Skip to content

fix(identity): issue Coinflow sessions for verified wallets - #14614

Merged
raymondjacobson merged 1 commit into
mainfrom
codex/coinflow-session-auth-backend
Sep 29, 2026
Merged

raymondjacobson merged 1 commit into
mainfrom
codex/coinflow-session-auth-backend

Conversation

@raymondjacobson

@raymondjacobson raymondjacobson commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Coinflow is retiring wallet/blockchain-only authentication. Add POST /coinflow/session-key to identity service so authenticated clients can obtain a session using a server-side merchant API key.

The endpoint requires a fresh Ed25519 proof of ownership of the root Solana wallet, bound to the authenticated identity and environment. The public spl_wallet is a user bank, so it cannot be used to identify the Coinflow wallet. Responses are non-cacheable; timeouts, malformed upstream responses, and upstream errors fail closed without exposing credentials.

Rollout: deploy this PR first with coinflowApiKey and coinflowEnvironment. The API key must match the clients' merchant (audius in sandbox, tikilabs in production). Client PR #14615 must follow this configured deployment. Deployment instructions and sandbox/device checks are in the identity-service README. No database migration is needed.

Validation: 8 isolated backend tests pass, covering wallet/identity/signature tampering, stale/future proofs, environment mismatch, missing configuration, upstream response validation, and credential-safe errors. Targeted lint passes with dependency-resolution checks disabled in the isolated environment; git diff --check passes. Full npm run verify could not start because this checkout has no project dependencies (turbo: command not found). Live Coinflow and full identity-service integration tests have not been run.

@changeset-bot

changeset-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 46ef99f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@raymondjacobson
raymondjacobson merged commit 741db1c into main Sep 29, 2026
8 checks passed
@raymondjacobson
raymondjacobson deleted the codex/coinflow-session-auth-backend branch September 29, 2026 01:52
raymondjacobson added a commit that referenced this pull request Sep 29, 2026
Coinflow purchase and withdrawal now wait for a session key before
rendering on web and mobile. A shared hook signs a root-wallet ownership
proof, requests the key from identity service, keeps it in memory,
refreshes it after 25 minutes, and stops using it before expiry. Loading
and retry UI covers authentication failures.

Keys are scoped to identity, wallet, account, and environment; stale
adapter initialization and late responses cannot carry a previous
account's credentials into the new account. All four components retain
their transaction-signing adapters. The pinned SDKs already forward
session keys, so no SDK upgrade is required. Correct the common Vitest
source alias so the new hook tests resolve their mocked modules.

**Rollout:** this PR is stacked on [the backend session endpoint PR
#14614](#14614). Merge and
deploy that endpoint with the matching Coinflow API key/environment
before merging this PR. Release the mobile update as well as web, then
test purchase/withdrawal in sandbox on web, iOS, and Android, including
guest checkout, expiry/retry, and account switching. Confirm completion
with Coinflow only after production rollout and verification.

**Validation:** 6 hook tests pass with React 19 and the pinned TanStack
Query version in an isolated dependency environment. They cover the
signing proof, closed-modal gating, refresh failure/expiry/retry,
account/logout isolation, late wallet responses, stale adapters, and
expired credentials. Scoped hook typechecking and prop compatibility
checks against web SDK 5.9.1 / native SDK 4.5.2 pass. Targeted lint
passes with dependency-resolution checks disabled; `git diff --check`
passes. Full `npm run verify` could not start (`turbo: command not
found`); full application typechecks, live checkout, and iOS/Android
device tests remain unrun.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant