Release 2.13.0: verify session before paying, single-flight PaymentIntent creation, mppx 0.11.0 - #136
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Release 2.13.0: a way to get a verify_url before paying, a fix for Stripe rate-limit failures under concurrent identical requests, and the coupled-set move. Worked with Varun.
Verification session without a payment credential. On an identity-gated
Checkoutthe gate runs only on the settle leg, so a buyer with no identity reached the session-bearing 403 only by first sending a payment credential. A Stripe SPT buyer therefore had to mint a token just to learn they needed to verify, and a real buyer on a storefront read the 402 as offering no path to a verify link at all. Now:identity_bootstrapblock (header,value,instructions) whenever the store is identity-gated and the request has no identity header.X-Verification-Session: create(case-insensitive), no identity and no payment credential runs the gate, which returns its existing session 403 withverify_url,session_id,poll_secretandpoll_url.llms.txtidentity section and the Stripe/Link onboarding step name the header.Concurrent PaymentIntent creation. Storefront logs showed Stripe
rate_limit429s taggedstripe-rate-limited-reason: resource-specificandstripe-should-retry: false, all fromcreateMultichainPaymentIntent, clustered on a scanner's 30-minute cycle: identical requests racing in one process each sentpaymentIntents.createunder the same idempotency key. Keyed calls now share one in-flight promise, cleared when it settles (success or failure), so parallel identical requests make one Stripe call. Unkeyed calls are unchanged.Coupled set.
mppx0.11.0 andviem2.57.0 (dev pins and the viem override), matching pay 0.5.9. The Tempo zero-amount proof domain is still version 3, and 0.11.0's attribution-memo change only removes the custom-memo exemption, which no consumer here uses; the 0.10.1 client already writes the challenge-bound memo and the encoding is byte-identical.fast-uri advisories. The dependency scan flagged GHSA-58mr-gqgx-xq4g and GHSA-qw65-cvwx-89v3 on the locked
fast-uri3.1.6 (underajv) and 4.1.3 (under@fastify/ajv-compilerandfast-json-stringify). Both fixes sit inside the declared ranges, so no install re-resolves them, and a top-level override cannot serve two majors at once. The three lock entries are rewritten in place to 3.1.8 and 4.2.1 (the newest in each line, both well past the release-age soak) with their registry integrity hashes; a frozen install accepts the lock and installs those versions at each position, and osv-scanner reports no issues across 898 packages.Type of change
Public API
Additive. New export
VERIFICATION_SESSION_HEADERfrom the top-level entry. Identity-gated 402 bodies gain a top-levelidentity_bootstrapobject; a merchantbodyExtraskey of the same name still wins.createMultichainPaymentIntentkeeps its signature. No migration needed.Test plan
tests/checkout_verification_bootstrap.test.ts: the 402 advertises the header only on a gated store with no identity; the header returns the session 403 without payment; name and value match case-insensitively; an identity header or any other value is ignored; a gateless store neither advertises nor honors it. With the new logic disabled, the three behavior tests fail and the three controls pass.tests/stripe-multichain/payment_intent.test.ts: concurrent same-key calls make one Stripe call; different keys and unkeyed calls do not share; a later call after settle calls again; a failure reaches every waiter and clears the key. The two sharing tests fail on the previous code.Checklist