- 收款方
- 示例专业数据服务
- 商品
- AI 支付行业趋势数据 API
- 金额
- 0.01 CNY
等待服务返回机器账单。
diff --git a/README.en.md b/README.en.md index 6e3263b..b1581b4 100644 --- a/README.en.md +++ b/README.en.md @@ -8,20 +8,29 @@ ACT (Agentic Commerce Trust Protocol) is an open protocol for agentic commerce. | Goal | Entry | |---|---| +| Experience the ACT flow online | [ACT website demo](https://www.act-protocol.com/demo) | | Read ACT 2.1 | [Specification overview](docs/specification/overview.en.md) | | Understand end-to-end flows | [Scenarios and Business Flows](docs/specification/scenarios.en.md) | -| Run the TSD-CRD credit-association reference flow | [TSD-CRD Reference Implementation](code/samples/tsd-crd-reference/README.md) | | Run the safe local A402 sample | [Local A402 Sample](code/samples/local-a402/README.md) | -| Explore the interactive flow | [Web Showcase](code/web-client/alipay-ai-pay-showcase/README.md) | +| Run the interactive demo locally | [Web Showcase](code/web-client/alipay-ai-pay-showcase/README.en.md) | +| Run the TSD-CRD credit-association reference flow | [TSD-CRD Reference Implementation](code/samples/tsd-crd-reference/README.md) | | Integrate Alipay | [Alipay Reference Integration](integrations/alipay/README.md) | -For a first visit: read the [English overview](docs/specification/overview.en.md), keep the [bilingual glossary](docs/glossary.md) open, run the local sample, and then choose the buyer or seller Alipay integration. The local sample intentionally demonstrates safe rejection rather than manufacturing payment success; a successful paid delivery requires verified proof from the official product workflow. +For a first visit: + +1. Open the [ACT website demo](https://www.act-protocol.com/demo) to see the business steps, participants, and protocol components together. +2. Read the [English overview](docs/specification/overview.en.md) to distinguish ADD, CID, PSD, TSD, and A402; keep the [bilingual glossary](docs/glossary.md) open for abbreviations. +3. Read [Scenarios and Business Flows](docs/specification/scenarios.en.md) to map the demo onto complete protocol flows. +4. Run the Local A402 Sample or TSD-CRD Reference Implementation depending on whether you are exploring the safe payment path or credit association. +5. For a real successful payment flow, choose the [Alipay buyer](integrations/alipay/buyer-agent/README.md) or [Java seller](integrations/alipay/seller-java/README.md) integration and complete authorization and payment in the official sandbox. + +The Local A402 Sample intentionally rejects fake proof instead of manufacturing payment success. A successful paid delivery requires verified proof from the official product workflow. The TSD-CRD Reference Implementation uses only mock capabilities and test keys; it is not a production credit service. The five human-readable specification documents and the non-normative scenario guide live in `docs/specification/`. A402 and commerce-to-payment integration guides are grouped with the Alipay reference integration under `integrations/alipay/`. JSON Schemas, fixtures, and tests live in `code/schemas/`; they support implementation without adding requirements that are absent from the specification. ACT 2.1 is available in both [Chinese](docs/specification/overview.md) and [English](docs/specification/overview.en.md). The English documents are official informative translations of the final 2.1 publication; if a translation discrepancy is found, the Chinese publication remains controlling until the translation is corrected in a subsequent repository release. -The overview and four domain specifications under `docs/specification/` are the sole versioned ACT 2.1 normative publication in this repository release; the scenario guide is explicitly non-normative. [act-protocol.com](https://www.act-protocol.com/) is a project-information entry point. Website content that is not explicitly labeled ACT 2.1 is informative and is not a normative source for this release. If a web page omits a component, uses a different structure, or conflicts with this release, it MUST NOT override or interpret the repository's ACT 2.1 requirements. +The overview and four domain specifications under `docs/specification/` are the versioned ACT 2.1 normative publication; the scenario guide is non-normative. [act-protocol.com](https://www.act-protocol.com/) provides project information and the online demo; it does not replace the versioned specification in this repository. ## Repository layout @@ -37,18 +46,27 @@ tools/ Repository quality and release tooling The dependency direction is specification → artifacts → product integration → sample/demo. Product code, demos, and repository tools do not define ACT semantics. +## Online demo + +Open the [ACT website demo](https://www.act-protocol.com/demo) to experience the protocol flow without downloading or installing anything. The website demo is an interactive walkthrough, not a payment implementation or conformance certification. + ## Run locally -After downloading or cloning this repository, run from the repository root using Node.js 18 or later: +The following Node.js programs have no third-party runtime dependencies, so `npm install` is not required. Download or clone the repository and run the commands from its root. + +### Local A402 Sample + +Requires Node.js 18 or later: ```bash npm --prefix code/samples/local-a402 run local -npm --prefix code/web-client/alipay-ai-pay-showcase run demo ``` -The local A402 sample performs no payment. The Showcase explains the protocol flow and does not constitute a payment implementation or conformance claim. +The sample returns `402 Payment Required`, decodes `Payment-Needed`, and verifies that a fake `Payment-Proof` does not deliver the paid resource. It never connects to a payment product or performs payment. -The TSD-CRD reference suite requires Node.js 22.18 or later: +### TSD-CRD Reference Implementation + +Requires Node.js 22.18 or later. Run its tests, baseline conformance checks, and local demo: ```bash npm --prefix code/samples/tsd-crd-reference run check @@ -57,9 +75,29 @@ npm --prefix code/samples/tsd-crd-reference run demo It uses Mock providers, in-memory state, temporary test keys, and the optional non-normative `reference-v1` machine profile. Passing its tests is not a claim of full ACT 2.1 conformance or production readiness. +### Web Showcase + +Requires Node.js 18 or later. To inspect or modify the interactive demo locally, run: + +```bash +npm --prefix code/web-client/alipay-ai-pay-showcase run demo +``` + +Open `http://127.0.0.1:4173/`. The local Showcase explains the protocol flow and is not a payment implementation or conformance certification. + +## Alipay reference integration + +`integrations/alipay/` separates the two sides of the product integration: + +- `buyer-agent/` checks the environment and hands off to the buyer wallet and payment package `@alipay/agent-payment`. +- `seller-java/` uses the Alipay Java SDK for Machine Pay proof verification