Repository navigation
Carry main fixes into redesign main (#746) - #677
Conversation
* fix: add Cloudflare staging health pinger for ticket 1009 * ci: report staging pinger coverage to SonarCloud The pinger's node tests ran in the Terraform workflow only, so SonarCloud read 0% coverage on the new Worker. Run them with coverage beside the web plan guard and pass both lcov reports. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit d879947)
(cherry picked from commit 2b50ca8)
* fix: correct Stripe checkout success routes * fix: bind Stripe session idempotency keys to request inputs (cherry picked from commit 6444752)
There was a problem hiding this comment.
Important
The staging pinger fails before sending its health request because Cloudflare rejects the configured redirect mode. This needs correction before the Worker can replace the existing keepalive.
Reviewed changes Reviewed the three carried commits, their infrastructure configuration, runtime behavior, regression tests, and source-PR interface evidence.
- Staging pinger: Adds the Cloudflare Worker, five-minute schedules, observability, deployment proof instructions, and CI coverage while retaining the GitHub keepalive.
- Play isolation: Overrides the staging Android package without changing production billing configuration or the staging RTDN audience.
- Stripe redirects and idempotency: Corrects per-environment success routes and incorporates variable checkout and portal request inputs into deterministic keys, with regression tests.
Validation: all 33 infrastructure Node tests and all 19 Stripe service tests passed. A separate workerd 2026-10-01 runtime probe with compatibility date 2026-09-30 reproduced the redirect-mode failure; the inline finding includes the evidence and required outcome. No live deployment or purchase verification was performed.
openai/gpt-6.1-sol | 𝕏
Cloudflare's runtime rejects redirect: "error" when it builds the Request, so every scheduled ping failed before reaching staging /health. Manual mode is accepted, and the existing response.ok check still fails the invocation on a 3xx response, now covered by its own test. Refs thomasluizon/orbit-tickets#1009 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 819165f)
…46-carry-stripe-play-pinger
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes Reviewed the delta since the prior Pullfrog review at 28a07512, with the complete PR diff as context. The resolved redirect finding is fixed and remains settled.
- Corrected Worker redirects: Switched to Cloudflare-supported
manualmode while preserving invocation failure on redirect responses. - Added regression coverage: Updated the request-option assertion and added a 301-response case verifying rejection and failure logging.
- Updated deployment documentation: Explained the redirect restriction and retained the existing live cutover proof requirements.
- Merged the base branch: Carried
redesign/mainforward without additional net behavioral changes in the reviewed delta.
Validation: node --test infra/*.test.mjs passed all 34 tests. No live deployment or Terraform apply was performed; documented rollout verification remains required.
openai/gpt-6.1-sol | 𝕏

Refs thomasluizon/orbit-tickets#746
Carries the three requested main commits into redesign/main in order, with their cherry-pick provenance trailers. No additional behavior changes, skipped commits, or manual conflict resolutions. All source tests are retained.
Carried commits and resolutions
d8799479becomesba2a9ca7: carries the Cloudflare staging health pinger, Terraform resources, deployment documentation, tests, and CI coverage wiring ininfra/staging-pinger.tf,infra/workers/staging-pinger.mjs,infra/staging-pinger.test.mjs,infra/README.md,.github/workflows/terraform.yml, and.github/workflows/sonarcloud.yml. SonarCloud merged automatically; inspection confirmed the existing redesign workflow configuration remains alongside both coverage reports. The other files applied unchanged.2b50ca81becomesbec2e293: carries the staging Google Play package override ininfra/configuration.tf, its regression tests ininfra/google-play-isolation.test.mjs, and their Terraform workflow entry. Applied unchanged without conflicts.6444752abecomes28a07512: carries production and staging Stripe success URLs ininfra/configuration.tf, the corresponding infrastructure assertions, and request-input digests for checkout and portal idempotency insrc/Orbit.Infrastructure/Services/StripeBillingService.cs, with all tests intests/Orbit.Infrastructure.Tests/Services/StripeBillingServiceTests.cs. Applied unchanged without conflicts. Those four files match the source commit byte for byte.main:819165fb(fix: send the staging pinger with manual redirects #678, "fix: send the staging pinger with manual redirects") becomesed0e3e3bwith-x. Cloudflare rejectsredirect: "error"when it builds the Request, so the Worker now sendsmanualand fails the invocation on a 3xx;infra/README.mdandinfra/staging-pinger.test.mjschange with it. The branch then mergedredesign/main(6144fe84) forward.The separate source files and tests remain together as each original coherent change. No DTO, version floor, user-date, background notification, route, or module changes. No migrations were carried, so there is no migration ordering question. OpenAPI was regenerated by the build after the final cherry-pick and remains byte-identical.
