https://sonarly.com/issue/4334?type=bug
The `createDirectSubscription` method throws a `BillingException` when a customer already has a non-canceled subscription, but nothing upstream prevents the user from reaching this code path when that condition is true.
Fix: ## Root Cause
A TOCTOU (Time-Of-Check-Time-Of-Use) race condition in the `createDirectSubscription` flow: the frontend checks `onboardingStatus === PLAN_REQUIRED` (no subscriptions exist), but by the time the user clicks "Continue" a subscription may already have been created (e.g. a prior request succeeded but the response was lost, or a double-click). The guard added in commit `65f0a5bb18` prevented a database unique-constraint crash but replaced it with a user-facing `BillingException` instead of handling the duplicate-request case idempotently.
## Fix
In `createDirectSubscription`, change the existing-subscription guard from **throwing an exception** to **returning `successUrl` idempotently**. If the customer already has a non-canceled subscription, the desired end-state (an active subscription + redirect to success) is already satisfied — we just return the success URL, exactly as the method would have done after creating it fresh.
```typescript file=packages/twenty-server/src/engine/core-modules/billing/services/billing-portal.workspace-service.ts lines=106-115
if (
isNonEmptyArray(customer?.billingSubscriptions) &&
customer.billingSubscriptions.some(
(subscription) => subscription.status !== SubscriptionStatus.Canceled,
)
) {
// Subscription already exists (e.g. race condition / duplicate request).
// Return successUrl idempotently instead of throwing a user-facing error.
return successUrl;
}
```
This makes `createDirectSubscription` consistent with the `computeCheckoutSessionURL` path (which uses Stripe checkout sessions and is inherently idempotent). The change is a 1-line replacement in a single file; no other layers need to be touched because the caller already handles the returned URL correctly.