Tags

Tags give the ability to mark specific points in history as being important
  • 1.0.0-beta6

    Subscription Manager 1.0.0-beta6
    
    Phase 3 of the stable-release roadmap (#3616939): features.
    
    - #3618739: Charge-based connector mode with a local billing cycle
      engine. New subscription_charge entity (one record per period, the
      idempotency key), monthly/yearly cycles with month-end day clamping,
      immediate prorated upgrades, downgrades at the anchor, refunds, and
      configurable zero-amount period records. Connectors declare
      supported_modes; charge-based ones implement
      ChargeBasedConnectorInterface.
    - #3616769: Connector chooser in the subscribe flow when multiple
      connectors offer visible plans, with configurable order and
      per-connector label/description overrides (restricted HTML allowed).
      The default_connector setting is replaced by the chooser_connectors
      sequence: the first installed entry is the default and recommended
      connector (update 10019 migrates existing sites). The subscribe-url
      API gains an additive multi-connector response shape.
    - #3615735: Usage rating seam. Sites implement UsageRaterInterface as
      tagged services; the cycle engine bills rated usage in arrears
      alongside the advance base fee and records the lines on the charge.
    - #3618741: Tax/invoice seam. TaxInvoiceServiceInterface (calculate,
      recordCharge, recordRefund) with a null default; bridges replace the
      service to plug in a real tax engine. Charges gain an
      invoice_reference field; exclusive tax is added to charges, inclusive
      tax recorded; refunds produce credit-note references.
    - #3621282: Subscriber billing-history page at
      /user/{user}/billing-history with invoice link-outs, plus an
      account-menu link.
    
    Also: default admin views for all three entities, Views data for
    subscription charges, and charge failure records now preserve the rated
    and tax line audit trail.
    
    Contains updates 10015-10020. Change records:
    https://www.drupal.org/list-changes/subscription_manager
  • 1.0.0-beta5

    1.0.0-beta5
    
    Multi-connector correctness release (roadmap Phase 2, #3616939): the
    structural work that makes several connectors running side by side safe.
    
    - One active subscription per user, site-wide, enforced at save time: the
      newest activation deactivates any other active subscription, revoking its
      snapshotted roles (#3616778; see the change record). Local subscription
      selection is now deterministic — active first, then newest — instead of
      storage order, and the "has a subscription" checks gained an active_only
      parameter, which the post-login subscribe redirect now uses so lapsed
      subscribers are redirected again.
    - The self-healing remote sync consults every installed connector (default
      first) instead of only default_connector, stopping at the first that
      yields; one provider's outage no longer blocks reconciliation against the
      others (#3616770; see the change record).
    - The remote-sync reconciliation moved into
      SubscriptionManagerService::syncRemoteSubscriptions(), and the hand-rolled
      cron drain became a QueueWorker plugin with core's per-item retry
      handling, fixing the poison-item stall that let one failing queue item
      block the whole queue (#3616880).
    - Plan lookups are scoped by the subscription's connector, so two connectors
      sharing a remote plan_id can no longer grant each other's roles or link
      the wrong plan (#3616776).
    - The post-login subscribe redirect polls every installed connector and
      redirects only on unanimity: any connector can veto ("this user is
      mid-flow with me"), broken connectors abstain, and login can no longer
      fatal on an unconfigured default connector (#3616773; see the change
      record).
    - Kernel test suite grown from 42 to 62 tests.
  • 1.0.0-beta4

    1.0.0-beta4
    
    Access-control, hardening and compatibility release (roadmap Phase 1, #3616939):
    - CRITICAL: role revocation now works from a granted_roles snapshot recorded at
      grant time, never a live plan lookup, so a deleted or renamed plan can no
      longer leave users with paid access indefinitely (#3616929; update 10014
      installs and backfills the field; change record:
      https://www.drupal.org/node/3620566).
    - Admin collections, settings forms and Field UI now use the defined
      administer subscriptions / administer subscription plans permissions instead
      of four never-defined strings that locked them to user 1 (#3616930).
    - Fresh installs no longer fatal on the subscribe paths when default_connector
      is unset: a single installed connector is inferred as the default, pages
      redirect with a friendly message, and the subscribe-url/portal-url APIs
      return a documented 503 error shape (#3616932). The settings form's
      connector select is required and config/install ships every schema key.
    - Drupal 12 compatibility: hooks converted to a #[Hook] attribute class with
      injected services; connector plugins are discovered by PHP attribute with
      the annotation still supported; core_version_requirement fixed to
      ^10 || ^11 (#3603421). The || ^12 flip follows once tested against
      Drupal 12 betas.
    - Kernel test suite grown from 27 to 42 tests.
  • 1.0.0-beta3

    1.0.0-beta3
    
    Bug-fix, hardening and performance release:
    - Hardened post-purchase token validation: tokens are now bound to the order's
      verified email as well as the order id and expiry. API change —
      PostPurchaseTokenService::createToken() and ::verifyToken() each take a
      required $email argument.
    - Performance: anonymous page requests no longer load the anonymous user account
      to check for a subscription.
    - Performance: one subscription lookup per request instead of two (memoized,
      cleared on any subscription write).
    - Performance: new refresh-throttle service caps how often a subscription's
      remote billing state is refreshed on the render path.
    - Role sync for a subscription whose remote plan has no local plan entity now
      logs at WARNING instead of ERROR.
    - subscription_manager:list-connectors no longer errors when no connectors are
      installed.
    - Consolidated the duplicate "My Membership" account-menu links into one and
      sorted it to the top of the account menu.
    - New update 10013 backfills entitlement roles for active subscribers missing a
      role granted by their active plan (additive and idempotent).
  • 1.0.0-beta2

    1.0.0-beta2
    
    Security and bug-fix release:
    - Security: close IDOR in /user/{user}/manage-subscription (subscription ownership now enforced)
    - Security: unforgeable HMAC-signed post-purchase auto-login tokens
    - Performance: defer remote billing sync off the login path
    - Resolve deploy-review findings from the contrib decoupling refactor
  • 1.0.0-beta1

    subscription_manager 1.0.0-beta1 — first beta release