Skip to content

fix(web): resolve Privy wallet payment selection - #123

Merged
SuPuHe merged 1 commit into
developfrom
fix/restore-user-wallet-prepare
Sep 13, 2026
Merged

SuPuHe merged 1 commit into
developfrom
fix/restore-user-wallet-prepare

Conversation

@SuPuHe

@SuPuHe SuPuHe commented Sep 13, 2026

Copy link
Copy Markdown
Member

Summary

Fix the Privy user-wallet payment flow so Privy users without a linked wallet receive an embedded Ethereum wallet and connected EVM wallets are selected correctly.

Scope and acceptance criteria

  • Create embedded Ethereum wallets for Privy users without a linked wallet.
  • Select active or connected EVM wallets through Privy.
  • Keep Arc Testnet chain ID 5042002 unchanged.
  • Preserve existing payment preparation, receipt verification, and idempotency behavior.
  • No unrelated cleanup is included.

Product and security invariants

  • Tenant isolation remains fail-closed.
  • Sponsor authorization, auditability, and daily caps remain enforced where applicable.
  • Recipients cannot modify sponsor controls or access sponsor-only data.
  • No secrets or credentials are included.
  • Settlement boundary and UNKNOWN reconciliation logic are unchanged; this candidate changes only web wallet selection/configuration, tests, and context.

Validation

pnpm test: PASS — 78 files / 1043 tests
pnpm test:browser: PASS — 8/8 Chromium tests
pnpm typecheck: PASS
pnpm lint: PASS
pnpm format:check: PASS
pnpm check:generated: PASS
pnpm build: PASS
pnpm --filter @oneshot/web build: PASS
pnpm --filter @oneshot/web exec vitest run test/privy-session.test.tsx: PASS — 7/7
 git diff --cached --check: PASS

Independent review evidence

Gate A — exact candidate tree before push

  • Base commit SHA: 246a38af36e291b0538eb0a8f87d1f3b3f1def60

  • Candidate tree SHA: 3a0087bc0be6c2bfed8cfa69bb400039f9478f46

  • Candidate commit SHA: 3728338d60d68476e5d37ab7ae31c4d8c16bb6ad

  • Reviewer tool: free-pi-cli

  • Reviewer model: not exposed by platform

  • Verdict: VERDICT: PASS

  • Findings: no blocking findings. Residual risks: embedded-wallet browser UX is not covered by a real Privy browser session; Privy app IDs must be aligned before deployment; PostgreSQL-gated tests were not run locally because no container runtime was available.

  • The reviewed tree equals the committed tree (HEAD^{tree} = 3a0087bc0be6c2bfed8cfa69bb400039f9478f46).

Gate B — exact remote PR head

  • Pull request URL/number: to be filled after creation

  • Remote head commit SHA: to be filled after creation

  • Remote head tree SHA: to be filled after creation

  • Reviewer tool: free-pi-cli

  • Reviewer model: pending

  • Verdict: pending

  • Findings or residual risks: pending

  • Gate B reviewed the current remote head and matches Gate A's approved tree, or a fresh Gate A was run for the changed tree.

  • Agent policy / repository-policy and all applicable CI checks pass.

Risk and rollback

  • Residual risks: production frontend/backend Privy app IDs must use the same Privy application; the policy must be created in that application if policy enforcement is required.
  • Rollback: revert commit 3728338d60d68476e5d37ab7ae31c4d8c16bb6ad.

Human merge

  • A human owner has reviewed the evidence and will perform the merge.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
oneshot 3728338 Sep 13 2026, 04:46 AM

@SuPuHe
SuPuHe marked this pull request as ready for review September 13, 2026 04:46
@SuPuHe
SuPuHe merged commit fb76eb0 into develop Sep 13, 2026
5 checks passed
@selezenart
selezenart deleted the fix/restore-user-wallet-prepare branch September 13, 2026 14:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant