Skip to content

feat: handle terminal Paykit payment requests - #65

Draft
dzdidi wants to merge 3 commits into
feat/lock-payment-drainingfrom
pubky-locks-public/t_bb25c3f2-paykit-rejection-publish-stacked-locks-r
Draft

dzdidi wants to merge 3 commits into
feat/lock-payment-drainingfrom
pubky-locks-public/t_bb25c3f2-paykit-rejection-publish-stacked-locks-r

Conversation

@dzdidi

@dzdidi dzdidi commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Stack and prerequisites

This is a stacked draft PR. Its base is Locks #61 (feat/lock-payment-draining), which must land first.

Upstream contract order:

  1. Paykit Server Bump dtolnay/rust-toolchain from 1.89.0 to 1.100.0 #3
  2. Paykit Server fix(connect): match the embedded shell to the app modal #27, stacked on Bump dtolnay/rust-toolchain from 1.89.0 to 1.100.0 #3
  3. This Locks rejection-lifecycle change, stacked on Locks feat/lock-payment-draining db reset #61

Development currently uses provisional exact Paykit Server PR #27 commit 44ed37886122a201b2d5f73c9578ecabb48f72bd. Final immutable Paykit Server release tag/pin remains a pre-merge gate. This branch is not release- or deployment-ready while that provisional source ref remains.

Frontend contract

Rejected payment requests surface as status=expired with terminal_reason=payment_request_rejected. They issue no entitlement. Retry requires a fresh Bundle ID.

SDK consumers must migrate terminal handling from status-only branching to the closed terminal_reason values. Unknown, missing, malformed, or conflicting terminal tuples fail closed. Connection-state observation remains separate from payment lifecycle polling.

Summary

  • map terminal Paykit rejection/cancellation/expiry outcomes into closed Locks terminal reasons
  • persist terminal reason and entitlement-publication intent safely
  • fail closed on malformed, unknown, conflicting, or oversized Paykit responses
  • expose terminal reason through Rust and browser SDK paths
  • provide executable Rust and JS/WASM consumer examples covering lifecycle polling, terminal-reason handling, credential retrieval, proxy reads, and separate connection observation
  • document and contract-test provisional stacked demo wiring

SDK consumer tests and docs

  • Rust public API tests exercise pending-to-terminal lifecycle lookup, exact terminal reasons, credential/resource-call absence on terminal outcomes, and separate connection observation.
  • JS/WASM generated-package smoke tests run copyable consumer examples for accepted, rejected, canceled, and proposal-expired outcomes.
  • Consumer docs enumerate all four terminal wire values and require fail-closed migration from status-only handling.

Verification

Exact commit and tree were independently reviewed before publication:

  • commit: 35ad885428157bf88c52105ba9aec93290ec5a4c
  • tree: 3832e3a802a5af068317fd3e27658e5ad58c4ce3
  • exact Locks feat/lock-payment-draining db reset #61 base/head: 7e65742332ed31183c1e23b5680f3c8b8dde10fd

Internal review passed Rust SDK flow tests, JS native/WASM/generated-package tests, example smoke coverage, npm release audit and pack inspection, formatting/diff checks, plus prior workspace, Clippy, rustdoc, browser, and Compose contract checks for the rejection feature. The provisional Paykit Server source build still has the documented upstream-only Criterion::paykit_payment_params compatibility blocker; this is a release/pre-merge dependency, not a regression introduced by these SDK tests/docs and not a claim of runtime readiness.

Prerequisites: #61, pubky/paykit-server#3, pubky/paykit-server#27.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant