Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,5 @@ VITE_WALLETCONNECT_PROJECT_ID=
VITE_PROOF_WORKER_URL=https://proofkey-relay.onrender.com
VITE_SEPOLIA_EXPLORER_URL=https://sepolia.etherscan.io
VITE_CREDITCOIN_EXPLORER_URL=https://creditcoin-testnet.blockscout.com
VITE_DEVICE_SIMULATOR_URL=http://localhost:4174
VITE_DEMO_MACHINE_NAME=Industrial Excavator
VITE_DEMO_MACHINE_LOCATION=Lagos Demo Yard · Bay 04
23 changes: 13 additions & 10 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,9 @@ ProofKey makes the source-chain receipt the authority:
6. Creditcoin's Native Query Verifier at `0x0FD2` verifies the proof.
7. `ProofKeyASC` decodes the proven receipt, validates every payment invariant, rejects replay, and atomically issues an expiring `AccessPass`.
8. The machine reads `AccessPass.isAuthorized` directly from Creditcoin and fails closed on expiry, deactivation, or RPC failure.
9. The customer creates a two-minute, one-use QR handoff bound to the machine, payer, order, and a random nonce; it never contains a private key.
10. The public `/device/:machineId` terminal claims that nonce once, continuously rechecks Creditcoin, and enables output only after the registered controller signs a start receipt.
11. A controller-signed end receipt seals the measured duration. My Rentals verifies both signatures locally against the live controller address.

The worker pays gas and provides liveness. It cannot forge a payment, choose a beneficiary, alter a tariff, extend access, or bypass Attestcoin verification.

Expand Down Expand Up @@ -152,11 +155,11 @@ npm run serve --workspace @proofkey/worker
# Customer payment and proof journey
npm run dev --workspace @proofkey/web

# Fail-closed machine simulator
# Optional standalone fail-closed diagnostic client
npm run dev --workspace @proofkey/device
```

The customer UI connects a wallet, switches to Sepolia, calculates exact token units without floating-point arithmetic, approves the payment token, settles usage, queues the Attestcoin relay, displays every proof phase, and reveals access only after Creditcoin execution succeeds.
The customer UI connects a wallet, switches to Sepolia, calculates exact token units without floating-point arithmetic, approves the payment token, settles usage, queues the Attestcoin relay, displays every proof phase, and reveals access only after Creditcoin execution succeeds. The same Vercel deployment serves the customer session page and independent `/device/:machineId` terminal, so QR links never point at localhost.

## Verify the recorded result

Expand Down Expand Up @@ -186,14 +189,14 @@ npm run check

The gate runs formatting, TypeScript checks, all automated tests, Solidity compilation, and production builds.

| Suite | Tests | Coverage focus |
| ---------------- | -----: | -------------------------------------------------------------------------------------------------- |
| Solidity | 52 | Receipt semantics, proof tampering, replay, authorization, pricing, ownership, expiry, reentrancy |
| Relay worker | 16 | Leases, restart recovery, retries, idempotency, CORS, rate limits, readiness, secret-safe evidence |
| Customer web | 19 | Proof state, route helpers, relay URL safety, exact token math, wallet lifecycle and errors |
| Wallet browser | 1 | EIP-6963 production connect button and prompt-free persisted reconnect |
| Device simulator | 6 | Locked/unlocking/unlocked/expired states, tampered results, RPC failure |
| **Total** | **94** | |
| Suite | Tests | Coverage focus |
| ---------------- | ------: | ------------------------------------------------------------------------------------------------------ |
| Solidity | 52 | Receipt semantics, proof tampering, replay, authorization, pricing, ownership, expiry, reentrancy |
| Relay worker | 23 | Leases, restart recovery, one-time handoffs, receipt signatures, CORS, readiness, secret-safe evidence |
| Customer web | 48 | Proof state, exact token math, operator workflow, session state machine, receipt tampering and expiry |
| Product browser | 7 | Multi-page rental, operator, proof, two-browser QR handoff, signed usage, and replay rejection |
| Device simulator | 6 | Locked/unlocking/unlocked/expired states, tampered results, RPC failure |
| **Total** | **136** | |

The Solidity suite uses explicit verifier doubles at `0x0FD2` to isolate adversarial proof cases. Those tests are distinct from the committed live CC3 transaction, which executed against Creditcoin's real Native Query Verifier.

Expand Down
2 changes: 1 addition & 1 deletion apps/device/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# ProofKey machine simulator

This standalone browser view visualizes one physical machine and reads its authorization directly from `AccessPass` and `MachineRegistry` on Creditcoin CC3 testnet. It does not accept an unlock command from the worker or a private backend.
This standalone browser view is retained as a low-level authorization diagnostic. The production product integrates the machine experience at the public `/device/:machineId?handoff=:nonce` route in `@proofkey/web`, including one-time QR claims, continuous Creditcoin checks, and controller-signed usage receipts. Neither client accepts an unlock command from the relay.

Copy `.env.example` to the repository root, supply the five `VITE_*` values, then run:

Expand Down
4 changes: 3 additions & 1 deletion apps/web/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,11 +15,13 @@ For mobile connections, create a project in [Reown Cloud](https://cloud.reown.co

The user chooses an EIP-6963 browser wallet, Coinbase Wallet, or WalletConnect mobile wallet; switches to Sepolia when prompted; chooses a duration; approves the payment token if necessary; and confirms `payForUsage`. The approved session reconnects silently after refresh and never requests a signature until the user starts a transaction. The app automatically submits the confirmed transaction hash to the worker and follows every proof phase through Creditcoin execution. It never exposes the worker wallet key to the browser.

After access activates, `/sessions/:sourceTransactionHash` creates a one-time QR for the public `/device/:machineId` route. The device claims it once, reads `AccessPass` and `MachineRegistry` directly from CC3 every four seconds, and fails closed on any mismatch or RPC failure. The registered controller signs the start and end receipts; the customer session and My Rentals screens recover them from the relay and verify the signatures locally.

Run wallet state and browser-fixture tests with:

```bash
npm test --workspace @proofkey/web
npm run test:e2e --workspace @proofkey/web
```

For a side-by-side recording, also run `npm run dev --workspace @proofkey/device`.
For a side-by-side flow, open the generated device link in a second browser or private window. The separate `@proofkey/device` application remains available only as a low-level authorization diagnostic.
Loading
Loading