feat(machine): seed + bunker-binding IPC bridge

get-atm-secrets now returns { spireSeed, bunkerBinding } instead of the raw
nsec (one-shot semantics kept). Adds IPC handlers + preload bindings for
saveBunkerBinding / clearBunkerBinding / resetBootstrapGate so the renderer
can persist a pairing and re-arm the cassette-state hello on re-pair (#56).
resetBootstrapGate added to state-store. Types mirrored in electron.d.ts.

Part of Phase C, aiolabs/bitspire#52.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-06-19 00:15:31 +02:00
commit 209e4c3e20
4 changed files with 75 additions and 8 deletions

View file

@ -39,10 +39,20 @@ export interface BrandingConfig {
logoDarkDataUrl: string | null
}
/** Persisted NIP-46 bunker binding (mirror of state-store's StoredBunkerBinding). */
export interface BunkerBindingRecord {
clientSecretHex: string
spirePubkey: string
bunkerUrl: string
seedFingerprint: string
pairedAt: number
}
export interface AtmSecrets {
atmPrivateKey: string
/** Legacy LP admin token — retained until 3d removes the LP backend. */
adminToken?: string
/** Spire pairing seed URL (`spire-seed:v1:…`); carries the one-shot connect token. */
spireSeed: string
/** Persisted bunker binding, or null when the ATM is unpaired. */
bunkerBinding: BunkerBindingRecord | null
}
declare global {
@ -85,6 +95,9 @@ declare global {
getLastKnownConfigCreatedAt: () => Promise<number>
getBootstrapPublishedAt: () => Promise<number | null>
markBootstrapPublished: (unixTimestamp: number) => Promise<void>
saveBunkerBinding: (binding: BunkerBindingRecord) => Promise<void>
clearBunkerBinding: () => Promise<void>
resetBootstrapGate: () => Promise<void>
applyOperatorCassettesConfig: (
payload: { positions: Record<string, { denomination: number; count: number }> },
eventCreatedAt: number