Skip to content

chore(game): update godot-iap to 3.6.1 and prepare the reference docs - #7

Merged
hyochan merged 9 commits into
mainfrom
chore/godot-iap-3.6.1
Sep 28, 2026
Merged

hyochan merged 9 commits into
mainfrom
chore/godot-iap-3.6.1

Conversation

@hyochan

@hyochan hyochan commented Sep 28, 2026

Copy link
Copy Markdown
Member

What

The game now vendors the official godot-iap 3.6.1 zip (SHA-256 matches the release digest and its build attestation). Two local patches remain: the 600 s iOS restore timeout (upstream is still 120 s) and exporting the iOS descriptor kept as .gdextension.ios, which desktop Godot 4.7 cannot skip. The fix_ios_embed.sh patches are upstream since 3.5.2, and the direct-distribution guard is no longer needed.

The shim that read the addon's private _native_plugin and _call_apple_async is gone. The backend calls the public get_available_purchases_result() and restore_purchases(), so a failed query still never reads as "no purchases". The IapStore autoload is renamed to Shop, which lets types.gd stay the official file.

3.6 also stops putting res://iapkit.cfg in release exports. That is where store exports wrote the IAPKit key, so the Play release AAB and the App Store archive would have shipped without it. Store exports now write res://iapkit_publishable.cfg, and the Play preset pins openiap/android_store="play".

Also in this PR: a "Using this as a reference" section in the README; the iOS team ID now comes from MOONLIT_APPLE_TEAM_ID, defaulting to PRDQGB267K; Monetize and the IAP setup notes now say sales are live; and the asset note moves from LICENSE to THIRD_PARTY_NOTICES.md, so GitHub can detect MIT. The release verdict in notes/release/iap-store-setup.md has a TODO for you: I could not confirm which of its boxes were verified before launch.

Lesson impact

None. Only the Monetize reference page changed.

Checks

  • pnpm verify is green (run with MOONLIT_PYTHON set to a Python that has Pillow)
  • No new binary over budget, no secrets, no Phase wording
  • Store-visible change: none. apps/game/ changed, so the capture fingerprints are stale; nothing was recaptured.

Exports, built with throwaway keystores and a fake IAPKit key: the direct APK and the debug and release Play AABs pass the CI boundary checks, and the release AAB carries exactly one pk-only iapkit_publishable.cfg. pnpm ios:export prints the Runtime embed check line, and an iOS release export keeps the key file. Device purchases were not run.

hyochan and others added 8 commits September 29, 2026 02:32
The shim called the wrapper's private _native_plugin and _call_apple_async
to keep a failed purchase query apart from an empty list. The wrapper
already does that publicly: get_available_purchases_result() and
restore_purchases() report failure separately, so the backend calls them
and the shim goes.

On Android, restore is now the wrapper's purchase query instead of the
native restorePurchases(), which also emitted purchase_updated per row.
The shop's follow-up sync already verifies and grants every row, so
nothing is lost. Tests now run queries and restore through the real
wrapper with a fake native bridge, including the typed round trip.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
godot-iap's types.gd declares an IapStore enum, and a global autoload
with the same name stops its `var store: IapStore` fields from parsing.
The vendored copy carried a local edit to get around that. Naming the
autoload Shop removes the clash, so types.gd is the official file again
and the vendor test pins its hash.

Only the global name and the three /root paths change; the script file,
save data, and product IDs stay the same.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Vendor the official godot-iap-3.6.1 zip. Its SHA-256 matches the release
asset digest and the release-godot.yml build attestation. The AARs, iOS
frameworks, and types.gd are byte-identical to 3.5.1.

Two local patches remain: the 600 s iOS restore timeout (upstream still
uses 120 s, and AppStore.sync() sign-in sheets can outlast it) and
exporting the iOS descriptor kept as .gdextension.ios, which desktop
Godot 4.7 cannot skip. The fix_ios_embed.sh patches are upstream since
3.5.2, and the direct-distribution guard only silenced a log line in the
itch.io APK.

3.6 leaves res://iapkit.cfg out of release exports, which would drop the
IAPKit key from the Play release AAB and the App Store archive, so store
exports now write res://iapkit_publishable.cfg. The Play preset pins
openiap/android_store="play" so a debug AAB never links another store's
flavor from an attached device. The locale check skips vendored addons,
whose env-var names look like translation keys.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/ios.mjs hard-coded team PRDQGB267K, so a copy of the project
could not sign with its own team. It now reads MOONLIT_APPLE_TEAM_ID and
keeps PRDQGB267K as the default. Every xcodebuild call already passes
DEVELOPMENT_TEAM, so release checks expect the archive to carry that
team; the export preset keeps the default because Godot requires a
value there. The App Store release helper reuses the same default, and a
test keeps it in step with the preset.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Monetize still said live sales stay off, but the App Store listing shows
all 10 items under In-App Purchases and the Play listing is marked
"In-app purchases". Section 9 now frames the store-side steps as work a
copy of the project repeats. The flow sample adds the result-form
purchase query the game uses, and third-party.md counts all 10 items.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The release verdict was never ticked although the App Store listing shows
all 10 items with prices and the Play listing is marked "In-app
purchases". Record that dated status and leave a TODO for the maintainer
to tick what was verified; nothing is checked off on their behalf. Also
name the key file store exports now write, and bump the store-page
credits to godot-iap 3.6.1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Replace the short godot-iap note in the README with "Using this as a
reference": what the project shows (one-time products and consumables,
IAPKit verification, finish or consume, restore, resume sync, refunds; no
subscriptions), what a copy must change to run purchases, and how the
vendored addon and iOS frameworks are wired. CONTRIBUTING and AGENTS.md
pick up the 3.6.1 version and the iapkit_publishable.cfg name.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
GitHub reported the license as "Other" because a third-party asset note
followed the MIT text. The note moves to THIRD_PARTY_NOTICES.md, which
the README links, so LICENSE now matches the standard MIT template.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@hyochan hyochan added 📦 update packages 🎮 game 💨 ci Cloud integration 📖 documentation Improvements or additions to documentation 🔖 license labels Sep 28, 2026
The locale check skipped every addons/ directory, so a missing key used from
a future addon script would pass; it now skips only the vendored godot-iap
addon, whose environment-variable names look like keys. The hygiene check
also fails when iapkit.cfg or iapkit_publishable.cfg is committed, instead of
relying on .gitignore alone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@hyochan
hyochan merged commit 17761af into main Sep 28, 2026
4 checks passed
@hyochan
hyochan deleted the chore/godot-iap-3.6.1 branch September 30, 2026 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

💨 ci Cloud integration 📖 documentation Improvements or additions to documentation 🎮 game 🔖 license 📦 update packages

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant