pr_01m47d15m3e54sn21z27rpy5n9/apps/sudo/README.md
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Billing accounts, terms and enterprises; g1t is no longer free | 1 | # sudo |
| 2 | ||
| A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales | 3 | g1t's staff console, at <https://sudo.g1t.sh>: the back office g1t is |
| 4 | building for itself, for sales, support and finance. It is organised the | |
| 5 | way customers know g1t: by **workspace**. | |
| 6 | ||
| 7 | The sidebar (`app/lib/nav.ts`) has Overview and Reach out at the top, then | |
| 8 | sections that fold open to their pages: Customers, Revenue, Platform, | |
| 9 | Support and Team. Each fold is a `<details>`, drawn open for the section | |
| 10 | holding the current page; on a phone the same menu sits behind a "Menu" | |
| 11 | button in the top bar. Pages not built yet are marked **Soon**: each is a | |
| 12 | real page (`routes/soon.tsx`, made from its entry in `nav.ts`) saying what | |
| 13 | it will do, why, and what it will have, so the sidebar doubles as the | |
| 14 | roadmap. | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 15 | |
| A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales | 16 | - **Overview** (`/`): this month charged, cost and margin; the last six |
| 17 | months as a chart; this month by kind of usage; paying workspaces; how | |
| 18 | many are stopped, near their limit or declined (each a link into Reach | |
| 19 | out); open invoices; follow-ups due; and the five most urgent signals. | |
| 20 | From billing's `admin_overview` and `admin_signals`. | |
| 21 | - **Reach out** (`/reach-out`): every workspace worth a word, most urgent | |
| 22 | first (at limit, declined, near limit, high spend, growing, established, | |
| 23 | first payment), with its owners, the reason in a sentence, the figure, | |
| 24 | and its sales stage and owner at g1t. Filter by why and by whose | |
| 25 | (everyone's, unassigned, mine). Each row opens the workspace's Sales. | |
| 26 | - **Workspaces** (`/workspaces`): every workspace, newest first, 50 to a | |
| Stripe webhooks, enterprise invoices, and sudo for both | 27 | page, with its owners, members, who it is billed to, its terms, this |
| 28 | month's usage against its limit, what it was charged and what it cost | |
| 29 | g1t. Search by workspace, owner, email or enterprise (across the whole | |
| 30 | list); filter to stopped or warning, comped or custom, or on an | |
| 31 | enterprise. Billing's figures are fetched for exactly the page shown, so | |
| 32 | the filters, and the totals over the list, cover that page; the page | |
| A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales | 33 | says so when there is more than one. A workspace's page shows its members; |
| 34 | **Sales** (its stage, the staff member who has it, the next step and its | |
| 35 | date, and notes, newest first; `admin_sales`, `admin_set_sales`, | |
| 36 | `admin_add_note`); and under **Billing** its limit in words (trust, the | |
| 37 | owners' own spend limit or the default, the most they may set, how it | |
| 38 | grows), its last six months as a chart, its invoices (`admin_workspace_invoices`, | |
| 39 | with Stripe's page and PDF), its terms, who it is billed to (move it onto or off an | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 40 | enterprise), a credit form, a Stripe billing link, its ledger and its |
| A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales | 41 | audit log. If billing does not answer for sales or invoices, the page |
| 42 | still opens and says so in those sections. | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 43 | - **Enterprises**: customers that pay for several workspaces with one |
| 44 | bill, one limit and one set of terms. Each has its workspaces (add or | |
| Stripe webhooks, enterprise invoices, and sudo for both | 45 | remove them), combined usage, terms, credits, ledger and audit log, and |
| 46 | **Invoices**: where they go (the billing email, which also makes its | |
| 47 | Stripe customer), a "Send invoice now" button, and every invoice with | |
| 48 | its status (open, paid, overdue, void), a line per workspace, and a link | |
| 49 | to Stripe's hosted invoice page. An invoice also goes out on its own as | |
| 50 | each month closes: one Stripe invoice, a line per workspace for what it | |
| 51 | owes, net 30, emailed by Stripe. | |
| 52 | - **Stripe**: whether billing's key is in test or live mode (or off), the | |
| 53 | webhook Stripe calls (URL, endpoint id, events, who registered it and | |
| 54 | when), and the events Stripe sent lately with what billing did with | |
| 55 | each. "Register webhook" (or "Replace") has billing delete the endpoint | |
| 56 | it made before, create a new one and keep its signing secret, which no | |
| 57 | one sees. Do it once per mode, and again after switching to live keys. | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 58 | |
| A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales | 59 | Sales changes are not money, so they have no confirmation step; they are |
| 60 | still POSTs from sudo's own pages, recorded with who made them. | |
| 61 | ||
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 62 | Billing's internal account ids (`ws_<slug>` for a workspace's own, |
| 63 | `ent_…` for an enterprise) are never shown as names; an enterprise's id | |
| 64 | appears only as small "Billing account id" text. Old `/accounts/…` links | |
| 65 | redirect to the workspace or enterprise they meant. | |
| 66 | ||
| 67 | **Cards stay on Stripe.** sudo never shows a card field. To help a customer | |
| 68 | update their card or see invoices, staff make a Stripe billing link on the | |
| 69 | workspace's page (it is recorded) and send it to the owner. | |
| Billing accounts, terms and enterprises; g1t is no longer free | 70 | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 71 | It holds no data. Workspaces, owners and members come from identity's |
| 72 | staff methods (`admin_workspaces`, `admin_workspace`; `IdentityAdminApi` in | |
| 73 | `packages/contracts/src/identity.ts`); everything about money goes to the | |
| 74 | billing service's (`admin_*`, `BillingAdminApi` in | |
| 75 | `packages/contracts/src/billing.ts`), where each change is recorded with | |
| 76 | the staff member's email. Both are reached over service bindings only, and | |
| 77 | nothing but sudo binds to them. | |
| Billing accounts, terms and enterprises; g1t is no longer free | 78 | |
| 79 | ## How it is locked | |
| 80 | ||
| 81 | 1. **Cloudflare Access** sits in front of `sudo.g1t.sh` and signs people in. | |
| 82 | 2. **The worker checks Access's work** on every request, the stylesheet | |
| 83 | included (`run_worker_first`): it verifies the `Cf-Access-Jwt-Assertion` | |
| 84 | JWT itself (RS256 against the team's published keys, audience, issuer, | |
| 85 | expiry), then requires its email to be in `STAFF_EMAILS`. That email is | |
| 86 | who every change is recorded as. See `app/lib/access.ts`. | |
| 87 | 3. **It fails closed.** Until `ACCESS_TEAM_DOMAIN`, `ACCESS_AUD` and | |
| 88 | `STAFF_EMAILS` are all set, every request gets a 403 saying sudo is not | |
| 89 | configured. | |
| 90 | 4. **Changes** are POSTs only, and only from sudo's own pages (`Origin`, or | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 91 | `Referer`, must be `https://sudo.g1t.sh`). Terms, enterprise moves, new |
| Stripe webhooks, enterprise invoices, and sudo for both | 92 | enterprises, Stripe billing links, invoice emails, invoices and the |
| 93 | webhook show a confirmation step first; a credit needs the workspace's | |
| 94 | slug typed out. | |
| Billing accounts, terms and enterprises; g1t is no longer free | 95 | 5. **The pages ship no JavaScript.** The content security policy forbids |
| 96 | every script and inline style; responses are `no-store`, `noindex` and | |
| 97 | cannot be framed. The worker has no `workers.dev` address or preview URLs. | |
| 98 | ||
| 99 | ## Setting up Access (once, in the Cloudflare dashboard) | |
| 100 | ||
| 101 | 1. **Zero Trust → Access → Applications → Add an application → Self-hosted.** | |
| 102 | - Application name: `sudo`. | |
| 103 | - Session duration: short, such as 8 hours. | |
| 104 | - Public hostname: `sudo.g1t.sh` (path empty, so it covers everything). | |
| sudo: Access is on, and everyone at g1t.sh is staff | 105 | 2. **Add a policy** (`g1t staff`): action *Allow*, include *Emails* → the |
| 106 | owner's address, and *Emails ending in* → `g1t.sh` for everyone with a | |
| 107 | g1t address (the same entries as `STAFF_EMAILS`, where a domain is | |
| 108 | written `@g1t.sh`). Add more staff here *and* in `STAFF_EMAILS`; either | |
| 109 | one alone is not enough. | |
| Billing accounts, terms and enterprises; g1t is no longer free | 110 | 3. Save, then open the application's **Overview** (or *Basic information*) |
| 111 | and copy the **Application Audience (AUD) tag**. | |
| 112 | 4. Find the **team domain** under **Zero Trust → Settings → Custom pages** | |
| 113 | (or *Team name and domain*): it looks like `<team>.cloudflareaccess.com`. | |
| 114 | 5. Put both into `wrangler.jsonc`: | |
| 115 | ||
| 116 | ```jsonc | |
| 117 | "vars": { | |
| 118 | "ACCESS_TEAM_DOMAIN": "<team>.cloudflareaccess.com", | |
| 119 | "ACCESS_AUD": "<the AUD tag>", | |
| sudo: Access is on, and everyone at g1t.sh is staff | 120 | "STAFF_EMAILS": "syntaqx@gmail.com, @g1t.sh" |
| Billing accounts, terms and enterprises; g1t is no longer free | 121 | } |
| 122 | ``` | |
| 123 | ||
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 124 | 6. Deploy: `scripts/deploy.sh sudo` (after `billing` and `identity`, whose |
| 125 | `admin_*` methods it calls). | |
| Billing accounts, terms and enterprises; g1t is no longer free | 126 | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 127 | Visit <https://sudo.g1t.sh>: Access asks you to sign in, then the workspaces |
| Billing accounts, terms and enterprises; g1t is no longer free | 128 | list opens. Anyone else gets Access's own refusal; anyone Access lets in who |
| 129 | is not in `STAFF_EMAILS` gets a 403 from the worker. | |
| 130 | ||
| sudo: WARP sign-in, and comped accounts say Comped | 131 | ## Signing in through WARP |
| 132 | ||
| 133 | Staff signed in to the Zero Trust org in the Cloudflare One agent (WARP) | |
| 134 | reach sudo without the login page: the org allows WARP sessions as Access | |
| 135 | sign-ins (8 hours), the sudo app accepts them, and the `g1t staff` policy | |
| 136 | is also on the WARP enrollment app, so staff can enroll their devices. | |
| 137 | The same two checks still apply: the Access policy, and `STAFF_EMAILS`. | |
| 138 | ||
| Billing accounts, terms and enterprises; g1t is no longer free | 139 | ## Working on it |
| 140 | ||
| 141 | ```sh | |
| 142 | npm run typecheck -w @g1t/sudo | |
| A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales | 143 | npm test -w @g1t/sudo # JWT verification, forms, money, the workspace join, paging, nav, charts, signals |
| Billing accounts, terms and enterprises; g1t is no longer free | 144 | npm run build -w @g1t/sudo |
| 145 | ``` | |
| 146 | ||
| 147 | `npm run dev` serves the pages, but every request is refused without a real | |
| 148 | Access token, by design. |