f871f4f588
Implements plans/STRIPE_PLAN.md sections 1-9 for solo Pro/Family
billing (family multi-user sharing, section 1a, deliberately deferred
-- flagged in that plan as the most novel/error-prone piece).
Decisions locked in: cancel/downgrade at period end (Stripe Portal
default), no trial period.
- lib/stripe.ts: single client factory reading STRIPE_SECRET_KEY via
site-settings (DB overrides env, same pattern as every other
provider key in this codebase).
- Webhook route rewritten on the real `stripe` SDK
(stripe.webhooks.constructEvent replaces the hand-rolled HMAC
verifier) and now handles the full event set: checkout.session.completed,
customer.subscription.{updated,deleted}, invoice.{payment_failed,paid}.
past_due deliberately never downgrades tier on its own -- Stripe
retries the card first, recovering via invoice.paid or eventually
giving up via subscription.deleted. Every handler audit-logs under
billing.<event>. Dedup via the existing processed_stripe_events
table, unchanged.
- Schema: tierDefinitions gained stripe{ProductId,PriceIdMonthly,
PriceIdYearly} (the lookup table mapping a Price back to a tier on
checkout); users gained stripeSubscriptionId/subscriptionStatus/
currentPeriodEnd.
- New POST /api/v1/billing/checkout (creates a subscription Checkout
Session, allow_promotion_codes: true), POST /api/v1/billing/portal
(Stripe's hosted self-serve cancel/upgrade/card-update), GET
/api/v1/billing/status.
- /settings/billing: current plan + renewal date, past_due warning,
usage-vs-limits (reuses the existing UsageQuotaSection), plan
comparison cards with per-tier Checkout buttons, manage-billing
button once a Stripe customer exists.
- /admin/billing: connection status (test/live mode detection),
subscriber counts, past-due list, recent billing audit events, link
to Stripe Dashboard. Tier Limits page extended with the three Stripe
price fields per tier (own render branch, not the numeric+Unlimited-
switch machinery the existing fields use).
Before going live: an admin needs to create real Products/Prices in
Stripe, enter the IDs on Tier Limits, and configure the Stripe-side
webhook endpoint -- all operational steps the plan always called for,
none of it code.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
93 lines
3.0 KiB
Bash
93 lines
3.0 KiB
Bash
# Database
|
|
DATABASE_URL=postgresql://epicure:epicure@localhost:5432/epicure
|
|
|
|
# Redis
|
|
REDIS_URL=redis://localhost:6379
|
|
|
|
# Storage (MinIO / S3-compatible)
|
|
STORAGE_ENDPOINT=http://localhost:9000
|
|
STORAGE_ACCESS_KEY=minioadmin
|
|
STORAGE_SECRET_KEY=minioadmin
|
|
STORAGE_BUCKET=epicure-uploads
|
|
STORAGE_REGION=us-east-1
|
|
|
|
# Auth (generate with: openssl rand -base64 32)
|
|
BETTER_AUTH_SECRET=
|
|
BETTER_AUTH_URL=http://localhost:3000
|
|
|
|
# Encryption key for BYOK AI keys stored in DB (generate with: openssl rand -base64 32)
|
|
# Separate from BETTER_AUTH_SECRET for key separation. Falls back to BETTER_AUTH_SECRET if unset.
|
|
ENCRYPTION_SECRET=
|
|
|
|
# OAuth — Google (always available)
|
|
GOOGLE_CLIENT_ID=
|
|
GOOGLE_CLIENT_SECRET=
|
|
|
|
# OAuth — GitHub (optional; set NEXT_PUBLIC_GITHUB_ENABLED=true to show button in UI)
|
|
GITHUB_CLIENT_ID=
|
|
GITHUB_CLIENT_SECRET=
|
|
NEXT_PUBLIC_GITHUB_ENABLED=
|
|
|
|
# OAuth — Discord (optional; set NEXT_PUBLIC_DISCORD_ENABLED=true to show button in UI)
|
|
DISCORD_CLIENT_ID=
|
|
DISCORD_CLIENT_SECRET=
|
|
NEXT_PUBLIC_DISCORD_ENABLED=
|
|
|
|
# OIDC — Authentik (or any OIDC provider)
|
|
# AUTHENTIK_BASE_URL: base URL including application slug, e.g.
|
|
# https://auth.example.com/application/o/epicure
|
|
# The discovery document is fetched from $AUTHENTIK_BASE_URL/.well-known/openid-configuration
|
|
# In authentik: create an OAuth2/OpenID provider, set redirect URI to
|
|
# $BETTER_AUTH_URL/api/auth/callback/authentik
|
|
AUTHENTIK_CLIENT_ID=
|
|
AUTHENTIK_CLIENT_SECRET=
|
|
AUTHENTIK_BASE_URL=
|
|
# Set to true to show Authentik login button in UI
|
|
NEXT_PUBLIC_AUTHENTIK_ENABLED=
|
|
|
|
# SMTP (leave blank to log emails to console in dev)
|
|
SMTP_HOST=
|
|
SMTP_PORT=587
|
|
SMTP_SECURE=false
|
|
SMTP_USER=
|
|
SMTP_PASS=
|
|
SMTP_FROM=Epicure <noreply@epicure.app>
|
|
|
|
# Web push (generate with: npx web-push generate-vapid-keys)
|
|
NEXT_PUBLIC_VAPID_PUBLIC_KEY=
|
|
VAPID_PRIVATE_KEY=
|
|
|
|
# Gitea (optional — in-app support tickets open an issue here if all three are set)
|
|
GITEA_URL=
|
|
GITEA_TOKEN=
|
|
GITEA_REPO=owner/repo
|
|
# Set as the webhook secret on the Gitea repo's webhook config (issues + issue_comment
|
|
# events) to sync issue close/reopen/comments back into Epicure support tickets.
|
|
GITEA_WEBHOOK_SECRET=
|
|
|
|
# USDA FoodData Central (optional, free — get a key at https://fdc.nal.usda.gov/api-key-signup)
|
|
# Improves recipe nutrition estimates with real per-ingredient data instead of AI-only guesses.
|
|
USDA_API_KEY=
|
|
|
|
# Stripe (optional — billing for Pro/Family tiers). Only needed as a
|
|
# bootstrap fallback for self-hosters without the admin settings UI set up
|
|
# yet — a value stored via Admin > Settings takes precedence.
|
|
STRIPE_SECRET_KEY=
|
|
STRIPE_PUBLISHABLE_KEY=
|
|
STRIPE_WEBHOOK_SECRET=
|
|
|
|
# Shared secret for internal cron-triggered endpoints (e.g. weekly digest email).
|
|
# Generate with: openssl rand -base64 32
|
|
CRON_SECRET=
|
|
|
|
# AI Providers (configure at least one)
|
|
OPENROUTER_API_KEY=
|
|
OPENROUTER_DEFAULT_MODEL=google/gemini-flash-1.5
|
|
OPENAI_API_KEY=
|
|
ANTHROPIC_API_KEY=
|
|
OLLAMA_BASE_URL=http://localhost:11434
|
|
|
|
# Grocery delivery handoff (optional — without these, shopping lists only offer "copy as text")
|
|
NEXT_PUBLIC_GROCERY_PROVIDER=
|
|
INSTACART_API_KEY=
|