Repository navigation
feat(billing): Stripe Managed Payments licensing with Polar fallback - #25
Merged
Merged
Conversation
Moves Dictx Pro checkout and licensing from Polar to Stripe Managed Payments (Link is the seller of record, as for the other SplitLabs products on the same Stripe account), without breaking installed apps or existing customers. - /buy is now api/buy.js: the Stripe Payment Link once STRIPE_SECRET_KEY, DICTX_STRIPE_PRICE_ID, DICTX_LICENSE_SECRET and a canonical live DICTX_STRIPE_PAYMENT_LINK are all valid; the Polar checkout until then. Deploying this changes nothing for buyers until Stripe is configured. - /api/pro/license issues dxp-<session>-<hmac> keys for verified purchases: live mode (forced in production), complete and paid, exactly one Dictx Pro price at quantity 1, charge neither refunded nor disputed. - /api/pro/verify checks dxp- keys against Stripe with no Polar config needed; lk_/polar_cl_ keys keep the Polar path. Refunds and disputes deactivate on the next app check; Stripe outages return 502, which the app treats as keep-current-state. Positive results cache for 10 minutes. - Keys use only [A-Za-z0-9_-], the charset installed app versions already send to /api/pro/verify, so no app release is needed to activate them. - /buy/success fetches and shows the key for Stripe sessions, keeps the Polar URL behaviour otherwise, and points failures to the published SplitLabs contact. Reopening the page reissues the same key. - Copy: landing FAQ and the licenseKeyPlaceholder in all 17 locales. - README: Stripe setup steps, env vars, lost-key recovery. - landing/tests/billing.test.js (7 tests) covers key integrity, exact classification, production live-mode, /buy fail-closed, the license endpoint, verify routing, and refund deactivation. Not included: email delivery of keys (no mail provider on this project) and a Stripe webhook; entitlement correctness comes from re-verifying the live session instead. Claude-Session: https://claude.ai/code/session_01CvRJfFeFvF96jhBFujxvHN
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Moves Dictx Pro checkout and licensing from Polar to Stripe Managed Payments (Link is the seller of record), without breaking installed apps or existing customers.
/buy→api/buy.js: the Stripe Payment Link onceSTRIPE_SECRET_KEY,DICTX_STRIPE_PRICE_ID,DICTX_LICENSE_SECRETand a canonical liveDICTX_STRIPE_PAYMENT_LINKare all valid; Polar until then./api/pro/licenseissuesdxp-<session>-<hmac>keys for verified purchases (live mode forced in production, complete and paid, exactly one Dictx Pro price at quantity 1, not refunded or disputed)./api/pro/verifychecksdxp-keys against Stripe without Polar config;lk_/polar_cl_keys keep the Polar path. Refunds and disputes deactivate on the next app check; Stripe outages return 502 (app keeps current state).[A-Za-z0-9_-], which installed app versions already send to/api/pro/verify, so no app release is needed./buy/successfetches the key for Stripe sessions and keeps Polar behaviour otherwise. FAQ copy, all 17 locale placeholders, README setup and env docs.Stripe objects (live, created with the Stripe CLI)
prod_VGAwMgXh0UgB0w, tax codetxcd_10202000(Downloadable Software)price_1UFeb2IOmsupAvc3VoCin47h, $29 USDplink_1UFebaIOmsupAvc3m6DV45ul, Managed Payments on, redirect to/buy/success?session_id={CHECKOUT_SESSION_ID}DICTX_STRIPE_PRICE_ID,DICTX_STRIPE_PAYMENT_LINK,DICTX_LICENSE_SECRETare set in Vercel production.STRIPE_SECRET_KEYis not yet;/buystays on Polar until it is.Verification
landing/tests/billing.test.js: 7/7 (key integrity, exact classification, production live mode,/buyfail-closed, license endpoint, verify routing, refund deactivation)https://claude.ai/code/session_01CvRJfFeFvF96jhBFujxvHN