Repository navigation
fix: refresh Paykit views and local completion - #914
ben-kaufman wants to merge 2 commits into
Conversation
|
talosmachina
left a comment
There was a problem hiding this comment.
No findings. Swaps the request and contact display reads for one identity- and generation-checked observeState observation, and publishes verified hardware-payment resolution before proof delivery on the reconcile path. Reviewed abc28553, full tier, reasoned from the code, the pinned paykit-rs source and CI; iOS is not built here.
What I checked, and 4 candidates I ruled out
Read in full: completeHardwareOnchainPayment, consumeOnchainPaymentResolution, submit/submitInBackground (PaykitPaymentProofService.swift), PaykitSdkService.observeState, withSdk, refreshPaykitKey, PaykitSdkOperationLock (PubkyService.swift), ContactsManager.loadContacts, PaykitPaymentRequestService.synchronize, PaykitPaymentRequestManager.refresh/performRefresh, SendPendingScreen.applyOnchainPaymentResolution
SDK side: observe_state, contact_records, list_payment_requests, load_remote_state at paykit-rs 0eff3d4 (tag v0.1.0-rc73, matches Package.resolved)
Call sites traced: onchainPaymentResolutionPublisher (AppScene, HwSendSignView, SendPendingScreen), loadContacts(for:) (AppScene, ContactsManager), service.synchronize (only performRefresh)
CI: validate, detect-changes and Greptile green; Run Tests, Run Integration Tests and build-local still running at review time
Ruled out
- Duplicate proof submission when resolution is published before
submiton the reconcile path:consumeOnchainPaymentResolutioncan now interleave with the foregroundsubmit(completed)and start a secondsubmit, both doing a check-then-submit againstpaymentRequests(). The same interleave already exists on the defaultdeliverInBackgroundpath, and the SDK documents a repeated proof for the same occurrence as evidence that implies no second payment. observeStatefailing where the old getters returned data: signed-out, no Paykit identity secret, and uninitialized identity all errored on the oldcontact_records()/payment_requests()path too, because the shared storage transaction needs the same session and secret. A missing blob with no registry noise key still yields default state, somissingDataIsEmpty: falseloses no empty-list case.performRefreshnow requiresactiveIdentitybefore syncing: the only state this skips is a manager whose stored acceptance or subscription state failed to load. Outbound proof delivery still runs fromPaykitPaymentProofService.submitand the otherprocessPendingMessagescallers.- Dropped identity guard after consume in
SendPendingScreen:applyOnchainPaymentResolutionalready matchesresolution.identityagainstpubkyProfile.publicKeyon entry, and navigation now runs on the main queue via the added.receive(on:).
Merge confidence: 4/5, the unit and build jobs were still running and the iOS target was not built here.
This PR:
Related: SDK #183, Server #78. Pins published rc73; neither PR needs to merge for this consumer build.
Description
0eff3d4e694ba0dbbea2d47852fe796e456671b0; the actual SwiftPM archive matches published SHA256511715acf3ca84e322d19ea6651c767c98b5325845d571abe2a9527b1eb6ae26, with no local override or unrelated dependency change.Out of Scope
Design
N/A - no UI layout or copy changes.
Preview
Not recorded: a dedicated funded hardware-payment recovery journey remains unrun; deterministic local fixtures cover the ordering change.
QA Notes
Journeys
shop-onchain-proof.xml- distinguishes durable local completion from remote acknowledgement; funded journey not run.Manual Tests
N/A.
Automated Checks
ContactsManagerTests.swift,PaykitPaymentRequestServiceTests.swift- preserve prior displays on failed/wrong-identity observations and keep cached display separate from action authority.PaykitSdkIdentityCheckTests.swift- enforce observation identity and cancellation without overlapping native operations.PaykitPaymentProofServiceTests.swift,TransferServiceActivityTests.swift- prove durable held-delivery/restart recovery and main-thread Pending completion before held acknowledgement, with exact-context rejection and proof retention.ContactsListViewTests.swift,ProfileDestinationViewTests.swift,PaykitPaymentRequestServiceTests.swift- cover the explicit display loader and full-observation failure.3d2283e2replaces fixed navigation/acknowledgement sleeps with bounded completion expectations; all 2,371 tests passed again with no introduced diagnostics and a clean bounded independent review. Production code and the measured read path are unchanged.Measurement Limits