Skip to content

payments: the reply that never comes, and the idempotency key - #8

Closed
sajonaro wants to merge 1 commit into
deploymentfrom
payments
Closed

sajonaro wants to merge 1 commit into
deploymentfrom
payments

Conversation

@sajonaro

@sajonaro sajonaro commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Stacked on #7 (base deployment).

Adds payments/: one order going through authorize, capture, settle, ship, refund and cancel, over a wire that loses replies, with a shop that retries. The pair is with and without an idempotency key.

  • With the key: never charged twice, never left charged for a cancelled order, and every order can still reach an end. Exit 0.
  • Without it: authorize → send-capture → capture → lose-reply → send-capture → capture-again, and the customer is charged twice. derive double-charged shows those orders looking normal in every stage, including settled-and-shipped, refunded and cancelled.
  • Also without it: a void overtakes the capture on the wire, finds nothing to refund, and the capture lands afterwards. The key is what lets a cancellation refer to a request that has not arrived yet.
  • writ failed my first draft of the safe file, key and all. cancel was allowed whenever the shop had not captured, so a capture still in flight landed after the cancellation. cancel now voids at the processor under the same key. The README tells the story.

Cross-check: 52 → 56 properties (54 compared). ./run-tests.sh all: 314 checks, 0 failed.

🤖 Generated with Claude Code

One order: authorize, capture over a wire that loses replies, settle, ship,
refund, cancel. Without a key, a lost reply and a retry charge twice in six
steps; derive double-charged shows the order looking normal in every stage.
The shortcut also charges for a cancelled order: the void overtakes the
capture, finds nothing, and the capture lands after it.

Writing it, writ failed the first draft of the SAFE file, key and all:
cancel was allowed whenever the shop had not captured, so a capture still on
the wire landed after the cancellation. cancel now voids at the processor,
under the same key.

Cross-check 52 -> 56 properties (54 compared); 314 checks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sajonaro

sajonaro commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Superseded: reached main through #10.

@sajonaro sajonaro closed this Oct 3, 2026
@sajonaro
sajonaro deleted the payments branch October 3, 2026 17:52
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant