A member's plan change does not see a grant issued while it runs, and replaces that grant when it finishes #202
Open
opened 2026-10-09 16:02:10 +00:00 by cgalo5758
·
0 comments
Labels
Clear labels
accessibility
area/billing
area/catalog
area/discourse
area/domains
area/entitlements
area/fedwiki
area/identity
area/integrations
area/licensing
area/member-ui
area/meta
area/operator-ui
area/ops
area/testing
duplicate
good-first-issue
invalid
privacy
security
upstream
wontfix
A barrier for people using assistive technology or a keyboard alone.
The Stripe mirror, checkout, subscriptions, invoices, fulfillment.
Products, prices, plan ladders, purchasability.
The Discourse integration.
The domains registry, claims, placements, the certificate ask.
Entitlement sets, rules, grants, pools, provisioning.
The Federated Wiki integration and farm sync.
Sign-in, sessions, persons, organizations, workspaces, roles.
The provider registry, outbox and webhooks in general.
Licenses, the contributor agreement, SPDX headers.
Member pages.
The repository itself, its contributing guide, CI, the tracker and the workflow.
Operator pages, forms, lists, the design system.
Deployment, configuration, migrations, workflows, instance settings.
The test stack, screens, lint, walkthroughs.
Closed because another issue already covers it.
Small, self-contained, and explained enough to be a first contribution.
Closed because it is not a ticket for this repository.
Touches what a person's data reveals.
Touches authentication, authorization, secrets or data exposure.
Waits on another repository or project before it can move.
Closed because it will not be done, with the reason in the last comment.
kind
bug
The software does something other than what it promises; closed when it again does what it promises.
kind
debt
Code, tests or tooling to clean up with nothing visible changing; closed when they are cleaner.
kind
design
A question to settle before work can be defined; closed when the decision is written down.
kind
docs
Documentation that is wrong or missing; closed when it says the right thing.
kind
enhancement
Something the software does not do yet; closed when it does.
priority
critical
Blocks the active milestone or harms members now.
priority
high
Next in line inside the active milestone.
priority
low
Inside the active milestone, when nothing else is left.
priority
medium
Inside the active milestone, after the high ones.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: wiki-cafe/member-console#202
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What happens
Switch, Cancel and Keep on the member's Products page all start in
resolveLadderSubscription(internal/fulfillment/plan_change.go). It reads which tier the organization holds on the ladder and the subscription that pays for it. (A ladder is a sequence of tiers such as Plus, Pro and Max. An organization holds one tier on each ladder at a time, from a subscription or from a grant.) These reads take no lock and run in no transaction, and nothing reads the tier again before the change goes to Stripe. Each change first reads the subscription from Stripe, so the gap lasts at least one Stripe round trip.An operator's grant runs
core.confer, which locks the organization's pool row and ends whatever holds the ladder. The plan change never takes that lock, so it does not see a grant that commits inside the gap. The change is sent to Stripe for a subscription that no longer holds the ladder. Each change then ends with a reconcile, which finds the subscription delivering nothing and confers its tier again, and that ends the grant. If the operator marked the grant to resume, it waits for the subscription to end. If not, it is gone.Neither order gives this result. If the grant had committed first, the change would have answered "There's no active subscription to change on this plan." If the change had finished first, the grant would have replaced its tier.
What should happen
A plan change and a conferral on the same organization run one after the other, so the outcome is always one of those two orders.
Where
internal/fulfillment/plan_change.go:resolveLadderSubscriptionand its callersSwitchPlan,CancelSubscriptionandKeepCurrentPlan. The pool row lock is taken incore.confer(internal/db/migrations/00023_grant_resumption.sql).Steps
A downgrade, a cancellation at the end of the period and a Keep of a scheduled change end the same way at step 4.
Why it matters
The member pays for a change to a plan an operator had just replaced, and the operator's grant is undone a moment after it was issued.