Skip to content

feat(escrow): cut over to Rust core and retire process-escrow - #44

Draft
DCT-Berinyuy wants to merge 2 commits into
devfrom
app-escrow-via-rust
Draft

DCT-Berinyuy wants to merge 2 commits into
devfrom
app-escrow-via-rust

Conversation

@DCT-Berinyuy

@DCT-Berinyuy DCT-Berinyuy commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

⚠️ Cutover order: merge only after #43 is deployed

Right now the live Rust service returns 404 for /escrow/confirm-receipt, which I verified. If this PR shipped first, confirm-receipt and dispute would break. It stays a draft until the steps below are done.

  1. Merge feat(rust-core): buyer confirm-receipt and dispute endpoints #43 and deploy it to Render. Set SUPABASE_URL and SUPABASE_ANON_KEY on the service first, because it won't start without them.
  2. Check the deploy: curl -i https://bookbridge-rust-core.onrender.com/escrow/confirm-receipt should now return 405, not 404.
  3. In the Supabase SQL editor, run SELECT vault.create_secret('<INTERNAL_API_SECRET from Render>', 'rust_internal_api_secret');
  4. Run supabase/migrations/20260927230000_auto_release_via_rust.sql. It refuses to run if step 3 hasn't been done.
  5. Merge this PR and build and install the app.
  6. Test end to end: one test purchase using confirm-receipt, and another using dispute.
  7. Only after that, run supabase functions delete process-escrow.

Why

This moves every escrow path off the process-escrow edge function (GHSA-xq84-qm9j-hf6p) and onto Rust's guarded release_escrow, which requires both rows to be held and de-duplicates payouts with Fapshi.

What

App

  • confirmReceipt → POST {RUST_CORE_URL}/escrow/confirm-receipt; disputeTransaction → POST {RUST_CORE_URL}/escrow/dispute.
  • Requests carry Authorization: Bearer <Supabase access token>, refreshing the session first if it has expired. With no session, the app asks the user to sign in and sends nothing.
  • A 401 shows "session expired, please sign in again". Other errors show Rust's {"error": ...} message, or Request failed (<status>) if the body isn't JSON.
  • 90 s timeout, because Render's free tier can take close to a minute to wake.
  • New RUST_CORE_URL dart-define, defaulting to https://bookbridge-rust-core.onrender.com. It's a public URL, so existing build commands and CI are unaffected.

Cron: auto-release-escrows-job (hourly) now calls /internal/escrow/process-releases with X-Internal-Secret from Vault and a 120 s timeout.

Removed: supabase/functions/process-escrow.

Known gap

The edge function's admin-only resolve-dispute action has no Rust equivalent yet. Nothing in the repo called it, and its "refund" only changed statuses without returning money. Until Rust gets an admin resolve endpoint, disputes are resolved by hand. That endpoint needs to exist before real buyers transact.

Test plan

Replace the process-escrow edge function calls with authenticated POSTs to
bookbridge-rust-core (/escrow/confirm-receipt, /escrow/dispute), using the
user's Supabase access token. Adds RUST_CORE_URL (defaults to the Render
deployment) and data source tests with a mock HTTP client.

Co-authored-by: Copilot App <[email protected]>
@vercel

vercel Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
book-bridge Ready Ready Preview Sep 27, 2026 9:46pm UTC

Repoint the hourly auto-release-escrows-job at the Rust core's
/internal/escrow/process-releases (X-Internal-Secret from Vault) and delete
the process-escrow edge function, now fully replaced by Rust.

Co-authored-by: Copilot App <[email protected]>
@DCT-Berinyuy DCT-Berinyuy changed the title feat(transactions): send confirm-receipt and dispute to Rust core feat(escrow): cut over to Rust core and retire process-escrow Sep 27, 2026
@ken-morel

Copy link
Copy Markdown
Member

An edge function?

This branch was successfully deployed

1 active deployment
Preview — 1397037b Deployed Sep 27, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants