Repository navigation
fix(contributions): keep gift and tip confirmation pending until finality - #239
Merged
Merged
Conversation
Keep a visible pending state and automatically recheck saved intents without resubmitting. Resume after reload, report only proven finalized EVM reverts as failures, and cover wallet, mobile, and recovery paths.
knzeng-e
marked this pull request as ready for review
October 4, 2026 19:44
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b1120df82a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Gifts and tips now show a calm pending state while Dotify checks finality. Recovery resumes from the saved intent after reload, never submits a second payment, and no longer polls the shared RPC indefinitely.
Issue and context
Refs #229; scope: native gifts and tips. A short confirmation timeout previously replaced progress with an ambiguous manual-check screen. The first fix kept checking forever; review correctly identified that Product finalized-event reads could then scan full history repeatedly.
Architecture and key concepts
The local journal is a reservation, not proof of payment. The connected payer, network, runtime and work identify it. A first attempt may submit once; later checks use its hash or intent ID only. A matching finalized contribution event produces success. A finalized reverted EVM receipt proves failure. Missing events and read-network errors remain pending because absence of evidence is not proof of failure.
How it works
Check status again, never a new payment action.Design decisions and tradeoffs
The bounded backoff reduces shared-RPC pressure while still observing finality for almost nine minutes. Explicit rechecks start another bounded read-only window. Product may expose no usable receipt for a failed native extrinsic; in that case Dotify cannot truthfully promise a terminal result, and the journal stays pending until independently reconcilable.
Security, failure, and operations
No signing key or secret is persisted. Storage reservation failure blocks submission; ambiguous host/network failures preserve the journal. An uncertain state cannot offer
Send another. Do not clear Product cache or manually repeat an unresolved contribution. No contract, payment policy, deployed CID or production environment changed.Review guide
Suggested order
web/src/features/donations/contributionFlow.ts: journal, read-only recovery and proof-bound terminal states.web/src/features/donations/contributionReconciliation.ts: bounded schedule, visibility pause and cancellation.web/src/components/ArtistDonationButton.tsx: one Product read per cycle and safe paused-state actions.web/README.md: no-resend, scan-count and operational boundaries.Verify carefully
Validation
463a3d8Raw
npm run lintstill traverses historical minified bundles in local.data/and fails there; changed-file lint passes. No funded Product-host tip was attempted.Known limitations and follow-ups
Product native failure without a receipt remains unprovable from the current read path. Live-host validation and reconciliation of earlier pending intents remain open under #229.
Metadata checklist