Skip to content

fix(tap-seller): preserve signed query spelling - #87

Merged
nkavian merged 1 commit into
inflowpayai:mainfrom
nkavian:fix/tap-query-spelling
Oct 4, 2026
Merged

nkavian merged 1 commit into
inflowpayai:mainfrom
nkavian:fix/tap-query-spelling

Conversation

@nkavian

@nkavian nkavian commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Preserve the original query spelling when verifying TAP signatures, including literal versus percent-encoded characters.
  • Cover valid signatures, query tampering, empty queries, fragments, URL objects, and replay protection with independent signatures.
  • Clarify URL input and configured key trust in the package README, and add a patch changeset.
  • Pin the expanded conformance cases from test(tap): cover original query spelling inflow-specs#26. Merge that PR first.

Verification

  • Full pnpm verify on Node 22 and 24; Node 22 rerun with TURBO_FORCE=true.
  • pnpm check-exports, pnpm verify-publish, and pnpm changeset status --since=origin/main.
  • Runtime, MPP, x402, and TAP shared conformance suites on Node 22 and 24.
  • PATCH_COVERAGE_TARGET=100 pnpm coverage:changed and git diff --check.

No changes to key trust, time validation, replay policy, payments, or instrument support.

@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@nkavian
nkavian merged commit a658ccb into inflowpayai:main Oct 4, 2026
9 checks passed
@nkavian
nkavian deleted the fix/tap-query-spelling branch October 4, 2026 07:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant