docs: distribution route decided — Microsoft Store MSIX + Store IAP
Creator ruling 2026-09-27. Criteria, verbatim: "zero headaches, minimal maintenance (for me) while still providing accountability and a reasonably easy upgrade flow." Route A is the only combination where all four are solved by handing the work to Microsoft rather than to a certificate vendor: $0/yr, no certificate, no HSM, no annual renewal, no SmartScreen ramp — plus Store auto-update, Store-side payments/entitlements/refunds/support, and Microsoft review as the accountability layer. The rejected options and their reasons stay in research-store-certification.md §3 so a later session reads the ruling instead of re-deriving it. What this deletes: - The entire licensing backend. PolarLicenseService, PolarLicense, MainViewModel.License.cs (PremiumUrl, customer portal, the OfflineGracePeriod = 14 days subscription-era artifact, renewal/lapse copy) and the wrong "Polar unlocks alerts" string all become dead code. IsPremium is derived from the Store entitlement instead of an HTTP call, which also removes the whole "network flaky -> app thinks I'm expired" bug class. - Velopack, the update URL, and the self-hosted droplet — the Store updates. - Distribution.md's premise: Polar as the distribution backbone, Polar file hosting, and code signing as our problem. The IP-protection sections (1, 5, 6, 7) still stand and the build-posture ceiling is unchanged. What does NOT change: the entitlement. Free gets everything; the branding flash stays the only paid delta. Store IAP changes how IsPremium is obtained, never what it gates. Still open, deliberately: the price. The Store revenue share is unverified (do not assume a percentage), and MONETIZATION.md's $29 -> $49 one-time decision is re-opened against a fresh instinct toward ~$99/yr. No price encoded yet. The first code unit is unchanged: bundle ffmpeg (TASK 48 item 1). That clears the one hard certification gate and fixes a real user-facing 404. MARCOM.md and MONETIZATION.md were edited too but are gitignored by design, so those changes stayed local.
This commit is contained in:
@@ -14,13 +14,18 @@
|
||||
|
||||
## 1. Bottom line
|
||||
|
||||
**✅ ROUTE DECIDED 2026-09-27 — the creator chose route A: Microsoft Store, MSIX package,
|
||||
Store IAP.** The research below is what the decision was made from, and it stays as the
|
||||
audit trail so the choice is never re-litigated. The executable checklist is
|
||||
`TASKS/task-48-distribution-msix.md`; the ruling and the criteria behind it are in that
|
||||
file's item 0.
|
||||
|
||||
**MSIX packaging is viable.** One real blocker, and it is a code change we should want
|
||||
anyway (§4). Three technical blockers that normally kill a Store submission — drivers,
|
||||
per-user services, elevation — we **do not trip** (§7).
|
||||
|
||||
**The decision is NOT made.** The route is open; this file records the options and their
|
||||
costs so the decision can be made from a clear page. `Distribution.md` holds the older
|
||||
plan and contains **one factually dead claim** — see §2.
|
||||
**Nothing else is open on distribution.** The only number still unverified is the Store
|
||||
revenue-share rate (§11 item 4), which is a *pricing* input, not a distribution one.
|
||||
|
||||
---
|
||||
|
||||
@@ -74,20 +79,28 @@ Also worth knowing before budgeting:
|
||||
| **C** | Polar file hosting | Polar | $150–300/yr | no |
|
||||
| **D** | Store EXE (10.2.9) | Polar | $150–300/yr | no |
|
||||
|
||||
**✅ A was chosen (2026-09-27)** — the creator's criteria were "zero headaches, minimal
|
||||
maintenance (for me) while still providing accountability and a reasonably easy upgrade
|
||||
flow," and A is the only option where *every* one of those is solved by handing the work to
|
||||
Microsoft rather than to a certificate vendor. The rest of this section stays as the record
|
||||
of what was rejected and why, so the decision is not reopened by a later session that
|
||||
remembers only that "certs cost $150/yr."
|
||||
|
||||
**A** is the only one where Polar becomes unnecessary — the Store handles payment,
|
||||
entitlement, and refunds, and you would delete `PolarLicenseService` and the
|
||||
customer-portal plumbing. That is a *distribution* choice that happens to subsume
|
||||
licensing.
|
||||
entitlement, and refunds, and `PolarLicenseService` and the customer-portal plumbing are
|
||||
deleted. That is a *distribution* choice that happens to subsume licensing.
|
||||
|
||||
**B** is the compromise worth serious consideration: the Store solves the SmartScreen
|
||||
problem and the annual cert bill while Polar stays the licensing system and we keep 100%
|
||||
of revenue. Cost is two systems to maintain.
|
||||
**B** is the compromise that was **not** taken: the Store would have solved the SmartScreen
|
||||
problem and the annual cert bill while Polar stayed the licensing system. Rejected because
|
||||
it keeps a licensing backend, a customer portal, activation limits, and an offline-grace
|
||||
machine alive — the exact maintenance the ruling was made to eliminate.
|
||||
|
||||
**C** is the status quo already sketched in `Distribution.md:14` / `:296` — Polar hosts the
|
||||
signed exe (10GB, signed personal download URLs, SHA-256 included). **The Store is not
|
||||
needed for delivery at all.** The Store's only unique value is *free Microsoft signing with
|
||||
no SmartScreen warning*, and its cost is MSIX packaging work, Store review, and a public
|
||||
listing.
|
||||
**C** is the status quo previously sketched in `Distribution.md:14` / `:296` — Polar hosts
|
||||
the signed exe (10GB, signed personal download URLs, SHA-256 included). **The Store is not
|
||||
needed for delivery at all**; its only unique value is *free Microsoft signing with no
|
||||
SmartScreen warning*, and its cost is MSIX packaging work, Store review, and a public
|
||||
listing. Note the irony: C is the only option with a recurring cost *and* the only one where
|
||||
the creator maintains payment plumbing themselves.
|
||||
|
||||
**D is dominated** — strictly worse than both A and C: cert required anyway, silent install
|
||||
required, and we maintain the versioned download URL. Documented in one line so it is
|
||||
|
||||
Reference in New Issue
Block a user