External interface evidence
Test evidence
This is an unchanged carry of already implemented fixes. Original pre-fix regression observations are recorded in PR 673, PR 674, and PR 675; they were not rerun against reverted implementations here.
env -u LANG dotnet build Orbit.slnx: exit 0, zero errors. Existing warnings remain.node --test infra/staging-pinger.test.mjs: exit 0, 14 passed.node --test infra/google-play-isolation.test.mjsafter the Play carry: exit 0, 3 passed.env -u LANG dotnet test tests/Orbit.Infrastructure.Tests --no-build --filter FullyQualifiedName~StripeBillingServiceTests: exit 0, 19 passed.node --test infra/*.test.mjs: exit 0, 33 passed, zero failures or skips. After the pinger review fix and the base merge: exit 0, 34 passed (the new redirect-response case included); with the oldredirect: "error"the updated option assertion fails 1 of 15 ininfra/staging-pinger.test.mjs.src/Orbit.Infrastructure,env -u LANG dotnet ef migrations has-pending-model-changes --project . --startup-project ../Orbit.Api --no-build: exit 0, "No changes have been made to the model since the last migration."env -u LANG dotnet build Orbit.slnxandenv LC_ALL=en_US.UTF-8 dotnet build Orbit.slnx: exit 0 each, zero errors.env -u LANG dotnet testandenv LC_ALL=en_US.UTF-8 dotnet test: exit 0 each, 8,500 passed in each locale (Application 4,861; Infrastructure 2,956; Domain 651; Analyzers 32), zero failures or skips.Manual steps
These are the carried changes' existing rollout requirements. No deployment, Terraform apply, dashboard edit, or live purchase verification was performed by this carry worker.
infra/README.mdusingCLOUDFLARE_API_TOKENand targetscloudflare_workers_script.staging_pingerandcloudflare_workers_cron_trigger.staging_pinger. In Workers & Pages > orbit-staging-pinger > Settings > Triggers > Cron Triggers, confirm*/5 11-23 * * *and*/5 0-2 * * *. In Observability, retain five-minute invocation evidence and the seven independent successful health probes over one hour specified in the README. Keep.github/workflows/staging-keepalive.ymluntil both proofs pass.GooglePlay__PackageName=org.useorbit.app.staging; verify the effective key in orbit-api-staging > Environment. In Google Play Console > Orbit Staging > Monetize with Play > Products > Subscriptions, confirmorbit_proand activemonthlyandyearlyplans, plusreferral10if enabled. Confirm the shared service accounts have Orbit Staging access in Users and permissions. Complete the staging-only RTDN topic/push subscription wiring in Google Cloud Console > Pub/Sub and Play Console > Monetization setup as specified in source PR 674. A licensed staging purchase must verify and acknowledge against the staging package.render_env_group.production_apiandrender_env_group.staging_api. In Render Dashboard > Environment Groups and each service's Environment screen, confirmStripe__SuccessUrlis productionhttps://app.useorbit.org/profile?subscription=successand staginghttps://app-staging.useorbit.org/upgrade?subscription=success;Stripe__CancelUrlremains/upgradeon the corresponding hosts. Create fresh checkout and portal sessions and inspectsuccess_url,cancel_url, andreturn_urlin Stripe Dashboard > Developers > Logs. At the redesign production release, change production success tohttps://app.useorbit.org/upgrade?subscription=successas specified by source PR 675's owner decision.The standing ticket stays open. This pull request is for redesign/main and must not close #746.