Skip to content

feature/INT-1711 - risk.score must be a decimal, not an integer - #685

Merged
rodrigojara-cko merged 1 commit into
masterfrom
feature/INT-1711-risk-score-decimal
Oct 7, 2026
Merged

rodrigojara-cko merged 1 commit into
masterfrom
feature/INT-1711-risk-score-decimal

Conversation

@rodrigojara-cko

@rodrigojara-cko rodrigojara-cko commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This pull request fixes the type of risk.score on payment responses. The API defines it as number (0 to 100, for example 22.5), but the SDK typed it as Integer, so Gson threw JsonSyntaxException on a fractional score and the whole payment response failed to deserialize. Reported internally.

Model changes:

  • RiskAssessment.score: Integer to Double. Used by PaymentResponse, GetPaymentResponse, AuthorizationResponse and the previous variants. Added doc comments for both properties.
  • handlepaymentsandpayouts...requestapaymentorpayoutresponsecreated.risk.Risk.score: Integer to Double.

Tests:

  • New RiskAssessmentSerializationTest: fractional, whole, boundary (0, 100) and null scores, serialization, round-trip, and the swagger example, both standalone and inside GetPaymentResponse / PaymentResponse.
  • New Risk section in RequestAPaymentOrPayoutResponseCreatedSerializationTest.
  • Full unit suite and the payments integration tests pass against sandbox.

API reference: POST /payments (201) and GET /payments/{id} (200), risk.score: type: number, minimum: 0, maximum: 100.

Breaking changes: getScore() now returns Double instead of Integer. Code assigning it to an int/Integer must be updated. Forced by the API, so this ships as a minor release.

@agent-wall-e

agent-wall-e Bot commented Oct 6, 2026

Copy link
Copy Markdown

🟢 Risk Classification: LOW

Approval route: AI Auto-Approval
Rollback controls: Automated Instant Rollback + feature flags

Classification reasons

  • no_low_class_matched
  • prod_source_modified
  • 2.2.6_logical_extension:The change is a non-destructive type correction (Integer→Double) on existing model fields to match the API spec, reusing all existing code paths and abstractions with no new endpoints, persistence, auth, or external integrations introduced.

Operational gates

  • ✅ jira_ticket (INT-1711)
  • ✅ independent_review

Files analysed: 4


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Oct 6, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
no_low_class_matched informational §2.2 (fall-through) None of the deterministic Low classes (§2.2.3, §2.2.4, §2.2.7, docs-only) applied; classifier fell through to LLM evaluation.
prod_source_modified informational §2.1 M7 (informational) At least one file is non-doc, non-test, non-IaC — i.e. application source code was modified.
2.2.6_logical_extension — The change is a non-destructive type correction (Integer→Double) on existing model fields to match the API spec, reusing all existing code paths and abstractions with no new endpoints, persistence, auth, or external integrations introduced. classifying §2.2.6 Sonnet 4.6 evaluator promoted minor → low: the change reuses existing code paths and does not cross a trust boundary.

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e agent-wall-e Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved — this PR meets all Low-risk criteria.

All checks passed, no unresolved comments, and the change classification is:

  • no_low_class_matched
  • prod_source_modified
  • 2.2.6_logical_extension:The change is a non-destructive type correction (Integer to Double) on existing model fields to match the API spec, reuses existing code paths and abstractions, introduces no new endpoints, persisted data, auth changes, or external integrations.

wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

The API returns risk.score as a number between 0 and 100 (for example
22.5). The SDK typed it as an integer, so a fractional score failed to
deserialize (Java) or was silently rounded (.NET). Reported internally.
@armando-rodriguez-cko
armando-rodriguez-cko force-pushed the feature/INT-1711-risk-score-decimal branch from fad4961 to ba8b200 Compare October 7, 2026 12:36
@agent-wall-e

agent-wall-e Bot commented Oct 7, 2026

Copy link
Copy Markdown

🟢 Risk Classification: LOW

Approval route: AI Auto-Approval
Rollback controls: Automated Instant Rollback + feature flags

Classification reasons

  • no_low_class_matched
  • prod_source_modified
  • 2.2.6_logical_extension:The change only corrects the type of an existing field from Integer to Double in two existing model classes to match the API spec, reusing all existing code paths without adding new endpoints, persistence, auth, or external integrations.

Operational gates

  • ✅ jira_ticket (INT-1711)
  • ✅ independent_review

Files analysed: 4


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Oct 7, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
no_low_class_matched informational §2.2 (fall-through) None of the deterministic Low classes (§2.2.3, §2.2.4, §2.2.7, docs-only) applied; classifier fell through to LLM evaluation.
prod_source_modified informational §2.1 M7 (informational) At least one file is non-doc, non-test, non-IaC — i.e. application source code was modified.
2.2.6_logical_extension — The change only corrects the type of an existing field from Integer to Double in two existing model classes to match the API spec, reusing all existing code paths without adding new endpoints, persistence, auth, or external integrations. classifying §2.2.6 Sonnet 4.6 evaluator promoted minor → low: the change reuses existing code paths and does not cross a trust boundary.

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

@rodrigojara-cko
rodrigojara-cko merged commit 491eb58 into master Oct 7, 2026
6 checks passed
@rodrigojara-cko
rodrigojara-cko deleted the feature/INT-1711-risk-score-decimal branch October 7, 2026 12:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants