Setup commercial launch: licenze + backend Cloudflare Worker
Client (Python/JS):
- core/license.py: attivazione, validazione, deactivate (HTTP client + JWT decode)
- core/config.py: campi license_* + URL endpoint + costanti grace/revalidate
- api/bridge.py: get_init_data ritorna license status; activate_license/
deactivate_license/revalidate_license/open_purchase_page
- check_update riscritto: punta a musictools.djluza.com/api/latest con
Bearer token, URL di download firmato dal server solo se licensed
- webui: schermata di attivazione bloccante all'avvio; sezione Licenza
in Impostazioni con verifica/disattiva
Backend (server/):
- Cloudflare Worker + D1 + R2 (vedi server/README.md)
- Endpoints: /api/license/{activate,validate,deactivate}, /api/latest,
/api/webhook/lemonsqueezy, /api/health
- JWT HS256 con rotazione; max 3 attivazioni/licenza
- Generazione licenze via webhook Lemon Squeezy + email Resend
- Schema D1 in migrations/0001_init.sql
Memory: nuova musictools-commercial-launch.md, rimosso pending obsoleto
NON taggare finche backend non e' deployato (l'app e' bloccante)
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
1 parent
05a2a58ace
commit
5202b2c586
19 files changed
+1572
-31
No files matched your search
@@ -0,0 +1,88 @@
|
||||
# MusicTools License & Update API
|
||||
|
||||
Cloudflare Worker che gestisce attivazione licenze, validazione e distribuzione binari MusicTools.
|
||||
|
||||
## Stack
|
||||
- **Cloudflare Workers** (compute serverless, free tier 100k req/giorno)
|
||||
- **Cloudflare D1** (sqlite gestito, free tier 5GB)
|
||||
- **Cloudflare R2** (storage zip binari, free tier 10GB)
|
||||
- **Lemon Squeezy** (Merchant of Record per i pagamenti, gestisce IVA UE)
|
||||
- **Resend** (invio email license-key, free tier 3k email/mese)
|
||||
|
||||
## Setup iniziale
|
||||
|
||||
Una volta sola, da terminale dentro `server/`:
|
||||
|
||||
```bash
|
||||
npm install
|
||||
npx wrangler login # autenticati a Cloudflare
|
||||
|
||||
# 1. Crea il database D1
|
||||
npx wrangler d1 create musictools-licenses
|
||||
# -> copia il database_id stampato nel wrangler.toml
|
||||
|
||||
# 2. Applica lo schema
|
||||
npm run db:migrate:prod
|
||||
|
||||
# 3. Crea il bucket R2 per i binari
|
||||
npx wrangler r2 bucket create musictools-builds
|
||||
|
||||
# 4. Imposta i secret (NON in chiaro nel wrangler.toml)
|
||||
npx wrangler secret put JWT_SECRET # > openssl rand -base64 32
|
||||
npx wrangler secret put LEMONSQUEEZY_SIGNING_SECRET # > dal dashboard LS
|
||||
npx wrangler secret put RESEND_API_KEY # > dal dashboard Resend
|
||||
|
||||
# 5. Deploy
|
||||
npm run deploy
|
||||
```
|
||||
|
||||
## DNS
|
||||
|
||||
Su Cloudflare Dashboard > djluza.com > DNS aggiungi:
|
||||
|
||||
```
|
||||
musictools CNAME <subdomain-worker>.workers.dev proxied
|
||||
```
|
||||
|
||||
Poi vai su Workers & Pages > musictools-api > Settings > Triggers > Custom Domains
|
||||
e aggiungi `musictools.djluza.com`.
|
||||
|
||||
## Endpoints
|
||||
|
||||
| Metodo | Path | Auth | Descrizione |
|
||||
|---|---|---|---|
|
||||
| POST | `/api/license/activate` | — | Attiva licenza, ritorna JWT |
|
||||
| POST | `/api/license/validate` | — (token nel body) | Rivalida + ruota token |
|
||||
| POST | `/api/license/deactivate` | — (token nel body) | Libera uno slot |
|
||||
| GET | `/api/latest?platform=…` | Bearer token (opzionale) | Versione + URL download firmato |
|
||||
| POST | `/api/webhook/lemonsqueezy` | X-Signature HMAC | Crea licenza dopo ordine |
|
||||
| GET | `/api/health` | — | Healthcheck |
|
||||
|
||||
## Workflow pubblicazione release
|
||||
|
||||
1. GitHub Actions builda macOS e Windows zip (gia in place).
|
||||
2. Step manuale (per ora): scarica i due zip, caricali su R2:
|
||||
```bash
|
||||
npx wrangler r2 object put musictools-builds/v1.5.3/MusicTools-macOS.zip --file=MusicTools-macOS.zip
|
||||
npx wrangler r2 object put musictools-builds/v1.5.3/MusicTools-Windows.zip --file=MusicTools-Windows.zip
|
||||
```
|
||||
3. Inserisci il record `releases`:
|
||||
```sql
|
||||
INSERT INTO releases (version, platform, r2_key, size_bytes, sha256, notes, published_at)
|
||||
VALUES ('v1.5.3', 'macos', 'v1.5.3/MusicTools-macOS.zip', 12345, '<sha256>', 'Note...', strftime('%s','now'));
|
||||
```
|
||||
(eseguibile da `npx wrangler d1 execute musictools-licenses --remote --command "..."`)
|
||||
|
||||
In futuro: workflow GitHub Actions che fa upload R2 + insert D1 in automatico.
|
||||
|
||||
## TODO
|
||||
|
||||
- [ ] Implementare `/api/download` che verifica firma e fa stream da R2
|
||||
- [ ] Endpoint admin per emettere licenze a mano (es. recensori, refund)
|
||||
- [ ] Rate limiting con KV su `/api/license/activate` (anti brute-force)
|
||||
- [ ] Cron worker giornaliero che marca le licenze inattive da > 1 anno
|
||||
|
||||
## Costi
|
||||
|
||||
A 0 vendite: **0€/mese** (tutto in free tier).
|
||||
A 100 vendite/mese: ~5€ Lemon Squeezy commission + 0€ Cloudflare = ~5€.
|
||||
Reference in new issue
Block a user