v1.7.0: piani Basic/Pro/Premium/Annual + quota giornaliera
Pricing model: subscription mensili (Basic 2.99 / Pro 5.99 / Premium 9.99) piu' Annual 49.90 one-time. Feature gating per piano (Basic = solo audio, Pro+ = tutto). Quota giornaliera (10/30/150) con reset mezzanotte Europe/Rome. Server: tabella daily_usage, endpoint /api/usage/consume e /status, webhook LS gestisce subscription_* events + mappatura variant_id -> plan via .env (LS_VARIANT_BASIC|PRO|PREMIUM|ANNUAL). Client: gating tab in sidebar in base ai features del piano, contatore "X/Y oggi" + bottone Upgrade, modal blocco con CTA verso landing.
This commit is contained in:
1 parent
bcd4f22b1e
commit
61459099f9
15 files changed
+1395
-108
No files matched your search
+253
-38
@@ -1,13 +1,26 @@
|
||||
/**
|
||||
* Webhook Lemon Squeezy.
|
||||
* URL pubblico: https://musictools.djluza.com/api/webhook/lemonsqueezy
|
||||
* Eventi gestiti: order_created, order_refunded.
|
||||
*
|
||||
* Eventi gestiti:
|
||||
* - order_created : crea licenza ANNUAL (one-time) con expires_at = now+365d.
|
||||
* Per le subscription ignora: il record nasce da subscription_created.
|
||||
* - order_refunded : status -> refunded.
|
||||
* - subscription_created : crea licenza con plan, subscription_id, current_period_end.
|
||||
* - subscription_updated : aggiorna current_period_end e plan se cambiato.
|
||||
* - subscription_payment_success : estende current_period_end al nuovo renews_at.
|
||||
* - subscription_payment_failed : (no-op qui) lasciamo scadere current_period_end.
|
||||
* - subscription_cancelled : niente, il periodo corrente resta valido fino a current_period_end.
|
||||
* - subscription_expired : status -> revoked, l'utente perde l'accesso.
|
||||
*
|
||||
* Tutto idempotente: ogni evento si puo' rispedire senza spaccare nulla.
|
||||
*/
|
||||
|
||||
import crypto from "node:crypto";
|
||||
import { one, exec } from "./db.js";
|
||||
import { generateLicenseKey } from "./license.js";
|
||||
import { sendLicenseEmail } from "./email.js";
|
||||
import { planByVariantId, getPlan, ANNUAL_TTL_SECONDS } from "./plans.js";
|
||||
|
||||
const now = () => Math.floor(Date.now() / 1000);
|
||||
|
||||
@@ -21,8 +34,210 @@ function timingSafe(a, b) {
|
||||
return crypto.timingSafeEqual(A, B);
|
||||
}
|
||||
|
||||
/** Converte una data ISO (es. "2026-07-09T13:24:00Z") in epoch seconds, o null. */
|
||||
function isoToEpoch(iso) {
|
||||
if (!iso) return null;
|
||||
const t = Date.parse(String(iso));
|
||||
if (Number.isNaN(t)) return null;
|
||||
return Math.floor(t / 1000);
|
||||
}
|
||||
|
||||
/** Estrae variant_id dal payload, gestendo le diverse forme degli eventi. */
|
||||
function extractVariantId(payload, attrs) {
|
||||
// subscription_*: attrs.variant_id (diretto)
|
||||
if (attrs.variant_id != null) return String(attrs.variant_id);
|
||||
// order_created: attrs.first_order_item.variant_id
|
||||
const item = attrs.first_order_item;
|
||||
if (item && item.variant_id != null) return String(item.variant_id);
|
||||
// alcune forme passano da relationships
|
||||
const rel = payload?.data?.relationships?.variant?.data?.id;
|
||||
if (rel) return String(rel);
|
||||
return "";
|
||||
}
|
||||
|
||||
/** Email cliente: nei subscription_* puo' essere customer_email. */
|
||||
function extractEmail(attrs) {
|
||||
const e = attrs.user_email || attrs.customer_email || attrs.email || "";
|
||||
return String(e).trim().toLowerCase();
|
||||
}
|
||||
|
||||
// ---- Handlers per famiglia evento -----------------------------------------
|
||||
|
||||
async function handleOrderCreated(payload, attrs, t) {
|
||||
const email = extractEmail(attrs);
|
||||
const orderId = String(payload?.data?.id || attrs.order_number || "");
|
||||
if (!email || !orderId) {
|
||||
return { status: 400, body: { error: "Missing email or order_id" } };
|
||||
}
|
||||
const variantId = extractVariantId(payload, attrs);
|
||||
const planCode = planByVariantId(variantId);
|
||||
const plan = planCode ? getPlan(planCode) : null;
|
||||
|
||||
// Subscriptions: il record vero arriva con subscription_created.
