Skip to content

Carry main fixes into redesign main (#746) - #677

Merged
thomasluizon merged 5 commits into
redesign/mainfrom
fix/ticket-746-carry-stripe-play-pinger
Oct 1, 2026
Merged

thomasluizon merged 5 commits into
redesign/mainfrom
fix/ticket-746-carry-stripe-play-pinger

Conversation

@thomasluizon

@thomasluizon thomasluizon commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Refs thomasluizon/orbit-tickets#746

Carries the three requested main commits into redesign/main in order, with their cherry-pick provenance trailers. No additional behavior changes, skipped commits, or manual conflict resolutions. All source tests are retained.

Carried commits and resolutions

  • d8799479 becomes ba2a9ca7: carries the Cloudflare staging health pinger, Terraform resources, deployment documentation, tests, and CI coverage wiring in infra/staging-pinger.tf, infra/workers/staging-pinger.mjs, infra/staging-pinger.test.mjs, infra/README.md, .github/workflows/terraform.yml, and .github/workflows/sonarcloud.yml. SonarCloud merged automatically; inspection confirmed the existing redesign workflow configuration remains alongside both coverage reports. The other files applied unchanged.
  • 2b50ca81 becomes bec2e293: carries the staging Google Play package override in infra/configuration.tf, its regression tests in infra/google-play-isolation.test.mjs, and their Terraform workflow entry. Applied unchanged without conflicts.
  • 6444752a becomes 28a07512: carries production and staging Stripe success URLs in infra/configuration.tf, the corresponding infrastructure assertions, and request-input digests for checkout and portal idempotency in src/Orbit.Infrastructure/Services/StripeBillingService.cs, with all tests in tests/Orbit.Infrastructure.Tests/Services/StripeBillingServiceTests.cs. Applied unchanged without conflicts. Those four files match the source commit byte for byte.
  • Review fix, carried from main: 819165fb (fix: send the staging pinger with manual redirects #678, "fix: send the staging pinger with manual redirects") becomes ed0e3e3b with -x. Cloudflare rejects redirect: "error" when it builds the Request, so the Worker now sends manual and fails the invocation on a 3xx; infra/README.md and infra/staging-pinger.test.mjs change with it. The branch then merged redesign/main (6144fe84) forward.

The separate source files and tests remain together as each original coherent change. No DTO, version floor, user-date, background notification, route, or module changes. No migrations were carried, so there is no migration ordering question. OpenAPI was regenerated by the build after the final cherry-pick and remains byte-identical.

External interface evidence

  • Source PR 673 records the installed Cloudflare 5.26.0 provider schema inspection proving the Worker and Cron Trigger arguments, plus evidence for scheduledTime, native Response status/ok/text, Request options, and Node coverage output. This carry retains that implementation and its native Request/Response tests unchanged.
  • Source PR 675 records installed Stripe.net 52.4.2 XML and assembly reflection proving RequestOptions.IdempotencyKey, virtual typed CreateAsync signatures, and session Url properties used by the carried service tests. No new external response fields are introduced.

Test evidence

This is an unchanged carry of already implemented fixes. Original pre-fix regression observations are recorded in PR 673, PR 674, and PR 675; they were not rerun against reverted implementations here.

  • Before each commit, env -u LANG dotnet build Orbit.slnx: exit 0, zero errors. Existing warnings remain.
  • node --test infra/staging-pinger.test.mjs: exit 0, 14 passed.
  • node --test infra/google-play-isolation.test.mjs after the Play carry: exit 0, 3 passed.
  • env -u LANG dotnet test tests/Orbit.Infrastructure.Tests --no-build --filter FullyQualifiedName~StripeBillingServiceTests: exit 0, 19 passed.
  • node --test infra/*.test.mjs: exit 0, 33 passed, zero failures or skips. After the pinger review fix and the base merge: exit 0, 34 passed (the new redirect-response case included); with the old redirect: "error" the updated option assertion fails 1 of 15 in infra/staging-pinger.test.mjs.
  • From src/Orbit.Infrastructure, env -u LANG dotnet ef migrations has-pending-model-changes --project . --startup-project ../Orbit.Api --no-build: exit 0, "No changes have been made to the model since the last migration."
  • env -u LANG dotnet build Orbit.slnx and env LC_ALL=en_US.UTF-8 dotnet build Orbit.slnx: exit 0 each, zero errors.
  • env -u LANG dotnet test and env LC_ALL=en_US.UTF-8 dotnet test: exit 0 each, 8,500 passed in each locale (Application 4,861; Infrastructure 2,956; Domain 651; Analyzers 32), zero failures or skips.
  • Commit hooks passed. Bare narration-comment inspection and whitespace checks passed. Generated architecture artifacts remain uncommitted.

Manual steps

These are the carried changes' existing rollout requirements. No deployment, Terraform apply, dashboard edit, or live purchase verification was performed by this carry worker.

