Skip to content

Create new production release - #1345

Merged
ebma merged 44 commits into
mainfrom
staging
Aug 19, 2026
Merged

ebma merged 44 commits into
mainfrom
staging

Conversation

@ebma

@ebma ebma commented Aug 19, 2026

Copy link
Copy Markdown
Member

No description provided.

gianfra-t and others added 30 commits August 5, 2026 17:25
# Conflicts:
#	docs/proposal-headless-profiles-and-pricing-plans.md
# Conflicts:
#	apps/api/src/api/controllers/brla.controller.test.ts
#	apps/api/src/api/controllers/brla.controller.ts
#	docs/security-spec/05-integrations/brla.md
#	packages/shared/src/services/brla/brlaApiService.test.ts
#	packages/shared/src/services/brla/brlaApiService.ts
#	packages/shared/src/services/brla/mappings.ts
#	packages/shared/src/services/brla/schemas.test.ts
#	packages/shared/src/services/brla/schemas.ts
#	packages/shared/src/services/brla/types.ts
# Conflicts:
#	docs/api/openapi/vortex.openapi.d.ts
#	docs/api/openapi/vortex.openapi.json
#	docs/api/pages/10-sandbox.md
#	docs/api/scripts/check-openapi.ts
#	docs/security-spec/05-integrations/alfredpay.md
#	docs/security-spec/05-integrations/brla.md
Bring the managed-profile idempotency ledger (runFinancialOperation, the
064 profile-scope migration) and the associated infrastructure into the
streamlined KYC/KYB branch. createSubaccount now claims an exactly-once
financial operation keyed on the tax-reference hash, keeping HEAD's Avenia
attempt-state simplification while removing the overwrite-on-retry hazard.

Resolve conflicts in favor of HEAD's Avenia simplification (no submission
state machine) plus the merged idempotency block. Regenerate the
wire-contract snapshot for the now-required record-attempt quoteId, and fix
check-openapi to resolve the record-attempt request-body $ref before
asserting its required fields.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Avenia omits resultMessage and retryable until an attempt settles, so a
PENDING poll parsed by aveniaAttemptSchema raised a ZodError that surfaced
to the client as a 502 and could permanently block hosted KYB resume.
Make both fields optional in the schema and the KycAttempt /
AveniaVerificationAttempt types; every consumer already reads them
optional-safely.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
recordInitialKycAttempt only null-checked quoteId and never used it, so any
authenticated caller could plant a Consulted provider_customers marker on
another profile's CPF/CNPJ — a started row that then blocks the rightful
owner's createSubaccount. Assert the caller owns the referenced quote and
that it is a Brazil corridor (BRL on either leg) before persisting the
marker. Update the F-064 security-spec entry to record quoteId as an
authorization input.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gianfra-t and others added 14 commits August 18, 2026 12:11
Adds the requirements-discovery endpoint, the BR individual and KYB
Level 1 API sequences with their retry/reconciliation semantics, the
bank-transfer corridors' three onboarding modes, and an AI-agent
section covering how to consume discovery. Fixes the stale claim that
onboarding requires the Vortex app or Widget.
Adds a workflow page covering child provisioning, delegation vs
child-owned credentials, delegated onboarding including the BR
token-import ordering rule, ramping on behalf, pricing inheritance,
and common errors. Links it from the overview, auth contract, and
AI-agent pages and registers it in the Apidog page manifest.
Replaces Avenia/Alfredpay/BRLA prose mentions with neutral provider
wording across the corridor, auth, ramp-lifecycle, and KYB pages. Path
literals for the supported legacy /v1/brla and /v1/alfredpay aliases
stay, as do the branded values still emitted by the OpenAPI document,
discovery payload, and API error strings - making those agnostic is a
wire-contract change tracked separately.
Partner-visible identifiers were named after the payment partners behind
them, so a change of provider would break the published contract. Name
them after the corridor family instead: Br for the BRL corridor and
Domestic for the USD/MXN/COP/ARS bank-transfer corridors.

Renames 52 OpenAPI schemas, 34 operationIds, the TypeScript endpoint
contracts backing them, ~60 public error messages, and the SDK's exported
types and error classes. Discovery now reports `family` instead of
`provider` and drops the brand segment from `flow` ids. Documents the
canonical /v1/brl/* paths and adds /v1/domestic as a country-neutral mount
alongside the existing /v1/ar|co|mx ones.

Shapes, wire values, and behavior are unchanged. Legacy /v1/brla and
/v1/alfredpay routes keep working, previous SDK export names remain as
deprecated aliases, and internal provider-protocol types, the BRLA token
ticker, and the onboarding-status `provider` field stay as they are.
submitStandardAveniaKyc caught every submitKycLevel1 failure and recorded
the claim as ambiguous. Avenia answers an invalid Level 1 payload with a
400, so a routine data-entry rejection was quarantined as an unknown
outcome. Nothing transitions ambiguous back to a preparable state: a
corrected payload failed the fingerprint binding with 409, an identical
retry found no candidate attempt to reconcile, and getKycStatus,
onboarding aggregation, and the webhook outcome writers all refuse to act
on an ambiguous claim with no bound attempt. Only a manual database edit
cleared it.

Classify deterministic 4xx the way UBO creation already does and release
the claim as failed, which prepareSubmission re-prepares. Retryable
statuses and transport failures stay ambiguous because the POST may still
have reached Avenia.
importBrKycToken classified only provider 401 as failed, so a deterministic
rejection of the share token was quarantined as ambiguous. That left the
claim unrecoverable under any idempotency key even though the rejected
token created no attempt and transferred no data.

Classify deterministic 4xx as failed there too. Recovery still requires a
new idempotency key, so the original token is never replayed automatically
and the ambiguous quarantine keeps covering timeouts, rate limits,
conflicts and 5xx, where the send may have reached Avenia.

The predicate now lives in one module instead of being restated in each
service, since the defect in both paths was a classification that existed
in one send site and not another.
[Ready] Implement and unify KYC/B processes via API.
@netlify

netlify Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for vrtx-dashboard ready!

Name Link
🔨 Latest commit b106a3c
🔍 Latest deploy log https://app.netlify.com/projects/vrtx-dashboard/deploys/6a85fb4327151f00085163bd
😎 Deploy Preview https://deploy-preview-1345--vrtx-dashboard.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for vortexfi ready!

Name Link
🔨 Latest commit b106a3c
🔍 Latest deploy log https://app.netlify.com/projects/vortexfi/deploys/6a85fb43272dba00083277f3
😎 Deploy Preview https://deploy-preview-1345--vortexfi.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for vortex-sandbox ready!

Name Link
🔨 Latest commit b106a3c
🔍 Latest deploy log https://app.netlify.com/projects/vortex-sandbox/deploys/6a85fb438931a600091a2168
😎 Deploy Preview https://deploy-preview-1345--vortex-sandbox.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@ebma
ebma merged commit d211638 into main Aug 19, 2026
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants