A default ladder's last tier can be removed while organizations hold it, leaving the ladder empty #214
Open
opened 2026-10-10 23:59:46 +00:00 by cgalo5758
·
0 comments
Labels
Clear labels
accessibility
area/billing
area/catalog
area/discourse
area/domains
area/entitlements
area/fedwiki
area/identity
area/integrations
area/licensing
area/member-ui
area/meta
area/operator-ui
area/ops
area/testing
duplicate
good-first-issue
invalid
privacy
security
upstream
wontfix
A barrier for people using assistive technology or a keyboard alone.
The Stripe mirror, checkout, subscriptions, invoices, fulfillment.
Products, prices, plan ladders, purchasability.
The Discourse integration.
The domains registry, claims, placements, the certificate ask.
Entitlement sets, rules, grants, pools, provisioning.
The Federated Wiki integration and farm sync.
Sign-in, sessions, persons, organizations, workspaces, roles.
The provider registry, outbox and webhooks in general.
Licenses, the contributor agreement, SPDX headers.
Member pages.
The repository itself, its contributing guide, CI, the tracker and the workflow.
Operator pages, forms, lists, the design system.
Deployment, configuration, migrations, workflows, instance settings.
The test stack, screens, lint, walkthroughs.
Closed because another issue already covers it.
Small, self-contained, and explained enough to be a first contribution.
Closed because it is not a ticket for this repository.
Touches what a person's data reveals.
Touches authentication, authorization, secrets or data exposure.
Waits on another repository or project before it can move.
Closed because it will not be done, with the reason in the last comment.
kind
bug
The software does something other than what it promises; closed when it again does what it promises.
kind
debt
Code, tests or tooling to clean up with nothing visible changing; closed when they are cleaner.
kind
design
A question to settle before work can be defined; closed when the decision is written down.
kind
docs
Documentation that is wrong or missing; closed when it says the right thing.
kind
enhancement
Something the software does not do yet; closed when it does.
priority
critical
Blocks the active milestone or harms members now.
priority
high
Next in line inside the active milestone.
priority
low
Inside the active milestone, when nothing else is left.
priority
medium
Inside the active milestone, after the high ones.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: wiki-cafe/member-console#214
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What happens
An organization type can name a plan ladder as its default. (A plan ladder is an ordered list of tiers, and rank 0 is the bottom tier.) New organizations of that type start on the ladder's rank-0 tier, and an organization of that type left with no plan is put back on it. Deleting the only tier of such a ladder is refused with "This ladder's only remaining tier; defaults new signups to it. Deleting it would leave those signups without a starting plan, so the removal is refused."
Only the plain delete runs that check, and the plain delete is only for a tier that nobody holds. A tier with holders is removed through Preview removal and Apply change, and neither of those checks whether the tier is the last one on a default ladder:
What follows from an empty default ladder:
ReapplyDefaultsIfVacant, which returns an error when the default ladder has no rank-0 tier, so the whole act fails. #153 reports the same failure for a rank-0 product that confers nothing.The plain delete's check can also skip itself. When
orgTypesDefaultingToLaddercannot read the organization types, it logs the error and returns an empty list, and the delete goes ahead as though no type used the ladder as its default.What should happen
Removing the last tier of a ladder that an organization type uses as its default is refused, whichever way the tier is removed, as the plan ladder management spec ("The last tier of a live default ladder cannot be deleted") and
docs/models/plan-ladders-transitions.mdsay. Preview removal shows the refusal before a disposition is chosen. Apply change checks again inside its transaction, whatever disposition is posted, and uses the plain delete's wording. If the organization types cannot be read, the delete or removal is refused, not allowed.Where
internal/server/operator_plan_ladders.go:DeletePlanLadderTier(has the check),buildTierRemovalPreviewandCommitPlanLadderTierRemoval(lack it),orgTypesDefaultingToLadder. The consequences:ReapplyDefaultsForPoolininternal/entitlements/reapply_defaults.go, andinternal/provisioning/provisioning.go. The recorded answers ininternal/server/testdata/plan_acts/remove-last-tier-keep.jsonandremove-last-tier-migrate.jsonshow today's behaviour and will change with the fix.Steps
Why it matters
New organizations of that type start with no plan, and revoking, expiring or cancelling a plan fails for every organization of that type until an operator adds a tier back.