|
||||
// Se per qualche motivo arriva prima (ordine pagato ma sottoscrizione
|
||||
// non ancora generata), accettiamo l'evento ma non creiamo nulla.
|
||||
if (plan && plan.is_subscription) {
|
||||
return { status: 200, body: { ok: true, deferred: "wait_for_subscription_created" } };
|
||||
}
|
||||
|
||||
// Annual one-time (o piano non mappato -> trattalo come annual di default
|
||||
// cosi' non lasciamo l'utente senza licenza se ha pagato).
|
||||
const planForRecord = plan?.code || "annual";
|
||||
const limit = plan?.daily_limit ?? null;
|
||||
const expiresAt = t + ANNUAL_TTL_SECONDS;
|
||||
const key = generateLicenseKey();
|
||||
|
||||
try {
|
||||
await exec(
|
||||
`INSERT INTO licenses
|
||||
(license_key, email, status, plan, daily_limit,
|
||||
source, order_id, expires_at, created_at, updated_at)
|
||||
VALUES (?, ?, 'active', ?, ?, 'lemonsqueezy', ?, ?, ?, ?)`,
|
||||
[key, email, planForRecord, limit, orderId, expiresAt, t, t],
|
||||
);
|
||||
} catch (e) {
|
||||
if (e?.code === "ER_DUP_ENTRY") {
|
||||
return { status: 200, body: { ok: true, duplicate: true } };
|
||||
}
|
||||
throw e;
|
||||
}
|
||||
|
||||
try {
|
||||
await sendLicenseEmail(email, key, { plan: planForRecord, expiresAt });
|
||||
} catch (e) {
|
||||
console.error("[email] send failed:", e?.message || e);
|
||||
}
|
||||
|
||||
return { status: 200, body: { ok: true, plan: planForRecord } };
|
||||
}
|
||||
|
||||
async function handleOrderRefunded(payload, attrs, t) {
|
||||
const orderId = String(payload?.data?.id || attrs.order_number || "");
|
||||
if (!orderId) return { status: 400, body: { error: "Missing order_id" } };
|
||||
await exec(
|
||||
`UPDATE licenses SET status='refunded', updated_at=? WHERE order_id=?`,
|
||||
[t, orderId],
|
||||
);
|
||||
return { status: 200, body: { ok: true } };
|
||||
}
|
||||
|
||||
async function handleSubscriptionCreated(payload, attrs, t) {
|
||||
const email = extractEmail(attrs);
|
||||
const subId = String(payload?.data?.id || attrs.subscription_id || "");
|
||||
const variantId = extractVariantId(payload, attrs);
|
||||
const planCode = planByVariantId(variantId);
|
||||
if (!email || !subId) {
|
||||
return { status: 400, body: { error: "Missing email or subscription_id" } };
|
||||
}
|
||||
if (!planCode) {
|
||||
// Niente mapping -> non sappiamo che limiti applicare. Logghiamo e
|
||||
// ritorniamo 200 cosi' LS non rispedisce all'infinito.
|
||||
console.warn("[ls] subscription_created variant non mappato:", variantId, "email=", email);
|
||||
return { status: 200, body: { ok: true, ignored: "unknown_variant" } };
|
||||
}
|
||||
const plan = getPlan(planCode);
|
||||
const periodEnd = isoToEpoch(attrs.renews_at) || isoToEpoch(attrs.ends_at);
|
||||
const orderId = String(attrs.order_id || "");
|
||||
const key = generateLicenseKey();
|
||||
|
||||
// Idempotenza: se ricevo lo stesso subscription_created due volte,
|
||||
// riuso la licenza esistente (non ne creo un'altra).
|
||||
const existing = await one(
|
||||
"SELECT id, license_key FROM licenses WHERE subscription_id=? LIMIT 1",
|
||||
[subId],
|
||||
);
|
||||
if (existing) {
|
||||
await exec(
|
||||
`UPDATE licenses
|
||||
SET status='active', plan=?, daily_limit=?, current_period_end=?, updated_at=?
|
||||
WHERE id=?`,
|
||||
[planCode, plan.daily_limit, periodEnd, t, existing.id],
|
||||
);
|
||||
return { status: 200, body: { ok: true, duplicate: true } };
|
||||
}
|
||||
|
||||
try {
|
||||
await exec(
|
||||
`INSERT INTO licenses
|
||||
(license_key, email, status, plan, daily_limit,
|
||||
source, order_id, subscription_id, current_period_end,
|
||||
created_at, updated_at)
|
||||
VALUES (?, ?, 'active', ?, ?, 'lemonsqueezy', ?, ?, ?, ?, ?)`,
|
||||
[key, email, planCode, plan.daily_limit, orderId || null, subId, periodEnd, t, t],
|
||||
);
|
||||
} catch (e) {
|
||||
if (e?.code === "ER_DUP_ENTRY") {
|
||||
return { status: 200, body: { ok: true, duplicate: true } };
|
||||
}
|
||||
throw e;
|
||||
}
|
||||
|
||||
try {
|
||||
await sendLicenseEmail(email, key, { plan: planCode, periodEnd });
|
||||
} catch (e) {
|
||||
console.error("[email] send failed:", e?.message || e);
|
||||
}
|
||||
return { status: 200, body: { ok: true, plan: planCode } };
|
||||
}
|
||||
|
||||
async function handleSubscriptionUpdated(payload, attrs, t) {
|
||||
const subId = String(payload?.data?.id || "");
|
||||
if (!subId) return { status: 400, body: { error: "Missing subscription_id" } };
|
||||
const variantId = extractVariantId(payload, attrs);
|
||||
const planCode = planByVariantId(variantId);
|
||||
const periodEnd = isoToEpoch(attrs.renews_at) || isoToEpoch(attrs.ends_at);
|
||||
|
||||
if (planCode) {
|
||||
const plan = getPlan(planCode);
|
||||
await exec(
|
||||
`UPDATE licenses
|
||||
SET plan=?, daily_limit=?, current_period_end=?, updated_at=?
|
||||
WHERE subscription_id=?`,
|
||||
[planCode, plan.daily_limit, periodEnd, t, subId],
|
||||
);
|
||||
} else if (periodEnd) {
|
||||
await exec(
|
||||
`UPDATE licenses SET current_period_end=?, updated_at=? WHERE subscription_id=?`,
|
||||
[periodEnd, t, subId],
|
||||
);
|
||||
}
|
||||
return { status: 200, body: { ok: true } };
|
||||
}
|
||||
|
||||
async function handleSubscriptionPaymentSuccess(payload, attrs, t) {
|
||||
// L'evento di pagamento riferisce alla subscription via attrs.subscription_id
|
||||
const subId = String(attrs.subscription_id || payload?.data?.id || "");
|
||||
if (!subId) return { status: 400, body: { error: "Missing subscription_id" } };
|
||||
|
||||
// Quando un rinnovo va a buon fine LS sposta avanti renews_at.
|
||||
// Per essere sicuri leggiamo l'evento PIU' recente (subscription_updated
|
||||
// viene inviato a stretto giro), oppure deduciamo: +30 giorni.
|
||||
const periodEnd = isoToEpoch(attrs.renews_at)
|
||||
|| isoToEpoch(attrs.created_at)
|
||||
|| (t + 30 * 24 * 3600);
|
||||
|
||||
await exec(
|
||||
`UPDATE licenses
|
||||
SET status='active', current_period_end=?, updated_at=?
|
||||
WHERE subscription_id=?`,
|
||||
[periodEnd, t, subId],
|
||||
);
|
||||
return { status: 200, body: { ok: true } };
|
||||
}
|
||||
|
||||
async function handleSubscriptionExpired(payload, attrs, t) {
|
||||
const subId = String(payload?.data?.id || attrs.subscription_id || "");
|
||||
if (!subId) return { status: 400, body: { error: "Missing subscription_id" } };
|
||||
await exec(
|
||||
`UPDATE licenses SET status='revoked', updated_at=? WHERE subscription_id=?`,
|
||||
[t, subId],
|
||||
);
|
||||
return { status: 200, body: { ok: true } };
|
||||
}
|
||||
|
||||
// ---- Entry point ----------------------------------------------------------
|
||||
|
||||
export async function webhook(req, res) {
|
||||
// express.raw() salva il body come Buffer in req.body
|
||||
const raw = req.body instanceof Buffer ? req.body.toString("utf-8") : "";
|
||||
const sig = req.get("X-Signature") || "";
|
||||
const secret = process.env.LEMONSQUEEZY_SIGNING_SECRET;
|
||||
@@ -39,45 +254,45 @@ export async function webhook(req, res) {
|
||||
|
||||
const eventName = payload?.meta?.event_name || "";
|
||||
const attrs = payload?.data?.attributes || {};
|
||||
const email = String(attrs.user_email || "").trim().toLowerCase();
|
||||
const orderId = String(payload?.data?.id || attrs.order_number || "");
|
||||
if (!email || !orderId) {
|
||||
return res.status(400).json({ error: "Missing email or order_id" });
|
||||
}
|
||||
|
||||
const t = now();
|
||||
|
||||
if (eventName === "order_created") {
|
||||
const key = generateLicenseKey();
|
||||
try {
|
||||
await exec(
|
||||
`INSERT INTO licenses
|
||||
(license_key, email, status, source, order_id, created_at, updated_at)
|
||||
VALUES (?, ?, 'active', 'lemonsqueezy', ?, ?, ?)`,
|
||||
[key, email, orderId, t, t],
|
||||
);
|
||||
} catch (e) {
|
||||
// duplicate webhook delivery
|
||||
if (e?.code === "ER_DUP_ENTRY") {
|
||||
return res.json({ ok: true, duplicate: true });
|
||||
}
|
||||
throw e;
|
||||
let out;
|
||||
try {
|
||||
switch (eventName) {
|
||||
case "order_created":
|
||||
out = await handleOrderCreated(payload, attrs, t);
|
||||
break;
|
||||
case "order_refunded":
|
||||
out = await handleOrderRefunded(payload, attrs, t);
|
||||
break;
|
||||
case "subscription_created":
|
||||
out = await handleSubscriptionCreated(payload, attrs, t);
|
||||
break;
|
||||
case "subscription_updated":
|
||||
case "subscription_resumed":
|
||||
case "subscription_unpaused":
|
||||
out = await handleSubscriptionUpdated(payload, attrs, t);
|
||||
break;
|
||||
case "subscription_payment_success":
|
||||
out = await handleSubscriptionPaymentSuccess(payload, attrs, t);
|
||||
break;
|
||||
case "subscription_expired":
|
||||
out = await handleSubscriptionExpired(payload, attrs, t);
|
||||
break;
|
||||
case "subscription_cancelled":
|
||||
case "subscription_paused":
|
||||
case "subscription_payment_failed":
|
||||
case "subscription_payment_refunded":
|
||||
// No-op: il record resta com'e' fino al prossimo evento che cambia stato.
|
||||
out = { status: 200, body: { ok: true, ignored: eventName } };
|
||||
break;
|
||||
default:
|
||||
out = { status: 200, body: { ok: true, ignored: eventName } };
|
||||
}
|
||||
try {
|
||||
await sendLicenseEmail(email, key);
|
||||
} catch (e) {
|
||||
console.error("[email] send failed:", e?.message || e);
|
||||
}
|
||||
return res.json({ ok: true });
|
||||
} catch (e) {
|
||||
console.error("[ls] handler error", eventName, e?.message || e);
|
||||
return res.status(500).json({ error: "Internal error" });
|
||||
}
|
||||
|
||||
if (eventName === "order_refunded") {
|
||||
await exec(
|
||||
`UPDATE licenses SET status='refunded', updated_at=? WHERE order_id=?`,
|
||||
[t, orderId],
|
||||
);
|
||||
return res.json({ ok: true });
|
||||
}
|
||||
|
||||
res.json({ ok: true, ignored: eventName });
|
||||
return res.status(out.status).json(out.body);
|
||||
}
|
||||
Reference in new issue
Block a user