PRs from outside forks are restricted on this repo, so raising this as an issue instead.
I've written a PHP conformance adapter and it's ready on a branch:
https://github.com/michaelhairetis/mpp-tools/tree/php-conformance-adapter
Diff: main...michaelhairetis:mpp-tools:php-conformance-adapter
It adds conformance/adapters/php/ and a php: entry in sdks.yaml, backed by mpp-php v0.1.1.
Advertised capabilities
challenge.parse, challenge.format, credential.parse, credential.format, receipt.parse, receipt.format, base64url.encode, base64url.decode, challenge.id.
http.payment_request, server.verify and the tempo.* / stripe.* operations are deliberately left unadvertised. They need settlement paths the SDK doesn't implement yet, and skipping seemed better than stubbing.
Notes
challenge.id reproduces the checked-in vectors, including the 32-byte secret minimum and the rule that a default Authorization credential field is omitted from the binding input.
- The harness carries a challenge
request as a decoded object while the SDK holds it in wire form, so the two are translated in the adapter.
credential.format emits canonical JSON, so challenge keys come back sorted rather than in input order. That assumes semantic comparison, and is easy to change if adapters are expected to preserve input ordering.
- The adapter's
composer.json points at the GitHub repo directly. Once the package is on Packagist that repositories block can be dropped.
- CI will need a PHP 8.2+ toolchain for the adapter's
build step.
On make all
CONTRIBUTING asks for a full cd conformance && make all before submitting, which needs every language toolchain present. I verified the PHP adapter against the vector fixtures directly instead. If someone with the full environment runs it, I'm happy to fix whatever falls out.
Building the SDK against the open Agricola findings meant several were handled before the adapter existed: AGR-2026-103 (case-insensitive auth-param names), AGR-2026-102 and AGR-2026-104 (method identifiers with digits and separators), AGR-2026-101 (non-Latin-1 header output), #158 (commas inside quoted values), and tempoxyz/mpp-go#151 (folded challenges on one header line).
Happy to open a PR if you'd rather add me as a collaborator, or you're welcome to pull the branch directly.
PRs from outside forks are restricted on this repo, so raising this as an issue instead.
I've written a PHP conformance adapter and it's ready on a branch:
https://github.com/michaelhairetis/mpp-tools/tree/php-conformance-adapter
Diff: main...michaelhairetis:mpp-tools:php-conformance-adapter
It adds
conformance/adapters/php/and aphp:entry insdks.yaml, backed by mpp-php v0.1.1.Advertised capabilities
challenge.parse,challenge.format,credential.parse,credential.format,receipt.parse,receipt.format,base64url.encode,base64url.decode,challenge.id.http.payment_request,server.verifyand thetempo.*/stripe.*operations are deliberately left unadvertised. They need settlement paths the SDK doesn't implement yet, and skipping seemed better than stubbing.Notes
challenge.idreproduces the checked-in vectors, including the 32-byte secret minimum and the rule that a defaultAuthorizationcredential field is omitted from the binding input.requestas a decoded object while the SDK holds it in wire form, so the two are translated in the adapter.credential.formatemits canonical JSON, so challenge keys come back sorted rather than in input order. That assumes semantic comparison, and is easy to change if adapters are expected to preserve input ordering.composer.jsonpoints at the GitHub repo directly. Once the package is on Packagist thatrepositoriesblock can be dropped.buildstep.On
make allCONTRIBUTING asks for a full
cd conformance && make allbefore submitting, which needs every language toolchain present. I verified the PHP adapter against the vector fixtures directly instead. If someone with the full environment runs it, I'm happy to fix whatever falls out.Building the SDK against the open Agricola findings meant several were handled before the adapter existed: AGR-2026-103 (case-insensitive auth-param names), AGR-2026-102 and AGR-2026-104 (method identifiers with digits and separators), AGR-2026-101 (non-Latin-1 header output), #158 (commas inside quoted values), and tempoxyz/mpp-go#151 (folded challenges on one header line).
Happy to open a PR if you'd rather add me as a collaborator, or you're welcome to pull the branch directly.