docs: distribution route decided — Microsoft Store MSIX + Store IAP
Creator ruling 2026-09-27. Criteria, verbatim: "zero headaches, minimal maintenance (for me) while still providing accountability and a reasonably easy upgrade flow." Route A is the only combination where all four are solved by handing the work to Microsoft rather than to a certificate vendor: $0/yr, no certificate, no HSM, no annual renewal, no SmartScreen ramp — plus Store auto-update, Store-side payments/entitlements/refunds/support, and Microsoft review as the accountability layer. The rejected options and their reasons stay in research-store-certification.md §3 so a later session reads the ruling instead of re-deriving it. What this deletes: - The entire licensing backend. PolarLicenseService, PolarLicense, MainViewModel.License.cs (PremiumUrl, customer portal, the OfflineGracePeriod = 14 days subscription-era artifact, renewal/lapse copy) and the wrong "Polar unlocks alerts" string all become dead code. IsPremium is derived from the Store entitlement instead of an HTTP call, which also removes the whole "network flaky -> app thinks I'm expired" bug class. - Velopack, the update URL, and the self-hosted droplet — the Store updates. - Distribution.md's premise: Polar as the distribution backbone, Polar file hosting, and code signing as our problem. The IP-protection sections (1, 5, 6, 7) still stand and the build-posture ceiling is unchanged. What does NOT change: the entitlement. Free gets everything; the branding flash stays the only paid delta. Store IAP changes how IsPremium is obtained, never what it gates. Still open, deliberately: the price. The Store revenue share is unverified (do not assume a percentage), and MONETIZATION.md's $29 -> $49 one-time decision is re-opened against a fresh instinct toward ~$99/yr. No price encoded yet. The first code unit is unchanged: bundle ffmpeg (TASK 48 item 1). That clears the one hard certification gate and fixes a real user-facing 404. MARCOM.md and MONETIZATION.md were edited too but are gitignored by design, so those changes stayed local.
This commit is contained in:
@@ -1794,14 +1794,34 @@ published decisions (recorded in `TASKS/task-43-native-alerts.md`):
|
||||
|
||||
---
|
||||
|
||||
## Windows packaging & distribution (2026-09-27 — research settled, route NOT decided)
|
||||
## Windows packaging & distribution (✅ DECIDED 2026-09-27 — Store MSIX + Store IAP)
|
||||
|
||||
Full analysis: `TASKS/research-store-certification.md` (Store Policies **7.20**, effective
|
||||
2026-10-22 — re-check the version before acting). Executable checklist:
|
||||
`TASKS/task-48-distribution-msix.md`. **The route is the creator's decision** (Store MSIX +
|
||||
Store IAP / Store MSIX + Polar / Polar-hosted + own cert / dominated Store-EXE). Do not build
|
||||
packaging work before that call, and do not re-derive the options — they are tabulated in the
|
||||
research file §3.
|
||||
**The distribution route is settled: Microsoft Store, MSIX package, Store IAP.** Creator's
|
||||
criteria, verbatim: *"zero headaches, minimal maintenance (for me) while still providing
|
||||
accountability and a reasonably easy upgrade flow."* Route A was chosen because it is the
|
||||
only option where all four are solved by handing the work to Microsoft rather than to a
|
||||
certificate vendor: **$0/yr, no certificate, no HSM, no annual renewal, no SmartScreen
|
||||
ramp**, plus Store auto-update, Store-side payments/entitlements/refunds/support, and
|
||||
Microsoft review as the accountability layer. The rejected options and their reasons live in
|
||||
`TASKS/research-store-certification.md` §3 — **read that before reopening the question**, not
|
||||
before re-deriving it. Executable checklist: `TASKS/task-48-distribution-msix.md`.
|
||||
|
||||
**Consequences that are architecture, not packaging detail:**
|
||||
|
||||
- **⛔ Velopack and the update URL are deleted** — the Store auto-updates. 3 edit sites,
|
||||
`ytLive.csproj:92` + `App.xaml.cs:3,38-46`. The self-hosted DO droplet dies with it.
|
||||
- **⛔ The Polar licensing subsystem is deleted** — `PolarLicenseService`, `PolarLicense`,
|
||||
`MainViewModel.License.cs` (`PremiumUrl`, customer portal, the
|
||||
`OfflineGracePeriod = 14 days` subscription-era artifact, renewal/lapse copy), and the
|
||||
wrong "Polar unlocks alerts" string in `OverlayHost.xaml`. **`IsPremium` is derived from the
|
||||
Store entitlement**, not a remote HTTP call. That deletes the entire "network flaky → app
|
||||
thinks I'm expired" bug class along with the offline-grace machine.
|
||||
- **⛔ Bundle ffmpeg — no runtime downloads** (Store policy 10.2.2; also the 2026-09-01 404).
|
||||
See the FFmpeg locator section above. **This is the first code unit.**
|
||||
|
||||
**What does NOT change: the monetization posture.** Free gets everything; the branding flash
|
||||
stays the **only** paid delta (`TASK 36` item 2). Store IAP changes how `IsPremium` is
|
||||
*obtained*, never what it *gates*. `Monetization` above still governs.
|
||||
|
||||
### ⛔ Durable invariant: full trust, or recording silently breaks
|
||||
|
||||
@@ -1833,15 +1853,15 @@ line item) and private keys must live on an **HSM or hardware token**. The **Sto
|
||||
needs no certificate at all** — Microsoft re-signs. `Distribution.md` §4.3 was corrected
|
||||
2026-09-27; it previously recommended EV.
|
||||
|
||||
### Distribution and licensing are independent
|
||||
### Distribution and licensing are independent — but the ruling collapsed them
|
||||
|
||||
A **Store-distributed** app may still verify licenses with **Polar** (policy 10.8.1
|
||||
explicitly permits a secure third-party purchase API for non-game PC products; the box is
|
||||
ticked in Partner Center). So "should we use the Store?" does **not** imply "should we drop
|
||||
Polar?" — the only combination that removes Polar is Store + Store IAP, and that is a
|
||||
*licensing* choice which happens to ride on a *distribution* decision. (The monetisation
|
||||
posture itself is unchanged and lives in the Monetization section above: free gets
|
||||
everything; the branding flash is the only paid delta.)
|
||||
A **Store-distributed** app *may* still verify licenses with **Polar** (policy 10.8.1
|
||||
explicitly permits a secure third-party purchase API for non-game PC products), so "should we
|
||||
use the Store?" did not logically imply "drop Polar?" — route B was a real option. **The
|
||||
creator chose route A instead**, so Polar is gone. Recording the distinction because it was
|
||||
the reason the decision was thought-through rather than assumed: the licensing choice rode on
|
||||
a distribution decision, and the *only* route that removed the licensing backend was the one
|
||||
that also removed the certificate. Both burdens had the same single solution.
|
||||
|
||||
### ⛔ "Only when the user says so" is enforced by Windows, not by us
|
||||
|
||||
|
||||
Reference in New Issue
Block a user