Skip to content

g1t/services/billing/src/features.rs

838 lines38,642 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1//! The g1t plan: one monthly price per workspace, never per person, that
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas2//! includes $10 of usage. Everything that costs g1t money is metered from
3//! the first unit at cost plus the margin and drawn from that $10 first;
4//! past it, it is charged, up to the workspace's spend limit. There are no
5//! per-feature quotas: no count of apps, build minutes, requests or
6//! domains ever stops a workspace on the plan. Only its spend limit does
7//! (and g1t's protections against abuse). Projects, previews and
8//! repositories cost g1t next to nothing and are not metered. None of it is
9//! free, whatever `FREE_WHILE_BUILDING` says.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look10//!
11//! Deployments were once a plan of their own. They come with the g1t plan
12//! now: `has_feature(deployments)` answers whether the workspace has the
13//! plan, and a Deployments subscription from before keeps working until
14//! its period ends. Billing sets each one to end then, once
15//! (`retire_deployments_plans`), so no one pays for both.
Paid features: a workspace turns on Deployments with a monthly plan16
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas17use g1t_contracts::billing::deployment_costs as costs;
Paid features: a workspace turns on Deployments with a monthly plan18use g1t_contracts::billing::*;
19use g1t_contracts::time::rfc3339;
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put20use g1t_contracts::{FailureCode, Outcome, Role};
Paid features: a workspace turns on Deployments with a monthly plan21use g1t_kit::now_ms;
22use serde::Deserialize;
23use worker::Result;
24
Project dependencies: addresses, preview stacks, Affects, and agents who know25use crate::stripe::{StripeSubscription, is_missing};
Paid features: a workspace turns on Deployments with a monthly plan26use crate::{Billing, Touched, members_only, optional};
27
28#[derive(Deserialize)]
29struct SubscriptionRow {
30 feature: String,
31 subscription_id: String,
32 status: String,
33 period_end: Option<String>,
34 started_by: String,
35 started_at: String,
Billing answers every page in a few round trips, not forty: its reads run together, Stripe is asked at most hourly, and the ledger has a time index36 updated_at: String,
37}
38
39/// How long a plan's row is believed after it was last written, once its
40/// period is over, before the processor is asked again.
41const REFRESH_MS: u64 = 60 * 60 * 1000;
42
43/// Whether to ask the processor about a plan again: its period is over (or
44/// unknown) and it is not canceled, and it was not written in the last hour.
45/// Without the hour a plan the processor still shows as ended would be
46/// asked about on every page.
47fn needs_refresh(status: &str, period_end: Option<&str>, updated_at: &str, now_ms: u64) -> bool {
48 let now = rfc3339(now_ms);
49 let over = period_end.is_none_or(|end| end <= now.as_str()) && status != "canceled";
50 over && updated_at <= rfc3339(now_ms.saturating_sub(REFRESH_MS)).as_str()
Paid features: a workspace turns on Deployments with a monthly plan51}
52
53#[derive(Deserialize)]
54struct PlanCheckoutRow {
55 workspace: String,
56 created_by: String,
57 feature: String,
58}
59
60fn status_from(text: &str) -> SubscriptionStatus {
61 match text {
62 "active" => SubscriptionStatus::Active,
63 "canceling" => SubscriptionStatus::Canceling,
64 "past_due" => SubscriptionStatus::PastDue,
65 _ => SubscriptionStatus::Canceled,
66 }
67}
68
69fn status_text(status: SubscriptionStatus) -> &'static str {
70 match status {
71 SubscriptionStatus::Active => "active",
72 SubscriptionStatus::Canceling => "canceling",
73 SubscriptionStatus::PastDue => "past_due",
74 SubscriptionStatus::Canceled => "canceled",
75 }
76}
77
78/// What the processor's state for a plan means here.
79fn status_of(subscription: &StripeSubscription) -> SubscriptionStatus {
80 match subscription.status.as_str() {
81 "active" | "trialing" if subscription.cancel_at_period_end => SubscriptionStatus::Canceling,
82 "active" | "trialing" => SubscriptionStatus::Active,
83 "past_due" | "unpaid" | "incomplete" | "paused" => SubscriptionStatus::PastDue,
84 _ => SubscriptionStatus::Canceled,
85 }
86}
87
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put88/// `1 GB`, `50 GB`, or `500 MB`, as storage is priced (powers of ten).
89pub(crate) fn bytes(bytes: i64) -> String {
90 if bytes >= 1_000_000_000 && bytes % 1_000_000_000 == 0 {
91 format!("{} GB", bytes / 1_000_000_000)
92 } else if bytes >= 1_000_000_000 {
93 format!("{:.1} GB", bytes as f64 / 1e9)
94 } else {
95 format!("{} MB", bytes / 1_000_000)
96 }
97}
98
Deployments: a preview for every pull request, production on g1t.page99/// Dollars to the cent, or finer for prices under a cent, so that a
100/// build minute's $0.0015 does not read as nothing.
Usage limits: unpaid usage can only go so far101pub(crate) fn dollars(micros: i64) -> String {
Deployments: a preview for every pull request, production on g1t.page102 let text = format!("{:.4}", micros as f64 / MICROS_PER_DOLLAR as f64);
103 let (whole, fraction) = text.split_once('.').unwrap_or((&text, ""));
104 let fraction = fraction.trim_end_matches('0');
105 format!("${whole}.{fraction:0<2}")
Paid features: a workspace turns on Deployments with a monthly plan106}
107
Money in billing's messages reads to the cent, and the deploy reads migrations again after a failure108/// An amount of money to the cent, as balances and amounts owed read:
109/// `$3.99`, never `$3.987`. Prices use [`dollars`].
110pub(crate) fn cents(micros: i64) -> String {
111 format!("${:.2}", micros as f64 / MICROS_PER_DOLLAR as f64)
112}
113
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily114/// `units` at `each` micros a unit, as the pricing page writes it: a
115/// build second's price times 60 is the build minute both quote.
116pub(crate) fn per_units(each: f64, units: f64) -> String {
117 dollars((each * units).round() as i64)
118}
119
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar120/// The price book's meter for the Security and quality activation.
121pub(crate) const SECURITY_METER: &str = "security_activation";
122/// Its price when the price book cannot be read: $10 a month.
123const SECURITY_FALLBACK_MICROS: f64 = 10_000_000.0;
124
125/// The Security and quality activation at the price book's price.
126pub(crate) fn security_plan_at(book: &std::collections::BTreeMap<&str, f64>) -> Plan {
127 let micros = book.get(SECURITY_METER).copied().unwrap_or(SECURITY_FALLBACK_MICROS);
128 Plan {
129 feature: Feature::Security,
130 title: Feature::Security.title().to_owned(),
131 monthly_cents: (micros / 10_000.0).round().max(0.0) as u32,
132 includes: vec![
133 "For every private repository in the workspace; public repositories have it free".to_owned(),
134 "Custom secret patterns, validity checks with issuers, and delegated push protection bypass".to_owned(),
135 "Code scanning from SARIF, with pull request checks that can block merges".to_owned(),
136 "Dependency review on pull requests, and the workspace's security overview".to_owned(),
137 "Everyone in the workspace at one price, never per person".to_owned(),
138 ],
139 overage: "Fixes by g1t's agent are charged as agent usage, like any other agent run. Secret scanning, push protection, vulnerability alerts and security updates stay free.".to_owned(),
140 }
141}
142
Paid features: a workspace turns on Deployments with a monthly plan143impl SubscriptionRow {
144 fn subscription(&self) -> Option<Subscription> {
145 Some(Subscription {
146 feature: Feature::parse(&self.feature)?,
147 status: status_from(&self.status),
148 period_end: self.period_end.clone(),
149 started_by: self.started_by.clone(),
150 started_at: self.started_at.clone(),
151 })
152 }
153}
154
155impl Billing {
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily156 /// What the g1t plan costs and includes, as it is sold now, at the
157 /// price book's prices (the same figures as the pricing page's table).
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar158 pub(crate) async fn plan(&self, feature: Feature) -> Result<Plan> {
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily159 let mut book = std::collections::BTreeMap::new();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar160 if feature == Feature::Security {
161 if let Some((_, price)) = self.price(SECURITY_METER).await? {
162 book.insert(SECURITY_METER, price);
163 }
164 return Ok(security_plan_at(&book));
165 }
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily166 for meter in ["build_second", "app_requests", "app_cpu", "custom_domain_month", "private_storage", "git_operations"] {
167 if let Some((_, price)) = self.price(meter).await? {
168 book.insert(meter, price);
169 }
170 }
171 Ok(self.plan_at(&book))
172 }
173
174 /// The plan at the given prices per unit (micros, after the markup);
175 /// the published costs plus the margin for any not given.
176 pub(crate) fn plan_at(&self, book: &std::collections::BTreeMap<&str, f64>) -> Plan {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look177 let p = &self.plans;
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily178 let price_of = |meter: &str, cost: i64, units: f64| {
179 per_units(book.get(meter).copied().unwrap_or_else(|| Price::price_for(cost as f64, self.margin_percent)), units)
180 };
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look181 Plan {
182 feature: Feature::Plan,
183 title: Feature::Plan.title().to_owned(),
184 monthly_cents: p.plan_monthly_cents,
185 includes: vec![
186 format!(
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas187 "{} of usage each month at cost plus {}%, used first",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look188 dollars(p.plan_included_micros),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put189 self.margin_percent
190 ),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas191 "Everyone in the workspace at one price, never per person".to_owned(),
192 "Unlimited projects, previews and repositories".to_owned(),
193 "Agents, checks, workflows, the merge queue, deployments and semantic search".to_owned(),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look194 format!(
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas195 "Usage past {} is charged at cost plus {}%, up to your spend limit",
196 dollars(p.plan_included_micros),
197 self.margin_percent
Paid features: a workspace turns on Deployments with a monthly plan198 ),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look199 ],
200 overage: format!(
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas201 "Everything is metered from the first unit at what it costs g1t plus {}%: sandbox time and deploy builds by the second ({} a build minute), models at what the provider charged, {} per million app requests, {} per million CPU milliseconds, {} a month per custom domain, private storage past the free {} at {} per GB-month, and git operations past the free {} a month at {} per 1,000. Unused included usage does not roll over.",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look202 self.margin_percent,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily203 price_of("build_second", costs::MICROS_PER_BUILD_SECOND, 60.0),
204 price_of("app_requests", costs::MICROS_PER_MILLION_REQUESTS, 1.0),
205 price_of("app_cpu", costs::MICROS_PER_MILLION_CPU_MS, 1.0),
206 price_of("custom_domain_month", costs::MICROS_PER_DOMAIN_MONTH, 1.0),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas207 bytes(p.free_storage_bytes),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily208 price_of("private_storage", crate::storage::STORAGE_MICROS_PER_GB_MONTH, 1.0),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas209 thousands(p.git_included),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily210 price_of("git_operations", crate::storage::GIT_MICROS_PER_THOUSAND, 1.0),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look211 ),
Paid features: a workspace turns on Deployments with a monthly plan212 }
213 }
214
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look215 /// When the workspace's plan started, and when the period paid for
216 /// ends: its first billing cycle is the first month.
