Repository navigation
Conversation
The README verify example spliced the encrypt-otp output into the request
body as a nested JSON object, but the spec defines encryptedOtpBundle as a
string holding that JSON text. The raw-object form fails with
INVALID_INPUT "Invalid wallet request".
- Build the verify body once with jq (--arg string-encodes the bundle) and
reuse the saved file for both legs so the signed retry is byte-identical
- Loop the signed retry while the response is {"status":"PROCESSING"}
- Note in the helper's usage comment that encrypt-otp output is the string
value, not a nested object
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KeZ4QUyBQZVLZFceifFnYk
Contributor
|
This PR does not match any of the 3 configured review trigger rules. |
|
The latest updates on your projects. Learn more about Vercel for GitHub. 3 Skipped Deployments
|
Show the saved request body, label each verify leg, and replace the until-loop with a plain while-loop so the PROCESSING retry reads clearly. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KeZ4QUyBQZVLZFceifFnYk
encrypt-otp already prints a JSON string literal, so splicing it into the body yields the string field the API expects. Drop the jq --arg wrapper, which double-encoded the bundle, and say so in the README. Keep the labeled verify steps, the body example, and the PROCESSING retry loop. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KeZ4QUyBQZVLZFceifFnYk
Contributor
Author
|
this is not needed |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Updated the embedded wallet sign-in documentation and helper script to fix issues with the EMAIL_OTP verification flow. The main problems were incorrect JSON serialization of the encrypted OTP bundle and missing retry logic for asynchronous wallet provider processing.
Key Changes
Fixed
encryptedOtpBundleserialization: The field must be a string containing JSON text, not a nested object. Updated documentation and examples to usejqto wrap the helper output as a string value rather than splicing it directly into the request body.Added retry loop for verification: The wallet provider may return
{"status":"PROCESSING"}while finishing the login. Added anuntilloop that re-sends the identical signed request (same body and headers) every 2 seconds until a session is returned.Reuse verify request body: Build the verify request body once in
/tmp/verify-body.jsonand reuse it for both the initial challenge request and the signed retry, ensuring consistency.Updated helper script documentation: Clarified in
embedded-wallet-sign.jsthatencrypt-otpoutputs{encappedPublic, ciphertext}JSON text that must be passed as a string value, with examplejqusage.Implementation Details
encryptedOtpBundlefield was causing{"code":"INVALID_INPUT","reason":"Invalid wallet request."}errors when sent as a nested object; wrapping withjq -n --arg b "$ENC_BUNDLE" '{type: "EMAIL_OTP", encryptedOtpBundle: $b}'resolves this.statusis no longer"PROCESSING".-d @/tmp/verify-body.jsonfor consistency and to avoid shell escaping issues.https://claude.ai/code/session_01KeZ4QUyBQZVLZFceifFnYk