and fulfillment confirmation. The official seller integration assistant `@alipay/alipay-aipay` is referenced as an external tool only. +- `validation/` provides sandbox preflight and sanitized evidence guidance. + For Alipay onboarding, credentials, sandbox operation, and current product behavior, use the [AIPay website](https://aipay.alipay.com/callpay) and its [official integration guide](https://aipay.alipay.com/docs/ai-receive/MACHINE_PAY.html). -Run all checks with Python 3, Node.js 22.18+, JDK 8+, and Maven 3.8+: +## Quality checks + +Run all checks with Python 3, Node.js 22.18+, JDK 8+, and Maven 3.8+. The suite covers repository structure, internal links, key official external links, schemas, samples, integrations, and the demo: ```bash ./tools/verify.sh diff --git a/README.md b/README.md index c7e90cd..2e32a01 100644 --- a/README.md +++ b/README.md @@ -8,26 +8,27 @@ ACT(Agentic Commerce Trust Protocol)是面向智能体商业交互的开放 | 目标 | 入口 | |---|---| +| 在线体验 ACT 流程 | [ACT 官网 Demo](https://www.act-protocol.com/demo) | | 阅读 ACT 2.1 | [协议概览](docs/specification/overview.md) | | 理解完整业务流程 | [典型场景与业务流程](docs/specification/scenarios.md) | -| 运行 TSD-CRD 信用关联参考链路 | [TSD-CRD Reference Implementation](code/samples/tsd-crd-reference/README.md) | | 本地运行安全的 A402 样例 | [Local A402 Sample](code/samples/local-a402/README.md) | -| 查看交互演示 | [Web Showcase](code/web-client/alipay-ai-pay-showcase/README.md) | +| 本地运行交互演示 | [Web Showcase](code/web-client/alipay-ai-pay-showcase/README.md) | +| 运行 TSD-CRD 信用关联参考链路 | [TSD-CRD Reference Implementation](code/samples/tsd-crd-reference/README.md) | | 接入支付宝 | [Alipay Reference Integration](integrations/alipay/README.md) | 第一次进入仓库,建议按以下顺序阅读: -1. 用 2 分钟阅读[协议概览](docs/specification/overview.md),先区分 ADD、CID、PSD、TSD 与 A402; -2. 遇到缩写时查看[中英术语表](docs/glossary.md); -3. 需要理解信用关联时,运行 TSD-CRD Reference Implementation,观察关联、映射、生命周期、查询授权和验证; -4. 运行 Local A402 Sample,观察 `402 → Payment-Needed → 伪 Proof 被拒绝` 的安全路径; +1. 打开 [ACT 官网 Demo](https://www.act-protocol.com/demo),先直观看到 Agent 商业流程中的业务步骤、参与方和协议组件; +2. 用 2 分钟阅读[协议概览](docs/specification/overview.md),区分 ADD、CID、PSD、TSD 与 A402;遇到缩写时查看[中英术语表](docs/glossary.md); +3. 阅读[典型场景与业务流程](docs/specification/scenarios.md),把演示步骤对应到完整协议流程; +4. 根据关注点运行 Local A402 Sample 或 TSD-CRD Reference Implementation,分别观察安全支付路径或信用关联路径; 5. 需要真实支付成功链路时,选择[支付宝买方](integrations/alipay/buyer-agent/README.md)或[卖方 Java](integrations/alipay/seller-java/README.md),并在官网沙箱完成授权和支付。 Local A402 Sample 有意不伪造支付成功。真实资源交付必须来自已经验真的支付证明,因此“本地安全失败路径”和“官网沙箱成功路径”是两个不同的接入阶段。TSD-CRD Reference Implementation 同样只使用 Mock 能力和测试密钥,不是生产信用服务。 ACT 2.1 的五份规范正文和非规范性场景指南位于 `docs/specification/`。A402 与 Commerce–Payment 接入指南随支付宝参考接入放在 `integrations/alipay/`。JSON Schema、fixtures 和测试位于 `code/schemas/`,用于帮助实现与验证,不增加协议正文未规定的要求。 -本仓库发布版本中,`docs/specification/` 下的协议概览和四份域规范共同构成 ACT 2.1 唯一的版本化规范正文;场景指南明确为非规范性材料。[act-protocol.com](https://www.act-protocol.com/) 是项目信息入口;未明确标注 ACT 2.1 版本的网页内容属于信息性材料,不是本 Release 的规范来源。网页如果遗漏本 Release 的组件、采用不同结构或与正文冲突,只能按网页自身标明的版本理解,不得用于覆盖或解释本仓库的 ACT 2.1 要求。 +`docs/specification/` 下的协议概览和四份域规范共同构成 ACT 2.1 的版本化规范正文,场景指南属于非规范性材料。[act-protocol.com](https://www.act-protocol.com/) 提供项目信息和在线演示,不替代本仓库中的版本化规范。 ## 仓库结构 @@ -59,9 +60,17 @@ sample / demo 产品实现、演示和 `tools/` 下的验证程序不得反向定义协议语义。 -## 运行本地样例 +## 在线体验 Demo + +无需下载或安装,即可打开 [ACT 官网 Demo](https://www.act-protocol.com/demo) 体验协议流程。官网 Demo 是交互演示,不是支付实现或一致性认证。 + +## 本地运行 -下载或 clone 本仓库后,在仓库根目录执行以下命令,需要 Node.js 18 或更高版本: +以下三个 Node.js 程序均无第三方运行时依赖,不需要先执行 `npm install`。下载或 clone 本仓库后,在仓库根目录运行。 + +### Local A402 Sample + +需要 Node.js 18 或更高版本: ```bash npm --prefix code/samples/local-a402 run local @@ -69,7 +78,9 @@ npm --prefix code/samples/local-a402 run local 这个样例返回 `402 Payment Required`、解码 `Payment-Needed`,并验证伪造的 `Payment-Proof` 不会导致资源交付。它不连接支付产品,也不会执行支付。 -运行 TSD-CRD 测试、基础一致性检查和本地 Demo 需要 Node.js 22.18 或更高版本: +### TSD-CRD Reference Implementation + +需要 Node.js 22.18 或更高版本。运行测试、基础一致性检查和本地 Demo: ```bash npm --prefix code/samples/tsd-crd-reference run check @@ -78,27 +89,29 @@ npm --prefix code/samples/tsd-crd-reference run demo 该套件采用非规范性的 `reference-v1` 机器 Profile。测试通过只证明仓库内参考路径,不等于 ACT 2.1 全量 Conformance 或生产就绪。 -运行交互演示: +### Web Showcase + +需要 Node.js 18 或更高版本。如需在本地查看或修改交互演示源码,运行: ```bash npm --prefix code/web-client/alipay-ai-pay-showcase run demo ``` -打开 `http://127.0.0.1:4173/`。Showcase 是协议流程演示,不是支付实现或一致性认证。 +打开 `http://127.0.0.1:4173/`。本地 Showcase 是协议流程演示,不是支付实现或一致性认证。 ## 支付宝参考接入 `integrations/alipay/` 展示两侧能力: -- `buyer-agent/`:检查环境并引导安装支付宝官方 Agent Payment Skill/CLI; -- `seller-java/`:使用支付宝 Java SDK 验证支付凭证并确认履约; +- `buyer-agent/`:检查环境并引导安装买方钱包与支付工具 `@alipay/agent-payment`; +- `seller-java/`:使用支付宝 Java SDK 接入 Machine Pay,验证支付凭证并确认履约;支付宝官方卖方接入助手 `@alipay/alipay-aipay` 仅作为外部工具引用; - `validation/`:沙箱前置检查和脱敏证据格式。 支付宝开户、授权、密钥、沙箱和最新产品操作始终以 [AIPay 官网](https://aipay.alipay.com/callpay)及其[官方接入指南](https://aipay.alipay.com/docs/ai-receive/MACHINE_PAY.html)为准。本仓库不复制或实现官网沙箱。 ## 质量检查 -完整检查需要 Python 3、Node.js 22.18+、JDK 8+ 和 Maven 3.8+: +完整检查需要 Python 3、Node.js 22.18+、JDK 8+ 和 Maven 3.8+。检查包含仓库结构、内部链接、关键官网外链、Schema、样例、集成和 Demo: ```bash ./tools/verify.sh diff --git a/code/README.md b/code/README.md index 8ee5cb0..a2ba0e9 100644 --- a/code/README.md +++ b/code/README.md @@ -6,6 +6,6 @@ This directory contains executable and machine-readable assets. It does not defi |---|---| | [`schemas/`](schemas/README.md) | JSON Schemas, fixtures, examples, test vectors, and implementation tests | | [`samples/`](samples/README.md) | Small runnable samples and the TSD-CRD reference implementation | -| [`web-client/`](web-client/README.md) | Interactive protocol demonstrations | +| [`web-client/`](web-client/README.en.md) | Interactive protocol demonstrations | The ACT 2.1 text is under [`docs/specification/`](../docs/specification/README.md). Reference implementation guidance and product-specific code belong under [`integrations/`](../integrations/README.md). diff --git a/code/web-client/README.en.md b/code/web-client/README.en.md new file mode 100644 index 0000000..399e0c3 --- /dev/null +++ b/code/web-client/README.en.md @@ -0,0 +1,9 @@ +# Web client + +[简体中文](README.md) | English + +The demos in this directory explain protocol flows visually. They do not establish real payment, product compatibility, or production readiness. + +- [ACT 2.1 Machine Payment Showcase](alipay-ai-pay-showcase/README.en.md): presents business execution, participants, and protocol steps side by side using explanatory data only; it neither connects to nor replays an official product sandbox. + +To connect to the Alipay product or its sandbox, use the [Alipay Reference Integration](../../integrations/alipay/README.md). diff --git a/code/web-client/README.md b/code/web-client/README.md index 6bc26d5..a5dba97 100644 --- a/code/web-client/README.md +++ b/code/web-client/README.md @@ -1,7 +1,9 @@ # Web client +[English](README.en.md) | 简体中文 + Demo 用于直观展示协议流程,但不能据此声明真实支付、产品兼容或生产就绪。 -- [ACT 2.1 Machine Payment Showcase](alipay-ai-pay-showcase/README.md):对照业务与协议步骤,并可回放官方产品沙箱产生的脱敏证据。 +- [ACT 2.1 Machine Payment Showcase](alipay-ai-pay-showcase/README.md):以左右对照方式展示业务执行、参与方和协议步骤;只使用说明性演示数据,不连接或回放官方产品沙箱。 连接支付宝产品或沙箱请使用 [Alipay Reference Integration](../../integrations/alipay/README.md)。 diff --git a/code/web-client/alipay-ai-pay-showcase/README.en.md b/code/web-client/alipay-ai-pay-showcase/README.en.md new file mode 100644 index 0000000..2c5a27e --- /dev/null +++ b/code/web-client/alipay-ai-pay-showcase/README.en.md @@ -0,0 +1,78 @@ +# ACT × Alipay AI Pay Guided Showcase + +[简体中文](README.md) | English + +This demo explains how an agent purchases professional data during research. It presents business execution, participants, ACT 2.1 components, and Alipay product mappings side by side. + +> **Scope: Guided Demo / Non-normative / No real payment** +> The demo does not connect to an Alipay sandbox, wallet, payment API, or proof-verification API. It receives no real events and performs no payment. + +## What the demo covers + +| Scenario | Core distinction | Alipay implementation boundary | +|---|---|---| +| L1 / `PSD-PAY-INS` | The user authenticates and confirms every payment | Shows an explanatory Alipay binding QR-code placeholder and payment confirmation card; the QR code cannot be scanned | +| L2 / `PSD-PAY-DEL` | The user pre-authorizes a specific item, merchant, amount, and number of payments; matching payments proceed automatically | Demonstrates ACT 2.1 semantics only; this repository makes no claim about an Alipay L2 implementation | +| L3 / `PSD-PAY-AUP` | The user sets task and budget boundaries; the agent selects and pays autonomously within them | Demonstrates ACT 2.1 semantics only; this repository makes no claim about an Alipay L3 implementation | + +Each scenario shows `CID-PCA-NEG`, commercial confirmation, the resource request, HTTP 402, `Payment-Needed`, payment handling, retrying the original request with `Payment-Proof`, proof verification, resource delivery, and fulfillment confirmation. Failure modes cover an unknown payment result, proof mismatch, unavailable proof verification, and idempotent retry. + +## Requirements + +- Node.js 18 or later. +- No `npm install` is required. +- Run the commands below from the repository root. + +## Start + +```bash +npm --prefix code/web-client/alipay-ai-pay-showcase run demo +``` + +After startup, the terminal prints: + +```text +ACT showcase: http://127.0.0.1:4173/ +``` + +The server does not open a browser automatically. Visit `http://127.0.0.1:4173/`, then: + +1. Select L1, L2, or L3 to compare the three authorization levels. +2. Use step-by-step playback to inspect the business action, participants, and protocol component at each stage. +3. Use autoplay to watch the complete flow. +4. Switch failure modes to inspect an unknown payment result, proof mismatch, unavailable verification, and idempotent retry. + +The server runs in the foreground. Press `Ctrl+C` to stop it. + +## Change the port + +The default port is `4173`. If it is already in use, set `PORT` to another value. + +macOS or Linux: + +```bash +PORT=4174 npm --prefix code/web-client/alipay-ai-pay-showcase run demo +``` + +Windows PowerShell: + +```powershell +$env:PORT=4174; npm --prefix code/web-client/alipay-ai-pay-showcase run demo +``` + +Open the new address printed by the terminal. If startup reports `EADDRINUSE`, the selected port is also occupied; choose another port and retry. + +## Boundaries + +- Orders, amounts, transaction references, QR codes, and results shown in the page are explanatory demo data. +- The demo does not verify a real `Payment-Proof`, provide payment-success evidence, or constitute conformance certification. +- ACT semantics come from the finalized specification under [`docs/specification/`](../../../docs/specification/README.md). +- Use the [AIPay website](https://aipay.alipay.com/callpay) and its official integration documentation for Alipay product integration. This repository provides reference integration material only under [`integrations/alipay/`](../../../integrations/alipay/README.md). +- The official sandbox is provided and operated by Alipay. This demo does not copy, proxy, or offer a “connect sandbox” feature. + +## Checks + +```bash +npm --prefix code/web-client/alipay-ai-pay-showcase test +npm --prefix code/web-client/alipay-ai-pay-showcase run build +``` diff --git a/code/web-client/alipay-ai-pay-showcase/README.md b/code/web-client/alipay-ai-pay-showcase/README.md index 24417f6..e6d43d4 100644 --- a/code/web-client/alipay-ai-pay-showcase/README.md +++ b/code/web-client/alipay-ai-pay-showcase/README.md @@ -1,5 +1,7 @@ # ACT × Alipay AI Pay Guided Showcase +[English](README.en.md) | 简体中文 + 本 Demo 说明“Agent 在调研过程中如何购买专业数据”,以左右对照方式展示业务执行、参与方、ACT 2.1 组件和支付宝产品映射。 > **范围:Guided Demo / Non-normative / No real payment** @@ -9,13 +11,19 @@ | 场景 | 核心区别 | 支付宝实现边界 | |---|---|---| -| L1 / `PSD-PAY-INS` | 用户对每一笔支付核身确认 | 展示支付宝绑定、支付卡片和二维码占位图,均不可扫码 | +| L1 / `PSD-PAY-INS` | 用户对每一笔支付核身确认 | 展示支付宝绑定二维码占位图和付款确认卡片;二维码不可扫码 | | L2 / `PSD-PAY-DEL` | 用户预先明确商品、商户、金额和次数,匹配后自动支付 | 仅演示 ACT 2.1 语义,本仓库不声明支付宝 L2 实现 | | L3 / `PSD-PAY-AUP` | 用户给出任务与预算边界,Agent 在边界内自主选择和支付 | 仅演示 ACT 2.1 语义,本仓库不声明支付宝 L3 实现 | 每个场景均展示 `CID-PCA-NEG`、商业确认、资源请求、HTTP 402、`Payment-Needed`、支付处理、携 `Payment-Proof` 重试原请求、验款、资源交付和履约确认。异常选项覆盖支付结果未知、Proof 不匹配、验款不可用和幂等重试。 -## 运行 +## 运行要求 + +- Node.js 18 或更高版本; +- 无需执行 `npm install`; +- 以下命令从仓库根目录运行。 + +## 启动 在仓库根目录执行: @@ -23,7 +31,38 @@ npm --prefix code/web-client/alipay-ai-pay-showcase run demo ``` -浏览器打开 `http://127.0.0.1:4173/`,选择 L1、L2 或 L3,再逐步或自动播放。 +启动成功后,终端会显示: + +```text +ACT showcase: http://127.0.0.1:4173/ +``` + +服务不会自动打开浏览器。访问 `http://127.0.0.1:4173/` 后: + +1. 选择 L1、L2 或 L3,比较三种授权等级的核心区别; +2. 使用单步播放逐项查看业务动作、参与方和协议组件; +3. 使用自动播放观察完整流程; +4. 切换异常场景,查看支付结果未知、Proof 不匹配、验款不可用和幂等重试。 + +服务在当前终端前台运行;按 `Ctrl+C` 停止。 + +## 更换端口 + +默认端口为 `4173`。端口已被占用时,可以通过 `PORT` 指定其他端口。 + +macOS 或 Linux: + +```bash +PORT=4174 npm --prefix code/web-client/alipay-ai-pay-showcase run demo +``` + +Windows PowerShell: + +```powershell +$env:PORT=4174; npm --prefix code/web-client/alipay-ai-pay-showcase run demo +``` + +然后打开终端输出的新地址。如果出现 `EADDRINUSE`,说明指定端口仍被占用;请换一个端口重试。 ## 边界 diff --git a/code/web-client/alipay-ai-pay-showcase/guided-demo.test.mjs b/code/web-client/alipay-ai-pay-showcase/guided-demo.test.mjs index 7a1d165..3cbdc4e 100644 --- a/code/web-client/alipay-ai-pay-showcase/guided-demo.test.mjs +++ b/code/web-client/alipay-ai-pay-showcase/guided-demo.test.mjs @@ -13,6 +13,25 @@ test("offers guided L1, L2, and L3 scenarios", () => { } }); +test("keeps the synchronized L1 request, validation, confirmation, and delivery flow", () => { + assert.match(index, /id="eventCounter">0 \/ 17/); + for (const state of [ + "PAYMENT_REQUEST_SUBMITTED", + "PAYMENT_REQUEST_VALIDATED", + "USER_AUTHORIZATION_REQUIRED", + "PAYMENT_PROCESSING", + "PAYMENT_RESULT_RECEIVED", + "RESOURCE_REQUEST_RETRIED", + "PAYMENT_VERIFIED", + "RESOURCE_DELIVERED", + "FULFILLMENT_CONFIRMED", + ]) { + assert.match(app, new RegExp(`${state}:`)); + } + assert.equal(app.includes("PAYMENT_QR_PRESENTED"), false); + assert.match(app, /payment_validation_status/); +}); + test("does not expose a sandbox, live-event, or evidence-replay mode", () => { const published = `${index}\n${app}\n${JSON.stringify(packageJson.scripts)}`; for (const marker of ["LIVE_SANDBOX", "SANITIZED_REPLAY", "liveTab", "replayTab", "连接官方沙箱事件", "证据回放"]) { diff --git a/code/web-client/alipay-ai-pay-showcase/package.json b/code/web-client/alipay-ai-pay-showcase/package.json index 6737102..4d8ed7d 100644 --- a/code/web-client/alipay-ai-pay-showcase/package.json +++ b/code/web-client/alipay-ai-pay-showcase/package.json @@ -3,6 +3,9 @@ "version": "0.1.0", "private": true, "type": "module", + "engines": { + "node": ">=18" + }, "scripts": { "demo": "node server.mjs", "dev": "node server.mjs", diff --git a/code/web-client/alipay-ai-pay-showcase/public/app.js b/code/web-client/alipay-ai-pay-showcase/public/app.js index 12f042e..6b12404 100644 --- a/code/web-client/alipay-ai-pay-showcase/public/app.js +++ b/code/web-client/alipay-ai-pay-showcase/public/app.js @@ -27,13 +27,6 @@ const stateCatalog = { explanation: "授权后用户将短时绑定指令返回 Agent,官方能力确认绑定成功;后续每笔支付仍需按 L1 逐笔授权。", agent: "支付宝支付功能已经绑定。短时绑定指令未被记录,现在可以继续本次购买。", }, - PAYMENT_QR_PRESENTED: { - label: "核身后生成付款码", phase: "INS / L1", domain: "PSD", component: "PSD-PAY-INS · L1", - binding: "支付宝官方支付卡片", profile: "用户逐笔确认后生成本笔支付二维码", - product: "Agent 支付 · 扫码支付", code: "INS · QR", - explanation: "本笔交易生成支付宝支付卡片和二维码。二维码由官方产品生成;Demo 仅展示不可扫码占位图。", - agent: "本笔 0.01 元支付卡片已经生成,请使用支付宝扫码完成付款。", - }, SPECIFIED_INTENT_CAPTURED: { label: "明确自动支付意图", phase: "ADD / L2", domain: "ADD", component: "ADD-INT-ICS · SPECIFIED", binding: "指定商品、商户、金额与受托 Agent", profile: "ACT L2 协议语义", @@ -138,28 +131,52 @@ const stateCatalog = { explanation: "Seller 返回机器可读 Payment-Needed,并回显已协商的 method_id;资源继续锁定。", agent: "服务返回了一张机器账单。我正在核对商品、金额、支付方法和有效期。", }, + PAYMENT_REQUEST_SUBMITTED: { + label: "Agent 发起本笔支付", + phase: "INS / L1", + domain: "PSD", + component: "PSD-PAY-INS · payment request", + binding: "Buyer Agent → PSP 支付请求", + profile: "订单、金额、支付工具引用与唯一请求标识", + product: "AI 按量付费 · 将账单交给支付宝支付能力", + code: "INS · REQUEST", + explanation: "Buyer Agent 根据 Payment-Needed 构造本笔支付请求,携带商户订单、金额、币种、支付工具引用和唯一请求标识后提交给 PSP。", + agent: "我已核对机器账单,正在把本笔 0.01 元支付请求提交给支付宝支付能力。", + }, + PAYMENT_REQUEST_VALIDATED: { + label: "PSP 校验支付请求", + phase: "INS / L1", + domain: "PSD", + component: "PSD-PAY-INS · PSP validation", + binding: "PSP 校验请求、时效、签名与支付工具", + profile: "ACT 基础校验 ↔ 支付宝受理与风控", + product: "Agent 支付 · 支付受理与风险校验", + code: "INS · CHECK", + explanation: "PSP 在唤起用户确认前完成请求完整性、时效、Agent 身份或签名以及支付工具有效性的基础校验;本 Demo 不虚构支付宝内部报文字段。", + agent: "支付宝已受理请求并完成基础校验,下一步由用户在官方确认界面核对本笔交易。", + }, USER_AUTHORIZATION_REQUIRED: { - label: "用户对本笔核身确认", + label: "用户确认本笔支付", phase: "INS / L1", domain: "PSD", component: "PSD-PAY-INS · L1", - binding: "支付宝官方 Skill / CLI", - profile: "INS/L1 场景 ↔ 用户逐笔确认", - product: "Agent 支付 · 用户在场", + binding: "PSP 收银台 / 确认界面", + profile: "核身方式由 PSP 按风控与终端环境决定", + product: "Agent 支付 · 用户逐笔确认", code: "INS · L1", - explanation: "当前场景预先采用 L1。PSP 完成基础校验,并在资金处理前取得用户对本笔金额、商户与支付方式的确认和身份验证。", - agent: "L1 不允许自动扣款:请你对这一笔核身,并确认收款方、商品、金额和支付方式。", + explanation: "当前场景采用 L1。用户在 PSP 官方确认界面核对金额、商户和支付方式,并按 PSP 基于风控与终端环境选择的方式完成本笔确认或身份验证。", + agent: "用户已在支付宝确认界面核对本笔交易并完成确认,可以进入支付执行。", }, PAYMENT_PROCESSING: { - label: "支付宝处理中", + label: "支付执行中", phase: "INS / L1", domain: "PSD", - component: "Payment execution / status", - binding: "支付宝官方 Skill / CLI", + component: "PSD-PAY-INS · 支付执行", + binding: "PSP 资金扣划或额度冻结", profile: "ACT 支付执行 ↔ 支付宝官方支付流程", product: "Agent 支付 · 支付与查询", code: "INS · PAY", - explanation: "支付宝官方能力处理本次支付;结果未知时查询原交易,不能创建第二笔支付。", + explanation: "用户完成本笔即时确认后,PSP 执行资金扣划或额度冻结;结果未知时只能查询原交易,不能创建第二笔支付。", agent: "支付宝正在处理本次支付。结果确认前不会重复付款。", }, PAYMENT_RESULT_RECEIVED: { @@ -167,7 +184,7 @@ const stateCatalog = { phase: "INS / L1", domain: "PSD", component: "Payment result / Proof reference", - binding: "支付宝官方 Skill / CLI", + binding: "PSP → Buyer Agent 支付结果", profile: "官方支付结果提供脱敏 Proof 引用", product: "Agent 支付 · 支付结果", code: "INS · RESULT", @@ -187,40 +204,40 @@ const stateCatalog = { agent: "正在携带支付凭据重试同一个资源请求。", }, PAYMENT_VERIFIED: { - label: "服务方验款", + label: "核验 Payment-Proof", phase: "A402", domain: "PSD", - component: "Proof verification / Validation mapping", - binding: "支付宝 payment.verify", - profile: "ACT 2.1 Payment-Validation ↔ 支付宝验款结果", - product: "AI 按量付费 · payment.verify", + component: "PSD-PAY-A402 · Payment-Proof verification", + binding: "由 method_id 对应支付方法规范定义", + profile: "ACT 验款抽象 ↔ 支付宝 active、金额、订单与资源校验", + product: "AI 按量付费 · alipay.aipay.agent.payment.verify", code: "A402 · VERIFY", - explanation: "Seller 通过支付宝官方接口核验状态、金额、订单、资源和防重。ACT 2.1 Payment-Validation 映射到验款结果,不冒充已上线 Header。", - agent: "卖方已通过支付宝官方接口完成验款,正在准备交付资源。", + explanation: "Seller 解析 Buyer 携带的 Payment-Proof。ACT 2.1 只规定按支付方法规范向 PSP 或受信验证服务核验;本 Demo 映射为支付宝 AI 按量付费的 alipay.aipay.agent.payment.verify,并检查 active、金额、订单、资源和重复履约。", + agent: "卖方已取得 Payment-Proof 核验结果,接下来由卖方生成 A402 成功响应。", }, RESOURCE_DELIVERED: { - label: "资源交付", - phase: "FULFILLMENT", - domain: "BUSINESS FULFILLMENT", - component: "Resource delivery", - binding: "HTTP 成功响应", - profile: "资源交付是独立业务事实,不等同于支付成功", - product: "AI 按量付费 · 服务交付", - code: "DELIVERY", - explanation: "验款通过后,Seller 对同一请求返回对应资源;重复请求只返回幂等结果。", - agent: "专业数据已经交付,我正在把它整理成最终报告。", + label: "返回付费资源", + phase: "A402", + domain: "PSD", + component: "PSD-PAY-A402 · resource delivery", + binding: "HTTP 200 + 付费资源;可选 Payment-Validation", + profile: "ACT 要求交付资源;本 Demo 选择附带可选验证 Header", + product: "AI 按量付费 · 验凭通过后返回资源内容", + code: "A402 · DELIVERY", + explanation: "验款通过后,Seller 必须向 Buyer Agent 返回资源或启动服务。ACT 2.1 允许但不强制在成功响应中携带 Payment-Validation;本 Demo 选择以 HTTP 200 同时返回该 Header 和付费资源。", + agent: "我已收到专业数据;本 Demo 的卖方还选择返回了可选的 Payment-Validation Header。", }, FULFILLMENT_CONFIRMED: { - label: "履约确认", + label: "异步发送履约回执", phase: "FULFILLMENT", domain: "PSD / PRODUCT", - component: "Method fulfillment confirmation", - binding: "支付宝 fulfillment.confirm · 卖方观察", - profile: "产品履约确认与可选 TSD 证据相互独立", - product: "AI 按量付费 · 履约确认", + component: "PSD-PAY-A402 · post-fulfillment confirmation", + binding: "按支付方法规范向 PSP 确认履约", + profile: "ACT 履约确认抽象 ↔ 支付宝异步履约回执", + product: "AI 按量付费 · alipay.aipay.agent.fulfillment.confirm", code: "RECEIPT", - explanation: "卖方已完成支付宝产品履约确认。本 Demo 不把该调用冒充 TSD 事件;买方 ack 与卖方 confirm 是不同方向的产品动作。", - agent: "资源已交付,卖方产品履约确认已完成;可选 TSD 证据仍独立异步处理。", + explanation: "ACT 2.1 要求卖方按具体支付方法规范确认履约,但不定义 API 名称;支付宝 AI 按量付费将它实现为资源返回后的异步 alipay.aipay.agent.fulfillment.confirm 调用。该产品回执不是 TSD 事件。", + agent: "资源已经交付,卖方正在异步向支付宝发送产品履约回执。", }, PAYMENT_PENDING: { label: "结果待确认", @@ -240,7 +257,7 @@ const stateCatalog = { phase: "RECOVERY", domain: "PSD", component: "Proof consistency / replay checks", - binding: "payment.verify 拒绝", + binding: "Payment-Proof 验证失败", profile: "必须同时通过产品验款与本地账单一致性检查", product: "AI 按量付费 · 验款失败", code: "REJECTED", @@ -249,15 +266,15 @@ const stateCatalog = { failure: true, }, VERIFICATION_UNAVAILABLE: { - label: "验款暂不可用", + label: "凭证核验暂不可用", phase: "RECOVERY", domain: "PSD", component: "Verification availability", binding: "503 + Retry-After", profile: "示例恢复响应,不代表支付宝线上报文承诺", - product: "AI 按量付费 · payment.verify", + product: "本 Demo 不声明具体支付宝核验接口", code: "RETRY", - explanation: "官方验款暂不可用。Seller 返回可重试错误,不能猜测支付成功或提前交付。", + explanation: "凭证核验服务暂不可用。Seller 返回可重试错误,不能猜测支付成功或提前交付。", agent: "验款服务暂不可用。稍后会重试同一交易,不会重复扣款。", failure: true, }, @@ -267,7 +284,8 @@ const authorizationFlows = { L1: [ "PAYMENT_TOOL_STATUS_CHECKED", "WALLET_BINDING_REQUIRED", "WALLET_BINDING_QR_PRESENTED", "WALLET_BOUND", "CAPABILITY_NEGOTIATED", "ORDER_CONFIRMED", "RESOURCE_REQUESTED", "PAYMENT_REQUIRED", - "USER_AUTHORIZATION_REQUIRED", "PAYMENT_QR_PRESENTED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", + "PAYMENT_REQUEST_SUBMITTED", "PAYMENT_REQUEST_VALIDATED", "USER_AUTHORIZATION_REQUIRED", + "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED", ], L2: [ @@ -289,7 +307,6 @@ const exchangeCatalog = { WALLET_BINDING_REQUIRED: { from: "psp", to: "buyer", message: "返回官方开通与授权绑定指引" }, WALLET_BINDING_QR_PRESENTED: { from: "buyer", to: "principal", message: "展示支付宝官方绑定链接 / 二维码" }, WALLET_BOUND: { from: "principal", to: "psp", message: "提交短时绑定指令并确认支付能力就绪" }, - PAYMENT_QR_PRESENTED: { from: "psp", to: "principal", message: "生成本笔交易的支付宝扫码支付卡片" }, SPECIFIED_INTENT_CAPTURED: { from: "principal", to: "auth", message: "明确指定商户、资源、金额和受托 Agent" }, SPECIFIED_IAC_ISSUED: { from: "auth", to: "buyer", message: "签发 SPECIFIED IAC 与 delegation_id" }, SPECIFIED_IAC_VERIFIED: { from: "buyer", to: "buyer", message: "本地检查 IAC 状态、范围与 Agent 绑定" }, @@ -302,13 +319,15 @@ const exchangeCatalog = { ORDER_CONFIRMED: { from: "buyer", to: "seller", message: "确认商品:趋势数据 API · 单价 0.01 元 · 调用 1 次" }, RESOURCE_REQUESTED: { from: "buyer", to: "seller", message: "Agent 请求调用 AI 支付行业趋势数据 API" }, PAYMENT_REQUIRED: { from: "seller", to: "buyer", message: "服务返回报价:0.01 CNY,并保持数据锁定" }, - USER_AUTHORIZATION_REQUIRED: { from: "buyer", to: "principal", message: "请确认:向示例专业数据服务支付 0.01 元" }, - PAYMENT_PROCESSING: { from: "principal", to: "psp", message: "支付宝处理本次 0.01 元支付" }, + PAYMENT_REQUEST_SUBMITTED: { from: "buyer", to: "psp", message: "提交商户订单、金额、支付工具引用与唯一请求标识" }, + PAYMENT_REQUEST_VALIDATED: { from: "psp", to: "psp", message: "校验请求、时效、Agent 身份或签名与支付工具" }, + USER_AUTHORIZATION_REQUIRED: { from: "principal", to: "psp", message: "在支付宝确认界面核对交易并完成本笔确认或身份验证" }, + PAYMENT_PROCESSING: { from: "psp", to: "psp", message: "确认通过后执行资金扣划或额度冻结" }, PAYMENT_RESULT_RECEIVED: { from: "psp", to: "buyer", message: "付款结果已确认,Agent 获得脱敏支付凭据" }, RESOURCE_REQUEST_RETRIED: { from: "buyer", to: "seller", message: "Agent 携付款凭据重新请求同一份趋势数据" }, - PAYMENT_VERIFIED: { from: "seller", to: "psp", message: "核对交易、金额、订单和目标数据资源" }, - RESOURCE_DELIVERED: { from: "seller", to: "buyer", message: "验款通过,返回结构化趋势数据" }, - FULFILLMENT_CONFIRMED: { from: "seller", to: "psp", message: "服务方确认本次数据交付已完成" }, + PAYMENT_VERIFIED: { from: "seller", to: "psp", message: "按支付方法规范核验 Proof;本实现调用支付宝 payment.verify" }, + RESOURCE_DELIVERED: { from: "seller", to: "buyer", message: "HTTP 200 返回资源;本 Demo 另附可选 Payment-Validation" }, + FULFILLMENT_CONFIRMED: { from: "seller", to: "psp", message: "异步调用支付宝 fulfillment.confirm 发送履约回执" }, PAYMENT_PENDING: { from: "buyer", to: "psp", message: "查询原支付结果;不会再次发起付款" }, PROOF_REJECTED: { from: "seller", to: "buyer", message: "付款凭据不匹配,数据保持锁定" }, VERIFICATION_UNAVAILABLE: { from: "psp", to: "seller", message: "验款暂不可用,稍后重试且不提前交付" }, @@ -326,33 +345,27 @@ const phaseCatalogs = { L1: [ { eyebrow: "PMT-BND", label: "开通并绑定", states: ["PAYMENT_TOOL_STATUS_CHECKED", "WALLET_BINDING_REQUIRED", "WALLET_BINDING_QR_PRESENTED", "WALLET_BOUND"] }, { eyebrow: "CID + A402", label: "选服务与报价", states: ["CAPABILITY_NEGOTIATED", "ORDER_CONFIRMED", "RESOURCE_REQUESTED", "PAYMENT_REQUIRED"] }, - { eyebrow: "INS / L1", label: "逐笔核身确认", states: ["USER_AUTHORIZATION_REQUIRED", "PAYMENT_QR_PRESENTED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "PAYMENT_PENDING"] }, - { eyebrow: "A402", label: "凭据与验款", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE"] }, - { eyebrow: "FULFILLMENT", label: "获取数据", states: ["RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, + { eyebrow: "INS / L1", label: "逐笔请求与确认", states: ["PAYMENT_REQUEST_SUBMITTED", "PAYMENT_REQUEST_VALIDATED", "USER_AUTHORIZATION_REQUIRED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "PAYMENT_PENDING"] }, + { eyebrow: "A402", label: "支付凭证核验", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE"] }, + { eyebrow: "A402 + FULFILLMENT", label: "响应与履约", states: ["RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, ], L2: [ { eyebrow: "ADD", label: "明确委托", states: ["SPECIFIED_INTENT_CAPTURED"] }, { eyebrow: "SPECIFIED IAC", label: "签发授权", states: ["SPECIFIED_IAC_ISSUED"] }, { eyebrow: "CID + A402", label: "选服务与报价", states: ["CAPABILITY_NEGOTIATED", "ORDER_CONFIRMED", "RESOURCE_REQUESTED", "PAYMENT_REQUIRED"] }, { eyebrow: "DEL / L2", label: "意图匹配自动付", states: ["SPECIFIED_IAC_VERIFIED", "DEL_PSP_AUTHORIZED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "PAYMENT_PENDING"] }, - { eyebrow: "A402", label: "验款与交付", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, + { eyebrow: "A402", label: "凭证核验、响应与履约", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, ], L3: [ { eyebrow: "ADD", label: "定义任务边界", states: ["BOUNDED_INTENT_CAPTURED"] }, { eyebrow: "BOUNDED IAC", label: "签发授权", states: ["BOUNDED_IAC_ISSUED"] }, { eyebrow: "CID + A402", label: "自主选服务", states: ["CAPABILITY_NEGOTIATED", "ORDER_CONFIRMED", "RESOURCE_REQUESTED", "PAYMENT_REQUIRED"] }, { eyebrow: "AUP / L3", label: "边界内自主付", states: ["AUP_BOUNDARY_CHECKED", "AUP_PSP_AUTHORIZED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "PAYMENT_PENDING"] }, - { eyebrow: "A402", label: "验款与交付", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, + { eyebrow: "A402", label: "凭证核验、响应与履约", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, ], }; const forbiddenKeys = /(^|_)(secret|private_key|access_token|app_auth_token|payment_proof|client_session|binding_code|password)($|_)/i; -const detailKeys = [ - "authorization_level", "delegation_mode", "delegation_id", "method_id", "method_version", "psp_id", "http_method", "commerce_confirmation_ref", - "request_ref", "request_fingerprint", "order_ref", "proof_ref", "transaction_ref", - "resource_id", "amount", "currency", "validation_mapping", "delivery_ref", "fulfillment_ref", - "idempotent_replay", "recovery_action", -]; const demoBase = { mode: "GUIDED_DEMO", source: "illustrative-ui-demo", @@ -368,7 +381,7 @@ const authorizationCopy = { description: "Agent 可以准备订单,但每笔扣款前都必须回到用户确认金额、商户与支付方式。", facts: ["用户逐笔在场", "逐笔核身确认", "Agent 不可自动扣款"], userRequest: "帮我生成《2026 AI 支付趋势报告》,需要付款时每一笔都让我核身确认。", - intro: "L1 中 Agent 可以寻找并报价,但每一笔支付都必须由用户在场核身确认。本页演示首次绑定、逐笔确认、扫码付款和数据交付。", + intro: "L1 中 Agent 可以寻找并报价,但每一笔支付都必须由用户在场核身确认。本页演示首次绑定、逐笔核身、支付执行和数据交付。", idle: "我会先寻找专业数据;收到报价后必须请你对本笔支付核身确认。", }, L2: { @@ -393,19 +406,19 @@ const authorizationCopy = { const elements = Object.fromEntries( [ - "actBinding", "actComponent", "actDomain", "agentMessage", "alipayProduct", "controlStatus", - "correlationChain", "currentState", "eventCounter", "evidenceDetails", "baselineValue", "footerScenarioValue", - "evidenceRef", "exchangeCard", "fromActor", "directionArrow", "layerCode", - "methodId", "modeBadge", "phaseRail", "playDemo", "demoControls", + "actBinding", "actComponent", "agentMessage", "alipayProduct", "controlStatus", + "currentState", "eventCounter", "baselineValue", "footerScenarioValue", + "exchangeCard", "fromActor", "directionArrow", "layerCode", + "modeBadge", "phaseRail", "playDemo", "demoControls", "resetDemo", "resourceCard", "resourceDescription", "resourceId", "resourcePrice", "resourceState", "resourceTitle", "scenarioSelect", "stateExplanation", "stepDemo", - "stepReplay", "taskResult", "taskStatusDot", "timeline", "toActor", "wireBadge", "wireMessage", - "principalActor", "buyerActor", "sellerActor", "pspActor", "authActor", "profileMapping", "tsdStatus", + "taskResult", "taskStatusDot", "timeline", "toActor", "wireBadge", "wireMessage", + "principalActor", "buyerActor", "sellerActor", "pspActor", "authActor", "profileMapping", "businessJourney", "purchaseStatus", "businessActionTitle", "agentThinkingLabel", - "paymentCard", "paymentCardKind", "paymentCardTitle", "paymentCardStatus", "paymentCardHint", "paymentQr", "resultArtifact", + "paymentCard", "paymentCardKind", "paymentCardTitle", "paymentCardStatus", "paymentCardHint", "resultArtifact", "authorizationSelect", "authorizationCard", "authorizationCardKind", "authorizationCardTitle", - "authorizationCardStatus", "authorizationCardDescription", "authorizationFacts", "bindingQr", "bindingCommand", "protocolLayerValue", - "productLayerValue", "footerProfileValue", "pspActorIcon", "pspActorName", "pspActorDescription", "layerExplanation", + "authorizationCardStatus", "authorizationCardDescription", "authorizationFacts", "bindingQr", "bindingCommand", + "footerProfileValue", "pspActorIcon", "pspActorName", "pspActorDescription", "authorizationSummary", "authorizationSummaryLevel", "authorizationSummaryEyebrow", "authorizationSummaryTitle", "authorizationSummaryDescription", "authorizationSummaryFacts", "userRequest", "introScenarioCopy", ].map((id) => [id, document.getElementById(id)]), @@ -491,8 +504,8 @@ function displayState(id, index) { }[id] || state.code, explanation: { RESOURCE_REQUEST_RETRIED: "Buyer 再次提交相同 Proof 与同一请求指纹;不会创建第二笔支付。", - PAYMENT_VERIFIED: "Seller 仍执行权威验款与一致性检查,并命中既有防重占用记录。", - RESOURCE_DELIVERED: "Seller 返回已保存的交付结果,不重复非幂等交付,也不再次触发履约确认。", + PAYMENT_VERIFIED: "Seller 仍调用支付方法的权威验款能力,并命中既有防重占用记录;此时尚未向 Buyer 返回资源。", + RESOURCE_DELIVERED: "Seller 以 HTTP 200 返回既有交付结果,并可附带 Payment-Validation;不重复非幂等交付,也不再次触发履约确认。", }[id] || state.explanation, }; } @@ -513,22 +526,22 @@ const businessJourneys = { { title: "检查支付能力", detail: "首次使用确认开通状态", states: ["PAYMENT_TOOL_STATUS_CHECKED", "WALLET_BINDING_REQUIRED"] }, { title: "完成钱包绑定", detail: "扫码授权并返回短时指令", states: ["WALLET_BINDING_QR_PRESENTED", "WALLET_BOUND"] }, { title: "获取服务报价", detail: "选择 API 并收到 0.01 元账单", states: ["CAPABILITY_NEGOTIATED", "ORDER_CONFIRMED", "RESOURCE_REQUESTED", "PAYMENT_REQUIRED"] }, - { title: "本笔核身确认", detail: "每笔都回到用户确认后付款", states: ["USER_AUTHORIZATION_REQUIRED", "PAYMENT_QR_PRESENTED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "PAYMENT_PENDING"] }, - { title: "验款并交付", detail: "携 Proof 重试并生成报告", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, + { title: "发起并确认本笔支付", detail: "Agent 提交,PSP 校验,用户逐笔确认", states: ["PAYMENT_REQUEST_SUBMITTED", "PAYMENT_REQUEST_VALIDATED", "USER_AUTHORIZATION_REQUIRED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "PAYMENT_PENDING"] }, + { title: "凭证核验、响应并履约", detail: "携 Proof 重试,接收资源和可选验证 Header", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, ], L2: [ { title: "明确委托目标", detail: "限定商户、资源和金额", states: ["SPECIFIED_INTENT_CAPTURED"] }, { title: "签发定向授权", detail: "生成 SPECIFIED IAC", states: ["SPECIFIED_IAC_ISSUED"] }, { title: "调用目标服务", detail: "命中指定 API 并收到报价", states: ["CAPABILITY_NEGOTIATED", "ORDER_CONFIRMED", "RESOURCE_REQUESTED", "PAYMENT_REQUIRED"] }, { title: "自动执行指定支付", detail: "完全匹配意图,不再询问用户", states: ["SPECIFIED_IAC_VERIFIED", "DEL_PSP_AUTHORIZED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "PAYMENT_PENDING"] }, - { title: "验款并交付", detail: "A402 恢复原请求", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, + { title: "凭证核验、响应并履约", detail: "A402 恢复原请求并接收资源", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, ], L3: [ { title: "定义任务边界", detail: "设置目标与 1 元总预算", states: ["BOUNDED_INTENT_CAPTURED"] }, { title: "签发任务授权", detail: "生成 BOUNDED IAC", states: ["BOUNDED_IAC_ISSUED"] }, { title: "自主选择服务", detail: "Agent 在边界内比较并调用", states: ["CAPABILITY_NEGOTIATED", "ORDER_CONFIRMED", "RESOURCE_REQUESTED", "PAYMENT_REQUIRED"] }, { title: "自主选择并支付", detail: "AUP 每笔检查预算与范围", states: ["AUP_BOUNDARY_CHECKED", "AUP_PSP_AUTHORIZED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "PAYMENT_PENDING"] }, - { title: "验款并交付", detail: "更新预算并完成报告", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, + { title: "凭证核验、响应并履约", detail: "接收验证 Header,更新预算并完成报告", states: ["RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED"] }, ], }; @@ -565,14 +578,15 @@ function renderBusinessJourney(stateId = null, failure = false) { "CAPABILITY_NEGOTIATED": "正在选择服务", "ORDER_CONFIRMED": "购买内容已确认", "RESOURCE_REQUESTED": "正在调用数据服务", - "PAYMENT_REQUIRED": "已报价 · 等待确认", - "USER_AUTHORIZATION_REQUIRED": "等待用户确认 0.01 元", - "PAYMENT_QR_PRESENTED": "等待支付宝扫码付款", + "PAYMENT_REQUIRED": "已报价 · 等待付款", + "PAYMENT_REQUEST_SUBMITTED": "Agent 已提交本笔支付请求", + "PAYMENT_REQUEST_VALIDATED": "PSP 已完成基础校验", + "USER_AUTHORIZATION_REQUIRED": "用户已确认本笔支付", "PAYMENT_PROCESSING": authorizationLevel === "L1" ? "支付宝处理中" : "授权范围内支付处理中", "PAYMENT_RESULT_RECEIVED": "付款结果已确认", "RESOURCE_REQUEST_RETRIED": "正在请求交付数据", "PAYMENT_VERIFIED": "验款通过", - "RESOURCE_DELIVERED": "数据已交付", + "RESOURCE_DELIVERED": "验证结果与数据已返回", "FULFILLMENT_CONFIRMED": "报告可以生成", }[stateId] || "等待开始"; } @@ -582,7 +596,7 @@ function renderAgentExecution(stateId = null, current = null) { const delivered = events.some((item) => item.state === "RESOURCE_DELIVERED"); const toolVisible = events.some((item) => item.state === "CAPABILITY_NEGOTIATED"); const paymentVisible = events.some((item) => [ - "PAYMENT_REQUIRED", "USER_AUTHORIZATION_REQUIRED", "PAYMENT_QR_PRESENTED", "SPECIFIED_IAC_VERIFIED", + "PAYMENT_REQUIRED", "PAYMENT_REQUEST_SUBMITTED", "PAYMENT_REQUEST_VALIDATED", "USER_AUTHORIZATION_REQUIRED", "SPECIFIED_IAC_VERIFIED", "DEL_PSP_AUTHORIZED", "AUP_BOUNDARY_CHECKED", "AUP_PSP_AUTHORIZED", "PAYMENT_PROCESSING", "PAYMENT_RESULT_RECEIVED", "PAYMENT_PENDING", "RESOURCE_REQUEST_RETRIED", "PAYMENT_VERIFIED", "PROOF_REJECTED", "VERIFICATION_UNAVAILABLE", "RESOURCE_DELIVERED", "FULFILLMENT_CONFIRMED", @@ -603,7 +617,6 @@ function renderAgentExecution(stateId = null, current = null) { if (!stateId) { elements.paymentCard.className = "agent-payment-card hidden"; - elements.paymentQr.classList.add("hidden"); elements.paymentCardStatus.textContent = "待确认"; elements.paymentCardHint.textContent = "等待服务返回机器账单。"