Skip to content

fix(payments): use Coinflow session keys on web and mobile - #14615

Merged
raymondjacobson merged 2 commits into
mainfrom
codex/coinflow-session-auth-clients
Sep 29, 2026
Merged

raymondjacobson merged 2 commits into
mainfrom
codex/coinflow-session-auth-clients

Conversation

@raymondjacobson

Copy link
Copy Markdown
Member

Coinflow purchase and withdrawal now wait for a session key before rendering on web and mobile. A shared hook signs a root-wallet ownership proof, requests the key from identity service, keeps it in memory, refreshes it after 25 minutes, and stops using it before expiry. Loading and retry UI covers authentication failures.

Keys are scoped to identity, wallet, account, and environment; stale adapter initialization and late responses cannot carry a previous account's credentials into the new account. All four components retain their transaction-signing adapters. The pinned SDKs already forward session keys, so no SDK upgrade is required. Correct the common Vitest source alias so the new hook tests resolve their mocked modules.

Rollout: this PR is stacked on the backend session endpoint PR #14614. Merge and deploy that endpoint with the matching Coinflow API key/environment before merging this PR. Release the mobile update as well as web, then test purchase/withdrawal in sandbox on web, iOS, and Android, including guest checkout, expiry/retry, and account switching. Confirm completion with Coinflow only after production rollout and verification.

Validation: 6 hook tests pass with React 19 and the pinned TanStack Query version in an isolated dependency environment. They cover the signing proof, closed-modal gating, refresh failure/expiry/retry, account/logout isolation, late wallet responses, stale adapters, and expired credentials. Scoped hook typechecking and prop compatibility checks against web SDK 5.9.1 / native SDK 4.5.2 pass. Targeted lint passes with dependency-resolution checks disabled; git diff --check passes. Full npm run verify could not start (turbo: command not found); full application typechecks, live checkout, and iOS/Android device tests remain unrun.

@changeset-bot

changeset-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: a186548

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

raymondjacobson added a commit that referenced this pull request Sep 29, 2026
Coinflow is retiring wallet/blockchain-only authentication. Add `POST
/coinflow/session-key` to identity service so authenticated clients can
obtain a session using a server-side merchant API key.

The endpoint requires a fresh Ed25519 proof of ownership of the root
Solana wallet, bound to the authenticated identity and environment. The
public `spl_wallet` is a user bank, so it cannot be used to identify the
Coinflow wallet. Responses are non-cacheable; timeouts, malformed
upstream responses, and upstream errors fail closed without exposing
credentials.

**Rollout:** deploy this PR first with `coinflowApiKey` and
`coinflowEnvironment`. The API key must match the clients' merchant
(`audius` in sandbox, `tikilabs` in production). [Client PR
#14615](#14615) must follow
this configured deployment. Deployment instructions and sandbox/device
checks are in the identity-service README. No database migration is
needed.

**Validation:** 8 isolated backend tests pass, covering
wallet/identity/signature tampering, stale/future proofs, environment
mismatch, missing configuration, upstream response validation, and
credential-safe errors. Targeted lint passes with dependency-resolution
checks disabled in the isolated environment; `git diff --check` passes.
Full `npm run verify` could not start because this checkout has no
project dependencies (`turbo: command not found`). Live Coinflow and
full identity-service integration tests have not been run.
Base automatically changed from codex/coinflow-session-auth-backend to main September 29, 2026 01:52
@raymondjacobson
raymondjacobson merged commit c5abd7e into main Sep 29, 2026
18 checks passed
@raymondjacobson
raymondjacobson deleted the codex/coinflow-session-auth-clients branch September 29, 2026 02:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant