Worker: POST /updates and Play subscriptions - #236
Conversation
POST /updates answers the batch update check from the served, non-yanked catalog. The Play exchange verifies subscription listings through subscriptionsv2 and issues an entitlement that expires with the current period, keyed to the base order id across renewals. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Reviewer's GuideThe Worker now supports spec-compliant POST /updates checks using served non-yanked versions and SemVer precedence, and verifies Play subscription listings through subscriptionsv2 to issue renewable, expiring entitlements with stable subjects and best-effort acknowledgement. Sequence diagram for the POST /updates batch checksequenceDiagram
participant Host
participant Worker
participant Catalog
participant Listings
participant Revocations
participant Semver
Host->>Worker: POST /updates
Worker->>Catalog: getCatalog(req, env)
Worker->>Listings: getListings(req, env)
Worker->>Revocations: revocations(env)
Worker->>Semver: compareSemver(latest, version)
Semver-->>Worker: precedence result
Worker-->>Host: { updates: [{ id, latest }] }
Sequence diagram for Play subscription entitlement verificationsequenceDiagram
participant App
participant Worker
participant Play as Google Play
participant Entitlement
App->>Worker: POST /entitlements/play
Worker->>Play: verifyPlaySubscription(...)
Play-->>Worker: subscriptionState, lineItems, expiryTime
alt ACTIVE or IN_GRACE_PERIOD and product matches
opt acknowledgement pending
Worker->>Play: POST subscriptions/{productId}/tokens/{token}:acknowledge
end
Worker->>Entitlement: issueEntitlement(kind subscription, expiresAt)
Entitlement-->>Worker: signed entitlement
Worker-->>App: encoded expiring entitlement
else Not entitled
Worker-->>App: 402 payment_required
end
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
🚀 Deploying Preview to Cloudflare 🚀Preview Deployments by commit
|
OpenCode security review |
There was a problem hiding this comment.
Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 23 hours and 16 minutes by commenting @sourcery-ai review. Upgrade to get a review now.
This closes two of the store Worker's remaining gaps against
spec/repository-api.md. The third, registry-sync, is #235.POST /updates(§ 6)[{ id, version }], capped at 5000 entries and 1 MB.{ updates: [{ id, latest }] }, listing only ids whose served, non-yanked version is strictly newer. Current, ahead and unknown ids are omitted.400with the repository error envelope.src/semver.ts, a mirror ofpackages/registry'scompareSemver. The Worker can't import that package because it needsnode:crypto; the header says to keep the two in step.Play subscriptions (§ 7)
A listing with an
intervalused to answer501. It is now verified throughpurchases.subscriptionsv2.ACTIVEorIN_GRACE_PERIOD, it includes that product, and the period hasn't ended.kind: "subscription"entitlement withexpiresAtset to the product'sexpiryTime, so the store app exchanges again after a renewal...Nrenewal suffix stripped so renewals keep one subject. AnobfuscatedExternalAccountIdis used instead when the app set one.The old test asserted the
501for subscriptions. That behaviour was removed on purpose, and real subscription cases replace the assertion.Docs: Worker README (the route table, "Play purchases", and a new "Update checks" section). Changeset included.
Verification
/updateswith newer, current, ahead, unknown and prerelease ids;tsc --noEmitis clean.🤖 Generated with Claude Code
https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
Generated by Claude Code
Summary by Sourcery
Implement repository update checks and Play subscription entitlements in the storefront Worker.
New Features:
POST /updates, returning strictly newer served, non-yanked versions for installed packages.Enhancements:
Documentation:
POST /updatesupdate-check API in the Worker README.Tests: