payments: the portal's upgrade surface and typed calls into the payment service #145
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web#145
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Replaces #34 and #35, which were filed before the payments architecture was decided and asked for the
schema and the provider integration to be built in this repository. Both belong to the separate
private payment service. This issue is the part that genuinely remains here.
Scope
The portal's role is the upgrade surface and the typed client calls — not billing state, not the
provider.
checkout, and handle the return.
Kanidm group membership is the seam, and the reconciler projects it onto Forgejo.
creation is currently granted to nobody (the Kanidm
ent_orgsgroup was emptied on 2026-08-01, becausean organisation is a priced add-on), so the org path has an infrastructure prerequisite outside this
repo.
Already in place
PAYMENTS_ENABLED(src/lib/payments-access.ts) gates the whole surface, off by default. The invertedpolarity is deliberate: a missing or mistyped variable leaves payment surfaces dark rather than
exposing half-built billing.
typed end to end with no codegen. Import that rather than hand-rolling request shapes.
/pricingalready carries the prices and states that paid accounts are not yet purchasable.Blocked on
The payment service being deployed and reachable. Until then this cannot be built beyond the UI shell,
and building the shell against an unpublished contract is how the shapes drift.
Label is
blockedrather thanready-for-implementationfor that reason — the dependency is real andoutside this repo, and marking it ready would misrepresent it as pickable.