* feat(billing): paywall conversion pass: deferred first charge, trial touchpoint, sell-view upgrade
- checkout passes subscription_data.trial_end (trial grant expiry, 49h floor)
so a mid-trial upgrade costs 0 kr today instead of double-billing days the
company already has free; billing/status counts 'trialing' as paying
- trial countdown pill in the sidebar (CompanyContext.trialEndsAt via
getCompanyEntitlements); hidden for sandbox, dev bypass, and once any
non-trial grant is active
- sell view: what-happens-when timeline, free-vs-paid comparison table,
risk-reversal copy + chevron CTA, post-checkout confirmation state
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(billing): review triage: fail-closed trial lookup, hourly countdown refresh, BFL retention note
- checkout returns 500 (no Stripe session) when the trial-grant lookup errors,
instead of silently charging immediately after the UI promised 0 kr idag
- sidebar trial countdown recomputes hourly so a long-lived tab stays honest
- sell-view retention copy states BFL 7-year retention explicitly
(compliance-bot suggestion)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* chore: retrigger CI (pull_request event delivery stuck)
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(billing): block demo/sandbox accounts from Stripe checkout
An anonymous demo user on a sandbox company reached POST /api/billing/checkout
and created a live Stripe customer. Neither the checkout nor the portal route
checked is_anonymous or is_sandbox, and withRouteContext lets anonymous users
through (they are authenticated, just anonymously).
Guard both routes on both conditions before any Stripe call: refuse anonymous
users (identity truth, cheap in-memory check) and sandbox companies (matches the
existing lib/sandbox/guard.ts "never charge a token" doctrine). Surface isDemo
on GET /api/billing/status so the client hides the upgrade CTA instead of
showing a button that 403s.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* docs(billing): redact tenant/customer IDs from incident note (CodeRabbit)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- Register BillingSettingsContent in SETTINGS_SECTIONS so the settings MODAL renders Abonnemang (it was falling back to Företag — billing was only a standalone page, never a registered section). Page is now a thin wrapper over the same component.
- Add GET /api/billing/status (isPaying / configured / trialEndsAt) so the client section gets state without server-only reads.
- Redesign for conversion: trial days-left urgency banner, reactive monthly/yearly price with a 'Spara 2 mån' badge, full-width price-bearing CTA, Stripe trust line, design-system-compliant chrome (flat Card, no shadow/rounded-xl, on-scale spacing, serif headline). Trialing companies now see the upgrade path (not the manage button).
The reported 'peach band' was not reproduced in code — no peach/salmon color exists in the app CSS and the only bottom drag-handle is in a md:hidden mobile sheet; most likely a macOS screenshot/desktop artifact.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>