Skip to content

fix: adopt core bip21 validation - #1454

Draft
pwltr wants to merge 1 commit into
masterfrom
codex/adopt-core-bip21-validation
Draft

pwltr wants to merge 1 commit into
masterfrom
codex/adopt-core-bip21-validation

Conversation

@pwltr

@pwltr pwltr commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

This PR delegates Bitcoin payment URI validation to the shared core decoder instead of the app-side substring workaround.

Draft: blocked on bitkit-core #151 being merged and released. The current draft intentionally still uses 0.5.18; the dependency bump will follow once the release exists.

Description

  • Removes the substring guard from scanning and manual entry so legitimate bitcoin: text in query metadata is accepted.
  • Keeps core decoding failures on the existing invalid-address and incoming-payment-request failure paths so rejected data cannot become a new payment.
  • Replaces heuristic tests with app delegation and real Android native-binding coverage while preserving invoice generation.
  • Adds the same deeplink journey as iOS so the two platforms verify matching payment behavior.

Merge blockers

  • Merge and release bitkit-core Navigation intro buy #151, then bump bitkit-core in the version catalog to that actual published Android SDK release.
  • Run Bip21DecodingTest.kt against the released SDK. Its duplicate-key cases are expected to fail against 0.5.18; a mocked app test is not proof of native decoder correctness.
  • Rerun compile, unit tests and lint after the bump, then run the shared deeplink journey on both platforms and verify clipboard/manual-entry behavior.

Out of Scope

  • Core parser: complete BIP321 and general required-parameter semantics beyond Navigation intro buy #151.
  • Payments: unrelated network, fee, Quickpay and payment-method selection changes.

Design

N/A — no UI changes.

Preview

N/A — validation only.

QA Notes

Journeys

  • new bip21-core-validation.xml — valid metadata preserves recipient/amount; the original concatenated URI and duplicate parameters cannot open a payment sheet. Not run: requires the released SDK containing Navigation intro buy #151.

Manual Tests

  • Copy a valid Bitcoin URI with message=bitcoin:donation to the system clipboard → return to Home and confirm Read Clipboard → the correct payment opens; repeat with the String formmating error lint #63 malformed URI → no payment opens — arbitrary OS clipboard injection is not in Capabilities.

Automated Checks

  • added Bip21DecodingTest.kt — checks the actual Android native decoder using the String formmating error lint #63 fixture, duplicate singleton keys, valid metadata and question marks in notes; device execution is pending the SDK release.
  • updated AppViewModelSendFlowTest.kt — verifies manual-entry, scanning and clipboard delegation, rejected-payment state clearing, and incoming-payment-request failure feedback.
  • removed substring-workaround cases in Bip21UrlBuilderTest.kt — replaced by decoder integration coverage; invoice generation tests remain.
  • ran the full unit suite — 3,628 tests executed; three new mock-stub failures were corrected, then all 365 cases in AppViewModelSendFlowTest.kt passed on the focused rerun.
  • ran native-test compilation — the new Android binding coverage compiles against 0.5.18, but its device execution remains pending the fixed SDK release.
  • ran shared journey XML checks — the platform journey files are identical; neither device journey was run against the unfixed SDK.

iOS counterpart: #909.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant