Stripe webhooks, enterprise invoices, and sudo for both
Stripe now tells billing what happens while no one is looking, at api.g1t.sh/stripe/webhook: payment pages finished after the tab closed, plan renewals and failures, refunds (partial ones add up), disputes (which stop work until resolved), and enterprise invoices paid, overdue or voided. Events are signature-checked against the endpoint billing registered itself from sudo, whose secret stays in billing, refused when older than five minutes, and handled once each. Enterprises are invoiced: when a month closes, one Stripe invoice to the enterprise's billing email with a line per workspace, net 30, paid on Stripe's hosted page. Paid clears each workspace; overdue stops their work. Staff can send one now from sudo. sudo gains a Stripe page (mode, webhook, recent events), invoices on each enterprise, and pages its workspace list, with billing figures fetched for exactly that page.
No changes