#!/bin/bash

# PurchaseKit Google Cloud Setup
# ==============================
# This script configures Google Cloud for receiving Play Store webhooks.
# Run it in Google Cloud Shell: https://console.cloud.google.com/cloudshelleditor
#
# What it does:
#   - Enables required Google Cloud APIs
#   - Creates a Pub/Sub topic and push subscription
#   - Grants Google Play permission to publish notifications
#   - Creates a service account and generates a JSON key
#
# Before running:
#   1. Set your PROJECT_ID below
#   2. Run: bash setup.sh

PROJECT_ID="your_project_id"

# --- You don't need to change anything below this line ---

set -e

if [ "$PROJECT_ID" = "your_project_id" ]; then
  echo "Error: Set PROJECT_ID to your Google Cloud project ID on line 18"
  exit 1
fi

echo ""
echo "PurchaseKit Google Cloud Setup"
echo "=============================="
echo "Project: $PROJECT_ID"
echo ""

gcloud config set project "$PROJECT_ID"

echo "Enabling APIs..."
gcloud services enable cloudresourcemanager.googleapis.com --quiet
gcloud services enable iam.googleapis.com --quiet
gcloud services enable androidpublisher.googleapis.com --quiet
gcloud services enable pubsub.googleapis.com --quiet
echo "Done."
echo ""

echo "Creating Pub/Sub topic..."
if gcloud pubsub topics describe purchasekit-play-notifications &>/dev/null; then
  echo "Topic already exists, skipping."
else
  gcloud pubsub topics create purchasekit-play-notifications
  echo "Created: projects/$PROJECT_ID/topics/purchasekit-play-notifications"
fi
echo ""

echo "Creating push subscription..."
if gcloud pubsub subscriptions describe purchasekit-push &>/dev/null; then
  echo "Subscription already exists, skipping."
else
  gcloud pubsub subscriptions create purchasekit-push \
    --topic=purchasekit-play-notifications \
    --push-endpoint=https://purchasekit.com/webhooks/google
  echo "Created with endpoint: https://purchasekit.com/webhooks/google"
fi
echo ""

echo "Granting Google Play publish access..."
gcloud pubsub topics add-iam-policy-binding purchasekit-play-notifications \
  --member="serviceAccount:google-play-developer-notifications@system.gserviceaccount.com" \
  --role="roles/pubsub.publisher" \
  --quiet >/dev/null
echo "Done."
echo ""

echo "Creating service account..."
if gcloud iam service-accounts describe "purchasekit@$PROJECT_ID.iam.gserviceaccount.com" &>/dev/null; then
  echo "Service account already exists, skipping."
else
  gcloud iam service-accounts create purchasekit \
    --display-name="PurchaseKit"
  echo "Created: purchasekit@$PROJECT_ID.iam.gserviceaccount.com"
fi
echo ""

echo "Waiting for service account to be ready..."
sleep 10
echo ""

echo "Generating JSON key..."
gcloud iam service-accounts keys create purchasekit-credentials.json \
  --iam-account="purchasekit@$PROJECT_ID.iam.gserviceaccount.com"
echo "Saved to: purchasekit-credentials.json"
echo ""

echo "=============================="
echo "Setup complete!"
echo ""
echo "Next steps:"
echo ""
echo "1. Add the service account to Play Console:"
echo "   - Go to https://play.google.com/console"
echo "   - Setup > Users and permissions > Invite new users"
echo "   - Email: purchasekit@$PROJECT_ID.iam.gserviceaccount.com"
echo "   - Grant: View app info, View financial data"
echo ""
echo "2. Enable real-time notifications in Play Console:"
echo "   - Select your app > Monetize > Monetization setup"
echo "   - Topic: projects/$PROJECT_ID/topics/purchasekit-play-notifications"
echo ""
echo "3. Upload purchasekit-credentials.json to PurchaseKit:"
echo "   - Go to https://purchasekit.com/account/developer"
echo ""
echo "Note: Play Console permissions can take up to 24 hours to work."
