Skip to content

fix(kit): sync store products end to end - #208

Merged
hyochan merged 3 commits into
mainfrom
codex/kit-product-sync
Jul 6, 2026
Merged

hyochan merged 3 commits into
mainfrom
codex/kit-product-sync

Conversation

@hyochan

@hyochan hyochan commented Jul 6, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Fix App Store Connect and Play Console product sync for create/update/delete flows.
  • Activate Play one-time purchase options, preserve consumable types on pull, and surface delete counts.
  • Add Petgu-based IAPKit E2E skill and clarify iOS-only metadata guidance in the products UI.

Verification

  • bun run typecheck
  • bun run test -- convex/products
  • bun run lint:eslint
  • pre-commit kit gate: install, lint, prettier, full kit tests, smoke server
  • Petgu App Store Connect / Play Console push-pull-delete sync verified with temporary SKUs

Notes

  • No preview recording: this is primarily sync/backend behavior. The visible UI change is a conditional iOS-only note on the Products form, verified locally.

Summary by CodeRabbit

  • New Features
    • Product sync now deletes upstream store products for rows marked Removed during push/both syncs, and reports deleted counts in job results.
    • Sync UI messaging and banners now clearly differentiate between standard syncs and purge-local runs.
  • Bug Fixes
    • Removed kit products are now preserved during pull syncs and won’t be unintentionally restored.
    • Android one-time product sync now better preserves kit-authored product types and improves pricing handling for edge cases.
  • Tests
    • Added coverage for ASC JWT issuer behavior and kit upsert state defaults.

@hyochan hyochan added kit IAPKit (receipt-validation SaaS) 🛠 bugfix All kinds of bug fixes 🤖 android Related to android 📱 iOS Related to iOS cross-platform Cross-platform (both Android & iOS) labels Jul 6, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces upstream product deletion capabilities for both App Store Connect and Google Play Console, allowing kit-authored 'Removed' products to be deleted from upstream stores during sync. It also adds support for individual App Store Connect API keys that omit an issuer ID, preserves kit-authored removals during pull-sync, and updates the UI and MCP tools to reflect these deletion flows. The review feedback identifies two critical issues in the Google Play sync implementation: the 'googleErrorStatus' helper fails to correctly extract HTTP status codes from 'gaxios' errors, which prevents proper detection of 404 errors, and the sync process incorrectly attempts to activate purchase options on legacy in-app products, which is unnecessary and likely to cause sync failures.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread packages/kit/convex/products/play.ts
Comment thread packages/kit/convex/products/play.ts
@coderabbitai

coderabbitai Bot commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@hyochan, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 40 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: f977ded6-b532-4838-97b9-cab3f907ca3e

📥 Commits

Reviewing files that changed from the base of the PR and between 9818763 and 87f445b.

📒 Files selected for processing (4)
  • .codex/skills/iapkit-e2e-petgu/SKILL.md
  • packages/kit/convex/products/asc.ts
  • packages/kit/convex/products/play.ts
  • packages/kit/convex/products/sync.ts
📝 Walkthrough

Walkthrough

This PR adds kit-authored product removal handling across sync flows, updates App Store Connect and Google Play product sync behavior, refreshes product UI/MCP wording, and adds a Codex Petgu E2E skill with agent config.

Changes

Product removal and store sync changes

Layer / File(s) Summary
Product state and origin tracking
packages/kit/convex/products/mutation.ts, mutation.test.ts
Adds nextStateForKitProductUpsert defaulting to "Draft" and marks state/removal patches with origin: "kit".
Pull-sync preservation and removed-product queries
packages/kit/convex/products/sync.ts, sync.test.ts
Adds shouldPreserveKitRemovedDuringPull, product-type lookup queries, and removed-row listing/deletion support.
ASC client credentials and v2 endpoint migration
packages/kit/convex/products/asc.ts, jwt.ts, jwt.test.ts
Makes issuerId optional, updates JWT claim handling, adds conflict classification, and migrates IAP endpoints to /v2/.
ASC pricing schedule and localization upserts
packages/kit/convex/products/asc.ts
Adds conditional price updates plus patch-or-create localization handling for IAP and subscriptions.
ASC push-removals phase and result counters
packages/kit/convex/products/asc.ts, schema.ts
Adds push-removals deletion flow and persists/labels the deleted count.
Play helper functions for upsert/delete/money conversion
packages/kit/convex/products/play.ts
Adds Google error classification, one-time upsert/delete orchestration helpers, and money conversion.
Play sync push/pull wiring using new helpers
packages/kit/convex/products/play.ts
Wires removed-row deletion, deleted counting, one-time upserts, and type preservation during pull.
Dashboard UI and MCP tool description updates
packages/kit/src/pages/.../products.tsx, packages/mcp-server/src/mcp.ts
Updates sync copy, dry-run messaging, banners/toasts, and MCP tool descriptions to match removal behavior.

Codex E2E skill documentation

Layer / File(s) Summary
Skill documentation and agent config
.codex/skills/iapkit-e2e-petgu/SKILL.md, .codex/skills/iapkit-e2e-petgu/agents/openai.yaml
Adds the Petgu E2E skill guidance, safety rules, workflow, and agent interface config.

Estimated code review effort: 4 (Complex) | ~60 minutes

Possibly related PRs

  • hyodotdev/openiap#127: Shares the product-sync job/result flow that this PR extends with removed-row deletion and deleted counts.
  • hyodotdev/openiap#128: Also changes the Products page sync completion messaging in the same UI area.
  • hyodotdev/openiap#168: Also updates MCP tool descriptions in packages/mcp-server/src/mcp.ts.

Suggested labels: 🎯 feature, 📖 documentation

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly reflects the main change: end-to-end sync handling for store products in the kit package.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/kit-product-sync

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces upstream product and subscription deletion capabilities for both App Store Connect (iOS) and Google Play Console (Android) during push/both sync directions, while preserving kit-authored 'Removed' rows during pull-sync to prevent premature resurrection. It also adds support for individual App Store Connect API keys (which omit the issuer ID), moves edited products back to 'Draft' state to queue them for a sync push, and introduces a Codex skill for Petgu E2E testing. The review feedback highlights several critical issues: a potential failure in the Google Play legacy fallback path due to an unnecessary purchase option activation, an incorrect HTTP status check for Google API errors that breaks 404 detection, a redundant conditional check in the App Store Connect credential resolver, and an N+1 query pattern in the Android pull-sync loop that should be optimized to avoid sequential database round-trips.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread packages/kit/convex/products/play.ts Outdated
Comment thread packages/kit/convex/products/play.ts
Comment thread packages/kit/convex/products/asc.ts Outdated
Comment thread packages/kit/convex/products/play.ts Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/kit/convex/products/asc.ts (1)

566-644: 🗄️ Data Integrity & Integration | 🔴 Critical | 🏗️ Heavy lift

Use the subscription price change endpoint here, not PATCH on the subscription. Apple’s pricing flow is per-territory; sending a single USA prices entry through the subscription relationship risks replacing the full schedule and dropping the other territories. Switch this path back to per-territory POST /v1/subscriptionPrices updates.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/kit/convex/products/asc.ts` around lines 566 - 644, The pricing
update in setSubPriceSchedule is using a PATCH to the subscription with a single
USA prices relationship, which can overwrite the full schedule. Update this flow
to use the per-territory subscription price change path by routing through
createSubPriceChange and posting to /v1/subscriptionPrices, keeping the existing
attributes, subscriptionPricePoint, and territory wiring intact.
🧹 Nitpick comments (2)
.codex/skills/iapkit-e2e-petgu/SKILL.md (1)

14-24: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Make the default paths portable.

These references are pinned to one home directory, so anyone with a different checkout layout will need to edit the skill. Prefer repo-relative paths or environment variables for the repo, Petgu checkout, and rule files.

Also applies to: 41-43

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.codex/skills/iapkit-e2e-petgu/SKILL.md around lines 14 - 24, The hardcoded
absolute paths and local-only URLs in SKILL.md make the default setup
non-portable. Update the IAPKit E2E skill references to use repo-relative paths
or environment-based placeholders for the OpenIAP repo, Kit package, Petgu
checkout, and rule files, and keep the identifying labels like "OpenIAP repo",
"Kit package", and "Petgu app" so the targets remain clear without a specific
home directory.
packages/kit/convex/products/sync.ts (1)

454-533: 🗄️ Data Integrity & Integration | 🔵 Trivial | 💤 Low value

deleteRemovedProductRow doesn't re-check origin/storeRef, relying entirely on callers pre-filtering.

The delete guard only checks existing.state === "Removed" — it doesn't re-verify the origin === "kit" || storeRef === undefined condition that removedProductsForPush uses to select candidates. In the current wiring this is safe because the only callers are expected to pass ids sourced from listRemovedIosProducts/listRemovedAndroidProducts, but as a standalone internal mutation it would happily delete a store-authored Removed row (e.g. one pulled with origin: "store") if ever invoked with such an id directly.

🛡️ Optional defensive check
-    if (!existing || existing.state !== "Removed") return false;
+    if (
+      !existing ||
+      existing.state !== "Removed" ||
+      !(existing.origin === "kit" || existing.storeRef === undefined)
+    ) {
+      return false;
+    }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/kit/convex/products/sync.ts` around lines 454 - 533, The delete
guard in deleteRemovedProductRow only checks that the row is Removed, so it can
still delete store-authored removed rows if called directly. Update the handler
to re-apply the same eligibility check used by removedProductsForPush, namely
origin === "kit" || storeRef === undefined, before deleting. Keep the logic
aligned with listRemovedIosProducts and listRemovedAndroidProducts so the
mutation remains safe even when invoked outside those query paths.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/kit/convex/products/play.ts`:
- Around line 1116-1153: The delete flow in play.ts is swallowing failures from
the modern one-time product endpoint. In the
deleteModernAndroidOneTimeProduct/onetime.delete path, keep the existing 404
handling for Google not-found errors, but re-throw any other error instead of
falling back to androidpublisher.inappproducts.delete; only use the legacy
fallback when the modern endpoint is truly unavailable or returns not-found.
This preserves errors from monetization.onetimeproducts.delete and prevents
masking auth/transient failures.

