项目文件夹

文件
Claude 661ff6aeed
govulncheck / govulncheck (push) Has been cancelled
Harness (E2E) / Harnesses (mock LLM) (push) Has been cancelled
Harness (E2E) / Provider harnesses (live LLM conformance) (push) Has been cancelled
Lint / golangci-lint (push) Has been cancelled
Run Tests / Unit Tests (push) Has been cancelled
Run Tests / Etcd Integration Tests (push) Has been cancelled
a2a: verify inbound AP2 mandates into the paid path (opt-in)
The AP2 primitives (checkout/payment mandates, Ed25519 sign/verify, the
x402 rail reference, attach-to-message) already existed, but the gateway
only *carried* mandates on the resulting task — it never verified them, so
ap2Verifications was never populated and a downstream paid path had no
trust signal.

Wire opt-in verification: set Options.AP2PublicKey (gateway) or
a2a.WithAP2PublicKey (embedded handler) and each mandate carried on a task
is verified (signature + task/context binding) with the result recorded in
task.AP2Verifications; the x402 settlement rail rides along for the paid
path. Off by default — mandates stay carried-but-unverified — so no payment
trust decision enters the default flow.

Adds a gateway integration test driving a real message/send that carries a
signed x402 payment mandate (verified, rail carried; tampered → surfaced as
unverified) plus a default-path test proving carry-only is unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL
2026-07-15 11:26:19 +00:00
..