feat: restrict agent profile access and search results to active, trialing, or past-due subscriptions
This commit is contained in:
@@ -155,6 +155,12 @@ export class AgentsService {
|
|||||||
return { ...profile, user: userWithoutPrefs };
|
return { ...profile, user: userWithoutPrefs };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Block access to non-paid agents (PAST_DUE included as grace period during Stripe retries)
|
||||||
|
const visibleStatuses = ['ACTIVE', 'TRIALING', 'PAST_DUE'];
|
||||||
|
if (!profile.subscriptionStatus || !visibleStatuses.includes(profile.subscriptionStatus)) {
|
||||||
|
throw new NotFoundException('Agent profile not found');
|
||||||
|
}
|
||||||
|
|
||||||
if (visibility === 'private') {
|
if (visibility === 'private') {
|
||||||
throw new ForbiddenException('This profile is not available');
|
throw new ForbiddenException('This profile is not available');
|
||||||
}
|
}
|
||||||
@@ -305,10 +311,12 @@ export class AgentsService {
|
|||||||
|
|
||||||
const skip = (page - 1) * limit;
|
const skip = (page - 1) * limit;
|
||||||
|
|
||||||
// Build where clause — only show active, admin-approved profiles in search
|
// Build where clause — only show active, admin-approved, paid subscribers in search
|
||||||
|
// PAST_DUE included as grace period (Stripe is retrying payment)
|
||||||
const where: Prisma.AgentProfileWhereInput = {
|
const where: Prisma.AgentProfileWhereInput = {
|
||||||
verificationStatus: 'APPROVED',
|
verificationStatus: 'APPROVED',
|
||||||
user: { status: 'ACTIVE' },
|
user: { status: 'ACTIVE' },
|
||||||
|
subscriptionStatus: { in: ['ACTIVE', 'TRIALING', 'PAST_DUE'] },
|
||||||
};
|
};
|
||||||
|
|
||||||
if (search) {
|
if (search) {
|
||||||
|
|||||||
Reference in New Issue
Block a user