---

Outside diff comments:
In `@packages/kit/convex/products/asc.ts`:
- Around line 566-644: The pricing update in setSubPriceSchedule is using a
PATCH to the subscription with a single USA prices relationship, which can
overwrite the full schedule. Update this flow to use the per-territory
subscription price change path by routing through createSubPriceChange and
posting to /v1/subscriptionPrices, keeping the existing attributes,
subscriptionPricePoint, and territory wiring intact.

---

Nitpick comments:
In @.codex/skills/iapkit-e2e-petgu/SKILL.md:
- Around line 14-24: The hardcoded absolute paths and local-only URLs in
SKILL.md make the default setup non-portable. Update the IAPKit E2E skill
references to use repo-relative paths or environment-based placeholders for the
OpenIAP repo, Kit package, Petgu checkout, and rule files, and keep the
identifying labels like "OpenIAP repo", "Kit package", and "Petgu app" so the
targets remain clear without a specific home directory.

In `@packages/kit/convex/products/sync.ts`:
- Around line 454-533: The delete guard in deleteRemovedProductRow only checks
that the row is Removed, so it can still delete store-authored removed rows if
called directly. Update the handler to re-apply the same eligibility check used
by removedProductsForPush, namely origin === "kit" || storeRef === undefined,
before deleting. Keep the logic aligned with listRemovedIosProducts and
listRemovedAndroidProducts so the mutation remains safe even when invoked
outside those query paths.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 273479a5-418f-43be-a844-0cd134046a69

📥 Commits

Reviewing files that changed from the base of the PR and between 3297efb and d201ad9.

📒 Files selected for processing (13)
  • .codex/skills/iapkit-e2e-petgu/SKILL.md
  • .codex/skills/iapkit-e2e-petgu/agents/openai.yaml
  • packages/kit/convex/products/asc.ts
  • packages/kit/convex/products/jwt.test.ts
  • packages/kit/convex/products/jwt.ts
  • packages/kit/convex/products/mutation.test.ts
  • packages/kit/convex/products/mutation.ts
  • packages/kit/convex/products/play.ts
  • packages/kit/convex/products/sync.test.ts
  • packages/kit/convex/products/sync.ts
  • packages/kit/convex/schema.ts
  • packages/kit/src/pages/auth/organization/project/products.tsx
  • packages/mcp-server/src/mcp.ts

Comment thread packages/kit/convex/products/play.ts

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces support for upstream product and subscription deletion in both App Store Connect (iOS) and Google Play Console (Android) during product sync. Key changes include updating App Store Connect API integrations to use v2 endpoints, supporting individual API keys (omitting issuer ID) in JWT generation, and implementing robust deletion flows that prevent pull-sync from resurrecting kit-deleted products before they are deleted upstream. Additionally, it adds a new Codex skill for E2E testing with the Petgu app, introduces modern Google Play one-time product management with legacy fallbacks, and updates the dashboard UI to reflect deletion states and constraints. I have no feedback to provide on these changes.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@hyochan

hyochan commented Jul 6, 2026

Copy link
Copy Markdown
Member Author

Addressed the latest CodeRabbit follow-ups in 87f445b.\n\nChanges:\n- setSubPriceSchedule now routes through /v1/subscriptionPrices.\n- modern Play one-time delete no longer masks non-404 errors.\n- deleteRemovedProductRow re-checks kit-authored removal eligibility.\n- IAPKit Petgu E2E skill paths now use environment placeholders.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

Gemini encountered an error creating the review. You can try again by commenting /gemini review.

@hyodotdev hyodotdev deleted a comment from coderabbitai Bot Jul 6, 2026
@hyodotdev hyodotdev deleted a comment from coderabbitai Bot Jul 6, 2026
@hyodotdev hyodotdev deleted a comment from coderabbitai Bot Jul 6, 2026
@hyochan
hyochan merged commit df8bc7f into main Jul 6, 2026
11 checks passed
@hyochan
hyochan deleted the codex/kit-product-sync branch July 6, 2026 18:14
@coderabbitai coderabbitai Bot mentioned this pull request Aug 13, 2026
7 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🤖 android Related to android 🛠 bugfix All kinds of bug fixes cross-platform Cross-platform (both Android & iOS) 📱 iOS Related to iOS kit IAPKit (receipt-validation SaaS)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant