What is inside
Every file, and why it is there.
The tree
config/index.js every setting and the plan definitions
lib/db.js Postgres pool, query helpers, transactions, migrate
lib/schema.sql the whole schema, idempotent
lib/auth.js passwords, sessions, tokens, route guards
lib/billing.js payment API client, webhook signatures, license keys
lib/mail.js SMTP and the message templates
lib/http.js cookies, CSRF, rate limiting
lib/flash.js redirect messages, by code
routes/ public, auth, dashboard, billing, webhooks
views/ layout.js is the shell, pages.js is the pages
public/styles.css one stylesheet, light and dark
scripts/ migrate, check, smoke, mail:test
What the code looks like
This is the actual webhook handler, unedited. It is representative: short, commented where it matters, nothing clever.
// routes/webhooks.js — the only place a plan ever changes.
const valid = ls.verifyWebhook(raw, req.get('x-signature'));
if (!valid) return res.status(401).send('bad signature');
// Providers retry any non-2xx, so the same event WILL arrive twice.
// The primary key on webhook_events is what makes the second one a no-op.
const inserted = await db.one(
`insert into webhook_events (id, name, payload) values ($1, $2, $3)
on conflict (id) do nothing returning id`,
[eventId, eventName, payload]
);
if (!inserted) return res.status(200).send('duplicate');
Feature by feature
| Accounts | Sign up, log in, log out, email verification, password reset, change password, delete account |
|---|---|
| Sessions | Stored in Postgres, revocable individually or all at once, cleared on password change |
| Passwords | scrypt with OWASP parameters, constant-time comparison, no native dependency |
| Forms | Double-submit CSRF on every write, server-side validation, errors rendered back with the values kept |
| Abuse | Rate limits on login, signup and password reset. Identical answers for existing and missing accounts |
| Checkout | Hosted checkout created through the provider API, with the user id carried in custom data |
| Webhooks | Signature verified over the raw body, events stored for idempotency, eight event types handled |
| Subscriptions | Created, updated, resumed, cancelled, expired and payment-failed all mapped to plan state |
| Customer portal | One button: change card, download invoices, switch plan, cancel — hosted by the provider |
| Licenses | Validate, activate and deactivate license keys, for when you sell a download instead |
| Plan limits | Declared in config, enforced in routes, with a worked example you can copy |
| SMTP through any provider, plain-text-first templates, console fallback in development | |
| Ops | npm run check pre-flight, npm run smoke route test, /healthz, graceful shutdown |