Skip to content

fix: bind appraisal client payment to the requested quote - #448

Merged
karagozemin merged 3 commits into
Sub-Rosa-Issue:mainfrom
emmixeryng:fix/issue-414-make-the-appraisal-client-pay-only-the-quote-it
Oct 1, 2026
Merged

karagozemin merged 3 commits into
Sub-Rosa-Issue:mainfrom
emmixeryng:fix/issue-414-make-the-appraisal-client-pay-only-the-quote-it

Conversation

@emmixeryng

Copy link
Copy Markdown
Contributor

Overview

This PR makes the appraisal client pay a 402 quote only when the asset, amount, destination, and expiry match the request it just made. The client now records its own request, compares the incoming challenge against that record, and refuses to submit a payment on mismatch, expiry, or an empty challenge — returning a typed error instead of leaking the raw challenge body.

Related Issue

Changes

🔒 Request-bound payment

  • [MODIFY] services/appraisal-api/src/client.ts

    • Records asset, amount, destination, and expiry from the outgoing request before the 402 challenge is handled.
    • Compares the returned challenge against the recorded request and only proceeds to payment on an exact match.
    • Skips payment on mismatch, expiry, or empty challenge, surfacing a typed error rather than the raw challenge body.
  • [MODIFY] services/appraisal-api/src/appraisal.ts

    • Threads the recorded request record through the appraisal flow so the client can validate the challenge against it.
  • [MODIFY] services/agent/src/bidder.ts

    • Handles the typed mismatch/expiry error so the agent can surface it without exposing the challenge body.
  • [MODIFY] services/appraisal-api/src/client.test.ts

    • Stubs HTTP for the appraisal client and asserts no broadcast occurs.
    • Covers the exact-challenge payable case, a different-amount rejection, and an expired-challenge rejection.

Verification Results

npm test -- services/appraisal-api/src/client.test.ts
✅ client tests passed (exact challenge payable; mismatched amount and expired challenge not paid)
Acceptance Criteria Status
An exact challenge is payable in the fixture ✅ Exact asset/amount/destination/expiry challenge is paid
A different amount is not paid ✅ Mismatched amount is rejected before payment
An expired challenge is not paid ✅ Expired challenge is rejected before payment
Tests stub HTTP and do not broadcast ✅ HTTP is stubbed; no broadcast in tests

Closes #414

@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@emmixeryng Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@karagozemin
karagozemin merged commit 1866050 into Sub-Rosa-Issue:main Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Make the appraisal client pay only the quote it just requested

2 participants