Skip to content

fix(tap): recognize signed empty HTTP requests - #19

Merged
nkavian merged 1 commit into
inflowpayai:mainfrom
nkavian:fix/tap-request-verification
Oct 4, 2026
Merged

nkavian merged 1 commit into
inflowpayai:mainfrom
nkavian:fix/tap-request-verification

Conversation

@nkavian

@nkavian nkavian commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Recognize signed empty content in the TAP HTTP example when Content-Digest is present without framing headers.
  • Exercise acceptance, invalid-digest rejection, and replay rejection over real loopback HTTP.
  • Pin the shared contract containing original-query spelling regression cases.

Verification

  • make sync and make verify passed on Python 3.11, 3.12, 3.13, and 3.14, including coverage and isolated package consumers.
  • All supported runtime, MPP, x402, and TAP shared conformance cases passed.
  • The empty-request regression failed before the fix and passes afterward.

Depends on inflowpayai/inflow-specs#26. Merge that fixture update first. No payment, key-trust, signature-lifetime, or replay-policy changes.

@nkavian
nkavian merged commit 5aa2e06 into inflowpayai:main Oct 4, 2026
12 checks passed
@nkavian
nkavian deleted the fix/tap-request-verification branch October 4, 2026 07:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant