This release adds a non-blocking interface to the receiver state machine.
Every step that previously required a synchronous validation closure is
now split in two: a method that extracts the data to be checked, and a
method that submits the results and advances the typestate. Wallets whose
signing, broadcast checks, or ownership lookups are asynchronous, or that
live in a separate process from the code driving the session, can now
drive both the v1 and v2 receiver flows without blocking. The existing
callback methods remain as convenience wrappers, so this release is
backward compatible.
Selected Improvements:
API Additions
- Split every callback-based receiver transition into an extract/apply
pair, available on both the v1 and v2 receiver flows:
extract_tx_to_check_broadcast_suitabilityand
apply_broadcast_suitability,inputs_owned_checklistand
apply_inputs_owned_checklist,inputs_seen_checklistand
apply_inputs_seen_checklist,outputs_owned_checklistand
apply_outputs_owned_checklist, andpsbt_to_signand
finalize_signed_proposal(#1446) - Add
ChecklistItem,MarkedChecklistItem, and the sealed
ChecklistKindtrait with theInputOwnership,InputSeenBefore, and
OutputOwnershipkinds, plus amark_checklisthelper for integrators
that prefer a closure. A submitted checklist must match the inputs or
outputs of the receiver's own original PSBT (#1446)
Bug Fixes
- Reject proposals that drop or reorder the sender's original inputs
before classifying any input as sender or receiver contributed. Input
classification treated any proposed input whose outpoint did not match
an original one as receiver-contributed, so a receiver that altered a
sender outpoint was validated as though the receiver had contributed
it. Dropped and reordered inputs are now both rejected up front with
MissingOrShuffledInputs(#1836)
What's Changed
- chore: update cargo.lock by @payjoin-robot[bot] in #1912
- Update anyio@4.15.1 by @benalleng in #1904
- Fix manifest lints by @xstoicunicornx in #1908
- Restore Kotlin build errors and expand tests by @chavic in #1875
- Test hosts with hyphens for caught mutant by @benalleng in #1915
- Non-blocking Interface for Payjoin State Machine by @xstoicunicornx in #1446
- Remove url from payjoin-ffi in favor of native payjoin::url by @benalleng in #1907
- chore: update flake.lock by @payjoin-robot[bot] in #1916
- Improve Sender Input Validation Tests by @Jolah1 in #1836
- Ask authors to choose their reviewer by @DanGould in #1922
- chore: update nightly toolchain pin by @payjoin-robot[bot] in #1923
- Remove vestigial and redundant #[allow(dead_code)] by @xstoicunicornx in #1925
- Require sign-off on an issue before opening a PR by @xstoicunicornx in #1926
- Rename FFI builder errors to match payjoin crate by @xstoicunicornx in #1733
- Derive first-boot OHTTP key from persisted ikm by @xstoicunicornx in #1930
- Preserve mailroom metrics privacy by @DanGould in #1754
- Fix /check-in issue with "Issues Opened" and "PRs Opened" by @xstoicunicornx in #1928
- Bump payjoin version to 1.2.0 by @benalleng in #1931
Full Changelog: payjoin-1.1.0...payjoin-1.2.0