Skip to content

Product finishing: badge embed, QR rendering, registry HTTP surface - #12

Merged
nrupala merged 2 commits into
mainfrom
wright/product-finishing
Oct 7, 2026
Merged

nrupala merged 2 commits into
mainfrom
wright/product-finishing

Conversation

@nrupala

@nrupala nrupala commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Product finishing — the last product-side mile before first revenue

Implements the three remaining SPEC open items: badge embed, QR image rendering, registry HTTP hosting.

Badge embed (core/badge.py, axiomcode badge)

  • Version-pinned SVG badges ("Certified v1.2.3", never bare "Certified"), shields.io flat style.
  • Tamper-evident by construction: the SVG is rendered server-side from LIVE registry data at request time. The embed snippet points at the issuer-hosted /badge/<serial>.svg, so a copied badge can never claim a false status — a revoked cert's badge turns red everywhere it is embedded, automatically.
  • Status-aware: certified (bright green) / verified / revoked (red) / expired (orange) / invalid signature (red) / unknown (grey). A tampered certificate's badge renders "Invalid signature", never "Certified".

QR rendering (core/qr.py, axiomcode qr)

  • Pure-Python segno (zero dependencies) renders the certificate's QR payload as PNG/SVG. Uses the signature-covered qr_payload when set, else the canonical verification URL.
  • segno added to requirements.txt.

Registry HTTP surface (services/registry_app.py, axiomcode serve-registry)

  • Zero-dependency stdlib WSGI app: / storefront, /health, /api/registry (active; ?status=all full transparency log), /api/export (agent machine-readable), /api/cert/<serial>, /cert/<serial> (human page with QR + badge snippet), /badge/<serial>.svg (live), /qr/<serial>.png.
  • Read-only by construction: no mutation endpoints exist; POST/PUT/DELETE → 405. Publication/revocation stay CLI-only.

Behavior-test evidence (terminal-confirmed, not just CI)

  • 24 new behavior tests in tests/test_product_finishing.py: revoked badge renders "Revoked" (never "Certified"); tampered registry cert → badge "Invalid signature"; QR PNG has valid magic bytes and payload differentiation; HTTP: active list excludes revoked/expired, ?status=all includes them, per-cert JSON carries signature+verify_key, badge endpoint reflects live revoked status, QR endpoint returns PNG, POST→405, path traversal rejected.
  • CLI exercised end-to-end against a scratch registry: badge snippet/SVG and QR PNG all produced correctly (scratch registry removed afterwards).
  • Full suite: 221 passed, 3 skipped (197 baseline + 24 new). ruff check + ruff format --check clean.
  • One honest limit: QR decode-verification (scan with a phone) not done locally — no zbar on the sandbox. segno is well-tested; recommend a one-time phone scan as acceptance.

Follow-ups (out of scope, noted)

  • services/api/ (verify_api.py, certs.py) is a pre-P0 prototype using HMAC certs and importing fastapi (not in requirements) — inconsistent with the Ed25519 architecture. Recommend deprecating/removing in a follow-up PR.
  • QR payload on older certs may be empty — the app/CLI fall back to the canonical verification URL.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Deploying axiomcode-site with  Cloudflare Pages  Cloudflare Pages

Latest commit: 5e9715a
Status: ✅  Deploy successful!
Preview URL: https://72338317.axiomcode-site.pages.dev
Branch Preview URL: https://wright-product-finishing.axiomcode-site.pages.dev

View logs

@nrupala
nrupala merged commit 828928c into main Oct 7, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant