Tags give the ability to mark specific points in history as being important
-
1.0.0-beta6
29469692 · ·Subscription Manager 1.0.0-beta6 Phase 3 of the stable-release roadmap (#3616939): features. - #3618739: Charge-based connector mode with a local billing cycle engine. New subscription_charge entity (one record per period, the idempotency key), monthly/yearly cycles with month-end day clamping, immediate prorated upgrades, downgrades at the anchor, refunds, and configurable zero-amount period records. Connectors declare supported_modes; charge-based ones implement ChargeBasedConnectorInterface. - #3616769: Connector chooser in the subscribe flow when multiple connectors offer visible plans, with configurable order and per-connector label/description overrides (restricted HTML allowed). The default_connector setting is replaced by the chooser_connectors sequence: the first installed entry is the default and recommended connector (update 10019 migrates existing sites). The subscribe-url API gains an additive multi-connector response shape. - #3615735: Usage rating seam. Sites implement UsageRaterInterface as tagged services; the cycle engine bills rated usage in arrears alongside the advance base fee and records the lines on the charge. - #3618741: Tax/invoice seam. TaxInvoiceServiceInterface (calculate, recordCharge, recordRefund) with a null default; bridges replace the service to plug in a real tax engine. Charges gain an invoice_reference field; exclusive tax is added to charges, inclusive tax recorded; refunds produce credit-note references. - #3621282: Subscriber billing-history page at /user/{user}/billing-history with invoice link-outs, plus an account-menu link. Also: default admin views for all three entities, Views data for subscription charges, and charge failure records now preserve the rated and tax line audit trail. Contains updates 10015-10020. Change records: https://www.drupal.org/list-changes/subscription_manager -
1.0.0-beta5
42fbec41 · ·1.0.0-beta5 Multi-connector correctness release (roadmap Phase 2, #3616939): the structural work that makes several connectors running side by side safe. - One active subscription per user, site-wide, enforced at save time: the newest activation deactivates any other active subscription, revoking its snapshotted roles (#3616778; see the change record). Local subscription selection is now deterministic — active first, then newest — instead of storage order, and the "has a subscription" checks gained an active_only parameter, which the post-login subscribe redirect now uses so lapsed subscribers are redirected again. - The self-healing remote sync consults every installed connector (default first) instead of only default_connector, stopping at the first that yields; one provider's outage no longer blocks reconciliation against the others (#3616770; see the change record). - The remote-sync reconciliation moved into SubscriptionManagerService::syncRemoteSubscriptions(), and the hand-rolled cron drain became a QueueWorker plugin with core's per-item retry handling, fixing the poison-item stall that let one failing queue item block the whole queue (#3616880). - Plan lookups are scoped by the subscription's connector, so two connectors sharing a remote plan_id can no longer grant each other's roles or link the wrong plan (#3616776). - The post-login subscribe redirect polls every installed connector and redirects only on unanimity: any connector can veto ("this user is mid-flow with me"), broken connectors abstain, and login can no longer fatal on an unconfigured default connector (#3616773; see the change record). - Kernel test suite grown from 42 to 62 tests. -
1.0.0-beta4
8ad186fb · ·1.0.0-beta4 Access-control, hardening and compatibility release (roadmap Phase 1, #3616939): - CRITICAL: role revocation now works from a granted_roles snapshot recorded at grant time, never a live plan lookup, so a deleted or renamed plan can no longer leave users with paid access indefinitely (#3616929; update 10014 installs and backfills the field; change record: https://www.drupal.org/node/3620566). - Admin collections, settings forms and Field UI now use the defined administer subscriptions / administer subscription plans permissions instead of four never-defined strings that locked them to user 1 (#3616930). - Fresh installs no longer fatal on the subscribe paths when default_connector is unset: a single installed connector is inferred as the default, pages redirect with a friendly message, and the subscribe-url/portal-url APIs return a documented 503 error shape (#3616932). The settings form's connector select is required and config/install ships every schema key. - Drupal 12 compatibility: hooks converted to a #[Hook] attribute class with injected services; connector plugins are discovered by PHP attribute with the annotation still supported; core_version_requirement fixed to ^10 || ^11 (#3603421). The || ^12 flip follows once tested against Drupal 12 betas. - Kernel test suite grown from 27 to 42 tests.
-
1.0.0-beta3
adbf17f6 · ·1.0.0-beta3 Bug-fix, hardening and performance release: - Hardened post-purchase token validation: tokens are now bound to the order's verified email as well as the order id and expiry. API change — PostPurchaseTokenService::createToken() and ::verifyToken() each take a required $email argument. - Performance: anonymous page requests no longer load the anonymous user account to check for a subscription. - Performance: one subscription lookup per request instead of two (memoized, cleared on any subscription write). - Performance: new refresh-throttle service caps how often a subscription's remote billing state is refreshed on the render path. - Role sync for a subscription whose remote plan has no local plan entity now logs at WARNING instead of ERROR. - subscription_manager:list-connectors no longer errors when no connectors are installed. - Consolidated the duplicate "My Membership" account-menu links into one and sorted it to the top of the account menu. - New update 10013 backfills entitlement roles for active subscribers missing a role granted by their active plan (additive and idempotent).
-
1.0.0-beta2
c892bf17 · ·1.0.0-beta2 Security and bug-fix release: - Security: close IDOR in /user/{user}/manage-subscription (subscription ownership now enforced) - Security: unforgeable HMAC-signed post-purchase auto-login tokens - Performance: defer remote billing sync off the login path - Resolve deploy-review findings from the contrib decoupling refactor