Pro: restore the Session Pro gate, off by default - #2226
Open
mpretty-cyro wants to merge 1 commit into
Open
mpretty-cyro wants to merge 1 commit into
mpretty-cyro wants to merge 1 commit into
Conversation
Brings back the post-Pro-launch preference (pref_force_post_pro) removed in 0b751f7, now off by default in every build, with a `sessionPro` launch extra (the iOS key) so QA harnesses can turn it on. Off, this account can neither use nor buy Pro and nothing is restricted for lacking it; other people's Pro (badges, message features) is still honoured. One commit so it reverts cleanly. - Every self-facing guard 0b751f7 deleted, reapplied in the code's current shape. The logged-in Pro loops share one gate; turning it off cancels the status and proof workers, while the revocation list keeps polling for other people's proofs. Clearing our own revoked proof stays gated. - Recipients always get a Pro data context; only our own proof is skipped, so a proof synced from another device grants nothing here and is left in config. - Gates Pro code added since the removal: the display plan seeded from config, proof renewal scheduling and the proof worker, the access source (outgoing proof and declared features), the rotating-key signature, and the purchase-in-flight path. - The conversation list's pref-event filter regains SET_FORCE_POST_PRO with the `||` it was missing, so the two force-Pro events are no longer ignored.
mpretty-cyro
force-pushed
the
feature/restore-pro-gate
branch
from
September 28, 2026 21:02
645c00e to
580478f
Compare
mpretty-cyro
marked this pull request as ready for review
September 28, 2026 23:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Restores the Session Pro gate removed in 0b751f7 (#2150), off by default in every build while the Pro release is delayed (previously it defaulted on outside release builds).
Toggle: debug menu → Set app as post Pro launch, or the new
QaLaunchConfiglaunch extrasessionPro=true(debug/QA builds only; same key as iOS).What the gate does when off (the default)
Same rule on iOS, Android and Desktop. One commit per client so each reverts cleanly when Pro ships.
Implementation notes
ProStatusManagershare one gate; turning it off cancels the status and proof-generation workers. The revocation worker keeps polling, and clearing our own proof on revocation stays gated.currentUserProProofForAccess()returns nothing when off, which covers the outgoing proof, declared message features and compose-limit enforcement. The Pro rotating-key signature is also withheld.onPurchaseInFlightare gated.SET_FORCE_POST_PROwith the||the removed line was missing (without it the lambda only returned its last comparison).Testing
ProPreLaunchGateTest(6) andQaLaunchConfigSessionProTest(3); flag-off assertions have flag-on controls.:app:testPlayDebugUnitTeston the currentdevbase: 370 tests, 0 failures.Appium results (2026-09-29, overnight)
Method: every failure was re-run on a pre-gate build (this branch's parent, built separately). Each build was probed for a literal only the gate adds, alongside a control literal present in both. "Gate-caused" means it fails with the gate, passes without it, and holds under an alternating tie-break on fresh devices.
Tested
645c00e5bfagainst pre-gate16782ae45f, on API 37 emulators (about 30% noise on both builds):Verdict: no gate-caused regression; the Settings baseline diff is expected.
Since those runs: the revocation list is now also fetched while Pro is off (architect-approved), with clearing our own revoked proof still gated. Unit tests pass on the current head; a targeted Appium re-check of the revocation fetch and the badge is running.
Companion PRs
Same gate and rule on each client: session-foundation/session-ios#797 · #2226 · session-foundation/session-desktop#2018