docs(adr): ADR-005 §4 — outOfCash after payment is owed too; only the cause and the latch differ

This commit is contained in:
Padreug 2026-10-10 21:26:53 +02:00
commit 7f055cd4c6

View file

@ -195,10 +195,16 @@ instead of a clean ledger.
Two distinct terminal states replace the single `dispenseError`:
- **`outOfCash`** — the request could not be met from inventory and the dispenser reported
**no error**. Nothing was charged beyond what was dispensed.
- **`outOfCash`** — the request could not be met and the dispenser reported **no error**
(an inventory refusal, or simply short). In the cash-out flow this state is reached *after*
payment, so the customer **has paid** and is owed the shortfall exactly as below; the
difference is the cause — no hardware fault, so the machine stays in service and nothing
latches. (An earlier draft said "nothing was charged beyond what was dispensed"; that is
only true of the inventory check *before* payment, which already prevents the sale.)
- **`dispenseFault`** — the dispenser reported an error. The customer **has paid** and is
owed the shortfall.
owed the shortfall, and a `terminal` class also latches cash-out off (Decision 5).
Both screens therefore show the same evidence; the heading and the latch differ.
`dispenseFault` shows: the amount paid, the amount dispensed (per denomination, as now), the
txid as QR (as now) **and as text**, the first 12 characters of the payment hash, the time,