You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This issue evaluates and, if justified, adds a public read-only preview for the PayStream-owned plan validation used by subscribe().
The preview can confirm that a plan exists and currently accepts subscriptions. It must not be represented as proof that the later authenticated subscribe() transaction will succeed.
Blocked by #44: follow its final naming, shared-validation, result-shape, public-read, and RPC-simulation conventions.
or a dedicated struct containing only merged, stable terms relevant to consent. If #28 plan versioning is merged, include the exact resolved plan ID/version and do not allow the preview to imply that a group alias cannot change before execution.
Shared validation
Extract the deterministic plan-eligibility checks into one internal helper used by both subscribe() and the preview.
The helper must:
load the plan or return PlanNotFound;
reject inactive plans with PlanInactive;
return the validated concrete plan needed by subscribe();
perform no authorization, token call, or storage mutation.
Keep subscriber authorization in the real subscribe() path. The preview intentionally has no require_auth() because it only reads public plan eligibility.
The refactor must not change real subscription behavior, authorization, ID allocation, due-time calculation, allowance state, trial behavior, or storage writes.
RPC simulation comparison
Document how the explicit preview differs from Soroban RPC simulation of the real subscribe() operation.
Confirm behavior using the pinned SDK/toolchain rather than assuming that a prospective user must pay a fee simply to simulate. Explain:
RPC simulation can execute the actual contract path and produce authorization requirements without submitting a transaction;
a contract preview may offer a smaller/richer public read response;
preview results can become stale;
successful preview does not guarantee successful authenticated execution.
Public data
Document that no authorization is required and anyone may query:
whether a plan exists and is active;
any plan terms returned by the preview;
resolved plan/version identifiers where applicable.
Do not return private or subscriber-specific information.
Suggested Execution
Branch name:feat/simulate-subscribe-preview
Files to touch:
src/lib.rs — shared plan validation and optional preview API
src/test.rs — parity, public-read, zero-mutation, and regression tests
docs/ARCHITECTURE.md — API purpose, no-auth decision, return shape, and RPC comparison
Example commit message:feat(core): add subscription eligibility preview with shared validation
Description
This issue evaluates and, if justified, adds a public read-only preview for the PayStream-owned plan validation used by
subscribe().The preview can confirm that a plan exists and currently accepts subscriptions. It must not be represented as proof that the later authenticated
subscribe()transaction will succeed.Blocked by #44: follow its final naming, shared-validation, result-shape, public-read, and RPC-simulation conventions.
Requirements and Context
The proposed API is:
However, this signature receives neither
subscribernorallowance. It therefore cannot validate the complete real subscription path, including:The PR must define this honestly as a plan-eligibility preview, not an exact subscription simulation.
API value and naming
Evaluate overlap with the existing public
get_plan(plan_id), which already returns plan terms without authorization.Choose and justify one approach:
No new API
get_plan()plus client-sideactivechecking provides the same reliable value, document that conclusion and avoid unnecessary ABI surface.Validated plan preview
preview_subscribeorget_subscribable_plan.Requested
simulate_subscribeAPIA useful result may be:
or a dedicated struct containing only merged, stable terms relevant to consent. If #28 plan versioning is merged, include the exact resolved plan ID/version and do not allow the preview to imply that a group alias cannot change before execution.
Shared validation
Extract the deterministic plan-eligibility checks into one internal helper used by both
subscribe()and the preview.The helper must:
PlanNotFound;PlanInactive;subscribe();Keep subscriber authorization in the real
subscribe()path. The preview intentionally has norequire_auth()because it only reads public plan eligibility.The refactor must not change real subscription behavior, authorization, ID allocation, due-time calculation, allowance state, trial behavior, or storage writes.
RPC simulation comparison
Document how the explicit preview differs from Soroban RPC simulation of the real
subscribe()operation.Confirm behavior using the pinned SDK/toolchain rather than assuming that a prospective user must pay a fee simply to simulate. Explain:
Public data
Document that no authorization is required and anyone may query:
Do not return private or subscriber-specific information.
Suggested Execution
feat/simulate-subscribe-previewsrc/lib.rs— shared plan validation and optional preview APIsrc/test.rs— parity, public-read, zero-mutation, and regression testsdocs/ARCHITECTURE.md— API purpose, no-auth decision, return shape, and RPC comparisonfeat(core): add subscription eligibility preview with shared validationTest and Commit Steps
get_plan()and document why new ABI surface is or is not justified.subscribe()before refactoring.PlanNotFound;PlanInactive;subscribe()still requires subscriber authorization;crate-type = ["rlib"]on Windows if required:crate-type = ["cdylib", "rlib"]and build:Guidelines
Closes #<issue-number>.get_plan()without a demonstrated benefit.subscribe()authorization unchanged.27.0.3.Complexity
High (200 pts)