Sample CodeReviewed 2026-07-21View on Apple Developer

Determining service entitlement on the server

At a glance

Item Summary
Purpose Identify a customer’s entitlement to your service, offers, and messaging by analyzing a validated receipt and the state of their subscription.
App architecture A JavaScript sample whose app entry flows through Routes, receiptProcessor, Subscription before reaching StoreKit topic boundary.
Main patterns Route-service-model layering
Project style 5 scanned source file(s) across JavaScript, organized around ranked entry, type, and file boundaries.
Execution model No structured execution marker indexed; callback threading requires source review.
State/event model No structured observation or publisher-scheduling marker indexed.
Key frameworks/packages No path-level import or package-manifest evidence indexed.

Project structure

Source bundle/
├── routes/
│   └── index.js
├── app.js
├── services/
│   └── receiptProcessor.js
├── promo-offer-gen/
│   └── index.js
└── models/
    └── Subscription.js

Structure observations

  • Architecturally prominent files are ranked from entry points and role-named declarations; resource-only paths are omitted.
  • Primary languages: JavaScript.
  • The verified tree contains 0 project/configuration file(s) and 0 source declaration(s).

Overall architecture

Reference code

app.js:14 — architecture anchor

const app = express();

Interpretation

The arrows summarize the source-visible entry, role-named types or folders, and framework direction; when nodes come from structural folders, the sequence is a high-level interpretation rather than proof that every adjacent node calls the next. Ownership is claimed only where the next section cites a stored property or assignment. The diagram is intentionally limited to the dominant path into StoreKit.

Ownership and state

Ownership evidence

routes/index.js:10 — stored dependency or nearest verified ownership anchor

const router = express.Router();
Owner Object or state Relationship Mutation authority
RoutesModule Router (router) creates and retains App/module collaborators
app express (app) creates and retains App/module collaborators
receiptProcessor Subscription (newSub) creates and retains App/module collaborators
receiptProcessor OriginalTransaction (original) creates and retains App/module collaborators

Composition arrows indicate a source-visible construction expression or locally owned value state; aggregation means the owner stores or receives a dependency without proving exclusive lifetime ownership.

Concurrency, scheduling, and thread safety

Evidence limit: actor isolation, async/await, or Task creation does not by itself prove background-thread execution; Sendable conformance alone does not prove thread-safe mutation.

No source-visible execution, scheduling, or synchronization boundary was found in the indexed source.

@MainActor/MainActor.run, DispatchQueue.main, and RunLoop.main are reported as distinct isolation, queue, and event-loop mechanisms. A plain Task is kept separate from Task.detached; neither is labeled as a background thread.

State propagation, frameworks, and dependencies

Evidence limit: an import proves a source-level compilation dependency at the cited line; it does not prove runtime use, architectural adoption, or whether a Swift package is a direct application dependency.

No source-visible state propagation, framework import, or package dependency was found in the indexed source.

receive(on:) describes downstream delivery scheduling, while subscribe(on:) describes upstream subscription/request/cancel scheduling. An import Combine alone establishes neither behavior nor a Store, reducer, Redux, or other application architecture.

Class and protocol design

services/receiptProcessor.js:8 — representative type boundary

require('dotenv').config();
Type Responsibility Depends on or conforms to
No local class/protocol declaration Procedural or file-level feature logic Language module and imported APIs

No local protocol conformance is claimed as protocol-oriented design; external framework conformances are listed only as dependencies.

Access control

Symbol Access Verified effect Likely rationale
index (promo-offer-gen/index.js:10) language/file boundary Visibility follows the language’s file, module, and export rules rather than Swift access modifiers. Inference: the language’s file or module boundary is sufficient for this sample collaboration.

Reference code

promo-offer-gen/index.js:10 — representative boundary

const ECKey = require('ec-key');

Swift declarations without a modifier are internal; explicit private, fileprivate, private(set), public, or open entries above are interpreted by language semantics. Objective-C/C samples instead rely on header and implementation boundaries, which are not equivalent to Swift lexical privacy.

Logic ownership and placement

Logic Owning type or file Placement rationale
Request routing Routes Folder and filename roles place this logic at routes/index.js.
Service logic receiptProcessor Folder and filename roles place this logic at services/receiptProcessor.js.
Data model Subscription Folder and filename roles place this logic at models/Subscription.js.

Design patterns

Pattern Source evidence Purpose or tradeoff
Route-service-model layering services/receiptProcessor.js:1 Directory and file roles separate request routing, service processing, and data representation.

Naming conventions

  • Types: feature-specific names rather than reusable layer suffixes.
  • Protocols: no local protocol declaration in the scanned source.
  • Methods: OriginalTransaction, subProductIndex, originalProductIndex, applyExpirationIntent, calcSubMovments, processLatestReceiptInfo, processPendingRenewalArray, genSubObjects.
  • Files: feature/project roles rather than a strict one-type-per-file rule.

Architecture takeaways

  • app is the main source-visible entry or composition anchor for this sample.
  • Framework work reaches StoreKit through a deliberately small high-level chain; the detailed API graph remains inside the cited implementation files.
  • Stored-property evidence identifies lifecycle collaboration; it does not by itself prove exclusive object ownership.
  • Access-control conclusions separate verified language visibility from the likely design rationale.
  • The source does not justify labeling the design protocol-oriented.

Source map

Source file Relevant symbols
app.js Cited implementation, Feature implementation
routes/index.js Cited implementation, Feature implementation
services/receiptProcessor.js receiptProcessor, Cited implementation, Feature implementation
promo-offer-gen/index.js index, Feature implementation
models/Subscription.js Feature implementation