Skip to content

fix: confirm RI exchanges with quoted payment - #470

Open
cristim wants to merge 1 commit into
mainfrom
fix/ri-exchange-confirmation
Open

cristim wants to merge 1 commit into
mainfrom
fix/ri-exchange-confirmation

Conversation

@cristim

@cristim cristim commented Oct 1, 2026

Copy link
Copy Markdown
Member

RI exchange Execute previously submitted an irreversible exchange without confirmation. Approve omitted the payment and the fact that execution uses a fresh quote.

Confirm the exact raw payment, currency, source RIs, region and submitted targets before Execute. Approval discloses the previous ledger quote and existing spending limits. Reject stale quotes after target edits, keep old modal callbacks from closing a new session, and refresh inventory/history after success even when the originating modal has closed.

Closes #250

Independent Astra review approved exact commit a513872 with no actionable findings. Fresh independent production-browser verification passed all 22 cases with committed-source and production source-map parity. Full Jest verification passed 3,000 tests across 92 suites, with one existing skip; pinned lint, type checking, build and normal commit hooks passed. Parent-code and three guard-removal probes fail their intended assertions, then restored code passes.

Tests use synthetic HTTP responses and make no cloud purchases. Existing backend currency enforcement and currencyless ledger limitations remain tracked by Go #42; this frontend change preserves raw quote currency and does not claim to resolve that issue.

Show the raw quote and submitted targets before irreversible execution.
Disclose the stored approval amount as a previous quote, since approval
executes a fresh quote under the existing spending limits.

Discard late quotes after target edits and keep old modal callbacks from
closing a new session. Refresh inventory and history after execution even
when its modal has closed.

Verify both confirmation failures against the original production bundle,
all dismissal paths and precise payloads in Chromium, and quote/session
guards by removing them and observing the expected browser failures.
@cristim cristim added severity/medium Moderate harm urgency/this-sprint Within the current sprint triaged Item has been triaged priority/p1 Next up; this sprint impact/many Affects most users effort/s Hours type/bug Defect labels Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

  • Run on-demand review

This review includes 3 billable files and costs up to $0.75.

  • Ask an admin to make reviews automatic

Open in CodeRabbit

Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing.

Or wait 5 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 75 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: LeanerCloud/cloud-commitments-platform/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 803a38b9-944c-493e-b664-310dc391f0a3

📥 Commits

Reviewing files that changed from the base of the PR and between 6d9a70f and a513872.

📒 Files selected for processing (3)
  • frontend/src/__tests__/riexchange.test.ts
  • frontend/src/riexchange.ts
  • frontend/tests-e2e/ri-exchange-confirmation.spec.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/s Hours impact/many Affects most users priority/p1 Next up; this sprint severity/medium Moderate harm triaged Item has been triaged type/bug Defect urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(frontend): RI exchange Execute has no confirmation step for an irreversible payment

1 participant