Repository navigation
Consolidate x402 host and payment flows in one package - #2057
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
mu/x402/billing/subscription_page.go
Line 157 in 2420e62
When a user starts a subscription on X402_HOST, this passes the developer-host origin into startSubscription, whose ensureSubscriptionWebhook consequently requires a Stripe endpoint at that second hostname. Existing installations have the shared webhook on the primary hostname, and the single STRIPE_WEBHOOK_SECRET cannot normally verify independently configured endpoints on both hosts, so the advertised developer-host checkout fails before reaching Stripe. Keep return URLs on the originating host, but validate/deliver renewals through the shared configured webhook origin.
AGENTS.md reference: AGENTS.md:L373-L377
Line 383 in 2420e62
When an authenticated user submits this form on X402_HOST, x402.Handler applies auth.StrictCSRF to the POST before dispatching it, but the form supplies neither _csrf nor an X-CSRF-Token header. Every developer-host credit transfer therefore receives a 403 before handleTransfer runs; add app.CSRFField(auth.CSRFToken(r)) as the other shared billing forms do.
AGENTS.md reference: AGENTS.md:L373-L377
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The x402 host's pages, account redirects, payment gate and billing implementation were scattered across the consumer site. That made the developer account flow depend on switching hosts and made changes affect unrelated pages.
This moves ownership to a top-level
x402package. The server detects the host once and sends every request through its router. The package owns the dark landing, filtered tools catalogue, pricing, username/password sign-in, account, service tokens, OAuth consent and usage flow. Browser sessions use a host-onlyx402_sessioncookie; explicit API credentials take precedence. Sign-in and payment returns stay on the developer host.x402/billingnow contains the existing credit ledger, allowances, subscriptions, Stripe checkout/webhooks, crypto top-ups, usage rendering and browser checkout code. Both hosts call that implementation.x402/paymentcontains the moved protocol/facilitator implementation, andx402/gatewaycontains the shared API payment and quota enforcement. The old implementations and cross-host redirect flow are deleted. Identity, credential storage, service dispatch and ledger filenames are unchanged.Service tokens created on the developer host use the shared account and service scopes, expire after 90 days, and work on its MCP/REST endpoints. They are not a separate balance or a new host-specific token format. The host provides existing-account password sign-in; it does not expose Google sign-in or registration.
Validation:
go build ./...,go test ./... -short,go vet ./...,gofmt -l .andgit diff --checkpass. Integration coverage exercises login, host-only cookies, CSRF, token creation and use on MCP, explicit credential precedence, logout, unknown routes, and checkout returns on both hosts. Browser checks at 390px and 1280px show no horizontal overflow, three desktop columns on both tools catalogues, and spacing above the pricing top-up button. Payment provider calls are mocked in tests; no live charge was made.