Skip to content

add a payment link switch for the pro request flow, empty until a live link exists - #421

Open
gerardrecinto wants to merge 1 commit into
masterfrom
pro-payment-link
Open

gerardrecinto wants to merge 1 commit into
masterfrom
pro-payment-link

Conversation

@gerardrecinto

Copy link
Copy Markdown
Collaborator

The Request Pro form now redirects to a Stripe Payment Link with the email prefilled when window.JOLTRIN_PRO_PAYMENT_LINK is set. It ships empty, so nothing changes for visitors and the email fallback stays. A test-mode link must not go there: a test-mode page cannot take a real card. When a live-mode Pro price and link exist, setting that one value in demo/index.html turns it on.

Pro is fulfilled by hand after payment, and docs/MONETIZATION_AND_TIERS.md now says so. The hosted billing code still only changes the hosted server's own tier, and nothing issues a license key to a self-hosted install, so the hosted app is not used to sell Pro.

Added an e2e test for the payment link path with the link stubbed. The existing email fallback test and the rest of the homepage spec pass on chromium.

Thanks, Gerard Recinto

@gerardrecinto gerardrecinto self-assigned this Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Gemini PR Review

Reviewed commit: a3440e4db8ded4ce688470bae1d97e2df8ceb2f9
Verdict: FAIL

  • Security Problem: demo/index.html directly uses the window.JOLTRIN_PRO_PAYMENT_LINK variable in window.location.href without any validation that it points to an allowed domain (e.g., https://buy.stripe.com/). While comments indicate this variable should be a trusted Stripe URL, the code itself does not enforce this. If this variable were ever to be controlled by an attacker (e.g., via XSS) or accidentally misconfigured with a malicious URL (like a javascript: URL), it could lead to an arbitrary redirect or XSS vulnerability.

This result blocks merge. Push a fix and comment /gemini review. To contest a finding, see the Gemini dispute process in CONTRIBUTING.md.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant