feat(account): start checkout from the account page #274

Sammanfogat
supernaut sammanfogade 2 incheckningar från feat/portal-checkout in i main 2026-10-01 19:49:36 +00:00
Ägare

What

Start a paid plan from the account page. Version 1.14.0.

  • New POST /api/checkout: auth guard, feature gate, rate limit (10 per hour per account), then the existing beginCheckout. Name and email come from the session only.
  • The redirect goes only to an https: URL on mollie.com or a subdomain. Anything else falls back to the account page with a billing error.
  • An account already in tier_pro gets "subscribed" before any consent row is written or the billing service is called.
  • Upgrade section on the account panel with the start-at-once consent. Notices for each checkout status, including a clear message when the profile lacks a display name or email.
  • Dark unless PAYMENTS_ENABLED, BILLING_API_URL and BILLING_API_TOKEN are all set.
  • Swedish and English strings.

Not in this PR

  • #149 (paid option at sign-up). It is blocked on #146.
  • Subscription status on the account page, and a monthly or annual choice. The billing service default interval applies.

Verification

  • pnpm test: 405/405. astro check: 0 errors. lang-check clean. Build and e2e pass.
  • Tests cover the feature gate, the profile and consent reasons, the redirect allowlist (http, foreign host, mollie.com.evil.test, evilmollie.com, unparsable) and the paid-account refusal.
  • Not covered: CSRF relies on Astro's default security.checkOrigin, which is not set explicitly. Worth one cross-origin POST against the deploy.

Closes #145

## What Start a paid plan from the account page. Version 1.14.0. - New `POST /api/checkout`: auth guard, feature gate, rate limit (10 per hour per account), then the existing `beginCheckout`. Name and email come from the session only. - The redirect goes only to an `https:` URL on `mollie.com` or a subdomain. Anything else falls back to the account page with a billing error. - An account already in `tier_pro` gets "subscribed" before any consent row is written or the billing service is called. - Upgrade section on the account panel with the start-at-once consent. Notices for each checkout status, including a clear message when the profile lacks a display name or email. - Dark unless `PAYMENTS_ENABLED`, `BILLING_API_URL` and `BILLING_API_TOKEN` are all set. - Swedish and English strings. ## Not in this PR - #149 (paid option at sign-up). It is blocked on #146. - Subscription status on the account page, and a monthly or annual choice. The billing service default interval applies. ## Verification - `pnpm test`: 405/405. `astro check`: 0 errors. `lang-check` clean. Build and e2e pass. - Tests cover the feature gate, the `profile` and `consent` reasons, the redirect allowlist (http, foreign host, `mollie.com.evil.test`, `evilmollie.com`, unparsable) and the paid-account refusal. - Not covered: CSRF relies on Astro's default `security.checkOrigin`, which is not set explicitly. Worth one cross-origin POST against the deploy. Closes #145
supernaut lade till 2 incheckningar 2026-10-01 18:26:40 +00:00
Adds an upgrade section to the account panel and POST /api/checkout. It
requires the start-at-once consent, sends the session's display name and
email to the billing service, and redirects to the hosted payment page.
A missing name or email shows a message saying what to fix. The return
URL lands on the account page with a notice.

The section and endpoint stay off unless PAYMENTS_ENABLED, BILLING_API_URL
and BILLING_API_TOKEN are all set.

Closes #145
fix(account): pin checkout redirect and refuse paid accounts
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m22s
296ee5a48f
Redirect only to https URLs on the Mollie host, else show the billing
error. A paid account posting directly to checkout now returns
"subscribed" before any consent row is stored. The payment-return
notice no longer claims the payment happened.

Refs #145
supernaut sammanfogade incheckning d2e23ba259 till main 2026-10-01 19:49:36 +00:00
supernaut tog bort grenen feat/portal-checkout 2026-10-01 19:49:36 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-10-01 19:49:37 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-10-02 17:56:59 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web!274
Ingen beskrivning angiven.