Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions docs/paykit-interface.md
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,7 @@ Canonical defaults (today they drift):
| `operator.signer` | `Signer.demo` (refused on mainnet at boot) |
| `operator.fee_payer` | `true` |
| `mpp.realm` | `"App"` |
| `mpp.expires_in` | **120 seconds** (Ruby currently says 300 — align down) |
| `mpp.expires_in` | **120 seconds** |
| `x402.scheme` | `"exact"` |
| `preflight` | `true` |

Expand Down Expand Up @@ -265,7 +265,6 @@ What each SDK changes to meet this spec. Everything not listed is already
conformant.

**Ruby**
- `mpp.expires_in` default 300 → 120.
- Add `accepts?(protocol)` on `Gate`; keep `x402_accepted?` / `mpp_accepted?`
as deprecated aliases for one release.
- Add `payer` and ensure `scheme` on `Payment`.
Expand Down
6 changes: 3 additions & 3 deletions lua/pay_kit/internal/config.lua
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ Surface (issue #140):
mpp = {
realm = "MyApp",
challenge_binding_secret = "...",
expires_in = 300,
expires_in = 120,
},
})

Expand Down Expand Up @@ -200,15 +200,15 @@ function M.configure(opts)
local mpp = opts.mpp or {}
local mpp_realm = mpp.realm or 'App'
local mpp_secret = mpp.challenge_binding_secret
-- expires_in defaults to a short 300s TTL so issued challenges are not
-- expires_in defaults to a short 120s TTL so issued challenges are not
-- valid indefinitely (parity with Python/Rust/Ruby short-TTL defaults
-- and the PHP/Lua expiry-wiring fix). `expires_in = false` is the
-- explicit development opt-out: challenges are then issued with no
-- expiry. Any non-positive number is rejected so `0` is not silently
-- treated as "never expires".
local mpp_expires_in = mpp.expires_in
if mpp_expires_in == nil then
mpp_expires_in = 300
mpp_expires_in = 120
end
if mpp_secret ~= nil and type(mpp_secret) ~= 'string' then
return nil, 'pay_kit: mpp.challenge_binding_secret must be a string or nil'
Expand Down
2 changes: 1 addition & 1 deletion lua/pay_kit/protocols/mpp/init.lua
Original file line number Diff line number Diff line change
Expand Up @@ -241,7 +241,7 @@ function Adapter:challenge_headers(gate, _req)
if splits then options.splits = splits end
-- Wire the configured challenge TTL into issuance so signed challenges
-- are not valid indefinitely. `config.mpp.expires_in` is seconds-from-now
-- (default 300); `false` is the explicit development opt-out that leaves
-- (default 120); `false` is the explicit development opt-out that leaves
-- the challenge without an expiry. Mirrors PHP/Ruby/Python which seed a
-- short TTL at challenge construction rather than relying on every caller
-- to pass one. `verify_credential_with_expected` enforces the expiry via
Expand Down
2 changes: 1 addition & 1 deletion lua/plugins/kong/plugins/pay-kit/init.lua
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,7 @@ function M.setup()
mpp = {
realm = os.getenv('PAY_KIT_MPP_REALM') or 'PayKit (Kong)',
challenge_binding_secret = os.getenv('PAY_KIT_MPP_CHALLENGE_BINDING_SECRET'),
expires_in = env_int('PAY_KIT_MPP_EXPIRES_IN', 300),
expires_in = env_int('PAY_KIT_MPP_EXPIRES_IN', 120),
},
}
local ok, err = pay_kit.configure(opts)
Expand Down
2 changes: 1 addition & 1 deletion lua/tests/pay_kit/config_spec.lua
Original file line number Diff line number Diff line change
Expand Up @@ -146,7 +146,7 @@ end)
helper.test('configure() mpp.expires_in default + override', function()
reset()
assert(pay_kit.configure())
helper.assert_equal(pay_kit.config().mpp.expires_in, 300)
helper.assert_equal(pay_kit.config().mpp.expires_in, 120)

reset()
assert(pay_kit.configure({mpp = {expires_in = 60}}))
Expand Down
2 changes: 1 addition & 1 deletion lua/tests/pay_kit/kong_plugin_runtime_spec.lua
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@ helper.test('Kong bootstrap honours empty / blank env defaults', function()
restore_env()
local cfg = pay_kit.config()
helper.assert_equal(cfg.network, 'solana_devnet')
helper.assert_equal(cfg.mpp.expires_in, 300) -- env_int default
helper.assert_equal(cfg.mpp.expires_in, 120) -- env_int default
helper.assert_true(#cfg.accept >= 1)
end)

Expand Down
2 changes: 1 addition & 1 deletion ruby/lib/pay_kit/config.rb
Original file line number Diff line number Diff line change
Expand Up @@ -194,7 +194,7 @@ class MppConfig
def initialize
@realm = "App"
@challenge_binding_secret = nil
@expires_in = 300
@expires_in = 120
end

# Server-side HMAC secret used for stateless challenge binding
Expand Down
2 changes: 1 addition & 1 deletion ruby/test/pay_kit/config_test.rb
Original file line number Diff line number Diff line change
Expand Up @@ -184,7 +184,7 @@ def test_challenge_binding_secret_setter_and_reader

def test_mpp_expires_in_default_and_override
PayKit.configure { |_c| }
assert_equal 300, PayKit.config.mpp.expires_in
assert_equal 120, PayKit.config.mpp.expires_in

PayKit.reset!
PayKit.configure { |c| c.mpp.expires_in = 600 }
Expand Down
Loading