Problem
A failed refund or callback can leave a stream marked canceled while funds remain locked or become withdrawable twice.
Objective
Deliver a production-quality improvement to cancel path, refunds, and stream state that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
- Perform checks and state transitions atomically; define refund destination and failure behavior; prevent repeat cancellation.
Acceptance criteria
- Any failed cancellation leaves status and balances unchanged; successful cancellation refunds exactly once; subsequent withdrawals follow policy.
Required validation
- Refund failure injection, repeat cancel, balance invariant, and state-machine tests.
- Existing tests and CI remain passing.
- Add regression coverage for the original failure mode.
- Do not weaken, delete, or skip unrelated tests to obtain a green build.
PR quality bar
- Keep the PR focused and explain design tradeoffs, compatibility impact, and test evidence.
- Avoid typo-only, documentation-only, cosmetic-only, or unrelated refactor submissions.
Out of scope
- Broad rewrites not required by the acceptance criteria.
- Changes to unrelated services, contracts, or user flows.
Problem
A failed refund or callback can leave a stream marked canceled while funds remain locked or become withdrawable twice.
Objective
Deliver a production-quality improvement to cancel path, refunds, and stream state that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
Acceptance criteria
Required validation
PR quality bar
Out of scope