feat: restrict agent profile access and search results to active, trialing, or past-due subscriptions

This commit is contained in:
pradeepkumar
2026-04-07 15:53:48 +05:30
parent 35b85c1cc0
commit 590b4efe9d

View File

@@ -155,6 +155,12 @@ export class AgentsService {
return { ...profile, user: userWithoutPrefs }; return { ...profile, user: userWithoutPrefs };
} }
// Block access to non-paid agents (PAST_DUE included as grace period during Stripe retries)
const visibleStatuses = ['ACTIVE', 'TRIALING', 'PAST_DUE'];
if (!profile.subscriptionStatus || !visibleStatuses.includes(profile.subscriptionStatus)) {
throw new NotFoundException('Agent profile not found');
}
if (visibility === 'private') { if (visibility === 'private') {
throw new ForbiddenException('This profile is not available'); throw new ForbiddenException('This profile is not available');
} }
@@ -305,10 +311,12 @@ export class AgentsService {
const skip = (page - 1) * limit; const skip = (page - 1) * limit;
// Build where clause — only show active, admin-approved profiles in search // Build where clause — only show active, admin-approved, paid subscribers in search
// PAST_DUE included as grace period (Stripe is retrying payment)
const where: Prisma.AgentProfileWhereInput = { const where: Prisma.AgentProfileWhereInput = {
verificationStatus: 'APPROVED', verificationStatus: 'APPROVED',
user: { status: 'ACTIVE' }, user: { status: 'ACTIVE' },
subscriptionStatus: { in: ['ACTIVE', 'TRIALING', 'PAST_DUE'] },
}; };
if (search) { if (search) {