Repository navigation
v0.9.0
feat(codex-ouronet): Pythia consumer-API-key management — Single/Dual API tabs (v0.9.0)
Adds Pythia consumer-API-key management to the Ouronet accounts view.
Two new account sub-tabs (after Standard/Smart):
- Single API — two columns of the codex's Apollo halves (Standard ₱. left,
Smart Π. right), each with search + pagination and live UNLINKED/LINKED/
not-deployed status (DPL-UR.URC_0031). Pick one unlinked half from each side
and Link them into a dual API key. - Dual API — the codex's mutually-linked ₱.|Π. composite keys, read via the new
DPL-UR.URC_0033_DualApiKeyMapper with Pythia prices from URC_0034_PythiaPrices.
Shows consumer-lane + active/revoked status with per-key Rename lane / Revoke.
Three ZBOM transaction modals, authorized by BOTH half-owners (P|TS):
- Link (no fee), Rename lane (100 STOA, undiscounted, 4-way split), Revoke
(1 IGNIS kill-switch). Costs + split receivers are read from the on-chain INFO
so they never drift when prices change. Both owners' guards are resolved from
chain, deduped when shared, and any missing owner key is requested via the
standard manual-key input. Rename mirrors the proven deploy modal's patron +
payment-key + coin.TRANSFER split; Revoke mirrors the IGNIS-only rotate ops.
Post-transaction refresh: a usePostTxRefresh hook subscribes to the onTxConfirmed
event (previously fired into the void), so URC_0027 account state, URC_0031
API-key status, and the dual-link/price reads all re-fetch automatically once any
Codex tx confirms — no manual reload.
Also: isApiKeyRegistered reads the mapper's explicit is-registered flag
(owner-account fallback); linkage detected by "counterpart is an Apollo account"
rather than a sentinel string (fixes registered-but-unlinked halves reading as
linked); SigningZone no longer shows a permanent "Waiting for account data…"
spinner for owner-only (no-patron) transactions; Rename/Revoke disable on an
already-revoked link; a clear "half not in this Codex" blocker replaces a stuck
spinner for cross-owner keys. Playground vite.config port-resolution fixed (the
constructors/ reorg left it one dir too shallow, silently falling back to :5173).
All three tx types live-tested on-chain by the owner. Adversarially reviewed
(no injection, no one-owner-signing bypass, no duplicate signers, no secret
leakage, no listener leak). codex-ouronet + codex bump 0.8.1 -> 0.9.0 (MINOR,
additive). Full workspace typecheck/build green; codex-ouronet 724 tests green.
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com