feat(premium): add App Store and Google Play purchases (#3052)

This commit is contained in:
Hampus
2026-09-30 01:55:19 +02:00
committed by GitHub
parent 0b3418dcbe
commit e8cb167dbf
202 changed files with 17095 additions and 49 deletions
+17 -1
View File
@@ -145,6 +145,22 @@ const OUT_OF_BAND_CREDENTIAL = new Map<string, OutOfBandRoute>([
documentedIn: {file: 'operator/configuration.mdx', anchor: 'POST /webhooks/sweego'},
},
],
[
'POST /webhooks/app-store',
{
reason:
'an App Store Server Notification whose signedPayload must verify against the pinned Apple root before it is queued. The route is hosted-only',
documentedIn: {file: 'http-api/in-app-purchases.mdx', anchor: 'POST /webhooks/app-store'},
},
],
[
'POST /webhooks/google-play',
{
reason:
'a Pub/Sub push whose Google-signed OIDC token must match the configured audience and service account before it is queued. The route is hosted-only',
documentedIn: {file: 'http-api/in-app-purchases.mdx', anchor: 'POST /webhooks/google-play'},
},
],
[
'GET /connections/bluesky/callback',
{
@@ -207,7 +223,7 @@ const EXEMPTION_RULES: ReadonlyArray<ExemptionRule> = [
{
name: 'out-of-band credential',
justification:
'no ordinary client holds the credential. Each entry states its guard, and three are covered in prose',
'no ordinary client holds the credential. Each entry states its guard, and five are covered in prose',
anchors: [{file: 'fluxer_api/src/api/app/ControllerRegistry.ts', anchor: 'installSmsWebhookForwarder(routes'}],
covers: (shape) => OUT_OF_BAND_CREDENTIAL.has(shape),
},