  • Cloudflare: follow infra/README.md using CLOUDFLARE_API_TOKEN and targets cloudflare_workers_script.staging_pinger and cloudflare_workers_cron_trigger.staging_pinger. In Workers & Pages > orbit-staging-pinger > Settings > Triggers > Cron Triggers, confirm */5 11-23 * * * and */5 0-2 * * *. In Observability, retain five-minute invocation evidence and the seven independent successful health probes over one hour specified in the README. Keep .github/workflows/staging-keepalive.yml until both proofs pass.
  • Play: apply the reviewed staging environment-group plan, then confirm Render Dashboard > Environment Groups > orbit-staging-api has GooglePlay__PackageName=org.useorbit.app.staging; verify the effective key in orbit-api-staging > Environment. In Google Play Console > Orbit Staging > Monetize with Play > Products > Subscriptions, confirm orbit_pro and active monthly and yearly plans, plus referral10 if enabled. Confirm the shared service accounts have Orbit Staging access in Users and permissions. Complete the staging-only RTDN topic/push subscription wiring in Google Cloud Console > Pub/Sub and Play Console > Monetization setup as specified in source PR 674. A licensed staging purchase must verify and acknowledge against the staging package.
  • Stripe: deploy the carried idempotency change before applying the reviewed Terraform changes to render_env_group.production_api and render_env_group.staging_api. In Render Dashboard > Environment Groups and each service's Environment screen, confirm Stripe__SuccessUrl is production https://app.useorbit.org/profile?subscription=success and staging https://app-staging.useorbit.org/upgrade?subscription=success; Stripe__CancelUrl remains /upgrade on the corresponding hosts. Create fresh checkout and portal sessions and inspect success_url, cancel_url, and return_url in Stripe Dashboard > Developers > Logs. At the redesign production release, change production success to https://app.useorbit.org/upgrade?subscription=success as specified by source PR 675's owner decision.

The standing ticket stays open. This pull request is for redesign/main and must not close #746.

thomasluizon and others added 3 commits September 30, 2026 23:21
* fix: add Cloudflare staging health pinger for ticket 1009

* ci: report staging pinger coverage to SonarCloud

The pinger's node tests ran in the Terraform workflow only, so SonarCloud read
0% coverage on the new Worker. Run them with coverage beside the web plan
guard and pass both lcov reports.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit d879947)
* fix: correct Stripe checkout success routes

* fix: bind Stripe session idempotency keys to request inputs

(cherry picked from commit 6444752)

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

The staging pinger fails before sending its health request because Cloudflare rejects the configured redirect mode. This needs correction before the Worker can replace the existing keepalive.

Reviewed changes Reviewed the three carried commits, their infrastructure configuration, runtime behavior, regression tests, and source-PR interface evidence.

  • Staging pinger: Adds the Cloudflare Worker, five-minute schedules, observability, deployment proof instructions, and CI coverage while retaining the GitHub keepalive.
  • Play isolation: Overrides the staging Android package without changing production billing configuration or the staging RTDN audience.
  • Stripe redirects and idempotency: Corrects per-environment success routes and incorporates variable checkout and portal request inputs into deterministic keys, with regression tests.

Validation: all 33 infrastructure Node tests and all 19 Stripe service tests passed. A separate workerd 2026-10-01 runtime probe with compatibility date 2026-09-30 reproduced the redirect-mode failure; the inline finding includes the evidence and required outcome. No live deployment or purchase verification was performed.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using openai/gpt-6.1-sol | 𝕏

Comment thread infra/workers/staging-pinger.mjs Outdated
thomasluizon and others added 2 commits September 30, 2026 23:39
Cloudflare's runtime rejects redirect: "error" when it builds the Request,
so every scheduled ping failed before reaching staging /health. Manual
mode is accepted, and the existing response.ok check still fails the
invocation on a 3xx response, now covered by its own test.

Refs thomasluizon/orbit-tickets#1009

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 819165f)

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes Reviewed the delta since the prior Pullfrog review at 28a07512, with the complete PR diff as context. The resolved redirect finding is fixed and remains settled.

  • Corrected Worker redirects: Switched to Cloudflare-supported manual mode while preserving invocation failure on redirect responses.
  • Added regression coverage: Updated the request-option assertion and added a 301-response case verifying rejection and failure logging.
  • Updated deployment documentation: Explained the redirect restriction and retained the existing live cutover proof requirements.
  • Merged the base branch: Carried redesign/main forward without additional net behavioral changes in the reviewed delta.

Validation: node --test infra/*.test.mjs passed all 34 tests. No live deployment or Terraform apply was performed; documented rollout verification remains required.

Pullfrog  | View workflow run | Using openai/gpt-6.1-sol | 𝕏

@thomasluizon
thomasluizon merged commit e71baf1 into redesign/main Oct 1, 2026
22 checks passed
@thomasluizon
thomasluizon deleted the fix/ticket-746-carry-stripe-play-pinger branch October 1, 2026 02:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant