CluPilotCloud/tests/Feature
nexxo 786318b6d4 Never tell anyone to delete a catalogue their contracts bill on
The refusal added in the previous commit had a state it read wrongly, and
the wrong reading was destructive.

record() sat at the END of handle() and in no try/finally, while
createProduct() and ensure() throw uncaught. A run that died after the
first object left hasStoredObjects() true and recorded() null. The same
state arises with no failure at all: CheckoutController → PlanPrices::
ensure() and BookAddon → SyncStripeAddonItems → AddonPrices::ensure()
mint missing prices and never call record().

In that state the next run — in the SAME mode — refused with the foreign
account message and its "Clear plan_families.stripe_product_id,
plan_prices.stripe_price_id and the … registers first", and
billing.catalogue_synced blocked with the same text. The objects were
from the account in force. The right move was to resume, which is what
the idempotency keys exist for; instead an operator was handed a delete
instruction for a catalogue live contracts are billed on.

Two changes:

  1. record() moves ahead of the creation loop, right behind the refusal.
     There it is already proved that either nothing is stored or what is
     stored belongs to the active account, so the moment carries the
     claim just as well — and a run that dies part-way can no longer
     leave a state that contradicts itself.
  2. "Origin never recorded" gets its own sentence and its own cure,
     separate from "established: other account".
     StripeCatalogueMode::matchesActiveMode() becomes
     belongsToAnotherMode(), which is only true where the other account
     is fact. The check still blocks — the origin cannot be proved — but
     it says "run the sync again", and it names no register to empty.

Red first:

  ⨯ it takes up a catalogue whose origin was never written down
      Failed asserting that 1 matches expected 0.
  ⨯ it leaves no half-built catalogue that contradicts itself when a run dies
      Failed asserting that null is identical to an object of class "App\Support\OperatingMode".
  ⨯ it tells an unrecorded origin apart from a foreign account

The two states are held apart by assertion, not by wording: only the
foreign-account sentence may name stripe_plan_prices, and the unrecorded
one must name stripe:sync-catalogue instead. The existing foreign-account
test keeps its teeth.

