Phase 5 billing: account-based annual sub + tag SKUs + SMS pool + tag lifecycle

- Schema: plans, orders subscription cols + plan_id + period_started_at,
  billing_events log, users.stripe_id + sms_credits, products.price_aud
  (db/schema.sql + Laravel migration, idempotent)
- Laravel/Cashier: Billable User, checkout (annual sub + one-off SKUs with
  Managed Payments tax_code), webhook controller (signature-verified,
  idempotent, BILLING_ENABLED kill-switch), account tag transitions,
  nightly reconcile, Stripe portal link, PlanResource + billing dashboard
- Go frontend: account-level gating (paid sub required), SMS pool
  (included 50/yr + credits, drawn after included), plan caps replace
  constants, 60s plan cache (credits fresh), 25-tag cap (plan max_tags)
- BillingSeeder: personal plan + 3 SKUs + dev paid orders
- Verified test-mode e2e: subscribe/paid/active/alerts, pool exhaust +
  credits resume, lapsed/suspended, cancelled/closed, recover/active,
  webhook idempotency, 25-cap, one-off SKUs, replacement, kill-switch,
  invalid signature 400
This commit is contained in:
2026-08-28 13:19:32 +10:00
parent 43ce4514c4
commit aabaa750f4
43 changed files with 2679 additions and 341 deletions

View File

@@ -111,3 +111,38 @@ SELECT * FROM url_shortened WHERE code = $1;
-- name: GetScanByID :one
SELECT * FROM scans WHERE id = $1;
-- name: GetActiveOrderByAccount :one
-- The account's current paid subscription order (if any), with its plan.
SELECT o.*, p.plan_type, p.price_aud, p.sms_included, p.max_tags,
p.alerts_per_day, p.alerts_per_hour
FROM orders o
LEFT JOIN plans p ON p.id = o.plan_id
WHERE o.account_id = $1 AND o.status = 'paid'
ORDER BY o.id DESC
LIMIT 1;
-- name: GetActiveOrderByOwner :one
-- Account-level gating for a tag: resolve the tag's owner account, then the
-- account's active paid subscription order (with plan). Returns zero rows
-- when the tag is unowned or the account has no paid order.
SELECT o.*, p.plan_type, p.price_aud, p.sms_included, p.max_tags,
p.alerts_per_day, p.alerts_per_hour
FROM tags t
JOIN orders o ON o.account_id = t.owner_id AND o.status = 'paid'
LEFT JOIN plans p ON p.id = o.plan_id
WHERE t.id = $1
ORDER BY o.id DESC
LIMIT 1;
-- name: CountAlertsByAccountSince :one
-- SMS pool draw: alerts sent for any tag owned by the account in the period.
SELECT count(*) FROM scans s
JOIN tags t ON t.id = s.tag_id
WHERE t.owner_id = $1 AND s.alert_sent = TRUE AND s.scanned_at > $2;
-- name: CountOwnedTags :one
-- Live owned-tag count for the per-account cap: everything bound to the
-- account except retired (closed) tags, including bound-but-unset codes.
SELECT count(*) FROM tags
WHERE owner_id = $1 AND status <> 'closed';