Phase 5 billing: account-based annual sub + tag SKUs + SMS pool + tag lifecycle

- Schema: plans, orders subscription cols + plan_id + period_started_at,
  billing_events log, users.stripe_id + sms_credits, products.price_aud
  (db/schema.sql + Laravel migration, idempotent)
- Laravel/Cashier: Billable User, checkout (annual sub + one-off SKUs with
  Managed Payments tax_code), webhook controller (signature-verified,
  idempotent, BILLING_ENABLED kill-switch), account tag transitions,
  nightly reconcile, Stripe portal link, PlanResource + billing dashboard
- Go frontend: account-level gating (paid sub required), SMS pool
  (included 50/yr + credits, drawn after included), plan caps replace
  constants, 60s plan cache (credits fresh), 25-tag cap (plan max_tags)
- BillingSeeder: personal plan + 3 SKUs + dev paid orders
- Verified test-mode e2e: subscribe/paid/active/alerts, pool exhaust +
  credits resume, lapsed/suspended, cancelled/closed, recover/active,
  webhook idempotency, 25-cap, one-off SKUs, replacement, kill-switch,
  invalid signature 400
This commit is contained in:
2026-08-28 13:19:32 +10:00
parent 43ce4514c4
commit aabaa750f4
43 changed files with 2679 additions and 341 deletions

View File

@@ -0,0 +1,104 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
/**
* Phase 5 billing schema — mirrors db/schema.sql (canonical shared schema).
* Applied to the shared Postgres via: php artisan migrate --path=database/migrations/<this file>
* Kept idempotent-friendly (fresh or existing DB).
*/
return new class extends Migration
{
public function up(): void
{
// Plans table (plan_type reserves the future business model).
if (! Schema::hasTable('plans')) {
Schema::create('plans', function (Blueprint $table) {
$table->id();
$table->string('plan_type')->default('personal');
$table->string('name');
$table->decimal('price_aud', 10, 2)->default(10.00);
$table->string('billing_interval')->default('year');
$table->integer('sms_included')->default(50);
$table->integer('max_tags')->default(25);
$table->integer('alerts_per_day')->default(5);
$table->integer('alerts_per_hour')->default(10);
$table->timestamp('created_at')->useCurrent();
$table->timestamp('updated_at')->useCurrent();
});
}
// Order subscription columns + plan linkage + billing-period marker.
Schema::table('orders', function (Blueprint $table) {
if (! Schema::hasColumn('orders', 'stripe_id')) {
$table->string('stripe_id')->nullable();
}
if (! Schema::hasColumn('orders', 'pm_type')) {
$table->string('pm_type')->nullable();
}
if (! Schema::hasColumn('orders', 'pm_last_four')) {
$table->string('pm_last_four')->nullable();
}
if (! Schema::hasColumn('orders', 'trial_ends_at')) {
$table->timestamp('trial_ends_at')->nullable();
}
if (! Schema::hasColumn('orders', 'plan_id')) {
$table->foreignId('plan_id')->nullable()->constrained('plans')->nullOnDelete();
}
if (! Schema::hasColumn('orders', 'period_started_at')) {
$table->timestamp('period_started_at')->nullable();
}
});
// User billing columns.
Schema::table('users', function (Blueprint $table) {
if (! Schema::hasColumn('users', 'stripe_id')) {
$table->string('stripe_id')->nullable();
}
if (! Schema::hasColumn('users', 'sms_credits')) {
$table->integer('sms_credits')->default(0);
}
});
// Product SKU price (AUD) for one-off checkouts.
Schema::table('products', function (Blueprint $table) {
if (! Schema::hasColumn('products', 'price_aud')) {
$table->decimal('price_aud', 10, 2)->default(0);
}
});
// Webhook audit log.
if (! Schema::hasTable('billing_events')) {
Schema::create('billing_events', function (Blueprint $table) {
$table->id();
$table->string('stripe_event_id')->unique();
$table->string('event_type');
$table->foreignId('order_id')->nullable()->constrained('orders')->nullOnDelete();
$table->jsonb('payload')->nullable();
$table->timestamp('created_at')->useCurrent();
});
}
}
public function down(): void
{
Schema::dropIfExists('billing_events');
Schema::table('products', function (Blueprint $table) {
$table->dropColumn(['price_aud']);
});
Schema::table('users', function (Blueprint $table) {
$table->dropColumn(['stripe_id', 'sms_credits']);
});
Schema::table('orders', function (Blueprint $table) {
$table->dropForeign(['plan_id']);
$table->dropColumn(['stripe_id', 'pm_type', 'pm_last_four', 'trial_ends_at', 'plan_id', 'period_started_at']);
});
Schema::dropIfExists('plans');
}
};

