feat(account): start checkout from the account page #274
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!274
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/portal-checkout"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Start a paid plan from the account page. Version 1.14.0.
POST /api/checkout: auth guard, feature gate, rate limit (10 per hour per account), then the existingbeginCheckout. Name and email come from the session only.https:URL onmollie.comor a subdomain. Anything else falls back to the account page with a billing error.tier_progets "subscribed" before any consent row is written or the billing service is called.PAYMENTS_ENABLED,BILLING_API_URLandBILLING_API_TOKENare all set.Not in this PR
Verification
pnpm test: 405/405.astro check: 0 errors.lang-checkclean. Build and e2e pass.profileandconsentreasons, the redirect allowlist (http, foreign host,mollie.com.evil.test,evilmollie.com, unparsable) and the paid-account refusal.security.checkOrigin, which is not set explicitly. Worth one cross-origin POST against the deploy.Closes #145