Add direct USDC checkout and advertise Pay with crypto - #2001
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 19992e1335
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| // CryptoConfigured advertises only native USDC on Base, the checkout supported | ||
| // by the browser signer and receipt verifier. | ||
| func CryptoConfigured() bool { return cryptoRequirement(100) != nil } |
There was a problem hiding this comment.
Check facilitator credentials before advertising crypto
When an operator sets only X402_PAY_TO, this predicate returns true and advertises checkout, even though the default Coinbase-hosted facilitator requires CDP credentials (internal/x402/x402.go documents this in Status). In that common configuration the customer can connect and sign, but every VerifySigned request is rejected for missing authentication, so checkout can never complete. Include facilitator authentication/readiness in this predicate for the hosted mainnet facilitator while preserving support for custom facilitators.
Useful? React with 👍 / 👎.
| if tx == "" && time.Now().Unix() < p.Before { | ||
| res, e := x402.SettleSigned(cryptoPayload(p), &p.Requirement) | ||
| if e != nil { |
There was a problem hiding this comment.
Settle with the persisted x402 version
If X402_VERSION is changed through live settings while an authorization is pending or before recovery after a restart, p.Requirement and cryptoPayload(p) retain the version the customer signed, but SettleSigned builds its facilitator request using the current global x402Ver(). The resulting mismatched envelope is rejected on every retry, leaving a valid signed payment pending until expiry. Derive the facilitator request version from the persisted requirement or payload for both verification and settlement.
Useful? React with 👍 / 👎.
Customers currently have to deposit USDC into a server-held wallet and then convert it. Add direct wallet checkout on the credit top-up page, with a “Pay with crypto” link on Pricing when native USDC on Base is configured. Preserve /wallet and its existing conversion flow.
The browser signs a fixed EIP-3009 authorization through an injected wallet (desktop extension or mobile wallet browser). Mu verifies it, persists the account-bound request before settlement, and adds credits through the existing ledger. Pending payments continue after closing the page and resume after restart. Recovery checks finalized on-chain authorization and Transfer events; expired requests are only released once the finalized chain proves no payment arrived. Retries credit once. Amounts are 1–500 USDC at 100 credits per USDC.
Validation: account, server, shell and CLI tests pass; concurrent payment recovery passes the race detector; full Go build passes with -buildvcs=false (workspace VCS stamping is unavailable); JS syntax and mocked checkout success/cancellation/rejection checks pass. Tests cover CSRF, amount bounds, account/nonce isolation, fixed signed terms, duplicate settlement, restart recovery, wrong transfer/token/recipient/amount, wrong network and finalized expiry.
No real-funds transaction or signed-in browser layout test was performed. This uses browser-provided wallets, not a WalletConnect QR flow. Runtime requires the existing x402 receiving address/facilitator setup and a Base RPC endpoint. No subscription or wallet-transfer changes.