View File

@@ -0,0 +1,78 @@
<?php
namespace Database\Seeders;
use App\Models\Order;
use App\Models\Plan;
use App\Models\Product;
use App\Models\User;
use Illuminate\Database\Seeder;
use Illuminate\Support\Facades\DB;
/**
* Billing seed: personal plan + tag/credit SKUs + a paid order for dev accounts.
*
* - Personal plan: $10/yr, 50 SMS included, 25 max tags, caps 5/day + 10/hr.
* - SKUs: single tag $5, 10-pack $20, 100-SMS credit pack $10.
* - Dev accounts that own tags get a paid order so existing verify suites
* keep alerting under the new account-level gating (idempotent).
*/
class BillingSeeder extends Seeder
{
public function run(): void
{
// 1. Personal plan (idempotent by name).
$plan = Plan::firstOrCreate(
['plan_type' => 'personal', 'name' => 'Personal'],
[
'price_aud' => 10.00,
'billing_interval' => 'year',
'sms_included' => 50,
'max_tags' => 25,
'alerts_per_day' => 5,
'alerts_per_hour' => 10,
]
);
// 2. Tag + credit SKUs (idempotent by sku).
$skus = [
['sku' => 'TAG-SINGLE', 'name' => 'Where Woof Tag (single)', 'item_type' => 'other', 'price_aud' => 5.00],
['sku' => 'TAG-10PACK', 'name' => 'Where Woof Tags (10-pack)', 'item_type' => 'other', 'price_aud' => 20.00],
['sku' => 'SMS-CREDITS-100', 'name' => '100 SMS Credits', 'item_type' => 'other', 'price_aud' => 10.00],
];
foreach ($skus as $s) {
Product::firstOrCreate(['sku' => $s['sku']], $s);
}
// 3. Paid order for any account that owns tags (dev regression safety),
// plus the known dev accounts (admin + owner) so verify suites that
// bind tags after a DB reset still alert under account-level gating.
$tagOwners = DB::table('tags')
->whereNotNull('owner_id')
->distinct()
->pluck('owner_id');
$devEmails = ['admin@where-woof.com', 'owner@where-woof.com'];
foreach (User::whereIn('email', $devEmails)->get() as $dev) {
$tagOwners->push($dev->id);
}
$tagOwners = $tagOwners->unique();
foreach ($tagOwners as $ownerId) {
$existing = Order::where('account_id', $ownerId)->where('status', 'paid')->first();
if ($existing) {
continue;
}
Order::create([
'account_id' => $ownerId,
'status' => 'paid',
'plan_id' => $plan->id,
'period_started_at' => now(),
'renews_at' => now()->addYear(),
'amount' => 10.00,
]);
}
$this->command?->info('BillingSeeder: plan + '.count($skus).' SKUs seeded; '.$tagOwners->count().' dev accounts given paid orders.');
}
}

View File

@@ -21,5 +21,9 @@ class DatabaseSeeder extends Seeder
'name' => 'Test User',
'email' => 'test@example.com',
]);
$this->call([
BillingSeeder::class,
]);
}
}