Checkout and the plan switch do not enforce what the Products page offers #175
Closed
opened 2026-10-06 21:11:37 +00:00 by cgalo5758
·
1 comment
Labels
Clear labels
accessibility
area/billing
area/catalog
area/discourse
area/domains
area/entitlements
area/fedwiki
area/identity
area/integrations
area/licensing
area/member-ui
area/meta
area/operator-ui
area/ops
area/testing
duplicate
good-first-issue
invalid
privacy
security
upstream
wontfix
A barrier for people using assistive technology or a keyboard alone.
The Stripe mirror, checkout, subscriptions, invoices, fulfillment.
Products, prices, plan ladders, purchasability.
The Discourse integration.
The domains registry, claims, placements, the certificate ask.
Entitlement sets, rules, grants, pools, provisioning.
The Federated Wiki integration and farm sync.
Sign-in, sessions, persons, organizations, workspaces, roles.
The provider registry, outbox and webhooks in general.
Licenses, the contributor agreement, SPDX headers.
Member pages.
The repository itself, its contributing guide, CI, the tracker and the workflow.
Operator pages, forms, lists, the design system.
Deployment, configuration, migrations, workflows, instance settings.
The test stack, screens, lint, walkthroughs.
Closed because another issue already covers it.
Small, self-contained, and explained enough to be a first contribution.
Closed because it is not a ticket for this repository.
Touches what a person's data reveals.
Touches authentication, authorization, secrets or data exposure.
Waits on another repository or project before it can move.
Closed because it will not be done, with the reason in the last comment.
kind
bug
The software does something other than what it promises; closed when it again does what it promises.
kind
debt
Code, tests or tooling to clean up with nothing visible changing; closed when they are cleaner.
kind
design
A question to settle before work can be defined; closed when the decision is written down.
kind
docs
Documentation that is wrong or missing; closed when it says the right thing.
kind
enhancement
Something the software does not do yet; closed when it does.
priority
critical
Blocks the active milestone or harms members now.
priority
high
Next in line inside the active milestone.
priority
low
Inside the active milestone, when nothing else is left.
priority
medium
Inside the active milestone, after the high ones.
Milestone
No items
No Milestone
Public launch
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: wiki-cafe/member-console#175
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What happens
The Products page decides which control a member gets on each tier: Checkout, a switch, a downgrade at the period end, or none (
buildPlansData,internal/server/member_products.go). It offers only a product's default price, and outside plan tiers only a recurring one. The endpoints that move money check less:HandleCheckout,internal/server/billing.go) refuses only when a subscription already holds the ladder. An organization on a granted tier can buy a tier below it, which replaces the grant; a tab opened before the grant was issued gets there.SwitchPlan,internal/fulfillment/plan_change.go) accept any active price of the product, such as an older, cheaper one kept for existing subscribers. Checkout also accepts a one-time price, which then fails at Stripe.switchTargetHeld,internal/server/member_products.go) and lets the request through when it cannot read the organization's pools.What should happen
One function without database access takes the organization's position on a ladder and a target price and returns the move offered. The page draws from it; Checkout, the switch and its preview refuse anything else, and refuse when a read fails.
Done when
Fixed on main, in
2e1617cthroughf66a80b.plans.Offer(internal/plans/offer.go) decides the move offered on a tier from the organization's position on the ladder and the target price, and reads nothing. The Products page draws its controls from it, and Checkout, the switch and its preview refuse any target it does not offer as that move, and refuse when a read they need fails. Checkout now also refuses the tier a grant holds and every tier below it, a price that is not the product's default, a one-time price, and a product whose other ladders do not all offer Checkout. A table test covers the decision, and each refusal has a database test beside a control that the same fixture allows. Two cases that come from one product sitting on several ladders remain, and are on #88.