Skip to content

Release 2.11.0: pre-payment verification path on conditional gates - #143

Merged
vvillait88 merged 1 commit into
mainfrom
feat/verify-session-on-conditional-gates
Sep 29, 2026
Merged

vvillait88 merged 1 commit into
mainfrom
feat/verify-session-on-conditional-gates

Conversation

@vvillait88

@vvillait88 vvillait88 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Release 2.11.0: the pre-payment verification path now works on the conditional gate adapters too, not only on Checkout. Worked with Varun.

2.10.0 let an identity-gated Checkout answer X-Verification-Session: create with the session 403. A merchant mounting the gate itself with a conditional adapter variant still ran the gate only on a payment credential. This release makes the rule one shared predicate:

  • should_run_conditional_gate(request_or_headers): a payment credential, or requests_verification_session(...) (the header set to create, case-insensitive, with no identity and no payment). Every conditional variant uses it: aiohttp, Django, FastAPI, Flask, the ASGI middleware and Sanic.
  • has_identity_header(...): operator token, wallet address, or a non-empty Agent-Identity.
  • build_identity_bootstrap(): the identity_bootstrap 402 block. Checkout now builds its block with it, and a merchant building its own 402 passes it in build_402_body's extra.
  • VERIFICATION_SESSION_HEADER / VERIFICATION_SESSION_VALUE move to agentscore_commerce.payment.payment_header, still exported from the top level.

Checkout drops its private copies of these checks. The README's hand-rolled conditional example and CLAUDE.md describe the shared predicate.

Type of change

  • Bug fix (no breaking change)
  • New feature (no breaking change)
  • Breaking change (existing callers must update)
  • Docs, tests, or internal maintenance only

Public API

Additive: should_run_conditional_gate, requests_verification_session, has_identity_header, VERIFICATION_SESSION_VALUE (top level and agentscore_commerce.payment), and build_identity_bootstrap (top level and agentscore_commerce.challenge). VERIFICATION_SESSION_HEADER keeps its top-level export. Behavior change on conditional variants: a request carrying X-Verification-Session: create and no identity or payment now runs the gate; every other request behaves as before.

Test plan

  • tests/test_verification_session.py: header handling, suppression by each identity and payment header, empty Agent-Identity, the predicate's truth table, and the builder.
  • tests/test_fastapi.py: the header with no identity runs the gate and returns the session 403 without calling assess; the header with an operator token flows through with neither assess nor session calls. With the adapter pointed back at has_payment_header, the first fails and the second passes.
  • Ran locally, as CI runs them: ruff check, ruff format --check, ty (package and examples), vulture, pytest (1886 passed, 4 skipped, 95.40% coverage).
  • Review loop: 2 rounds, both clean.

Checklist

  • Tests cover the new behavior, and the suite passes locally
  • Lint, format, and type checks pass
  • Docs and README examples updated if the public surface changed
  • No secrets, credentials, or personal data in the diff or the tests

@vvillait88
vvillait88 merged commit 5616b3a into main Sep 29, 2026
7 checks passed
@vvillait88
vvillait88 deleted the feat/verify-session-on-conditional-gates branch September 29, 2026 05:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant