mirror of
https://github.com/HeyPuter/puter.git
synced 2026-10-02 18:08:13 +00:00
Three related limits. Seats per team now depend on the owner's plan: 4 free, 40 paid, decided by `subscriptionSatisfies(id, true)` -- which is `!FREE_SUBSCRIPTION_IDS.has(id)`, so a plan an extension adds counts as paid without core knowing its name. The existing `max_seats_per_team` still overrides both, so a deployment that already set it keeps what it asked for, and `max_seats_per_team_free` / `_paid` tune each. An unreadable plan takes the smaller cap: over-provisioning a free team is the worse failure. A seat of a team that pays for nothing resolves `org_seat_free`, half the registered free plan. Without it a team is a way to mint free tiers -- provision four seats and each arrives with a full free allowance nobody paid for. The figures are derived from `REGISTERED_USER_FREE` rather than restated, so the two cannot drift, and the id joins `FREE_SUBSCRIPTION_IDS` because nobody paid for it either and it must not satisfy a plan gate. It is a *default* resolver, so a paid team tier -- which only prod knows about, through `registerSubscriptionResolver` -- still outranks it. The lookup is `getOrgSeat`, already cached with its negatives, because almost nothing is a seat. Found while testing: the suite was reading `max_seats_per_team` out of the developer's own config.json, so the cap under test was whatever that file said. It would have passed here and failed in CI, which has no such file. The suite now pins the value and the cap tests set their own. Falsified three ways, each breaking only its own test: equal caps fails "lets a paid owner past four"; a resolver returning null, and an unhalved allowance, both fail "resolves half the free plan". 186 team/whoami tests, 159 metering tests, typecheck clean.