mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-10-06 12:38:23 +00:00
Address review feedback on the key-config 422 passthrough: - Drop Ehbp-Response-Nonce (and content-length) from the passthrough. A nonce only carries meaning on an encrypted response body, and the stock ehbp client (shouldDecryptResponse) checks the nonce BEFORE the key-config mismatch -- a forwarded nonce would push that client into the decrypt path on the plaintext error body, so re-attestation would never fire. routstr-sdk checks key-config first, but the passthrough must stay correct for any EHBP client. Content-length is recomputed from the body instead of forwarded. - Match the media type exactly (split on ';') like the ehbp client's isProblemJSONContentType, instead of a substring check that also accepted e.g. 'text/html; x=application/problem+json'. - Add call-site tests: the bearer path (driven through the proxy handler) pins that a key-config 422 passes through as problem+json AND releases the reservation (the early return skips the UpstreamError handler, so the release depends on 422 remaining non-retryable); the x-cashu path pins the full refund and the X-Cashu header on the passthrough response. - Apply ruff format to the touched test file.