feat(auth): add local user signup, email verification, and Stripe billing
- Add LocalUser model with bcrypt password hashing, email verification tokens, and password reset tokens - Add ALLOW_LOCAL_SIGNUP config flag (requires SMTP to be configured) - Add Stripe billing config fields (STRIPE_SECRET_KEY, etc.) - Add stripe_customer_id to UserProfile and stripe_price_id_monthly/ stripe_price_id_yearly to SubscriptionPlan - Create migration 018_add_local_users_and_billing - Add app/utils/local_auth.py: hash_password, verify_password, generate_token, is_token_expired, send_verification_email, send_password_reset_email, build_session_user - Add app/api/local_auth.py: signup, email verification, password reset endpoints plus signup/verify-email-sent/reset-password page routes - Add app/api/billing.py: Stripe Checkout, Customer Portal, and webhook endpoints; syncs subscription tier from webhook events - Update auth() to check LocalUser table before admin credentials fallback - Update login() to pass allow_signup context variable to template - Add signup.html, verify_email_sent.html, password_reset_form.html, billing_success.html templates (Alpine.js, Tailwind, WCAG 2.1 AA) - Update login.html to show 'Create account' link when signup enabled - Update pricing.html CTA buttons to use Stripe Checkout for paid tiers - Add docs/BillingSetup.md with setup guide, webhook config, compliance - Add tests/test_local_auth.py (42 tests) and tests/test_billing.py (31 tests); all 106 tests in the modified test suite pass - Add stripe>=7.0.0,<15.0.0 to requirements.txt Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
@@ -117,6 +117,13 @@
|
||||
<a href="/login"
|
||||
class="block w-full text-center py-3 px-4 rounded-lg border-2 border-blue-600 text-blue-600 font-semibold hover:bg-blue-50 transition"
|
||||
>{{ tier.cta }}</a>
|
||||
{% elif tier.stripe_price_id_monthly or tier.stripe_price_id_yearly %}
|
||||
<button
|
||||
type="button"
|
||||
onclick="startCheckout('{{ tier.id }}')"
|
||||
class="block w-full text-center py-3 px-4 rounded-lg {% if tier.highlight %}bg-indigo-600 text-white font-semibold hover:bg-indigo-700 transition shadow-md{% else %}bg-blue-600 text-white font-semibold hover:bg-blue-700 transition{% endif %}"
|
||||
style="min-height:44px;"
|
||||
>{{ tier.cta }}</button>
|
||||
{% elif tier.highlight %}
|
||||
<a href="/login"
|
||||
class="block w-full text-center py-3 px-4 rounded-lg bg-indigo-600 text-white font-semibold hover:bg-indigo-700 transition shadow-md"
|
||||
@@ -377,3 +384,41 @@
|
||||
</div>
|
||||
</div>
|
||||
{% endblock %}
|
||||
|
||||
{% block extra_scripts %}
|
||||
<script>
|
||||
/**
|
||||
* Initiate a Stripe Checkout session for the given plan.
|
||||
* Uses the currently-selected billing cycle toggle (monthly/yearly).
|
||||
*
|
||||
* @param {string} planId - The plan identifier (e.g. 'starter', 'professional').
|
||||
*/
|
||||
async function startCheckout(planId) {
|
||||
const cycleEl = document.querySelector('[data-billing-cycle]');
|
||||
const billingCycle = (cycleEl && cycleEl.dataset.billingCycle) ? cycleEl.dataset.billingCycle : 'monthly';
|
||||
|
||||
try {
|
||||
const resp = await fetch('/api/billing/create-checkout-session', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ plan_id: planId, billing_cycle: billingCycle })
|
||||
});
|
||||
if (resp.status === 401) {
|
||||
window.location.href = '/login?message=Please+sign+in+to+subscribe';
|
||||
return;
|
||||
}
|
||||
if (resp.ok) {
|
||||
const data = await resp.json();
|
||||
if (data.checkout_url) {
|
||||
window.location.href = data.checkout_url;
|
||||
return;
|
||||
}
|
||||
}
|
||||
const data = await resp.json().catch(() => ({}));
|
||||
alert(data.detail || 'Unable to start checkout. Please try again.');
|
||||
} catch (e) {
|
||||
alert('Network error. Please try again.');
|
||||
}
|
||||
}
|
||||
</script>
|
||||
{% endblock %}
|
||||
|
||||
Reference in New Issue
Block a user