Conversation
🔧 CI Fix AvailableI've pushed a fix for the CI failure on this PR, rebuilt on the latest head ( What failed: The fix: drops the staging Behavior is unchanged: |
22a563b to
55056fd
Compare
# Conflicts: # cmd/vaults_commands.go # cmd/vaults_output_test.go
|
bugbot run verbose=true |
|
Bugbot request id: serverGenReqId_454b1f9d-c2e1-4cf2-a566-ba9f3b8fabc0 |
Bugbot rules debugBugbot rules included in this run
Bugbot request id: serverGenReqId_454b1f9d-c2e1-4cf2-a566-ba9f3b8fabc0 |
- temporarily replace kernel-go-sdk with the preview build for Link checkout cards - send credential updates through the generic client while the preview SDK lacks the item update method - omit fields from selector-free fills instead of sending an empty array - point fill help at each item's advertised fill description and drop authorize wording - drop merchant_url from display output and map browser_unavailable fill errors
Link card creation no longer contacts Link; authorize takes optional browser_id and page_url so Kernel can inspect the checkout and bind fill. - restore the card spec to main's shape (merchant_url, no browser binding) - accept browser_id/page_url together on authorize for Link cards only - map checkout inspection errors, binding conflicts, and rate limits on authorize - keep selector-free fills omitting fields; require page_url for card fills - remove cards update; card requests are immutable - send credential updates through the generic client - show server-generated item descriptions
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 64486bd. Configure here.
Depends on kernel/kernel#3950; do not merge before it and the SDK release.
Summary
vaults cards create) no longer contacts Link; the card isrequestedand advertisesauthorize. The card spec matches main (merchant_urlrequired, no browser binding).items invoke <vault> <key> authorizeaccepts optional--params '{"browser_id":"…","page_url":"…"}'. Both are required together; with them Kernel inspects the checkout, picks Link Pay Token or virtual-card execution, binds fill to that browser and page, and starts approval. Omitting both issues an unbound virtual card. Checkout binding is rejected locally for non-Link items.ambiguous_page/timeout400,destination_denied403,browser_not_found404,browser_unavailable409,browser_error500, each gated by its status and only for bound calls) report that no approval started and the call can be repeated after fixing the browser or page; 409conflictexplains the fixed binding; 429 says the card is retained and to retry the same authorize.fillstill takes the browser_id and page_url used to authorize. Card fills requirepage_url;fieldsare optional so Link Pay Token fills omit them from the request, and value-free results with no field entries are accepted.vaults cards updateis removed; card requests are immutable.description(wallets) is shown in human and JSON output.SDK pin
The preview SDK for kernel/kernel#3950 has not been regenerated from its latest contract yet, so this commit builds against main's SDK (
v0.114.1-0.20260930182635-e746d9980b83). Authorize parameters are sent withparam.Override, which works with both that SDK and the preview. Once the preview lands,go.modwill pin it with:The preview repository is private, so after the pin, CI jobs that download modules without access to it are expected to fail. Local builds need
GOPRIVATE=github.com/kernel/*and access to that repository.The preview SDK does not generate the vault item update method, so
vaults credentials updatesends its PATCH through the SDK's generic client (cmd/vaults_credentials.go).Before merge: remove the
replaceline, bumpgithub.com/kernel/kernel-go-sdkto the release that includes kernel/kernel#3950, rungo mod tidy, and switchsaveCredentialback toItems.Updateif that release exposes it.Validation
go build ./...,go vet ./...,go test ./...against main's SDKgo test ./cmd/against a local SDK copy with the expected authorize fields and without the item update method