Conversation
# Conflicts: # docs/proposal-headless-profiles-and-pricing-plans.md
# Conflicts: # apps/api/src/api/controllers/brla.controller.test.ts # apps/api/src/api/controllers/brla.controller.ts # docs/security-spec/05-integrations/brla.md # packages/shared/src/services/brla/brlaApiService.test.ts # packages/shared/src/services/brla/brlaApiService.ts # packages/shared/src/services/brla/mappings.ts # packages/shared/src/services/brla/schemas.test.ts # packages/shared/src/services/brla/schemas.ts # packages/shared/src/services/brla/types.ts
# Conflicts: # docs/api/openapi/vortex.openapi.d.ts # docs/api/openapi/vortex.openapi.json # docs/api/pages/10-sandbox.md # docs/api/scripts/check-openapi.ts # docs/security-spec/05-integrations/alfredpay.md # docs/security-spec/05-integrations/brla.md
Bring the managed-profile idempotency ledger (runFinancialOperation, the 064 profile-scope migration) and the associated infrastructure into the streamlined KYC/KYB branch. createSubaccount now claims an exactly-once financial operation keyed on the tax-reference hash, keeping HEAD's Avenia attempt-state simplification while removing the overwrite-on-retry hazard. Resolve conflicts in favor of HEAD's Avenia simplification (no submission state machine) plus the merged idempotency block. Regenerate the wire-contract snapshot for the now-required record-attempt quoteId, and fix check-openapi to resolve the record-attempt request-body $ref before asserting its required fields. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Avenia omits resultMessage and retryable until an attempt settles, so a PENDING poll parsed by aveniaAttemptSchema raised a ZodError that surfaced to the client as a 502 and could permanently block hosted KYB resume. Make both fields optional in the schema and the KycAttempt / AveniaVerificationAttempt types; every consumer already reads them optional-safely. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
recordInitialKycAttempt only null-checked quoteId and never used it, so any authenticated caller could plant a Consulted provider_customers marker on another profile's CPF/CNPJ — a started row that then blocks the rightful owner's createSubaccount. Assert the caller owns the referenced quote and that it is a Brazil corridor (BRL on either leg) before persisting the marker. Update the F-064 security-spec entry to record quoteId as an authorization input. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Adds the requirements-discovery endpoint, the BR individual and KYB Level 1 API sequences with their retry/reconciliation semantics, the bank-transfer corridors' three onboarding modes, and an AI-agent section covering how to consume discovery. Fixes the stale claim that onboarding requires the Vortex app or Widget.
Adds a workflow page covering child provisioning, delegation vs child-owned credentials, delegated onboarding including the BR token-import ordering rule, ramping on behalf, pricing inheritance, and common errors. Links it from the overview, auth contract, and AI-agent pages and registers it in the Apidog page manifest.
Replaces Avenia/Alfredpay/BRLA prose mentions with neutral provider wording across the corridor, auth, ramp-lifecycle, and KYB pages. Path literals for the supported legacy /v1/brla and /v1/alfredpay aliases stay, as do the branded values still emitted by the OpenAPI document, discovery payload, and API error strings - making those agnostic is a wire-contract change tracked separately.
Partner-visible identifiers were named after the payment partners behind them, so a change of provider would break the published contract. Name them after the corridor family instead: Br for the BRL corridor and Domestic for the USD/MXN/COP/ARS bank-transfer corridors. Renames 52 OpenAPI schemas, 34 operationIds, the TypeScript endpoint contracts backing them, ~60 public error messages, and the SDK's exported types and error classes. Discovery now reports `family` instead of `provider` and drops the brand segment from `flow` ids. Documents the canonical /v1/brl/* paths and adds /v1/domestic as a country-neutral mount alongside the existing /v1/ar|co|mx ones. Shapes, wire values, and behavior are unchanged. Legacy /v1/brla and /v1/alfredpay routes keep working, previous SDK export names remain as deprecated aliases, and internal provider-protocol types, the BRLA token ticker, and the onboarding-status `provider` field stay as they are.
submitStandardAveniaKyc caught every submitKycLevel1 failure and recorded the claim as ambiguous. Avenia answers an invalid Level 1 payload with a 400, so a routine data-entry rejection was quarantined as an unknown outcome. Nothing transitions ambiguous back to a preparable state: a corrected payload failed the fingerprint binding with 409, an identical retry found no candidate attempt to reconcile, and getKycStatus, onboarding aggregation, and the webhook outcome writers all refuse to act on an ambiguous claim with no bound attempt. Only a manual database edit cleared it. Classify deterministic 4xx the way UBO creation already does and release the claim as failed, which prepareSubmission re-prepares. Retryable statuses and transport failures stay ambiguous because the POST may still have reached Avenia.
importBrKycToken classified only provider 401 as failed, so a deterministic rejection of the share token was quarantined as ambiguous. That left the claim unrecoverable under any idempotency key even though the rejected token created no attempt and transferred no data. Classify deterministic 4xx as failed there too. Recovery still requires a new idempotency key, so the original token is never replayed automatically and the ambiguous quarantine keeps covering timeouts, rate limits, conflicts and 5xx, where the send may have reached Avenia. The predicate now lives in one module instead of being restated in each service, since the defect in both paths was a classification that existed in one send site and not another.
[Ready] Implement and unify KYC/B processes via API.
✅ Deploy Preview for vrtx-dashboard ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for vortexfi ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for vortex-sandbox ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.