Skip to content

feat(pro): restore the proAvailable gate, off by default - #2018

Open
mpretty-cyro wants to merge 1 commit into
session-foundation:devfrom
mpretty-cyro:feat/restore-pro-gate
Open

mpretty-cyro wants to merge 1 commit into
session-foundation:devfrom
mpretty-cyro:feat/restore-pro-gate

Conversation

@mpretty-cyro

@mpretty-cyro mpretty-cyro commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Restores the proAvailable gate removed in a64ae98 (#1972) and 59e18c8, plus the .webp avatar-picker gate that the conflict resolution of merge 4068098 dropped. Off by default (SESSION_PRO unset) while the Pro release is delayed.

Toggle: SESSION_PRO=1 in the launch environment, or the debug menu's Pro Beta Released (needs SESSION_DEV).

What the gate does when off (the default)

  • This account: can neither use nor buy Pro, and nothing is restricted for lacking it — standard compose limit, no pinned-conversation limit, no upsell CTAs, no Pro settings row or badge of its own, and no Pro status or proof requests.
  • Other users: their Pro is still honoured — badges and message Pro features show, animated avatars animate, and inbound messages are only cut at the Pro limit.
  • Pro bought on another device: a proof or access expiry synced into config grants nothing on this device, and nothing on this device removes or rewrites it. Every writer of the user's own Pro config is on a gated path, or records a true fact about a newly set/removed avatar.
  • The Pro revocation list is still fetched, so other users' revoked proofs stop showing promptly. This account's own proof is never cleared by a Pro-off device, even if the list revokes it; that is left to its devices with Pro on.

Same rule on iOS, Android and Desktop. One commit per client so each reverts cleanly when Pro ships.

Implementation notes

  • currentUserProofIsValid() — the access source that reads a synced proof — returns false when off, before any mock.
  • The pin and animated-avatar gates read access state that is false when off, so they check the flag explicitly; otherwise they would refuse instead of allow.
  • useProBadgeOnClickCb: when off, other users' badges show but never open a CTA; the contexts that only present our own Pro (edit-profile-pic, show-our-profile-dialog, character-count) are hidden.
  • The startup status fetch and mocked-status startup are gated before the stamps they write, so turning Pro on later is not throttled by a stamp written while it was off.
  • The revocation job still runs when off; only its clearing of our own revoked proof is gated.
  • The Pro debug section hides everything below its toggle, including controls added since the removal.

Testing

  • New pro_gate_test.ts (4, each flag-off case with a flag-on control).
  • Unit suite on the current dev base: 961 passing, 0 failing; tsc, ESLint, Prettier and commitlint clean.
  • Appium: see below.

Appium results (2026-09-29, overnight)

Method: every failure was re-run on a pre-gate build (this branch's parent, built separately). Each build was probed for a literal only the gate adds, alongside a control literal present in both. "Gate-caused" means it fails with the gate, passes without it, and holds under an alternating tie-break on fresh devices.

Tested 201a2a1c7 against pre-gate d1fd7e424:

  • Full suite (129): 125 pass, 1 flaky, 3 fail. All 3 reproduce without the gate (Pin and unpin has no Pin context-menu item on either build; Read status) or are flaky (username sync).

Verdict: no gate-caused regression.

Since those runs: the revocation list is now also fetched while Pro is off (architect-approved), with clearing our own revoked proof still gated. Unit tests pass on the current head; a targeted Appium re-check of the revocation fetch and the badge is running.

Companion PRs

Same gate and rule on each client: session-foundation/session-ios#797 · session-foundation/session-android#2226 · #2018

Brings back the proAvailable flag (SESSION_PRO, off by default) removed in
a64ae98 and 59e18c8, and the .webp avatar gate that merge 4068098's
conflict resolution dropped. Off, this account can neither use nor buy Pro and
nothing is restricted for lacking it; other people's Pro is still honoured.
One commit so it reverts cleanly.

- Every self-facing guard those removed, reapplied in the code's current shape.
  The Pro debug section hides everything below its toggle.
- Other people's badges and message features show while Pro is off; badges
  that only present our own Pro are hidden and no badge sells anything. The
  revocation list keeps polling for their proofs; clearing our own revoked
  proof stays gated.
- The pin and animated-avatar gates now read access state that is false when
  Pro is off, so they need the flag explicitly or they refuse instead of allow.
- Gates Pro code added since the removal: the access source that reads a synced
  proof, and the startup status fetch and mocked-status paths (both wrote
  stamps before the guarded fetch).
@mpretty-cyro
mpretty-cyro marked this pull request as ready for review September 28, 2026 23:28

@Bilb Bilb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants