Repository navigation
Shop v0.2.0
Shop v0.2.0
Released: 2026-09-13
Production: https://shop.pubky.app
Git: 049de2e7ec41dbf19535b5ec84a08bd697d0e61a
Vercel: dpl_6wK8KKY4ADCnTPeyPYietZ8znxi8
Added since Shop v0.1.0
- Sellers can confirm receipt of a service-observed Bitcoin payment from the order status surface.
- Sellers can resolve held or late Bitcoin payment reviews with bounded, typed outcomes.
- Seller review screens show six contract-defined payment observations without exposing them to buyers.
- Buyers receive a redacted manual-review status without seller-only evidence or controls.
Reliability and safety
- Confirmation and resolution requests use order-and-body-scoped idempotency keys.
- Changed-body conflicts clear stale intent and refetch canonical order state instead of retrying it.
- Authorization headers cannot be overridden by caller-supplied headers.
- Confirmation bodies never send transaction IDs or payment amounts.
- Unknown service errors become bounded static copy rather than exposing response bodies.
- Controls are restricted to sellers using the Bitcoin Paykit rail in valid states.
Retained from Shop v0.1.0
- Anonymous protected Shop routes redirect to the public catalog with one sign-in dialog.
- Seller-dashboard canonical refresh and the Awaiting payment order tab remain present.
Verification
- Integrated typecheck, lint, and production build passed.
- Full unit suite matched the established clean-base harness-debt baseline: 914/916 files and 14,118/14,121 tests passed, with no new failure signature.
- Seller-resolution focused tests: 151/151.
- Payment-state machine tests: 74/74.
- Production-component payment VRT: 66/66 with 12 new unique seller/buyer scene baselines.
- W1.16 Kimi payment/privacy audit: SHIP, no introduced P0/P1.
- V21 Kimi auth/session audit: SHIP, no introduced P0/P1.
- The promoted production deployment carries version
0.2.0, exact Git metadata, and serves the seller-resolution code paths.
Remaining production evidence
An authenticated real-order seller walkthrough still requires an existing controlled seller session. No replacement identity or fake payment state was created for this release.