Repository navigation
feat: Berlin Group signing baskets for the mapped connector (minimal) - #2936
Merged
simonredfern merged 1 commit intoOct 9, 2026
Merged
Conversation
…nd book what they authorise A minimal signing basket for the mapped connector. Responses and validation: transactionStatus is upper case, _links.scaStatus is a href object, the PUT answer links to the basket's authorisation, an empty or duplicated id list is a format error, and authorisation bodies the server does not implement are refused by name instead of discarded. Codes outside the standard's list (wrong OTP, unknown basket or authorisation, status conflicts) are mapped to ones inside it. Ownership: a basket records the consumer that created it and every operation is limited to that consumer; an unknown basket, another TPP's basket and a basket created before ownership was recorded answer 403 RESOURCE_UNKNOWN. State: delete and the move to AUTHORISING are conditional updates, so an answer and a delete racing each other have one winner. Answering the authorisation checks everything first (instance setting, ownership, basket and challenge state, every payment still waiting for SCA), then the answer, and only a challenge recorded as finalised authorises anything. The payments are then booked one after another, each awaited, and the basket is ACTC only if every one was. Authorisation is off by default (signing_basket_authorisation_enabled). Payments are admitted only if the caller lodged them and they await SCA. Consents in a basket are refused until their authorisation exists.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



A minimal Berlin Group (NextGenPSD2 1.3.16) signing basket for the mapped connector. A TPP creates a basket of payments it lodged, starts the basket's authorisation, and answers it with the OTP; the payments are then booked one after another and the basket becomes
ACTC. A basket belongs to the TPP that created it (new nullable columnsigningbasket.consumerid, added by Schemifier), and every operation is limited to that TPP. Responses and error codes follow the standard (upper-casetransactionStatus,_links.scaStatusas a{ "href" }object,PSU_CREDENTIALS_INVALID,RESOURCE_UNKNOWN,STATUS_INVALID), and unsupported authorisation bodies and consents are refused explicitly. Answering the authorisation is off by default and is enabled withsigning_basket_authorisation_enabled=true.