Skip to content

0.5.0

Choose a tag to compare

@dzakwannajmi dzakwannajmi released this 27 Sep 22:16
· 31 commits to main since this release

All three packages move to 0.5.0 together: @wasit-dev/core, @wasit-dev/cli and @wasit-dev/server.

Two reporting fixes found by running Wasit against code it did not write, and one addition that brings the MCP server level with the CLI. No check was added or removed.

Results can change on upgrade

Only in two situations:

  • A target that issues an x402 v1 challenge. See the first fix below.
  • An MPP channel target that refuses a replay with a status other than 402 or 2xx. The verdict is still FAIL, but it no longer calls the refusal a double-spend.

Against a conformant v2 target nothing changes: Wasit's own x402 fixture passes 7/7 with this build, as it did with 0.4.0.

Fixed: x402 v1 challenges are read, and payment checks no longer fail when nothing was paid

Run with its operator's written authorization against a service that speaks x402 v1, 0.4.0 reported X402-02 FAIL, skipped X402-03–05, and reported X402-06 and X402-07 as FAIL although no payment was ever built or sent. X402-07 therefore read as a corrupted signature that was not rejected. docs/CHECKS.md already said a challenge that cannot be read has no verdict.

Now:

  • X402-02 still fails, because the exact scheme on Stellar is defined for v2 only. The failure now says an x402 v1 challenge was found in the response body.
  • X402-03–05 inspect that body instead of being skipped. X402-04 applies the v1 field names, and X402-05 reports whether the network is a CAIP-2 identifier.
  • X402-06 and X402-07 are skipped with the reason, for a v1 challenge or any challenge the payment client cannot read. Nothing is sent.

Seven new offline tests, each mutation-checked.

Fixed: MPP-12 and MPP-14 no longer call a refused replay a double-spend

Both reported any non-402 response as "accepted twice … This is a double-spend." The official MPP SDK's channel server on its main branch refuses replays with HTTP 500 (stellar/stellar-mpp-sdk#82), so Wasit claimed a double-spend while the server had in fact refused. The verdict stays FAIL, since the required status is 402, but the double-spend wording now appears only for a 2xx.

Added: wasit_x402_test accepts method, body and headers

The CLI has had --method, --body and --header since 0.1.0, but the MCP tool could only send a GET, so an agent could not test a paid POST endpoint. The same request shape now applies to every probe, including X402-06 and X402-07. A body sent with GET or HEAD is refused as a configuration error. Header values appear in the agent's transcript, so never pass a credential as a header; use the CLI for an endpoint that needs one.

Install

npx -y @wasit-dev/cli@0.5.0 --version
claude mcp add wasit -- npx -y @wasit-dev/server@0.5.0

Testnet only. A passing result means the service behaved as the spec requires for the published checks; it is not a security audit.

Verified before publishing

  • 120 offline tests pass; npm run typecheck is clean.
  • npm run verify:clean-install: the three tarballs install into an empty project, wasit-mcp completes an MCP handshake, and reports 0.5.0.
  • Full x402 suite against Wasit's own v2 fixture: 7/7.

Still planned

On-chain verification for X402-06, a signature-only corruption for X402-07, and exit code 2 from wasit wallet status --role on an unreadable key are now planned for 0.6.0. See the changelog.

Full changelog: v0.4.0...v0.5.0