feat: add hash_operator_token helper - #22
Merged
Merged
Conversation
Canonical sha256 hex digest for plaintext operator tokens. Merchants hash them before storing in DB columns and before comparing against persisted hashes, so plaintext tokens never land in durable storage. Tests lock 6 fixtures with hardcoded digests as the cross-language contract with the Node sibling at @agent-score/commerce. Parametrized so multiple drifts surface independently rather than short-circuiting. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…atches) uv lock --upgrade picked up: - x402 2.9.0 -> 2.10.0 (minor) - cdp-sdk 1.45.0 -> 1.45.1 - ruff 0.15.12 -> 0.15.13 - solana 0.36.11 -> 0.36.12 - requests 2.34.0 -> 2.34.1 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
vvillait88
added a commit
that referenced
this pull request
May 14, 2026
## Summary Additive update to the README inventory table — documents the helpers that landed in PRs #22–#29 + the public-surface guard in #30. Pure docs, no code changes. ## What was added **`agentscore_commerce.identity` (package level)** row: - `load_ucp_signing_key_from_env` + `LoadUCPSigningKeyOptions` (env-driven UCP signing key loader; cached, alg-detected, sanitized errors) - `hash_operator_token` (sha256 hex of plaintext `opc_...` for merchants persisting `operator_token_id` to their own DB) **`agentscore_commerce.payment`** row: - `extract_payment_signer` now documents both the positional `x402_payment_header` path AND the `authorization_header=` MPP kwarg (`did:pkh:eip155` / `did:pkh:solana` source DIDs) - `detect_rail_from_headers` (returns `"x402"` / `"mpp"` / `None`) - `classify_orchestration_error` (companion to `classify_x402_settle_result` for orchestration-time exceptions) - `zero_amount_carve_out` (skip CDP/pympp upstream when settle_cents == 0) - `usd_to_atomic` (Decimal-based USD → atomic int, ROUND_HALF_UP) ## Test plan Docs-only; no code changes. Markdown renders cleanly in the existing table. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
agentscore_commerce.identity.hash_operator_token.Tests
@agent-score/commerce.Test plan
uv run pytest tests/test_tokens.py— 9 tests passuv run pytest— full suite 891 pass / 3 skip, coverage 95.02%uv run ruff check,uv run ruff format --check,uv run ty check— green🤖 Generated with Claude Code