From 4d7b87e1c65137d2ed5099911aa97329343c4629 Mon Sep 17 00:00:00 2001 From: Padreug Date: Sat, 10 Oct 2026 21:26:53 +0200 Subject: [PATCH] =?UTF-8?q?docs(adr):=20ADR-005=20=C2=A74=20=E2=80=94=20ou?= =?UTF-8?q?tOfCash=20after=20payment=20is=20owed=20too;=20only=20the=20cau?= =?UTF-8?q?se=20and=20the=20latch=20differ?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- docs/adr/005-cash-out-dispense-outcome.md | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/docs/adr/005-cash-out-dispense-outcome.md b/docs/adr/005-cash-out-dispense-outcome.md index 58a3b1b..22bc03a 100644 --- a/docs/adr/005-cash-out-dispense-outcome.md +++ b/docs/adr/005-cash-out-dispense-outcome.md @@ -195,10 +195,16 @@ instead of a clean ledger. Two distinct terminal states replace the single `dispenseError`: -- **`outOfCash`** — the request could not be met from inventory and the dispenser reported - **no error**. Nothing was charged beyond what was dispensed. +- **`outOfCash`** — the request could not be met and the dispenser reported **no error** + (an inventory refusal, or simply short). In the cash-out flow this state is reached *after* + payment, so the customer **has paid** and is owed the shortfall exactly as below; the + difference is the cause — no hardware fault, so the machine stays in service and nothing + latches. (An earlier draft said "nothing was charged beyond what was dispensed"; that is + only true of the inventory check *before* payment, which already prevents the sale.) - **`dispenseFault`** — the dispenser reported an error. The customer **has paid** and is - owed the shortfall. + owed the shortfall, and a `terminal` class also latches cash-out off (Decision 5). + +Both screens therefore show the same evidence; the heading and the latch differ. `dispenseFault` shows: the amount paid, the amount dispensed (per denomination, as now), the txid as QR (as now) **and as text**, the first 12 characters of the payment hash, the time,