Skip to content

Harden Stripe billing, slim README and homepage, bump to 5.8.0 - #415

Merged
gerardrecinto merged 9 commits into
masterfrom
use-joltrinhq-domain
Oct 2, 2026
Merged

gerardrecinto merged 9 commits into
masterfrom
use-joltrinhq-domain

Conversation

@gerardrecinto

Copy link
Copy Markdown
Collaborator

Hardens the Stripe billing path, slims the README and homepage, and bumps everything to 5.8.0. Nothing is tagged or published.

Billing

  • Live mode refuses webhooks until a signing secret is set. Before, a live server with no secret skipped signature checks.
  • /api/billing/checkout/simulate returns 404 outside simulation mode.
  • Pro checkout needs a real price ID, webhook secret, and absolute return URLs in live mode. Enterprise stays contact-sales without its own price ID.
  • GET /api/billing/plan now has a checkout block listing missing env var names, never values.
  • New tests: missing config, simulation, bad and missing signatures, duplicates (including after restart), and the payment failed, recovered, canceled, deleted lifecycle.

Azure

  • Bicep and deploy-azure.yml pass the Pro and Enterprise price IDs and JOLTRIN_PUBLIC_URL. Secrets still go through Key Vault. Stripe secrets should be set as GitHub secrets, not written to Key Vault by hand, since each deploy re-applies them.

Docs and site

  • README is about 100 lines. Deep content moved to nine new files under docs/.
  • Homepage is half the length, with the three live experiences under the hero and one pricing section. Removed claims the site could not back (Apple Pay, instant provisioning, annual price). Pro is "Request Pro" with an email fallback.
  • Canonical and social URLs and demo/CNAME use joltrinhq.com.

Version

  • scripts/update_version.sh 5.8.0. Bindings had stayed at 5.6.0 through the v5.7.0 tag.

Testing

  • gofmt, vet, build, and tests pass for governance and tools/httpserver, including -race on the billing tests.
  • Playwright on Chromium and mobile Chrome: 46 passed, 2 skipped.
  • go build ./... fails linking bindings/main on my machine because of a broken macOS SDK, unrelated to this change.

Still needed in the Stripe Dashboard (not part of this PR)
Create the Pro price, create the webhook endpoint and copy its signing secret, then set the GitHub secrets and variables listed in infra/azure/README.md.

Thanks, Gerard Recinto

@gerardrecinto gerardrecinto self-assigned this Oct 1, 2026
Comment thread tests/homepage.spec.ts Fixed
gerardrecinto and others added 3 commits October 2, 2026 09:33
…ession anchor'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@gerardrecinto
gerardrecinto merged commit b9b8cf1 into master Oct 2, 2026
27 of 29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants