fix(auth): preserve received payment headers and configure server payload capacity - #600
Conversation
|
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
ty-everett
left a comment
There was a problem hiding this comment.
Authoring maintainer review of 25b4c676c85cc7f2d8c427cf77abb9fa1874a1b7: no unresolved issue in the complete diff. I reviewed request/response framing, canonical payment validation and replay behavior, metadata and certificate bounds, ownership of message/configuration snapshots, legacy default behavior, exported types, package peers/artifacts, documentation and CI permissions.
The optional server policy is locally selected and captured once; it cannot be changed by a received message. Middleware preserves received headers for validation. SDK clients retain the documented higher capacities, and existing BRC100 calls, signed bytes and wallet records remain compatible. The three patch versions follow the maintainer's explicit release decision.
CI 36047564046 attempt 2 passes the complete merge gate, including 97.10% patch coverage and 88.54% SDK auth mutation score. The isolated first-attempt localhost failure passed on its targeted retry without changing source or weakening assertions. CodeQL on the PR merge ref has zero open alerts; its previous finding is automatically fixed and the review thread is resolved. Sonar zero-new and Socket checks pass.
Approve integration under the repository's maintainer review policy. Actual npm publication remains gated on reviewed main validation and exact protected candidate/attestation verification.



Program and scope
BRC-105 payments can carry valid Atomic BEEF larger than the hardened HTTP header ceilings. This restores compatibility at the transport boundary without changing BRC100 calls, signed wire bytes or wallet data. Coordination: BotBoard #596.
x-bsv-paymentmay use the full aggregate request budget. Response-frame overhead rises to 512 KiB.maxPaymentHeaderBytesfield remains accepted but ignored. HTTP servers, proxies, CDNs and WAFs own transport admission.AuthMessageValidationOptionsonPeerandsnapshotAuthMessagesupports a positive explicit general-payload byte budget ornullto delegate to the transport. Omission preserves legacy SDK policy. Auth middleware selects delegation and requires SDK 2.8.5, removing the indirect SDK envelope ceiling for received headers.Out of scope: BRC100 API/wire changes, wallet schemas, pricing, payment/replay relaxation, unrelated package revisions and #569.
Exact head reviewed:
25b4c676c85cc7f2d8c427cf77abb9fa1874a1b7. All applicable hosted checks passed at that head.Impact
Patch candidates, as explicitly directed by the maintainer: @bsv/sdk 2.8.5, @bsv/auth-express-middleware 2.2.8, @bsv/payment-express-middleware 2.1.8. None is published by this PR.
Verification
Final local validation uses the governed Node 24.18.0 and pnpm 10.33.2 toolchain.
b2f1989306b6f64677deff89f39596491e448d97; target 90%.pack:checkcommands pass: exact exports/declarations/maps, strict resolution, clean ESM/CJS and Express 4/5 runtime consumers. SDK exact-tarball Vite/esbuild/UMD browser checks pass within governed budgets.Security and dependency evidence
Auth middleware's required SDK peer moves to
^2.8.5because it uses the new local policy. Workspace dependencies remain linked; no third-party graph or lockfile change. Canonical framing, invalid-header rejection, body budgets, authentication and replay protection remain. This deliberately transfers header admission to the HTTP layer; operators must verify the complete route before accepting larger proofs. Clients still need sufficient client capacity for larger responses.4fda8de69dcedbc2c01ee34dd04db07e7b26204ereport zero results; alert 288 is automatically fixed and its review thread is resolved.Release and operations
After green review and merge, use protected publication, verify exact npm artifacts, then upgrade consumers and validate their configured HTTP routes. Publication and deployment remain separate acceptance steps.