Full suite: 1817 passed, 6366 assertions.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-30 17:30:56 +02:00
..
Admin Put every missing field on one page before a customer pays 2026-07-30 15:59:34 +02:00
Auth Ask whether they are a consumer, and let one change their mind 2026-07-29 21:06:06 +02:00
Billing Never tell anyone to delete a catalogue their contracts bill on 2026-07-30 17:30:56 +02:00
Console Restart a machine, enforce the quota that was sold, end a route that ended 2026-07-29 18:28:28 +02:00
Mail Stop mailing the initial admin password, hold it in the panel until noted 2026-07-28 23:19:20 +02:00
Portal Skip the invoice for a full gift, keep it out of revenue, hide its price 2026-07-29 12:41:32 +02:00
Provisioning Stop the suite from reading the operator's own .env for the DNS zone 2026-07-30 10:38:12 +02:00
Readiness Never tell anyone to delete a catalogue their contracts bill on 2026-07-30 17:30:56 +02:00
BillingTest.php Refuse the sale instead of reaching Stripe without a key 2026-07-30 11:58:01 +02:00
CartTest.php Refuse the sale instead of reaching Stripe without a key 2026-07-30 11:58:01 +02:00
CheckoutWithoutStripeKeyTest.php Pin the one question that must never throw 2026-07-30 16:58:22 +02:00
ComponentTest.php feat(portal): Fortify auth + Login/2FA/Dashboard + component kit 2026-07-25 01:20:25 +02:00
ConfirmInModalTest.php Replace native confirm() dialogs with the app's own modal pattern 2026-07-28 19:34:27 +02:00
ConnectionStateTest.php Recover silently from an expired session, and show a connection banner when offline 2026-07-28 21:36:21 +02:00
CustomDomainServingTest.php Fix nine defects in the provisioning pipelines 2026-07-30 01:34:55 +02:00
CustomDomainTest.php Close the domain page to packages that may not have one 2026-07-29 16:20:21 +02:00
CustomerTwoFactorTest.php Replace native confirm() dialogs with the app's own modal pattern 2026-07-28 19:34:27 +02:00
DashboardTest.php Stop mailing the initial admin password, hold it in the panel until noted 2026-07-28 23:19:20 +02:00
DeliveryPromiseTest.php Take the order, park it, and say when it will be delivered 2026-07-29 18:50:46 +02:00
DeploymentRunsAsTheAppUserTest.php Fix nine defects in the provisioning pipelines 2026-07-30 01:34:55 +02:00
DisplayTimezoneTest.php Show times on the operator's clock, keep storing them in UTC 2026-07-27 17:32:21 +02:00
DoubleOptInTest.php Require a confirmed address before an account can use anything 2026-07-28 23:43:20 +02:00
DowngradeTest.php Refuse the sale instead of reaching Stripe without a key 2026-07-30 11:58:01 +02:00
EditInModalTest.php Fix a cancel button that did nothing, and fit the answers on one screen 2026-07-29 22:50:16 +02:00
EnsureCustomerActiveTest.php Satisfy Pint on the two new guard-boundary tests 2026-07-28 15:10:58 +02:00
ErrorPagesTest.php Ask the tunnel gateway where it actually listens 2026-07-27 14:43:23 +02:00
ExampleTest.php chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
GrossPricingTest.php Quote what a person pays, and tab the settings page 2026-07-29 19:18:10 +02:00
HostStepTest.php Let an update install host packages, without handing out root 2026-07-29 10:27:56 +02:00
IconLayoutTest.php Ask the tunnel gateway where it actually listens 2026-07-27 14:43:23 +02:00
IdentitySeparationTest.php Write down that the console and the portal share no identity 2026-07-28 12:15:13 +02:00
ImpersonationTest.php Refuse a portal login for an address that already belongs to an operator 2026-07-28 14:42:16 +02:00
InstanceMetricsTest.php Measure what the template draws 2026-07-27 16:29:28 +02:00
LandingPriceSheetTest.php Quote what a person pays, and tab the settings page 2026-07-29 19:18:10 +02:00
MailTemplatesTest.php Actually issue the invoice when the money arrives 2026-07-29 03:25:56 +02:00
ModalHeightTest.php R24: a modal is never taller than the screen 2026-07-29 23:33:57 +02:00
MonitoringStatusSyncTest.php Move the console off /admin, give the status page its own address, and measure monitoring 2026-07-27 06:05:40 +02:00
NewDeviceWarningTest.php Recognise the devices an account signs in from, and warn about a new one 2026-07-28 23:28:34 +02:00
OfficialDomainsTest.php Re-apply what the last release commit silently reverted 2026-07-29 17:36:43 +02:00
OperatingModeTest.php Give the installation a test mode and a live mode 2026-07-30 10:41:23 +02:00
PortalHostTest.php Answer on every name for the website, and send them all to one 2026-07-29 01:29:33 +02:00
PortalTabsTest.php Re-apply what the last release commit silently reverted 2026-07-29 17:36:43 +02:00
PublicSiteGateTest.php Stop a disabled operator from bypassing the hidden-site gate 2026-07-28 14:42:29 +02:00
ReadinessPageTest.php Refuse a key that does not belong to the slot it sits in 2026-07-30 17:05:58 +02:00
ReleaseComparisonTest.php Stop the update agent dying on its own tag arithmetic 2026-07-29 00:00:17 +02:00
ReleaseVersionTest.php Move the console's identity out of the customer table 2026-07-28 10:31:43 +02:00
SeatsTest.php Replace native confirm() dialogs with the app's own modal pattern 2026-07-28 19:34:27 +02:00
SecretSlotMigrationTest.php Remember which Stripe account the catalogue was built in 2026-07-30 17:12:56 +02:00
SecretVaultModeTest.php Say which slot the value in force is really coming from 2026-07-30 17:01:33 +02:00
SelfServiceOrderTest.php Ask for the express request to begin, and send it to Stripe 2026-07-29 21:19:03 +02:00
ServerMarketTest.php Take the order, park it, and say when it will be delivered 2026-07-29 18:50:46 +02:00
SessionListTest.php Show where an account is signed in, and let it sign the other places out 2026-07-28 23:38:17 +02:00
SettingsTest.php Stop charging for a service that has ended 2026-07-30 00:52:19 +02:00
SiteDesignSystemTest.php One wordmark, one typeface, and the address the server actually issues 2026-07-29 14:30:44 +02:00
StatusHistoryTest.php Let an incident be deleted, and start measuring whether the hosts answer 2026-07-29 15:16:48 +02:00
StripeStrictModeTest.php Make source() respect strict entries like get() does 2026-07-30 11:21:07 +02:00
StripeWebhookSecretByModeTest.php Verify webhooks against the secret of the mode we are in 2026-07-30 12:13:55 +02:00
SupportRequestTest.php Editing in modals, an update button that is not gated on a stale reading, and a support page that is real 2026-07-27 17:55:49 +02:00
SwitchOperatingModeTest.php Fix round: name the slot on the card, and cover the modal that already worked 2026-07-30 15:32:16 +02:00
TrafficTest.php Measure availability, and let a customer move down again 2026-07-27 16:41:15 +02:00
TranslationParityTest.php Ask the tunnel gateway where it actually listens 2026-07-27 14:43:23 +02:00
WelcomeTest.php Give customers two-factor, and stop every button on the settings page reacting at once 2026-07-27 08:48:34 +02:00