217 pub(crate) async fn plan_cycle(&self, workspace: &str) -> Result<Option<(String, Option<String>)>> {
218 let row = match self.current(workspace, Feature::Plan).await? {
219 Some(row) => Some(row),
220 None => self.current(workspace, Feature::Deployments).await?,
221 };
222 Ok(row
223 .filter(|row| status_from(&row.status).on())
224 .map(|row| (row.started_at, row.period_end)))
225 }
226
Paid features: a workspace turns on Deployments with a monthly plan227 async fn subscription_row(&self, workspace: &str, feature: Feature) -> Result<Option<SubscriptionRow>> {
228 self.db
229 .prepare(
Billing answers every page in a few round trips, not forty: its reads run together, Stripe is asked at most hourly, and the ledger has a time index230 "SELECT feature, subscription_id, status, period_end, started_by, started_at, updated_at
Paid features: a workspace turns on Deployments with a monthly plan231 FROM subscriptions WHERE workspace = ? AND feature = ?",
232 )
233 .bind(&[workspace.into(), feature.as_str().into()])?
234 .first::<SubscriptionRow>(None)
235 .await
236 }
237
238 /// Writes down what the processor says about a plan.
Stripe webhooks, enterprise invoices, and sudo for both239 pub(crate) async fn record(
Paid features: a workspace turns on Deployments with a monthly plan240 &self,
241 workspace: &str,
242 feature: Feature,
243 subscription: &StripeSubscription,
244 started_by: &str,
245 ) -> Result<()> {
246 let now = rfc3339(now_ms());
247 let period_end = subscription.period_end().map(|seconds| rfc3339(seconds.max(0) as u64 * 1000));
Usage, Billing settings and prepaid AI credit; fixes from the UX audit248 // Whether this plan was on already: the upgrade credit is for starting it.
249 let was_on = self
250 .subscription_row(workspace, feature)
251 .await?
252 .is_some_and(|row| row.subscription_id == subscription.id && status_from(&row.status).on());
Paid features: a workspace turns on Deployments with a monthly plan253 self.db
254 .prepare(
255 "INSERT INTO subscriptions
256 (workspace, feature, subscription_id, status, period_end, started_by, started_at, updated_at)
257 VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?7)
258 ON CONFLICT (workspace, feature) DO UPDATE SET
259 subscription_id = ?3, status = ?4, period_end = ?5, updated_at = ?7,
260 started_by = CASE WHEN subscription_id = ?3 THEN started_by ELSE ?6 END,
261 started_at = CASE WHEN subscription_id = ?3 THEN started_at ELSE ?7 END",
262 )
263 .bind(&[
264 workspace.into(),
265 feature.as_str().into(),
266 subscription.id.as_str().into(),
267 status_text(status_of(subscription)).into(),
268 optional(period_end.as_deref()),
269 started_by.into(),
270 now.as_str().into(),
271 ])?
272 .run()
273 .await?;
Usage, Billing settings and prepaid AI credit; fixes from the UX audit274 // Starting the paid plan comes with $5 of AI credit, once (ai.rs).
275 if feature == Feature::Plan && !was_on && status_of(subscription) == SubscriptionStatus::Active {
276 self.grant_upgrade_credit(workspace).await?;
277 }
Paid features: a workspace turns on Deployments with a monthly plan278 Ok(())
279 }
280
281 /// A workspace's plan for a feature, asking the processor again once
Billing answers every page in a few round trips, not forty: its reads run together, Stripe is asked at most hourly, and the ledger has a time index282 /// the period it last knew of is over, at most once an hour.
Paid features: a workspace turns on Deployments with a monthly plan283 async fn current(&self, workspace: &str, feature: Feature) -> Result<Option<SubscriptionRow>> {
284 let Some(row) = self.subscription_row(workspace, feature).await? else {
285 return Ok(None);
286 };
Billing answers every page in a few round trips, not forty: its reads run together, Stripe is asked at most hourly, and the ledger has a time index287 let stale = needs_refresh(&row.status, row.period_end.as_deref(), &row.updated_at, now_ms());
Paid features: a workspace turns on Deployments with a monthly plan288 if let (true, Some(stripe)) = (stale, &self.stripe) {
Project dependencies: addresses, preview stacks, Affects, and agents who know289 match stripe.subscription(&row.subscription_id).await {
290 Ok(subscription) => self.record(workspace, feature, &subscription, &row.started_by).await?,
291 // A plan from another Stripe account: it has ended here.
292 Err(error) if is_missing(&error) => {
293 self.db
294 .prepare("UPDATE subscriptions SET status = 'canceled', updated_at = ? WHERE workspace = ? AND feature = ?")
295 .bind(&[rfc3339(now_ms()).into(), workspace.into(), feature.as_str().into()])?
296 .run()
297 .await?;
298 }
299 Err(error) => return Err(error),
300 }
Paid features: a workspace turns on Deployments with a monthly plan301 return self.subscription_row(workspace, feature).await;
302 }
303 Ok(Some(row))
304 }
305
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look306 /// The plan as a workspace sees it. A Deployments subscription from
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar307 /// before the plan shows as the plan until its period ends. The
308 /// Security and quality activation is its own subscription.
309 async fn state(&self, workspace: &str, feature: Feature) -> Result<FeatureState> {
310 if feature == Feature::Security {
311 let subscription = self.current(workspace, Feature::Security).await?.and_then(|row| row.subscription());
312 let included = self.security_included(workspace).await?;
313 return Ok(FeatureState {
314 plan: self.plan(Feature::Security).await?,
315 on: included || self.stripe.is_none() || subscription.as_ref().is_some_and(|s| s.status.on()),
316 subscription,
317 included,
318 });
319 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look320 let subscription = match self.current(workspace, Feature::Plan).await?.and_then(|row| row.subscription()) {
321 Some(plan) if plan.status.on() => Some(plan),
322 plan => self
323 .current(workspace, Feature::Deployments)
324 .await?
325 .and_then(|row| row.subscription())
326 .filter(|legacy| legacy.status.on())
327 .or(plan),
328 };
329 let included = self.included(workspace).await?;
Paid features: a workspace turns on Deployments with a monthly plan330 Ok(FeatureState {
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily331 plan: self.plan(Feature::Plan).await?,
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put332 on: included || self.stripe.is_none() || subscription.as_ref().is_some_and(|s| s.status.on()),
Paid features: a workspace turns on Deployments with a monthly plan333 subscription,
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put334 included,
Paid features: a workspace turns on Deployments with a monthly plan335 })
336 }
337
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look338 /// Whether the plan is on without its price: comped terms, an
339 /// enterprise's workspaces, or given by g1t staff.
340 async fn included(&self, workspace: &str) -> Result<bool> {
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put341 let account = self.account_of(workspace).await?;
Billing: credits with a kind and expiry, discounts instead of comped, and safer charging342 Ok(account.terms.full_discount()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look343 || account.kind == g1t_contracts::billing::AccountKind::Enterprise
344 || account.allowances.plan)
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put345 }
346
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar347 /// Whether the Security and quality activation is on without its
348 /// price: comped terms, or an enterprise's workspace. Giving the plan
349 /// as an allowance does not give the activation.
350 async fn security_included(&self, workspace: &str) -> Result<bool> {
351 let account = self.account_of(workspace).await?;
352 Ok(account.terms.kind == g1t_contracts::billing::TermsKind::Comped
353 || account.kind == g1t_contracts::billing::AccountKind::Enterprise)
354 }
355
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look356 /// Sets every Deployments subscription from before the plan to end
357 /// with its period, once, so no one pays for it and the plan both.
358 /// Until then it counts as the plan.
359 pub(crate) async fn retire_deployments_plans(&self) -> Result<()> {
360 let Some(stripe) = &self.stripe else { return Ok(()) };
361 #[derive(Deserialize)]
362 struct Legacy {
363 workspace: String,
364 subscription_id: String,
365 started_by: String,
366 period_end: Option<String>,
367 }
368 let legacy = self
369 .db
370 .prepare(
371 "SELECT workspace, subscription_id, started_by, period_end FROM subscriptions
372 WHERE feature = 'deployments' AND status = 'active' LIMIT 20",
373 )
374 .all()
375 .await?
376 .results::<Legacy>()?;
377 for plan in legacy {
378 match stripe.cancel_at_period_end(&plan.subscription_id, true).await {
379 Ok(subscription) => {
380 self.record(&plan.workspace, Feature::Deployments, &subscription, &plan.started_by).await?;
381 let account = self.account_of(&plan.workspace).await?;
382 self.audit(
383 &account.id,
384 "migration",
385 &format!(
386 "{}: the Deployments plan ends {} and is not renewed; deployments come with the g1t plan now",
387 plan.workspace,
388 plan.period_end.as_deref().map_or("at the end of its period", |end| &end[..10])
389 ),
390 "billing",
391 )
392 .await?;
393 }
394 Err(error) if is_missing(&error) => {
395 self.db
396 .prepare("UPDATE subscriptions SET status = 'canceled', updated_at = ? WHERE workspace = ? AND feature = 'deployments'")
397 .bind(&[rfc3339(now_ms()).into(), plan.workspace.as_str().into()])?
398 .run()
399 .await?;
400 }
401 Err(error) => worker::console_error!("could not end {}'s Deployments plan: {error}", plan.workspace),
402 }
403 }
404 Ok(())
405 }
406
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put407 /// Whether the workspace's plan for the feature is paid up.
408 pub(crate) async fn plan_on(&self, workspace: &str, feature: Feature) -> Result<bool> {
409 Ok(self
410 .current(workspace, feature)
411 .await?
