subscription found locally or in Stripe, reuses an open session and rejects the Free plan. A delayed payment no longer activates a plan. The plan list is public, and an optional yearly price is supported.
…kies
/users/me answered { user: null } once the 15-minute access cookie
expired, and the UI only refreshes on 401, so a reload logged the user
out. It now returns 401 while a refresh cookie exists. /auth/refresh
clears both cookies when the session is gone. Also: no stack for
validation errors in dev logs, notification events no longer import the
barrel, and a test keeps the cleanup table list complete.
The refresh retry re-read a consumed body, so the first write after token expiry failed. An unrecoverable 401 on /me now means logged out. The billing page polls after a Stripe return and offers a yearly price. Verify-email no longer runs its token twice under StrictMode, nginx 404s .well-known and missing data files, list errors get a retry, the error page gets a home action, devtools are opt-in and login returns to the page that asked for it.
…mages dorny/paths-filter lists PR files through the API, which needs pull-requests: read in a private repository; without it every PR check failed in the first product. A lint-meta rule now enforces it. pre-push no longer skips gates on SIGPIPE under pipefail and unsets inherited git variables. The API suite runs once in CI, agent verification cancels superseded PR runs, dev mail defaults to Mailpit, and packages/ reaches the API and UI images through a BuildKit context and dev containers through a read-only mount.
Mapping prices only through the built-in catalog dropped updates for plans a product adds outside it (the F10 security spec seeds one). Catalog prices still map first, so the yearly Pro price resolves to Pro; any other price matches plans.stripePriceId as before.
4 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Tinkercaster was created from the template at
cdacac0. This PR diffs every template file it changed since, reads the commit behind each change, keeps the ones that fixed a template bug or gap, and checks each against currentmain. Everything below was still present onmain. The findings are recorded as Report 3 (entries 102–119) indocs/maintenance/product-feedback.md.Billing
plan_features, so a Pro subscriber resolved Free entitlements. One typed catalog (billing.plans.ts) now seeds plans and their features. Pro must give every feature key a value, enforced by the type check and a unit test. Pro grants export, team invites and 10 seats.checkout.session.completedactivates the plan only forpaidorno_payment_required.async_payment_succeededandasync_payment_failedsettle the rest.GET /billing/plansis public, for the public site's pricing page, and works with billing off. The optionalSTRIPE_PRICE_ID_PRO_YEARLYadds a monthly/yearly choice on the billing page.Sessions
/users/meanswered{ user: null }and the UI refreshes only on 401. It now returns 401 while a refresh cookie exists. The UI refreshes, and an unrecoverable 401 resolves to logged out./auth/refreshnow clears both cookies when the session is gone.CI and repo
dorny/paths-filterlists PR files through the API, which needspull-requests: readin a private repository. BoringStack is public, so this never showed here, but every PR check failed in Tinkercaster. The permission is added to 14 workflows and enforced by the new lint-meta rulegithub-actions-paths-filter-permissions.echo | grep -qunderpipefailreturned 141 and the gate was skipped without a message. Here-strings replace it everywhere. The hook also unsets inheritedGIT_*variables.packages/*never reached the images. It now reaches them through a BuildKitpackagesbuild context and the dev containers through a read-only mount.packages/README.mdkeeps the directory present.UI
/.well-known/*and missing.json/.txt/.xml.?devtools, login returns to the page that asked for it (same-origin paths only), and the test setup gains jsdom stubs.API housekeeping
lib/notificationsbarrel.Not adopted (Report 3, entry 119): fast-by-default pre-push and skipping main runs after a verified PR weaken gates by policy. Removing the per-app release workflows would break Compose, which publishes through them.
Test plan
apps/api:bun run check, thenbun run test:coverageagainst a real Postgres (TEST_DATABASE_URL): 1346 pass, 0 fail, coverage gate passed (86.8% lines)apps/ui:bun run validate: 741 tests, build, size budgets, lint-meta, knip, formatapps/docs:bun run build:cibun run agent:check(101 pass),bun test infra/k3s/tests scripts/release, Compose guardrails, shellcheck, actionlint (only style notes already on main)nginx -ton the pinned image, and a throwaway container answered 404 for/.well-known/security.txtand 200 for SPA routespackages/build context: a scratch app importing a package built with--build-context packages, and the package files are present in the image--no-verify: the local pre-push e2e would run against another project's stack on :7331