Skip to content

Commit f71c22c

Browse files
committed
chore(commerce): drop attacker-controlled rationale from pi_cache docstring
Replace "Prevents agents from sending payment to an attacker-controlled address and replaying the credential" with the behavior-only equivalent ("Validates the credential's deposit address against the addresses the merchant has actually minted"). Mirrors the node-commerce pi-cache.ts sweep.
1 parent 5713755 commit f71c22c

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

‎agentscore_commerce/stripe_multichain/pi_cache.py‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@
44
55
1. **Is this on-chain ``pay_to`` address one we minted?** — when an MPP credential
66
arrives with a ``recipient``, verify it matches a recently-minted Stripe deposit
7-
address. Prevents agents from sending payment to an attacker-controlled address
8-
and replaying the credential against the merchant's endpoint.
7+
address. Validates the credential's deposit address against the addresses the
8+
merchant has actually minted.
99
1010
2. **Which PaymentIntent owns this deposit address?** — when settling, the
1111
``simulate_crypto_deposit`` test_helpers call needs the PaymentIntent id for the

0 commit comments

Comments
 (0)