Configure staging billing from SSM and verify test purchases - #629
Merged
Merged
Conversation
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes in commit 19a2f2e0, including staging billing configuration, rollout instructions, and purchase tests.
- Staging Stripe configuration: Five test-mode product and price IDs now come from SSM into the staging API environment group; the unused publishable key is removed.
- Play notifications: The staging RTDN audience points to the staging API, with matching Pub/Sub setup documented.
- Purchase coverage: Play license-tester responses pass through the Google SDK test client and existing verify and RTDN handlers; the signed Stripe checkout test now asserts the stored entitlement identifiers.
GPT Sol | 𝕏
|
thomasluizon
added a commit
that referenced
this pull request
Sep 28, 2026
) * Add Render Terraform for production and staging (#621) * Add Terraform for Render production and staging * Handle Render database URLs without explicit ports * Keep production intact through the first apply and isolate staging integrations The imported API service ignores its own env_vars so the first apply only adds and links the environment group, and the existing Render project is imported (environments keyed by their live names) so the API stays in its Production environment while a Staging environment is added. Staging gets placeholder Stripe identifiers, staging return URLs, its own redirect allowlist and an invalid Supabase host, so it cannot touch production billing or storage. Empty custom domain lists become null, the landing no longer auto-deploys, and the web health check uses /api/health. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 1480d1b) * Store confirmed waitlist contacts in Orbit database (#620) * feat: store confirmed waitlist marketing contacts locally * fix: preserve marketing opt-outs and canonicalize waitlist languages * Restore user marketing delivery after explicit opt-in (cherry picked from commit 4c7b76a) * Add Google authorization code sign in (#622) * Implement Google authorization code sign in for ticket 796 * Register Google code routes in agent catalog * Parse Google token responses with installed SDK * fix: retry Google code sign-in after redemption (cherry picked from commit 2301ccc) * Add Cloudflare DNS and Turnstile to Terraform (#623) * Add Cloudflare DNS and Turnstile Terraform resources * Verify Cloudflare DNS answers before the registrar switch Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 7e946a6) * Gate production API releases through Render (#624) * Add gated production API release workflow * Handle queued Render deploys and recheck the live commit before recording a release Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 78b42f2) * Keep Terraform from reverting web release digests (#627) * fix: preserve workflow deployed web digests in Terraform * docs: guard web service applies against Render image tag bug (cherry picked from commit b8ea2c1) * Configure staging billing from SSM and verify test purchases (#629) (cherry picked from commit 5e5623e) * Align Google code error assertion with redesign response --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




Change
/orbit/staging/api/String parameters ininfra/configuration.tf. The existing test-mode SecureString secret and webhook key remain staging-specific. Set the staging Google Play RTDN audience to the staging API URL.StripeSettings, andappsettings.json.infra/README.md. Add application tests for Play Subscriptions V2 test purchases through verify and RTDN, plus a signed Stripe test-mode checkout event.This keeps billing IDs in SSM and reuses the existing purchase handlers, which already accept test purchases and signed test events.
Test evidence
env -u LANG LC_ALL=en_US.UTF-8 dotnet test tests/Orbit.Application.Tests/Orbit.Application.Tests.csproj --filter 'FullyQualifiedName~VerifyPlayPurchaseCommandHandlerTests|FullyQualifiedName~HandlePlayNotificationCommandHandlerTests|FullyQualifiedName~HandleWebhookCommandHandlerTests' --no-restore -v minimalpassed, 98 tests.env -u LANG LC_ALL=en_US.UTF-8 dotnet build Orbit.slnx -v minimalpassed with zero errors.env -u LANG LC_ALL=en_US.UTF-8 dotnet test Orbit.slnx --no-restore -v minimalpassed, 6,813 tests.terraform fmt -check -recursive infraandterraform -chdir=infra validatepassed after provider initialization without the remote backend.infra/local.tfvars. The source diff keeps production price IDs, product ID, secret inputs, and Google Play values unchanged. The unused production publishable key is removed as the ticket comment requires.SubscriptionPurchaseV2.TestPurchaseas present only for a test purchase. AWS provider v6.66.0 schema introspection confirmsaws_ssm_parameter.valueis a computed, sensitive string. No live SSM value was read in this worktree.Assumptions
testPurchasemarker rather than the olderpurchaseTypefield named in the ticket body.Manual steps
/orbit/staging/api/Stripe__ProProductId,Stripe__MonthlyPriceIdUsd,Stripe__YearlyPriceIdUsd,Stripe__MonthlyPriceIdBrl, andStripe__YearlyPriceIdBrlexist as String parameters, andStripe__SecretKeyandStripe__WebhookSecretexist as SecureString test-mode values. A Terraform plan that reads all seven and maps the five IDs toorbit-staging-apiproves the parameters are available.RENDER_API_KEY,CLOUDFLARE_API_TOKEN, AWS credentials, andinfra/local.tfvars, then plan and apply. Inspect the plan before apply: production Stripe product and price IDs and Google Play values must stay unchanged, apart from removal ofStripe__PublishableKey. Confirm theorbit-staging-apienvironment group contains the five test IDs and the staging RTDN audience after apply.https://api-staging.useorbit.org/api/subscriptions/play/rtdn, using the configuredGooglePlay__RtdnServiceAccountEmail. A delivered test-purchase RTDN accepted by the staging API proves the audience matches.play/verifyand an RTDN update granting Pro in staging proves the Play path works.https://api-staging.useorbit.org/api/subscriptions/webhookuses the SSM signing secret and delivers the five events listed ininfra/README.md. A test card checkout and signedcheckout.session.completedthat grants Pro proves the Stripe path works.Closes thomasluizon/orbit-tickets#808