Repository navigation
Conversation
Extend the distribution contract coverage for the packaged binary by asserting that the bundled Flysystem rejects malformed paths while still normalizing valid paths as expected. This also captures the related Flysystem lockfile update that the new assertions depend on.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The broad security-sensitive credential migration, locking behavior, selection precedence, and packaged-runtime impact require final human verification.
Review effort: Balanced
Findings: None
What changed in this PR
Introduces multi-merchant credential storage and selection for Quickpay CLI, replacing the previous single-credential authentication workflow.
Changes:
- Adds secure named merchant storage, project bindings, explicit selection, and merchant management commands.
- Pins authenticated clients to resolved credentials and surfaces merchant context for sensitive operations.
- Updates documentation, tests, the bundled skill, and Flysystem.
| File | Description |
|---|---|
tests/Unit/Credentials/MerchantNameTest.php |
Tests merchant-name validation. |
tests/Unit/Credentials/MerchantConfigurationJsonTest.php |
Tests duplicate JSON-property detection. |
tests/Unit/Credentials/ApiKeyResolverTest.php |
Tests credential-selection precedence and conflicts. |
tests/Integration/Credentials/ProjectMerchantFileTest.php |
Tests project binding discovery and validation. |
tests/Integration/Credentials/MerchantStoreTest.php |
Tests secure, atomic merchant persistence. |
tests/Integration/Credentials/CredentialFileTest.php |
Removes obsolete single-credential tests. |
tests/Feature/Quickpay/MerchantAuthenticationCheckTest.php |
Tests merchant-scope validation. |
tests/Feature/Quickpay/AuthenticatedQuickpayFactoryTest.php |
Tests pinned authenticated credentials. |
tests/Feature/Console/AuthenticatedCommandTest.php |
Covers merchant-aware authenticated commands. |
tests/Feature/Commands/Payments/PaymentMutationCommandsTest.php |
Isolates project selection in mutation tests. |
tests/Feature/Commands/Payments/ListPaymentsCommandTest.php |
Adapts missing-credential behavior and setup. |
tests/Feature/Commands/Payments/GetPaymentCommandTest.php |
Isolates project selection. |
tests/Feature/Commands/Payments/CreatePaymentLinkCommandTest.php |
Isolates project selection. |
tests/Feature/Commands/Payments/CreatePaymentCommandTest.php |
Isolates project selection. |
tests/Feature/Commands/Merchants/MerchantCommandsTest.php |
Covers merchant-management workflows. |
tests/Feature/Commands/Callbacks/WatchCallbacksCommandTest.php |
Isolates callback project selection. |
tests/Feature/Commands/Callbacks/ReplayCallbackCommandTest.php |
Isolates callback project selection. |
tests/Feature/Commands/Authentication/AuthenticationCommandsTest.php |
Removes superseded authentication tests. |
tests/Feature/Commands/Api/ApiRequestCommandTest.php |
Isolates raw API project selection. |
tests/Feature/CommandHelpTest.php |
Verifies merchant options and skill commands. |
tests/Feature/ApplicationIdentityTest.php |
Updates the public command inventory. |
tests/Architecture/SkillContractTest.php |
Validates bundled skill naming and references. |
tests/Architecture/DistributionContractTest.php |
Tests updated Flysystem path handling. |
skills/quickpay-cli/SKILL.md |
Documents merchant-aware agent workflows. |
SECURITY.md |
Documents credential and selection invariants. |
README.md |
Documents merchant setup and usage. |
CONTRIBUTING.md |
Updates the skill path. |
composer.lock |
Updates Flysystem to 3.35.3. |
app/Quickpay/MerchantAuthenticationCheck.php |
Adds merchant-scope authentication checks. |
app/Quickpay/AuthenticatedQuickpayFactory.php |
Supports explicit merchant resolution. |
app/Providers/AppServiceProvider.php |
Registers the new credential services. |
app/Credentials/ProjectMerchantFile.php |
Implements project merchant bindings. |
app/Credentials/MerchantStore.php |
Implements locked named-credential storage. |
app/Credentials/MerchantName.php |
Validates merchant labels. |
app/Credentials/MerchantConfigurationJson.php |
Rejects ambiguous duplicate properties. |
app/Credentials/CredentialFile.php |
Removes single-credential persistence. |
app/Credentials/ApiKeyResolver.php |
Implements merchant-selection precedence. |
app/Credentials/ApiKey.php |
Carries merchant-selection context. |
app/Console/AuthenticatedCommand.php |
Adds --merchant and context output. |
app/Commands/Payments/AbstractPaymentMutationCommand.php |
Adds merchant details to confirmations. |
app/Commands/Merchants/SelectMerchantCommand.php |
Adds global and project selection. |
app/Commands/Merchants/RemoveMerchantCommand.php |
Adds credential removal. |
app/Commands/Merchants/ListMerchantsCommand.php |
Adds merchant listing. |
app/Commands/Merchants/AddMerchantCommand.php |
Adds validated credential enrollment. |
app/Commands/Merchants/ActiveMerchantCommand.php |
Adds local and checked status reporting. |
app/Commands/Callbacks/WatchCallbacksCommand.php |
Reports pinned watcher context. |
app/Commands/Authentication/LogoutCommand.php |
Removes obsolete logout command. |
app/Commands/Authentication/LoginCommand.php |
Removes obsolete login command. |
app/Commands/Authentication/AuthCommand.php |
Removes obsolete auth command. |
app/Commands/Api/ApiRequestCommand.php |
Reports merchant context for mutations. |
AGENTS.md |
Updates repository guidance and invariants. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.