PR #78 applies a tested redirect mitigation and explicitly enables only Stripe while retaining Pay 5. It does not complete the Pay major-version upgrade or change billing data. Track that work separately so a framework update cannot silently migrate payment records.
Follow the upstream upgrade guide through each applicable release:
- Add subscription billing-period, metered, and pause fields; backfill existing JSON values.
- Add payment-method and Stripe account fields and backfill existing records.
- Apply the STI conversion and rename the payment-method type field.
- Add the stored Stripe object columns and update Pay associations to the
pay_ names.
- Verify the selected Pay release's Stripe gem/API compatibility and webhook requirements, including
charge.updated.
Acceptance criteria:
- Choose a currently supported patched Pay release that resolves both CVE-2023-30614 and GHSA-mjgf-xj26-9qf9; verify current advisory ranges before selecting it.
- Rehearse migrations on an isolated database populated with representative legacy customers, subscriptions, charges, and payment methods. Check record counts, relationships, backfilled values, and an explicit rollback/recovery plan. Keep external synchronization out of schema migrations.
- Add request and job coverage for checkout, billing portal, trials, cancellation/resumption, payment authentication redirects, failed payments, and signed Stripe webhooks. Cover duplicate and out-of-order webhook delivery. Run all tests in SOLO and MULTIUSER modes without live billing calls.
- Preserve the explicitly Stripe-only routing configuration. Any future processor enablement needs its own verified-signature and route tests.
- Remove the Pay compatibility backports and both
.bundler-audit.yml exceptions only after the selected upstream version includes the fixes, protected-route regression tests pass, and an unignored dependency audit passes. Document any remaining compatibility constraints.
References: redirect advisory, Paddle signature advisory.
PR #78 applies a tested redirect mitigation and explicitly enables only Stripe while retaining Pay 5. It does not complete the Pay major-version upgrade or change billing data. Track that work separately so a framework update cannot silently migrate payment records.
Follow the upstream upgrade guide through each applicable release:
pay_names.charge.updated.Acceptance criteria:
.bundler-audit.ymlexceptions only after the selected upstream version includes the fixes, protected-route regression tests pass, and an unignored dependency audit passes. Document any remaining compatibility constraints.References: redirect advisory, Paddle signature advisory.