Skip to content

docs: refund limitation + remaining 3.1.0 race residual - #80

Merged
jules-paystack merged 1 commit into
masterfrom
docs/known-limitations-and-refunds
Sep 29, 2026
Merged

jules-paystack merged 1 commit into
masterfrom
docs/known-limitations-and-refunds

Conversation

@jules-paystack

Copy link
Copy Markdown
Collaborator

Summary

Prompted by a direct question after the 3.1.0 release: "are we actually good to deploy on Marketplace, what about the open issues?" Answer was mostly yes, but documentation was incomplete — CHANGELOG's Known Limitations only listed D9/R2.8; two other tracked residuals from the reconciliation work were never made public, and the refund limitation (pre-existing, not new) was undocumented anywhere.

  • User Guide: new "Refunds" section — a verified/registered order has no Credit Memo path through Magento; refunds go through Paystack's dashboard directly. This isn't new in 3.1.0, but is newly relevant since orders now show a real invoice/total_paid a merchant will reasonably expect to be refundable.
  • CHANGELOG: added two entries to Known Limitations, at the same restrained level of detail as the existing D9 entry (name the limitation, no exploit walkthrough): the reference-binding race that isn't closed by a lock (only the sequential case is), and the refund gap.

None of this changes code — it's the same level of transparency the D9 entry already set, extended to the other two items that should have been there from the start.

🤖 Generated with Claude Code

Neither was documented anywhere public before this: a verified,
registered payment has no Credit Memo path through Magento (canRefund()
is false; refunds go through Paystack's dashboard directly) -- a
pre-existing gap, not introduced by 3.1.0, but newly relevant now that
orders show a real invoice/total_paid a merchant will expect to be
able to refund. And 3.1.0's reference binding closes the sequential
"one charge settles two orders" case but not a same-instant race
between two verifications for a not-yet-bound reference -- recorded
in CHANGELOG's Known Limitations at the same restrained,
no-exploit-detail level as the existing D9 entry.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@jules-paystack
jules-paystack merged commit c3c6e57 into master Sep 29, 2026
5 checks passed
@jules-paystack
jules-paystack deleted the docs/known-limitations-and-refunds branch September 29, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant