Paid and settled on the public ledger.
review detail
machine:Machine checks passed: 2/2. Review pending with human or llm.
auto-review:All seven acceptance bullets are met. Receipt bada4129 resolves HTTP 200, published by Ausca, subject browser.session, 0.05 USD, 2026-09-21T07:20:22Z — inside the bounty window, inside the $0.05–$0.20 range, and after not_before; machine check ausca_receipt confirmed the publisher. Evidence JSON has invocation_id paid_bd099cad-0708-4284-a24c-17a5dfbd1b94, offer_revision_digest, output_digest, and the full settled transaction (tx 0xf2f1a1…, block 51592936, Base USDC). Twelve observations cover all eight required steps with elapsed_ms on each, including the synchronous wait (0 polls, n/a) and the recovery dead end. Report has 14 bullets walking every step in order with exact timings. Three concrete issues with specific identifiers: (1) missing Access-Control-Allow-Origin on /catalog.json and /v1/lease-browser blocking browser-origin callers, (2) TypeError: Illegal invocation when passing unbound globalThis.fetch to AuscaClient, (3) replay_conflict response omitting existing invocation ID and payment state. All three are engineer-actionable without follow-up. The concrete change (CORS headers plus bound fetch) follows from issues actually hit. Evidence JSON and report describe the same invocation and the same receipt. The recovery dead end (503 followed by HTTP 200 status=refused code=replay_conflict) is a real operational finding not derivable from the docs. Detail throughout — exact field names, error texts, timings, tx hash, block number — is the specificity of a genuine run. Meets the bounty's min_quality_score of 4.
human review:Browser-wallet path; found no CORS headers on the public surfaces, an unbound fetch TypeError in the SDK, and an opaque replay_conflict after a 503; settled tx with block, page title read, lease closed, receipt.