412 .and_then(|row| row.subscription())
413 .is_some_and(|s| s.status.on()))
414 }
415
Paid features: a workspace turns on Deployments with a monthly plan416 pub(crate) async fn features(&self, a: FeaturesArgs) -> Result<Outcome<Vec<FeatureState>>> {
417 let workspace = a.workspace.to_lowercase();
418 if !a.viewer.is_some_and(|viewer| viewer.is_member(&workspace)) {
419 return Ok(members_only());
420 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar421 let plan = self.state(&workspace, Feature::Plan).await?;
422 let security = self.state(&workspace, Feature::Security).await?;
423 Ok(Outcome::Ok(vec![plan, security]))
Paid features: a workspace turns on Deployments with a monthly plan424 }
425
426 pub(crate) async fn subscribe(&self, a: SubscribeArgs) -> Result<Outcome<Checkout>> {
427 let workspace = a.workspace.to_lowercase();
428 if a.actor.role_in(&workspace) != Some(Role::Owner) {
429 return Ok(Outcome::fail(
430 FailureCode::Forbidden,
431 "Only an owner can turn on a paid feature.",
432 ));
433 }
434 let Some(stripe) = &self.stripe else {
435 return Ok(Outcome::fail(
436 FailureCode::Conflict,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look437 "Payments are not set up on this g1t, so the plan is already on.",
Paid features: a workspace turns on Deployments with a monthly plan438 ));
439 };
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look440 // Deployments come with the plan: asking for them starts the plan.
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar441 // The Security and quality activation is its own subscription.
442 let feature = if a.feature == Feature::Security { Feature::Security } else { Feature::Plan };
443 let name = if feature == Feature::Security { "The Security and quality activation" } else { "The g1t plan" };
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look444 let state = self.state(&workspace, feature).await?;
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put445 if state.included {
446 return Ok(Outcome::fail(
447 FailureCode::Conflict,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar448 format!("{name} is included for {workspace} already, at no charge."),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put449 ));
450 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar451 if self.plan_on(&workspace, feature).await? {
452 return Ok(Outcome::fail(FailureCode::Conflict, format!("{name} is already on for {workspace}.")));
Paid features: a workspace turns on Deployments with a monthly plan453 }
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily454 let plan = self.plan(feature).await?;
Paid features: a workspace turns on Deployments with a monthly plan455 let customer = self.row(&workspace).await?.and_then(|row| row.customer_id);
Usage, Billing settings and prepaid AI credit; fixes from the UX audit456 // The card from the card check, or else the customer's default
457 // payment method (one added on Stripe's billing page counts): the
458 // plan starts on it at once, with no second page. A card that needs
459 // the bank's approval again goes through Stripe's page instead.
460 let saved = match (customer.as_deref(), self.checked_card(&workspace).await?) {
461 (Some(_), Some(method)) => Some(method),
462 (Some(customer), None) => match stripe.default_payment_method(customer).await {
463 Ok(method) => method.map(|m| m.id),
464 Err(error) => {
465 worker::console_log!("{workspace}: the default payment method could not be read: {error}");
466 None
467 }
468 },
469 (None, _) => None,
470 };
471 if let (Some(customer), Some(method)) = (customer.as_deref(), saved) {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look472 match stripe
473 .subscribe_with_card(&workspace, feature.as_str(), &plan.title, plan.monthly_cents, customer, &method)
474 .await
475 {
476 Ok(subscription) if matches!(subscription.status.as_str(), "active" | "trialing") => {
477 self.record(&workspace, feature, &subscription, &a.actor.username).await?;
478 let account = self.account_of(&workspace).await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar479 self.audit(
480 &account.id,
481 "plan",
Usage, Billing settings and prepaid AI credit; fixes from the UX audit482 &format!("{workspace}: {} started on the saved card", name.to_lowercase()),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar483 &a.actor.username,
484 )
485 .await?;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look486 let separator = if a.return_url.contains('?') { '&' } else { '?' };
487 return Ok(Outcome::Ok(Checkout { url: format!("{}{separator}plan=started", a.return_url) }));
488 }
489 Ok(subscription) => {
490 // Incomplete: let it lapse, and use the page.
491 let _ = stripe.cancel_now(&subscription.id).await;
492 }
Usage, Billing settings and prepaid AI credit; fixes from the UX audit493 Err(error) => worker::console_log!("{workspace}: the plan could not start on the saved card: {error}"),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look494 }
495 }
Project dependencies: addresses, preview stacks, Affects, and agents who know496 let start = |customer: Option<String>| {
497 let plan = &plan;
498 let workspace = &workspace;
499 let return_url = &a.return_url;
500 async move {
501 stripe
502 .start_subscription(
503 workspace,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look504 feature.as_str(),
Project dependencies: addresses, preview stacks, Affects, and agents who know505 &plan.title,
506 plan.monthly_cents,
507 customer.as_deref(),
508 return_url,
509 )
510 .await
511 }
512 };
Usage, Billing settings and prepaid AI credit; fixes from the UX audit513 let started = match start(customer.clone()).await {
Project dependencies: addresses, preview stacks, Affects, and agents who know514 // A customer saved under another Stripe account: start afresh.
