Skip to content

Receipt comment: canonical JSON is the JS profile, not Python json.dumps - #19

Merged
Fizzl13 merged 1 commit into
mainfrom
claude/x402-agents-solana-payments-nceg9b
Sep 27, 2026
Merged

Fizzl13 merged 1 commit into
mainfrom
claude/x402-agents-solana-payments-nceg9b

Conversation

@Fizzl13

@Fizzl13 Fizzl13 commented Sep 27, 2026

Copy link
Copy Markdown
Owner

What

The comment in src/receipt.ts claimed byte equality with Python json.dumps. That's only true for ASCII keys and integers. The comment now names the profile (js-json-stringify-sorted-utf16-ascii-v1) and points to the Python equivalent in presign-guard (examples/canonical.py).

It's a comment-only change: no behaviour change and no release needed. Goes together with Fizzl13/presign-guard#49.

Tests

41/41 pass.

🤖 Generated with Claude Code

https://claude.ai/code/session_01TsD5haPKxeWjYmErHzvU48


Generated by Claude Code

Our docs said the signed bytes are "the same as Python's json.dumps(sort_keys=True,
separators=(",", ":"), ensure_ascii=True)". That only holds for ASCII keys and
integers: Python writes 1.0 and 1e-06 where JSON.stringify writes 1 and
0.000001, and sorts U+E000 before U+10000 (code points) where the signer sorts
by UTF-16 code units. Paid answers carry decimals (prices, liquidity), so a
Python verifier following the old text could reject a genuine receipt. TAT
Risk surfaced this while pinning the profile for their signed evidence.

The normative profile is named js-json-stringify-sorted-utf16-ascii-v1: keys
by UTF-16 code units, compact, every code unit from U+007F up as lowercase
\uXXXX, numbers as JSON.stringify writes them, UTF-8 bytes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TsD5haPKxeWjYmErHzvU48
@Fizzl13
Fizzl13 merged commit e7dbee6 into main Sep 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants