Conversation
The corridor and customer-type resolvers preferred the query string while the Alfredpay POST handlers read the body, so a manager could present an allowed corridor in the query and have the operation run against a different one in the body, defeating the per-manager corridor grant.
Alfredpay identifies customers by email, so a creation conflict was resolved by adopting whatever customer that email returned. A managed child's contact email is chosen by its manager and never verified, so a manager could point a child at an email whose customer is already verified and inherit that KYC state. Adoption now requires the customer to be unclaimed or already ours, which still covers the retry case where an earlier creation reached Alfredpay but failed to persist.
parseAPIError still matched the pre-PR Mykobo message and a BRL message the backend retired, so both fell through to a generic error and consumers branching on MykoboKycRequiredError or BrlKycStatusError stopped seeing them.
Moving session routes onto requirePartnerOrUserAuth lost the 503 that tells a caller the provider is briefly unreachable rather than their token being rejected: the Bearer branch had no handler, so a transient failure reached the error converter as a 500.
Revoking an already-revoked child credential rewrote its revocation timestamp, losing when the credential actually stopped being valid; revocation stays idempotent but only the first call writes. Provisioning ignored the manager's allowedCustomerTypes narrowing, creating children the manager could never operate — a mismatched child now only arises by tightening policy after the child exists, which is how the delegated tests set that state up. The admin provisioning route mapped only one of the two error classes createManagedProfile raises, so a conflict surfaced as a 500.
The ADR declares the external subject id immutable but only contact_email had a trigger. The corridor grant CHECK is left as-is on purpose: an empty array is how every corridor is revoked from an active manager, and the schema test now pins that.
Webhooks register against the manager's own credential scope, so a child selection silently produced a subscription the caller did not ask for.
Provisioning locks the manager row and deletion did not, so a concurrent re-provision could observe a child mid-deletion.
Every public and secret key validation ran a second query just to learn whether the credential belongs to a managed profile, on the hottest authenticated paths.
The partner-facing pages are whitelabeled, and this line introduced provider brand names to describe which routes accept a managed child.
Also corrects two audit-facing imprecisions: the retry checklist still called MAX_RETRIES (8) a hard limit despite handler overrides, and invariant 12 claimed every request mismatch pauses for reconciliation when only the subsidy executors opt in via reconcileRequestMismatch.
Reduce vortex-review skill token consumption
Big.toString switches to exponential form at 1e21, which 18-decimals tokens reach at ~1000 units and defeats eyeballing one-unit shortfalls. Also covers the native-variant timeout message, which was untested.
The incident class fixed at the Nabla swap also existed one phase later: the destination-transfer precondition reconstructed its required raw from the decimal quote.outputAmount, which with an unrounded partner subsidy demands one raw unit more than subsidize-post funded and the presigned transfer spends, wedging same-chain BUY ramps. Flooring the subsidy to token decimals keeps the flow-final decimal/raw pair consistent, and the executor now reads the destinationTransfer block metadata raw. The offramp subsidize-post and both Pendulum Nabla blocks now carry or derive from the canonical raw too, and expected-output raws scale by the actual token decimals instead of a hardcoded 10^6.
…ntime Retire Moonbeam runtime operations
…rounding Prevent one-micro-USDC Nabla swap shortfalls
…flows Improve coding-agent setup and worktree bootstrap
A zero-fee presign is now admitted at registration when the server envelope is zero, but calculatePresignedGasBudgetRaw still treated the viem-decoded-absent fee as fatal missing data, so such a ramp would fail at payout execution instead of up front. An absent decoded fee means the transaction genuinely carries a zero fee, so it yields a zero budget.
…flows Require lean and safe fixes from coding agents
✅ Deploy Preview for vrtx-dashboard ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for vortex-sandbox ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for vortexfi ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
…ity-fee Accept zero EIP-1559 priority fees
…n-recovery Recover EVM subsidy transfers after pre-broadcast rejection
# Conflicts: # .github/workflows/autodeploy.yaml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.