Skip to content

Changelog

Unreleased

No changes queued after the prepared alpha.

0.1.0a1 — Early access (prepared; publication pending)

First alpha for developer evaluation. APIs may change before a stable release. Created and maintained by Mehedi H Faysal. Offline tests verify implementation behavior, not live provider compatibility. SSLCOMMERZ is experimental; authorized merchant lifecycle verification is pending. The provider audit and payment audit remain the source of verification limits.

Correctness and security

  • Audited AlphaSMS error codes; unknown BulkSMSBD classifications remain generic.
  • Reject cleartext endpoints by default; verify TLS and refuse redirects.
  • Metadata-only logs and withheld upstream exception text; raw data remains sensitive.
  • Malformed/schema response errors and preserved GreenWeb partial/unknown batches.
  • Pathao atomic token caching, process-local single-flight refresh and bounded replay; order POST replay is explicitly opt-in.
  • Shipment validation before HTTP; provider-scoped routing and separate RedX goods value.

Contracts and tooling

  • Reusable owned or injected borrowed HTTP clients with explicit lifetime.
  • Additive typed shipment/SMS results, options, capabilities, error metadata and reconciliation flags; preserve legacy raw methods and numeric inputs.
  • Exact Decimal handling with documented unverified wire formats; packaged py.typed.
  • Python 3.9–3.15 test/type/lint/wheel gates, branch-aware coverage and gated publication of the tested artifact for the immutable release commit and matching version/tag.
  • Complete strict-built documentation, offline Django/FastAPI/fake-provider examples, provider verification matrix and contributor/security/compatibility guidance.
  • Native asyncio clients for all six providers with shared sync/async contracts, owned/borrowed lifetime, cancellation-safe cleanup and Pathao single-flight refresh.
  • Native FastAPI lifespan/dependency example with bounded in-flight requests.
  • Scoped SSLCOMMERZ hosted BDT payment initiation, customer action, signature/server verification, complete transaction queries and partial refund request/query APIs.
  • Shared sync/async payment contracts, exact money, safe risk holds and ambiguous side-effect metadata, including state-changing refund GET; no automatic replay.
  • Durable SQLite entitlement/refund reservation example and offline lifecycle checks.
  • Suppress credential-bearing HTTPX URL records only during SDK payment requests.
  • bKash/Nagad remain planned. Sandbox/live verification is pending.

Migration

Review the compatibility guide before adopting this alpha: BulkSMSBD HTTP now requires an explicit insecure opt-in; unverified errors are generic; malformed responses raise UnexpectedProviderResponseError; GreenWeb batches may raise SMSBatchError; Pathao routing has no invented geography defaults and order replay is disabled by default; RedX fields/auth/creation path were corrected. No release was published as part of the implementation checklist. Provider compatibility limitations remain in the contract audit.