Documentation
¶
Overview ¶
Package paywall is the commerce admin subscription gate. Org == store == namespace: an org may use the commerce admin only when it has paid ($20/mo pro plan), is inside a funded trial, or holds a redeemed invite code. Otherwise the gate returns 402 subscription_required.
It reuses the existing money primitives — it does NOT invent a parallel billing stack:
- subscription: models/subscription (Status active|trialing) on the pro plan (billing/trial.PlanSlug), the same records SubscribeWithCard writes.
- trial credit: the billing/trial.CreditTag deposit auto-granted on signup.
- invite: billing/invite (the referrals code→org primitive, reimplemented natively — commerce never imports cloud).
Require is the per-request middleware — a sibling to middleware.TokenRequired in the zip chain, mounted AFTER it so the org is already resolved. It is NOT mounted on /healthz, /v1/billing/*, the subscribe/trial/invite endpoints, or the public catalog (those are how an org acquires access, or are unauthenticated probes/reads), and it always passes internal service-token and platform-admin callers straight through.
Index ¶
Constants ¶
const DeniedCode = "subscription_required"
DeniedCode is the machine-readable denial code the console routes to an upgrade/redeem prompt. Mirrors the cloud edge gate's denyVerdict shape.
Variables ¶
This section is empty.
Functions ¶
func Allowed ¶
func Allowed(subDBs []*datastore.Datastore, txDB, invDB *datastore.Datastore, org string, at time.Time) (bool, string, error)
Allowed is the single access decision. It ALLOWS when the org has, in order:
- an active|trialing pro subscription in ANY of subDBs, OR
- a live trial credit — an unexpired, positive trial-credit deposit (txDB, org namespace) — the funded-trial-window signal, OR
- a redeemed invite (invDB, the system-namespace invite directory).
Otherwise it returns (false, DeniedCode, nil). A backing-store error is surfaced so the gate can fail closed with 503 rather than silently allow.
subDBs is a slice because in production a subscription may live in EITHER the per-org file store (billing/trial via NewNamespaced) OR the shared namespace-scoped store (SubscribeWithCard via New) — the gate must be a strict superset of both money paths and never block a paying customer. txDB carries the trial-credit ledger; invDB is the global "system" invite directory.
Types ¶
This section is empty.