515 Err(error) if customer.is_some() && is_missing(&error) => {
516 self.forget_customer(&workspace).await?;
Usage, Billing settings and prepaid AI credit; fixes from the UX audit517 start(None).await
Project dependencies: addresses, preview stacks, Affects, and agents who know518 }
Usage, Billing settings and prepaid AI credit; fixes from the UX audit519 other => other,
Project dependencies: addresses, preview stacks, Affects, and agents who know520 };
Usage, Billing settings and prepaid AI credit; fixes from the UX audit521 let session = match started {
522 Ok(session) => session,
523 Err(error) => {
524 worker::console_error!("{workspace}: Stripe refused the plan's page: {error}");
525 return Ok(Outcome::fail(FailureCode::Conflict, crate::stripe::friendly(&error)));
526 }
Paid features: a workspace turns on Deployments with a monthly plan527 };
Usage, Billing settings and prepaid AI credit; fixes from the UX audit528 let Some(url) = session.url.clone() else {
529 return Ok(Outcome::fail(FailureCode::Conflict, "Stripe returned no payment page. Try again in a minute."));
530 };
531 if let Err(error) = self
532 .record_checkout(&crate::NewCheckout {
533 id: &session.id,
534 workspace: &workspace,
535 amount_cents: plan.monthly_cents,
536 fee_cents: 0,
537 created_by: &a.actor.username,
538 feature: Some(feature.as_str()),
539 })
540 .await
541 {
542 worker::console_error!("{workspace}: the plan's page could not be recorded: {error}");
543 return Ok(Outcome::fail(FailureCode::Conflict, "g1t could not keep track of the payment page. Nothing was charged; try again."));
544 }
Paid features: a workspace turns on Deployments with a monthly plan545 Ok(Outcome::Ok(Checkout { url }))
546 }
547
548 pub(crate) async fn confirm_subscription(
549 &self,
550 a: ConfirmSubscriptionArgs,
551 ) -> Result<Outcome<FeatureState>> {
552 let workspace = a.workspace.to_lowercase();
553 if !a.viewer.is_some_and(|viewer| viewer.is_member(&workspace)) {
554 return Ok(members_only());
555 }
556 let checkout = self
557 .db
558 .prepare(
559 "SELECT workspace, created_by, feature FROM checkouts
560 WHERE id = ? AND workspace = ? AND status = 'open' AND feature IS NOT NULL",
561 )
562 .bind(&[a.session.as_str().into(), workspace.as_str().into()])?
563 .first::<PlanCheckoutRow>(None)
564 .await?;
565 let (Some(stripe), Some(checkout)) = (&self.stripe, checkout) else {
566 // Unknown, someone else's, or already done: show where it stands.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look567 return Ok(Outcome::Ok(self.state(&workspace, Feature::Plan).await?));
Paid features: a workspace turns on Deployments with a monthly plan568 };
569 let Some(feature) = Feature::parse(&checkout.feature) else {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look570 return Ok(Outcome::fail(FailureCode::NotFound, "No such plan."));
Paid features: a workspace turns on Deployments with a monthly plan571 };
Usage, Billing settings and prepaid AI credit; fixes from the UX audit572 let session = match stripe.session(&a.session).await {
573 Ok(session) => session,
574 Err(error) => return Ok(Outcome::fail(FailureCode::Conflict, crate::stripe::friendly(&error))),
575 };
Paid features: a workspace turns on Deployments with a monthly plan576 if let (Some(subscription_id), true) = (&session.subscription, session.payment_status == "paid") {
577 let claimed = self
578 .db
579 .prepare("UPDATE checkouts SET status = 'paid' WHERE id = ? AND status = 'open' RETURNING id")
580 .bind(&[a.session.as_str().into()])?
581 .first::<Touched>(None)
582 .await?;
583 if claimed.is_some() {
Usage, Billing settings and prepaid AI credit; fixes from the UX audit584 let subscription = match stripe.subscription(subscription_id).await {
585 Ok(subscription) => subscription,
586 Err(error) => {
587 // Let the next look (or the webhook) settle it.
588 self.db.prepare("UPDATE checkouts SET status = 'open' WHERE id = ?").bind(&[a.session.as_str().into()])?.run().await?;
589 return Ok(Outcome::fail(FailureCode::Conflict, crate::stripe::friendly(&error)));
590 }
591 };
Paid features: a workspace turns on Deployments with a monthly plan592 self.record(&checkout.workspace, feature, &subscription, &checkout.created_by)
593 .await?;
594 // Keep the card's customer, so later payments need no retyping.
595 self.db
596 .prepare(
597 "INSERT INTO accounts (workspace, balance_micros, customer_id, created_at)
598 VALUES (?1, 0, ?2, ?3)
599 ON CONFLICT (workspace) DO UPDATE SET customer_id = COALESCE(customer_id, ?2)",
600 )
601 .bind(&[
602 checkout.workspace.as_str().into(),
603 optional(session.customer.as_deref()),
604 rfc3339(now_ms()).into(),
605 ])?
606 .run()
607 .await?;
608 }
609 }
610 Ok(Outcome::Ok(self.state(&workspace, feature).await?))
611 }
612
613 pub(crate) async fn cancel_subscription(
614 &self,
615 a: CancelSubscriptionArgs,
616 ) -> Result<Outcome<FeatureState>> {
617 let workspace = a.workspace.to_lowercase();
618 if a.actor.role_in(&workspace) != Some(Role::Owner) {
619 return Ok(Outcome::fail(
620 FailureCode::Forbidden,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look621 "Only an owner can change the workspace's plan.",
Paid features: a workspace turns on Deployments with a monthly plan622 ));
623 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar624 // The activation; or the plan, or a Deployments subscription from
625 // before it.
626 let row = if a.feature == Feature::Security {
627 self.current(&workspace, Feature::Security).await?.map(|row| (Feature::Security, row))
628 } else {
629 match self.current(&workspace, Feature::Plan).await? {
630 Some(row) if status_from(&row.status) != SubscriptionStatus::Canceled => Some((Feature::Plan, row)),
631 _ => self.current(&workspace, Feature::Deployments).await?.map(|row| (Feature::Deployments, row)),
632 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look633 };
634 let (Some(stripe), Some((feature, row))) = (&self.stripe, row) else {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar635 let name = if a.feature == Feature::Security { "The Security and quality activation" } else { "The g1t plan" };
636 return Ok(Outcome::fail(FailureCode::NotFound, format!("{name} is not on for {workspace}.")));
Paid features: a workspace turns on Deployments with a monthly plan637 };
Usage, Billing settings and prepaid AI credit; fixes from the UX audit638 let subscription = match stripe.cancel_at_period_end(&row.subscription_id, !a.resume).await {
639 Ok(subscription) => subscription,
640 Err(error) => return Ok(Outcome::fail(FailureCode::Conflict, crate::stripe::friendly(&error))),
641 };
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look642 self.record(&workspace, feature, &subscription, &row.started_by)
Paid features: a workspace turns on Deployments with a monthly plan643 .await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar644 let shown = if feature == Feature::Security { Feature::Security } else { Feature::Plan };
645 Ok(Outcome::Ok(self.state(&workspace, shown).await?))
Paid features: a workspace turns on Deployments with a monthly plan646 }
647
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar648 /// Whether the workspace has the plan, which deployments come with, or
649 /// the Security and quality activation.
Paid features: a workspace turns on Deployments with a monthly plan650 pub(crate) async fn has_feature(&self, a: HasFeatureArgs) -> Result<Outcome<bool>> {
651 let workspace = a.workspace.to_lowercase();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar652 if a.feature == Feature::Security {
653 let state = self.state(&workspace, Feature::Security).await?;
654 if state.on {
655 return Ok(Outcome::Ok(true));
656 }
657 return Ok(Outcome::fail(
658 FailureCode::PaymentRequired,
659 format!(
660 "This needs the Security and quality activation ({} a month for the workspace), and {workspace} does not have it. An owner can turn it on at /{workspace}/-/billing.",
661 dollars(i64::from(state.plan.monthly_cents) * 10_000)
662 ),
663 ));
664 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look665 if self.has_plan(&workspace).await? {
Paid features: a workspace turns on Deployments with a monthly plan666 return Ok(Outcome::Ok(true));
667 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look668 let what = match a.feature {
669 Feature::Deployments => "Deployments come with the g1t plan",
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar670 Feature::Plan | Feature::Security => "This needs the g1t plan",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look671 };
Paid features: a workspace turns on Deployments with a monthly plan672 Ok(Outcome::fail(
673 FailureCode::PaymentRequired,
674 format!(
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look675 "{what} ($20 a month for the workspace, with $10 of usage included), and {workspace} does not have it. An owner can start it at /{workspace}/-/billing."
Paid features: a workspace turns on Deployments with a monthly plan676 ),
677 ))
678 }
679
680 pub(crate) async fn charge_feature(&self, a: ChargeFeatureArgs) -> Result<Outcome<bool>> {
681 if self.stripe.is_none() || a.cost_micros <= 0 {
682 return Ok(Outcome::Ok(false));
683 }
684 let workspace = a.workspace.to_lowercase();
685 let seen = self
686 .db
687 .prepare("SELECT id FROM ledger WHERE reference = ?")
688 .bind(&[a.reference.as_str().into()])?
689 .first::<Touched>(None)
690 .await?;
691 if seen.is_some() {
692 return Ok(Outcome::Ok(false));
693 }
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put694 let timestamp = rfc3339(now_ms());
695 let month = crate::credits::month_of(&timestamp);
696 let mut description = a.description.clone();
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas697 // A build: every second is metered, at the price book's build
698 // second, which the keeper keeps at what Cloudflare bills, rather
699 // than at what the caller worked out. The month's build time is
700 // tallied for the Billing page.
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put701 let cost_micros = match a.build_seconds.filter(|s| *s > 0 && a.feature == Feature::Deployments) {
702 Some(seconds) => {
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas703 self.tally("build_seconds", &workspace, &month, seconds.into()).await?;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look704 let measured = self.price("build_second").await?.map(|(cost, _)| (f64::from(seconds) * cost).ceil() as i64);
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas705 measured.unwrap_or(a.cost_micros)
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put706 }
707 None => a.cost_micros,
708 };
Billing accounts, terms and enterprises; g1t is no longer free709 // Never free: the margin applies whatever FREE_WHILE_BUILDING says,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look710 // and only the account's terms change it. The plan's included usage
711 // pays what it can; the trial and the open-source pool never pay for
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put712 // deployments.
Billing: credits with a kind and expiry, discounts instead of comped, and safer charging713 let (charge, discount) = self.terms_of(&workspace).await?.discounted(crate::margin_on(cost_micros, self.margin_percent));
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put714 let drawn = self.draw(&workspace, charge, &month, &crate::credits::Eligible::default()).await?;
715 description.push_str(&drawn.note());
716 self.post_usage(crate::storage::UsageLine {
717 workspace: &workspace,
718 charged: charge - drawn.total(),
719 description: &description,
720 repo: a.repo.as_deref(),
721 task: a.feature.as_str(),
722 cost: cost_micros,
723 reference: &a.reference,
724 created_at: &timestamp,
725 drawn,
726 })
727 .await?;
Merge branch 'worktree-agent-a633ac0f7f66d419d'728 self.record_discount(&a.reference, discount).await?;
Spend caps: a monthly budget for comped workspaces and a daily breaker on what g1t pays729 self.count_spend(&workspace, cost_micros, charge - drawn.total(), &drawn).await;
Paid features: a workspace turns on Deployments with a monthly plan730 Ok(Outcome::Ok(true))
731 }
732}
Deployments: a preview for every pull request, production on g1t.page733
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas734/// `50,000`: a count as the plan reads it.
735pub(crate) fn thousands(n: u64) -> String {
736 let digits = n.to_string();
737 let mut out = String::new();
738 for (i, c) in digits.chars().enumerate() {
739 if i > 0 && (digits.len() - i).is_multiple_of(3) {
740 out.push(',');
741 }
742 out.push(c);
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put743 }
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas744 out
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put745}
746
Deployments: a preview for every pull request, production on g1t.page747#[cfg(test)]
748mod tests {
749 use super::*;
750
751 #[test]
Billing answers every page in a few round trips, not forty: its reads run together, Stripe is asked at most hourly, and the ledger has a time index752 fn an_ended_plan_is_asked_about_at_most_once_an_hour() {
753 let now = 1_791_000_000_000;
754 let at = |ago_ms: u64| rfc3339(now - ago_ms);
755 let ended = at(24 * 60 * 60 * 1000);
756 // Ended, and last written a day ago: ask.
757 assert!(needs_refresh("active", Some(&ended), &ended, now));
758 // Ended, but written ten minutes ago: believe the row.
759 assert!(!needs_refresh("active", Some(&ended), &at(10 * 60 * 1000), now));
760 // An hour on, ask again.
761 assert!(needs_refresh("active", Some(&ended), &at(REFRESH_MS), now));
762 // No period known is the same as ended.
763 assert!(needs_refresh("past_due", None, &ended, now));
764 // A period still running, or a canceled plan, is never asked about.
765 assert!(!needs_refresh("active", Some(&rfc3339(now + 1000)), &ended, now));
766 assert!(!needs_refresh("canceled", Some(&ended), &ended, now));
767 }
768
769 #[test]
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily770 fn the_plan_text_quotes_a_build_minute_as_the_table_does() {
771 // The price book's build second (16.44 millionths at cost, plus
772 // 20%) is 19.73 millionths: a minute is 1,184 millionths, $0.0012,
773 // as the pricing page's table says. The old fixed cost (15) gave
774 // $0.0011.
775 let each = Price::price_for(16.439_893_610_418_67, 20);
776 assert_eq!(per_units(each, 60.0), "$0.0012");
777 assert_eq!(per_units(Price::price_for(15.0, 20), 60.0), "$0.0011");
778 assert_eq!(per_units(Price::price_for(150_000.0, 20), 1.0), "$0.18");
779 }
780
781 #[test]
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas782 fn every_build_second_is_metered_at_cost_plus_the_margin() {
783 // A 5-minute build at 15 millionths a second costs g1t 4,500, and
784 // is charged at cost plus 20%, from the first second: there are no
785 // included build minutes, only the plan's included usage.
786 let cost = 300 * costs::MICROS_PER_BUILD_SECOND;
787 assert_eq!(cost, 4_500);
788 assert_eq!(crate::credits::with_margin(cost, 20), 5_400);
789 }
790
791 #[test]
792 fn counts_read_with_thousands_separators() {
793 assert_eq!(thousands(0), "0");
794 assert_eq!(thousands(999), "999");
795 assert_eq!(thousands(50_000), "50,000");
796 assert_eq!(thousands(1_234_567), "1,234,567");
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put797 }
798
799 #[test]
800 fn storage_reads_in_gigabytes() {
801 assert_eq!(bytes(1_000_000_000), "1 GB");
802 assert_eq!(bytes(50_000_000_000), "50 GB");
803 assert_eq!(bytes(1_500_000_000), "1.5 GB");
804 assert_eq!(bytes(500_000_000), "500 MB");
805 }
806
807 #[test]
Money in billing's messages reads to the cent, and the deploy reads migrations again after a failure808 fn amounts_of_money_read_to_the_cent() {
809 assert_eq!(cents(3_986_990), "$3.99");
810 assert_eq!(cents(5_000_000), "$5.00");
811 assert_eq!(cents(4_000), "$0.00");
812 }
813
814 #[test]
Deployments: a preview for every pull request, production on g1t.page815 fn prices_under_a_cent_keep_their_digits() {
816 assert_eq!(dollars(1512), "$0.0015");
817 assert_eq!(dollars(24_000), "$0.024");
818 assert_eq!(dollars(360_000), "$0.36");
819 assert_eq!(dollars(5_000_000), "$5.00");
820 }
821}
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar822
823#[cfg(test)]
824mod security_activation {
825 use super::*;
826
827 #[test]
828 fn the_activation_is_priced_from_the_price_book() {
829 let book = std::collections::BTreeMap::from([(SECURITY_METER, 12_000_000.0)]);
830 let plan = security_plan_at(&book);
831 assert_eq!((plan.feature, plan.monthly_cents), (Feature::Security, 1200));
832 assert_eq!(plan.title, "Security and quality");
833 // The price book unreadable: $10, as the migration seeds it.
834 assert_eq!(security_plan_at(&std::collections::BTreeMap::new()).monthly_cents, 1000);
835 assert!(plan.includes.iter().any(|line| line.contains("public repositories have it free")));
836 assert!(plan.overage.contains("agent usage"));
837 }
838}

This file's history is long; its oldest lines are credited to the oldest commit read.