Conversation
An Allowance now binds two identities, so a grant is one SDK Allowance on the contact's single Encrypted Link and coverage no longer depends on a receiver folder. Automatic payments claim the request before the automatic Acceptance, pass the payee's payment app on the proof and settle the private payment list with the same outcomes the manual flow uses.
A cancelled caller no longer stops an automatic payment after the request was accepted: admission runs in its own task once the ledger is reconciled.
The shared request flow only shows an accepted request again while this device owns its acceptance. Automatic payments now record that ownership before the automatic Acceptance, so a payment that never reached the node returns as an ordinary Payment Request.
…l-20260930' into feat/paykit-allowances
1a0051f to
8f0449c
Compare
|
I restacked this PR on #856 and pushed 8f0449c (draft, base
Local verification: |
…yment is decided A request an allowance covers belongs to the automatic flow from the moment it arrives. Before, a slow first pass let the incoming-request presentation open a manual sheet for a request that was then paid automatically.
…owance flow owns Skipping an owned request left it in the presentable list, so the presentation re-entered itself on the main thread until the allowance pass finished. The pass now logs how each covered request ended.
…l-20260930' into feat/paykit-allowances
|
I pushed a19ea87 with the device findings and the Preview media.
Device runs on two iOS 26.5 simulators against Paykit |
|
I ran the open checks on the current head (a19ea87), on two iOS 26.5 simulators against Paykit
The journeys are ticked in QA Notes; the manual test list is now N/A. |
…l-20260930' into feat/paykit-allowances
The clock offset from the demo clock PR is in the base now, so the three tests that assert allowance admission, coverage and status keep real time return.
|
I merged the latest #856 head (225ec3e, which brings in #798 and master) and pushed the result.
Local verification: |
…l-20260930' into feat/paykit-allowances
…l-20260930' into feat/paykit-allowances
|
Correction to my last comment: the test target does not build after that merge (33dcf4b), so "it builds" was wrong.
The app target and the allowance code are unaffected; the last full |
…l-20260930' into feat/paykit-allowances
…l-20260930' into feat/paykit-allowances
…l-20260930' into feat/paykit-allowances
…l-20260930' into feat/paykit-allowances
…l-20260930' into feat/paykit-allowances
…l-20260930' into feat/paykit-allowances # Conflicts: # Bitkit/AppScene.swift
|
I merged the latest #856 head (d78aaa3, "consolidate paykit background retries") and pushed 32d00d7.
Local verification: build and the full |
…l-20260930' into feat/paykit-allowances # Conflicts: # Bitkit/AppScene.swift
|
I merged the latest #856 head (dc785b4, "receive Paykit messages on each inbox poll") and pushed bb6b941.
Local verification: build and the full |
…l-20260930' into feat/paykit-allowances
…l-20260930' into feat/paykit-allowances # Conflicts: # Bitkit/AppScene.swift
|
I merged the latest #856 head (27e921a, "coalesce paykit preparation and reduce inbox polling") and pushed fe1ef54.
Local verification: build and the full |
…l-20260930' into feat/paykit-allowances
…l-20260930' into feat/paykit-allowances
…l-20260930' into feat/paykit-allowances # Conflicts: # Bitkit/AppScene.swift
|
I merged the latest #856 head (f5ca801, "avoid contact preparation waits for subscription notifications") and pushed 2073233.
Local verification: build and the full |
Closes #806
Twin: synonymdev/bitkit-android#1340
Stacked on #856
Refs:
This PR adds allowances: a payer sets a per-payment and a monthly limit for a Paykit contact, and that contact's requests within the limits are paid without asking.
Description
It builds on the published Paykit SDK
0.1.0-rc59that #856 moves Bitkit to, where an Allowance binds the two Pubky identities of a contact's single Encrypted Link and covers every Paykit app they use. It is stacked on #856; GitHub retargets it to master when #856 merges.Out of Scope
Design
Figma "Bitkit - Experimental New": Allowances empty state, Set Allowance, Allowances list. The receiver's review sheet and the detail sheet have no frame and follow the drawn film. Deliberate differences: the first tab stays "Overview", the list row's right column reads the monthly limit, and the copy typos are fixed.
Preview
auto-pay-clip.mp4
QA Notes
Journeys
set-and-accept.xml— the offer opens on the payee by itself and both rows turn Active; ran on two iOS 26.5 simulatorsauto-pay-under-limit.xml— a $2 request pays itself, the Payments row reads Auto-paid and the detail shows $2.00 paid automatically; ran on two iOS 26.5 simulatorsabove-limit-asks.xml— a $20 request arrives as an ordinary Payment Request, pays by swipe without the Auto-paid tag and stays out of the amount paid automatically; ran on two iOS 26.5 simulatorsmonthly-cap-reached.xml— the third $4 request on a $10 cap stays an ordinary Payment Request and the detail reads $8.00 paid automatically; ran on two iOS 26.5 simulators, the Limit Reached notification itself was not observedend-stops-auto-pay.xml— after either side ends it, the next request asks; both halves ran on two iOS 26.5 simulators: the ender's row and the other side's row read Ended, the payer's with the amount paid automatically, and the next request waited as an ordinary Payment Requestrestart-never-pays-twice.xml— the payer was killed 0.4 s after the hand-off and relaunched: one payment left the wallet and the payee received one; ran on two iOS 26.5 simulatorsManual Tests
N/A
Automated Checks
PaykitAllowanceTests.swift— limits, terms, capacity, month anchoring, grouping and admission decisionsPaykitAllowanceExecutorTests.swift— reserve, hand-off, claim, payment list outcomes, cancellation of the caller, outcome recording, deferral, channel readiness, granting over a ready link and restart recovery of automatic paymentsPaykitPaymentProofServiceTests.swift— payment proofs carry the allowance idBitkitTestson an iOS 26.5 simulator against Paykit0.1.0-rc59at the current head — 1,626 tests pass, 12 skipped