The Magic

What is inside

Every file, and why it is there.

The tree

config/index.js       every setting and the plan definitions
lib/db.js             Postgres pool, query helpers, transactions, migrate
lib/schema.sql        the whole schema, idempotent
lib/auth.js           passwords, sessions, tokens, route guards
lib/billing.js        payment API client, webhook signatures, license keys
lib/mail.js           SMTP and the message templates
lib/http.js           cookies, CSRF, rate limiting
lib/flash.js          redirect messages, by code
routes/               public, auth, dashboard, billing, webhooks
views/                layout.js is the shell, pages.js is the pages
public/styles.css     one stylesheet, light and dark
scripts/              migrate, check, smoke, mail:test

What the code looks like

This is the actual webhook handler, unedited. It is representative: short, commented where it matters, nothing clever.

// routes/webhooks.js — the only place a plan ever changes.
const valid = ls.verifyWebhook(raw, req.get('x-signature'));
if (!valid) return res.status(401).send('bad signature');

// Providers retry any non-2xx, so the same event WILL arrive twice.
// The primary key on webhook_events is what makes the second one a no-op.
const inserted = await db.one(
  `insert into webhook_events (id, name, payload) values ($1, $2, $3)
    on conflict (id) do nothing returning id`,
  [eventId, eventName, payload]
);
if (!inserted) return res.status(200).send('duplicate');

Feature by feature

AccountsSign up, log in, log out, email verification, password reset, change password, delete account
SessionsStored in Postgres, revocable individually or all at once, cleared on password change
Passwordsscrypt with OWASP parameters, constant-time comparison, no native dependency
FormsDouble-submit CSRF on every write, server-side validation, errors rendered back with the values kept
AbuseRate limits on login, signup and password reset. Identical answers for existing and missing accounts
CheckoutHosted checkout created through the provider API, with the user id carried in custom data
WebhooksSignature verified over the raw body, events stored for idempotency, eight event types handled
SubscriptionsCreated, updated, resumed, cancelled, expired and payment-failed all mapped to plan state
Customer portalOne button: change card, download invoices, switch plan, cancel — hosted by the provider
LicensesValidate, activate and deactivate license keys, for when you sell a download instead
Plan limitsDeclared in config, enforced in routes, with a worked example you can copy
EmailSMTP through any provider, plain-text-first templates, console fallback in development
Opsnpm run check pre-flight, npm run smoke route test, /healthz, graceful shutdown

Get it