Skip to content

feat: Berlin Group signing baskets for the mapped connector (minimal) - #2936

Merged
simonredfern merged 1 commit into
OpenBankProject:developfrom
hongwei1:feature/signing-basket-poc
Oct 9, 2026
Merged

simonredfern merged 1 commit into
OpenBankProject:developfrom
hongwei1:feature/signing-basket-poc

Conversation

@hongwei1

@hongwei1 hongwei1 commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

A minimal Berlin Group (NextGenPSD2 1.3.16) signing basket for the mapped connector. A TPP creates a basket of payments it lodged, starts the basket's authorisation, and answers it with the OTP; the payments are then booked one after another and the basket becomes ACTC. A basket belongs to the TPP that created it (new nullable column signingbasket.consumerid, added by Schemifier), and every operation is limited to that TPP. Responses and error codes follow the standard (upper-case transactionStatus, _links.scaStatus as a { "href" } object, PSU_CREDENTIALS_INVALID, RESOURCE_UNKNOWN, STATUS_INVALID), and unsupported authorisation bodies and consents are refused explicitly. Answering the authorisation is off by default and is enabled with signing_basket_authorisation_enabled=true.

…nd book what they authorise

A minimal signing basket for the mapped connector.

Responses and validation: transactionStatus is upper case, _links.scaStatus
is a href object, the PUT answer links to the basket's authorisation, an
empty or duplicated id list is a format error, and authorisation bodies the
server does not implement are refused by name instead of discarded. Codes
outside the standard's list (wrong OTP, unknown basket or authorisation,
status conflicts) are mapped to ones inside it.

Ownership: a basket records the consumer that created it and every operation
is limited to that consumer; an unknown basket, another TPP's basket and a
basket created before ownership was recorded answer 403 RESOURCE_UNKNOWN.

State: delete and the move to AUTHORISING are conditional updates, so an
answer and a delete racing each other have one winner.

Answering the authorisation checks everything first (instance setting,
ownership, basket and challenge state, every payment still waiting for SCA),
then the answer, and only a challenge recorded as finalised authorises
anything. The payments are then booked one after another, each awaited, and
the basket is ACTC only if every one was. Authorisation is off by default
(signing_basket_authorisation_enabled).

Payments are admitted only if the caller lodged them and they await SCA.
Consents in a basket are refused until their authorisation exists.
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

@hongwei1 hongwei1 changed the title fix: signing baskets follow NextGenPSD2 1.3.16, belong to their TPP and book what they authorise (minimal) feat: Berlin Group signing baskets for the mapped connector (minimal) Oct 8, 2026
@simonredfern
simonredfern merged commit 8066792 into OpenBankProject:develop Oct 9, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants