Skip to content

feat/lock-payment-draining db reset - #61

Open
dzdidi wants to merge 6 commits into
masterfrom
feat/lock-payment-draining
Open

dzdidi wants to merge 6 commits into
masterfrom
feat/lock-payment-draining

Conversation

@dzdidi

@dzdidi dzdidi commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

TO BE DEPLOYED TOGETHER WITH pubky/paykit-server#3

TO FIX CI:

1. Merge/commit Paykit changes.
2. Publish Paykit tag v0.1.0-rc5.
3. Verify manually:

─ bash
   git ls-remote --exit-code \
     https://github.com/pubky/paykit-server.git \
     refs/tags/v0.1.0-rc5

4. Re-run Locks PR job.
5. Merge/release Locks v0.1.0-rc7.

feat: coordinate Paykit HTTP signing and reset prototype state

Summary

Update the Locks → Paykit HTTP contract and add a one-time destructive SQLx migration for the coordinated Locks and Paykit Server prototype deployment.

  • Sign a versioned preimage binding uppercase method, exact query-free path, and exact raw body.
  • Require invoice creation to return exact 200 OK with closed invoice_created_at and payment_deadline fields.
  • Update active API/runtime documentation for that coordinated contract.

Migration 0010_reset_prototype_runtime_state clears Locks-owned private runtime state automatically during startup. SQLx records the migration in _sqlx_migrations, so later starts preserve post-upgrade state.

This change is intentionally reset-only. It does not attempt to migrate prototype runtime records and does not claim production-data compatibility.

Reset scope

Migration 0010 truncates the complete set of Locks runtime tables remaining after migrations 0001–0009:

  • verification_tasks;
  • access_credentials;
  • creator_authorities;
  • pending_creator_connect_flows;
  • frontend_session_codes;
  • frontend_sessions.

The migration:

  • runs through the existing embedded SQLx migrator;
  • runs transactionally and once only through SQLx migration history;
  • preserves the schema and _sqlx_migrations ledger;
  • does not use DROP SCHEMA;
  • does not connect to or modify the separate Paykit Server database;
  • does not delete Pubky-hosted content locks, guarded resources, Lock Service Pointers, or verified proof bundles.

Deployment

Warning: Migration 0010 permanently deletes all persisted Locks verification tasks, access credentials, creator authority, pending connect flows, frontend session codes, and frontend sessions. It is approved only for the undeployed/disposable prototype rollout.

Deploy this change together with the Paykit Server change that performs its own one-time reset.

1. Stop all Locks Server and Paykit Server instances.
2. Verify each service points to its dedicated disposable PostgreSQL database.
3. Stage Paykit Server `0.1.0-rc5` and Locks Server `0.1.0-rc7` as one rollout; do not start either revision alone.
4. Start one instance of each service and let both embedded migrations complete.
5. Verify both migration ledgers and readiness endpoints.
7. Reacquire Locks creator authority and frontend sessions.
8. Re-run Paykit Creator setup.

No manual schema deletion is required.

Migration sequencing

This migration claims SQLx version 0010 on master.

Existing follow-on branches that currently use version 0010 or later must be rebased and renumbered before merge, including the cancellation and graceful-deletion work. Duplicate SQLx migration versions must not be merged.

Test coverage

The focused upgrade regression:

  1. applies baseline migrations 0001–0009;
  2. seeds every surviving Locks runtime table;
  3. runs the complete embedded migrator;
  4. verifies all prototype rows were removed;
  5. verifies _sqlx_migrations contains versions 1 through 10;
  6. inserts post-upgrade state;
  7. runs the migrator again;
  8. verifies the post-upgrade state remains.

The PostgreSQL test harness now supports creating an isolated schema before applying migrations, allowing the real upgrade path to be exercised.

Verification

Passed locally:

cargo test -p locks-service infrastructure::postgres::migrations::tests::migration_versions_are_unique
TEST_DATABASE_URL='postgresql://postgres@127.0.0.1:55432/postgres' \
  cargo test --locked --workspace -- --test-threads=1
cargo clippy --workspace --all-targets --all-features -- -D warnings
cargo fmt --all -- --check
git diff --check

The PostgreSQL-backed reset regression and complete Locks workspace suite passed
against an isolated PostgreSQL 16 test database.

SDK consumer docs and tests

Commit 7e65742332ed31183c1e23b5680f3c8b8dde10fd adds executable locks-sdk
consumer guidance without adding or changing public SDK exports:

  • copyable Rust and JS/WASM Paykit-backed viewer flows;
  • lifecycle polling, terminal/error handling, and independent connection-state handling;
  • access-credential retrieval and bearer-only proxy-read placement;
  • public Rust API contract tests and generated-package JS example smoke coverage.

Signed-off-by: dzdidi <dzdidi@users.noreply.github.com>
- sign Paykit requests over method, query-free path, and raw body
- require exact invoice 200 responses with closed timestamp fields
- validate RFC 3339 invoice timestamps and bound response bodies
- add one-time prototype database reset migration
- update Paykit rc5 and Locks rc6 Compose integration

Signed-off-by: dzdidi <dzdidi@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant