mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-10-05 20:28:23 +00:00
The streaming /v1/responses X-Cashu handler split the SSE body on the two-character sequence backslash-n and re-emitted with the same literal, so a real event stream was never framed into events. Even when a line happened to parse, usage and model were read at the top level, but the canonical Responses API nests them under "response" on response.completed. Both together meant usage was never found, the refund branch never ran, and the customer's whole token was retained. cost_data was also only bound inside that branch, so any path that did reach the re-emission loop would have raised NameError. Parse the body with a real SSE reader (CRLF, comment/keepalive lines, multi-line data fields, trailing event without terminator, [DONE] sentinel), resolve model and usage from the nested response object, and re-frame each event with genuine newlines so downstream clients get valid SSE. Settlement now always runs: unmeasured usage goes through the existing bounded fallback and settles at the authorized maximum with the remainder refunded, rather than silently keeping the full token.