Skip to content

Hide the self-host banner from deployments that pay for Intelligence - #722

Merged
davidmckayv merged 1 commit into
mainfrom
david/banner-paid-plans
Oct 2, 2026
Merged

davidmckayv merged 1 commit into
mainfrom
david/banner-paid-plans

Conversation

@davidmckayv

Copy link
Copy Markdown
Contributor

The self-host banner from #720 stays on by default, but a deployment that pays for Intelligence no longer shows it.

The rule

The server reads the deployment's Intelligence entitlement (getRuntimeEntitlements on the client OpenBot already holds) and hides the banner when the entitlement is ready, active, and either on a paid plan (pro, team, team_self_hosted, enterprise) or from an AWS Marketplace licence. free, developer, an inactive entitlement, a missing plan code and every non-ready status show it. OPENBOT_SELF_HOST_BANNER=false still turns it off for everybody without asking Intelligence.

The plan codes come from Intelligence's license verifier (LicenseTier) and its entitlement routes, where a self-hosted licence reports its plan_code or tier as the plan code.

Never slows a page

  • The answer is cached in the server for ten minutes, so a plan bought today hides the bar within ten minutes and each replica makes at most six entitlement reads an hour.
  • A stale answer is returned at once and refreshed in the background.
  • The first page load after a start waits at most one second; after that the bar shows and the answer applies to the next load.
  • Any error shows the bar and is logged once per run of failures, not per request.

Upgrade note

The CHANGELOG's Before upgrading note now also covers:

  • the banner, and how to remove it;
  • Refuse a malformed IP range in an egress rule instead of reading it as /0 #706: an egress rule with a malformed IP range used to be read as /0. It is now refused, and a saved network policy containing one is refused as a whole (server/src/computer/policy-network.ts:55-60), so the Bots under it fall back to an empty allowlist and reach nothing until the rule is fixed.

Checks

  • 22 new tests cover every branch: each paid and unpaid plan code, AWS Marketplace, inactive, each non-ready status, the timeout, the cache, a stale refresh, concurrent loads, the off switch, and the capabilities endpoint. Breaking the rule or the wiring fails 9 of them.
  • Typecheck, lint, format and build pass.
  • bun run test:ci against a migrated pgvector database: 5,833 pass and 13 fail on this branch, 5,811 pass and the identical 13 fail on main. All 13 are local-environment only.
  • Live, against a real managed Intelligence project: the entitlement read back ready, active, managedOrgSubscription, plan enterprise. /api/capabilities answered selfHostBanner: false on the first request in 0.53 s, and the app showed no banner.

The banner offering help self-hosting OpenBot stays on by default, but a
deployment whose Intelligence entitlement is active on a paid plan (pro,
team, team_self_hosted, enterprise) or comes from an AWS Marketplace
licence no longer shows it. Free, developer, inactive and unreadable
entitlements still show it.

The server reads the entitlement through the Intelligence client it
already holds, keeps the answer for ten minutes, refreshes it in the
background when stale, waits at most a second for the first answer, and
falls back to showing the bar on any error, logged once per run of
failures.

The changelog's upgrade note also names the banner and the malformed
egress range change from #706, which refuses a saved network policy
that contains such a range as a whole.
@davidmckayv
davidmckayv merged commit 4881792 into main Oct 2, 2026
19 checks passed
@davidmckayv
davidmckayv deleted the david/banner-paid-plans branch October 2, 2026 23:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant