feat(pro): restore the proAvailable gate, off by default - #2018
Open
mpretty-cyro wants to merge 1 commit into
Open
mpretty-cyro wants to merge 1 commit into
mpretty-cyro wants to merge 1 commit into
Conversation
This was referenced Sep 28, 2026
Brings back the proAvailable flag (SESSION_PRO, off by default) removed in a64ae98 and 59e18c8, and the .webp avatar gate that merge 4068098's conflict resolution dropped. Off, this account can neither use nor buy Pro and nothing is restricted for lacking it; other people's Pro is still honoured. One commit so it reverts cleanly. - Every self-facing guard those removed, reapplied in the code's current shape. The Pro debug section hides everything below its toggle. - Other people's badges and message features show while Pro is off; badges that only present our own Pro are hidden and no badge sells anything. The revocation list keeps polling for their proofs; clearing our own revoked proof stays gated. - The pin and animated-avatar gates now read access state that is false when Pro is off, so they need the flag explicitly or they refuse instead of allow. - Gates Pro code added since the removal: the access source that reads a synced proof, and the startup status fetch and mocked-status paths (both wrote stamps before the guarded fetch).
mpretty-cyro
force-pushed
the
feat/restore-pro-gate
branch
from
September 28, 2026 21:02
201a2a1 to
d2c7c87
Compare
mpretty-cyro
marked this pull request as ready for review
September 28, 2026 23:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Restores the
proAvailablegate removed in a64ae98 (#1972) and 59e18c8, plus the.webpavatar-picker gate that the conflict resolution of merge 4068098 dropped. Off by default (SESSION_PROunset) while the Pro release is delayed.Toggle:
SESSION_PRO=1in the launch environment, or the debug menu's Pro Beta Released (needsSESSION_DEV).What the gate does when off (the default)
Same rule on iOS, Android and Desktop. One commit per client so each reverts cleanly when Pro ships.
Implementation notes
currentUserProofIsValid()— the access source that reads a synced proof — returnsfalsewhen off, before any mock.falsewhen off, so they check the flag explicitly; otherwise they would refuse instead of allow.useProBadgeOnClickCb: when off, other users' badges show but never open a CTA; the contexts that only present our own Pro (edit-profile-pic,show-our-profile-dialog,character-count) are hidden.Testing
pro_gate_test.ts(4, each flag-off case with a flag-on control).devbase: 961 passing, 0 failing;tsc, ESLint, Prettier and commitlint clean.Appium results (2026-09-29, overnight)
Method: every failure was re-run on a pre-gate build (this branch's parent, built separately). Each build was probed for a literal only the gate adds, alongside a control literal present in both. "Gate-caused" means it fails with the gate, passes without it, and holds under an alternating tie-break on fresh devices.
Tested
201a2a1c7against pre-gated1fd7e424:Verdict: no gate-caused regression.
Since those runs: the revocation list is now also fetched while Pro is off (architect-approved), with clearing our own revoked proof still gated. Unit tests pass on the current head; a targeted Appium re-check of the revocation fetch and the badge is running.
Companion PRs
Same gate and rule on each client: session-foundation/session-ios#797 · session-foundation/session-android#2226 · #2018