# FamChore — TODO (Completed work is tracked in MEMORY.md / git history.) ## Open / next features ### Payments / billing - [ ] Prod webhook secret wiring in Stripe Dashboard (dev uses CLI secret) - [ ] Optional hardening: server-side session verification on checkout return (`checkout.sessions.retrieve` reusing webhook apply logic) — only if SSE/webhook lag ever becomes a real problem (currently event-driven via PB realtime, see MEMORY 2026-08-22) ### Platform admin - [ ] Platform-admin UI for managing `accesscodes` globally (create/disable/delete access codes AND trial codes) — currently superuser/DB only. Natural home: `/admin` (has Platform Flags card already). - [ ] `/admin` Families table: name link and "Dashboard"/"View" are duplicates after the broken-link fix — tidy up. ### App / UX - [ ] Signup wizard: `?plan=` param only pre-highlights the tier at step 4 — confirm whether it should auto-scroll/pulse instead - [ ] Data card placeholder ("Download CSV / Delete Family coming soon") - [ ] Parent invite ("Invite Parent") is an alert stub ### Infra / deferred - [ ] WhatsApp notifications - [ ] Weekly CRON (`/api/weekly-cron`, Coolify) — settlement stays manual via complete-week/simulateEow