; return; @@ -614,8 +627,9 @@ function renderAgentExecution(stateId = null, current = null) { ORDER_CONFIRMED: "参数已确认", RESOURCE_REQUESTED: "调用中", PAYMENT_REQUIRED: "等待付款", - USER_AUTHORIZATION_REQUIRED: "等待确认", - PAYMENT_QR_PRESENTED: "等待扫码", + PAYMENT_REQUEST_SUBMITTED: "提交付款", + PAYMENT_REQUEST_VALIDATED: "请求已校验", + USER_AUTHORIZATION_REQUIRED: "用户已确认", SPECIFIED_IAC_VERIFIED: "授权已校验", DEL_PSP_AUTHORIZED: "委托已核准", AUP_BOUNDARY_CHECKED: "边界已检查", @@ -624,13 +638,12 @@ function renderAgentExecution(stateId = null, current = null) { PAYMENT_RESULT_RECEIVED: "付款成功", RESOURCE_REQUEST_RETRIED: "重新调用", PAYMENT_VERIFIED: "验款通过", - RESOURCE_DELIVERED: "已返回数据", + RESOURCE_DELIVERED: "验证通过并返回数据", FULFILLMENT_CONFIRMED: "调用完成", }[stateId] || elements.resourceState.textContent; if (!paymentVisible) { elements.paymentCard.className = "agent-payment-card hidden"; - elements.paymentQr.classList.add("hidden"); return; } @@ -644,12 +657,11 @@ function renderAgentExecution(stateId = null, current = null) { elements.paymentCardTitle.textContent = authorizationLevel === "L1" ? "专业数据服务调用" : "ACT 协议支付语义"; - elements.paymentQr.classList.toggle("hidden", authorizationLevel !== "L1" - || !["PAYMENT_QR_PRESENTED", "PAYMENT_PROCESSING"].includes(stateId)); elements.paymentCardStatus.textContent = { - PAYMENT_REQUIRED: "待确认", - USER_AUTHORIZATION_REQUIRED: "等待用户", - PAYMENT_QR_PRESENTED: "等待扫码", + PAYMENT_REQUIRED: "待发起", + PAYMENT_REQUEST_SUBMITTED: "请求已提交", + PAYMENT_REQUEST_VALIDATED: "等待用户确认", + USER_AUTHORIZATION_REQUIRED: "本笔已确认", SPECIFIED_IAC_VERIFIED: "授权已校验", DEL_PSP_AUTHORIZED: "委托已核准", AUP_BOUNDARY_CHECKED: "边界已检查", @@ -665,18 +677,19 @@ function renderAgentExecution(stateId = null, current = null) { FULFILLMENT_CONFIRMED: "支付已确认", }[stateId] || "支付已确认"; const l1Hint = { - PAYMENT_REQUIRED: "Agent 已收到 0.01 元报价,准备请求用户逐笔确认。", - USER_AUTHORIZATION_REQUIRED: "请核对收款方、商品与金额;本页面不会发起真实支付。", - PAYMENT_QR_PRESENTED: "支付卡片已生成。真实二维码由支付宝官方页面提供;这里是不可扫码的演示占位图。", + PAYMENT_REQUIRED: "Agent 已收到 0.01 元报价,准备向支付宝支付能力发起本笔支付。", + PAYMENT_REQUEST_SUBMITTED: "Agent 已提交包含订单、金额、支付工具引用与唯一请求标识的支付请求。", + PAYMENT_REQUEST_VALIDATED: "支付宝已完成基础校验,正在准备官方确认界面。", + USER_AUTHORIZATION_REQUIRED: "用户已在支付宝确认界面核对收款方、商品、金额和支付方式,并完成本笔确认或身份验证。", PAYMENT_PROCESSING: "支付宝正在处理本笔交易,Agent 不会重复付款。", PAYMENT_PENDING: "结果未知,Agent 只查询原交易,不会再次付款。", PAYMENT_RESULT_RECEIVED: "支付结果已确认,Agent 将携脱敏凭据恢复原工具调用。", RESOURCE_REQUEST_RETRIED: "Agent 正在使用同一付款结果重新请求数据。", - PAYMENT_VERIFIED: "服务方已完成验款,等待工具返回数据。", + PAYMENT_VERIFIED: "卖方已取得 Payment-Proof 核验结果;Payment-Validation 尚未返回给 Buyer Agent。", PROOF_REJECTED: "付款凭据与订单或资源不一致,工具不会返回数据。", - VERIFICATION_UNAVAILABLE: "官方验款暂不可用,工具调用暂停并等待重试。", - RESOURCE_DELIVERED: "支付与验款完成,专业数据已经返回给 Agent。", - FULFILLMENT_CONFIRMED: "本次服务交付确认完成。", + VERIFICATION_UNAVAILABLE: "凭证核验服务暂不可用,工具调用暂停并等待重试。", + RESOURCE_DELIVERED: "卖方已通过 HTTP 200 返回专业数据,并选择附带可选的 Payment-Validation Header。", + FULFILLMENT_CONFIRMED: "卖方已异步向支付宝发送履约回执。", }; const delegatedHint = { PAYMENT_REQUIRED: `Agent 已收到 0.01 元报价,准备按 ${authorizationLevel === "L2" ? "SPECIFIED" : "BOUNDED"} IAC 校验授权。`, @@ -688,11 +701,11 @@ function renderAgentExecution(stateId = null, current = null) { PAYMENT_PENDING: "结果未知,只查询原交易,不得再次支付。", PAYMENT_RESULT_RECEIVED: "支付结果已确认,Agent 将携脱敏凭据恢复原工具调用。", RESOURCE_REQUEST_RETRIED: "Agent 正在使用同一付款结果重新请求数据。", - PAYMENT_VERIFIED: "服务方已完成验款,等待工具返回数据。", + PAYMENT_VERIFIED: "卖方已取得 Payment-Proof 核验结果;Payment-Validation 尚未返回给 Buyer Agent。", PROOF_REJECTED: "付款凭据与订单或资源不一致,工具不会返回数据。", - VERIFICATION_UNAVAILABLE: "权威验款暂不可用,工具调用暂停并等待重试。", - RESOURCE_DELIVERED: "支付与验款完成,专业数据已经返回给 Agent。", - FULFILLMENT_CONFIRMED: "本次服务交付确认完成。", + VERIFICATION_UNAVAILABLE: "凭证核验服务暂不可用,工具调用暂停并等待重试。", + RESOURCE_DELIVERED: "卖方已通过 HTTP 200 返回专业数据,并选择附带可选的 Payment-Validation Header。", + FULFILLMENT_CONFIRMED: "卖方已异步向支付宝发送履约回执。", }; elements.paymentCardHint.textContent = (authorizationLevel === "L1" ? l1Hint : delegatedHint)[stateId] || "等待本次支付继续处理。"; @@ -749,9 +762,7 @@ function resetGuidedDemo() { const baseline = authorizationLevel === "L1" ? "PMT-BND + INS / L1 + A402" : authorizationLevel === "L2" ? "ADD + DEL / L2 + A402" : "ADD + AUP / L3 + A402"; elements.baselineValue.textContent = baseline; - elements.protocolLayerValue.textContent = baseline; elements.footerScenarioValue.textContent = authorizationLevel === "L1" ? "PSD-PAY-INS (L1)" : authorizationLevel === "L2" ? "PSD-PAY-DEL (L2)" : "PSD-PAY-AUP (L3)"; - elements.productLayerValue.textContent = authorizationLevel === "L1" ? "Agent 支付 + AI 按量付费" : "本仓库未提供 L2/L3 支付宝实现"; elements.footerProfileValue.textContent = authorizationLevel === "L1" ? "ALIPAY AI PAY" : "ACT PROTOCOL ONLY"; const copy = authorizationCopy[authorizationLevel]; elements.authorizationSummary.dataset.level = authorizationLevel; @@ -764,10 +775,7 @@ function resetGuidedDemo() { elements.introScenarioCopy.textContent = copy.intro; elements.pspActorIcon.textContent = authorizationLevel === "L1" ? "支" : "P"; elements.pspActorName.textContent = authorizationLevel === "L1" ? "支付宝" : "PSP(协议角色)"; - elements.pspActorDescription.textContent = authorizationLevel === "L1" ? "支付、查询、验款" : "协议角色,非产品声明"; - elements.layerExplanation.textContent = authorizationLevel === "L1" - ? "先看懂上面的购买故事,再用这里核对协议边界:ACT 描述协商、授权和支付服务消息;支付宝产品完成支付与验款;示例服务负责真正的数据交付。" - : "本档只对照 ACT 2.1 的授权与支付语义;PSP 是协议角色,本仓库未提供支付宝 L2/L3 接入实现;示例服务只负责资源交付。"; + elements.pspActorDescription.textContent = authorizationLevel === "L1" ? "支付、查询、凭证核验" : "协议角色,非产品声明"; elements.modeBadge.textContent = authorizationLevel === "L1" ? "引导演示 · 非支付证据" : `ACT 2.1 ${authorizationLevel} · 无支付宝实现`; @@ -814,10 +822,16 @@ function createDemoEvents() { request_fingerprint: "sha-256:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA", profile_mapping: "ALIPAY_PRODUCT_PAYLOAD_TO_ACT_2_1_EVIDENCE", }; + const paymentRequest = { + payment_request_ref: "pay-request-sha256-43c1", + payment_tool_ref: "payment-tool-sha256-89bd", + buyer_agent_ref: "buyer-agent-demo", + }; const payment = { transaction_ref: "trade-sha256-8c11", proof_ref: "proof-sha256-a831" }; const delivery = { delivery_ref: "delivery-sha256-42bd" }; const fulfillment = { fulfillment_ref: "fulfill-sha256-6d2a", + product_fulfillment_method: "alipay.aipay.agent.fulfillment.confirm", product_fulfillment_status: "CONFIRMED", }; const delegation = authorizationLevel === "L1" ? {} : { @@ -839,6 +853,7 @@ function createDemoEvents() { ...(seen("ORDER_CONFIRMED") ? commerce : {}), ...(seen("RESOURCE_REQUESTED") ? request : {}), ...(seen("PAYMENT_REQUIRED") ? bill : {}), + ...(authorizationLevel === "L1" && seen("PAYMENT_REQUEST_SUBMITTED") ? paymentRequest : {}), ...(paymentStarted ? { transaction_ref: payment.transaction_ref } : {}), ...(paymentCompleted ? { proof_ref: payment.proof_ref } : {}), ...(seen("RESOURCE_DELIVERED") ? delivery : {}), @@ -846,7 +861,12 @@ function createDemoEvents() { sequence: index + 1, state: id, occurred_at: new Date(startedAt + index * 1000).toISOString(), - validation_mapping: id === "PAYMENT_VERIFIED" ? "ACT 2.1 evidence ← Alipay payment.verify result" : undefined, + payment_request_validation_status: id === "PAYMENT_REQUEST_VALIDATED" ? "ACCEPTED" : undefined, + user_confirmation_status: id === "USER_AUTHORIZATION_REQUIRED" ? "CONFIRMED" : undefined, + payment_verification_status: id === "PAYMENT_VERIFIED" ? "VERIFIED" : undefined, + a402_response: id === "RESOURCE_DELIVERED" + ? { http_status: 200, payment_validation_status: "PAYMENT_VALIDATED", includes_paid_resource: true } + : undefined, idempotent_replay: replayStep && id === "RESOURCE_DELIVERED" ? true : undefined, payment_action: replayStep ? "NO_NEW_PAYMENT" : undefined, delivery_action: replayStep && id === "RESOURCE_DELIVERED" ? "RETURN_PRIOR_RESULT" : undefined, @@ -859,8 +879,8 @@ function createDemoEvents() { result_summary: replayStep && id === "RESOURCE_DELIVERED" ? "返回既有交付结果;未重复支付、交付或履约确认" : { - RESOURCE_DELIVERED: "专业数据已交付给 Agent", - FULFILLMENT_CONFIRMED: "卖方产品履约确认完成;TSD 证据未自动生成", + RESOURCE_DELIVERED: "HTTP 200 已返回专业数据;本 Demo 选择附带 Payment-Validation", + FULFILLMENT_CONFIRMED: "卖方已异步发送支付宝产品履约回执;TSD 证据未自动生成", }[id], }; }); @@ -928,18 +948,41 @@ function validateDemoEvidence(event, expectedIndex) { if (!event[field]) throw new Error(`Payment-Needed 证据缺少 ${field}`); } } + if (event.state === "PAYMENT_REQUEST_SUBMITTED" + && (!event.payment_request_ref || !event.payment_tool_ref || !event.order_ref || !event.amount || !event.currency)) { + throw new Error("L1 支付请求缺少订单、金额、支付工具或唯一请求引用"); + } + if (event.state === "PAYMENT_REQUEST_VALIDATED" + && event.payment_request_validation_status !== "ACCEPTED") { + throw new Error("PSP 基础校验结果尚未确认"); + } + if (event.state === "USER_AUTHORIZATION_REQUIRED" + && event.user_confirmation_status !== "CONFIRMED") { + throw new Error("L1 本笔用户确认尚未完成"); + } if (event.state === "PAYMENT_RESULT_RECEIVED" && (!event.transaction_ref || !event.proof_ref)) { throw new Error("支付结果缺少交易或 Proof 脱敏引用"); } - if (event.state === "PAYMENT_VERIFIED" && (!event.transaction_ref || !event.validation_mapping)) { - throw new Error("验款事件缺少权威交易或映射引用"); + if (event.state === "PAYMENT_VERIFIED" + && (!event.transaction_ref || event.payment_verification_status !== "VERIFIED")) { + throw new Error("卖方内部验款缺少权威交易或有效验款结果"); } - if (event.state === "RESOURCE_DELIVERED" && (!event.transaction_ref || !event.delivery_ref)) { - throw new Error("资源交付缺少独立交付引用"); + if (event.state === "RESOURCE_DELIVERED" + && (!event.transaction_ref || !event.delivery_ref + || event.a402_response?.http_status !== 200 + || event.a402_response?.includes_paid_resource !== true)) { + throw new Error("A402 验款成功后必须返回付费资源或启动服务"); + } + if (event.state === "RESOURCE_DELIVERED" + && event.a402_response?.payment_validation_status !== undefined + && event.a402_response.payment_validation_status !== "PAYMENT_VALIDATED") { + throw new Error("可选 Payment-Validation 与本次验款结果不一致"); } if (event.state === "FULFILLMENT_CONFIRMED" - && (!event.transaction_ref || !event.fulfillment_ref || event.product_fulfillment_status !== "CONFIRMED")) { - throw new Error("履约确认缺少独立产品确认事实"); + && (!event.transaction_ref || !event.fulfillment_ref + || event.product_fulfillment_method !== "alipay.aipay.agent.fulfillment.confirm" + || event.product_fulfillment_status !== "CONFIRMED")) { + throw new Error("支付宝 AI 按量付费履约回执缺少独立产品确认事实"); } if (scenario === "IDEMPOTENT_REPLAY" && expectedIndex === flow().length - 1) { if (event.idempotent_replay !== true @@ -988,7 +1031,7 @@ function render() { if (!current) { elements.currentState.textContent = "等待开始"; elements.stateExplanation.textContent = "这里会解释同一个动作在 ACT 场景组件、A402 Binding 与支付宝产品中的位置。"; - ["actDomain", "actComponent", "actBinding", "alipayProduct", "profileMapping"].forEach((id) => { elements[id].textContent = "—"; }); + ["actComponent", "actBinding", "alipayProduct", "profileMapping"].forEach((id) => { elements[id].textContent = "—"; }); elements.layerCode.textContent = "READY"; elements.fromActor.textContent = "—"; elements.toActor.textContent = "—"; @@ -1000,19 +1043,13 @@ function render() { renderPhaseRail(); elements.agentMessage.textContent = authorizationCopy[authorizationLevel].idle; elements.businessActionTitle.textContent = "等待 Agent 开始任务"; - elements.evidenceRef.textContent = "NO EVIDENCE"; - elements.methodId.textContent = "—"; - elements.tsdStatus.textContent = "NOT EMITTED · OPTIONAL"; - elements.correlationChain.textContent = "等待建立关联链"; renderBusinessJourney(); renderAgentExecution(); - renderEvidence(null); lockResource(); return; } elements.currentState.textContent = current.label; elements.stateExplanation.textContent = current.explanation; - elements.actDomain.textContent = current.domain; elements.actComponent.textContent = current.component; elements.actBinding.textContent = current.binding; elements.profileMapping.textContent = current.profile || "Demo evidence observation"; @@ -1022,12 +1059,7 @@ function render() { renderBusinessJourney(event.state, current.failure === true); elements.businessActionTitle.textContent = current.label; elements.agentMessage.textContent = current.agent; - elements.evidenceRef.textContent = event.evidence_ref; - elements.methodId.textContent = event.method_id || findLatest("method_id") || "—"; - elements.tsdStatus.textContent = event.tsd_evidence_ref || findLatest("tsd_evidence_ref") || "NOT EMITTED · OPTIONAL"; - elements.correlationChain.textContent = correlationText(); - renderEvidence(event); - applyResource(event, current); + applyResource(current); renderAgentExecution(event.state, current); if (events.length === flow().length) { elements.taskResult.textContent = current.failure @@ -1069,45 +1101,8 @@ function findLatest(key) { return [...events].reverse().find((item) => item[key])?.[key]; } -function correlationText() { - const fields = [ - ["IAC", findLatest("delegation_id")], - ["COMMERCE", findLatest("commerce_confirmation_ref")], - ["REQ", findLatest("request_ref")], - ["FINGERPRINT", findLatest("request_fingerprint")], - ["ORDER", findLatest("order_ref")], - ["RESOURCE", findLatest("resource_id")], - ["TRADE", findLatest("transaction_ref")], - ["FULFILL", findLatest("fulfillment_ref")], - ].filter(([, value]) => value); - return fields.length ? fields.map(([key, value]) => `${key} ${value}`).join(" → ") : "等待建立关联链"; -} - -function renderEvidence(event) { - const rows = event - ? [ - ["来源", event.source], - ["时间", new Date(event.occurred_at).toLocaleTimeString("zh-CN", { hour12: false })], - ...detailKeys.filter((key) => event[key]).slice(0, 4).map((key) => [labelFor(key), event[key]]), - ] - : [["来源", "—"], ["时间", "—"], ["结果", "—"]]; - elements.evidenceDetails.innerHTML = rows.map(([label, value]) => - `
WHY THESE LAYERS
先看懂上面的购买故事,再用这里核对协议边界:ACT 描述协商、授权和支付服务消息;支付宝产品完成支付与验款;示例服务负责真正的数据交付。
-PROTOCOL RECEIPT
等待建立请求、订单、资源、交易和履约关联
-只展示脱敏引用,不展示完整 Proof、签名、账号、密钥或可重放请求。
-