feat(machine): production safety — disable mock fallback and ndebit

When VITE_ALLOW_MOCK_FALLBACK is unset (production default), the ATM
now shows a maintenance screen instead of silently falling back to mock
services when hardware or Lightning initialization fails. Also disables
ndebit/CLINK in production since the static ndebit pointer is replayable
— cash-in uses LNURL-withdraw only (single-use by design).

- Add allowMockFallback config field (Electron IPC + types)
- Add strict config validation (no localhost, require private key)
- Gate all catch-block fallbacks behind allowMockFallback
- Disable debit approval service and ndebit generation in production
- Add maintenance screen in App.vue when initError is set

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-02-27 17:39:12 -05:00
commit e460765355
7 changed files with 238 additions and 120 deletions

View file

@ -118,6 +118,7 @@ ipcMain.handle('get-config', () => {
validatorDevice: process.env.VITE_LAMASSU_VALIDATOR_DEVICE,
dispenserDevice: process.env.VITE_LAMASSU_DISPENSER_DEVICE,
cassettes: process.env.VITE_LAMASSU_CASSETTES,
allowMockFallback: process.env.VITE_ALLOW_MOCK_FALLBACK === 'true',
}
})

View file

@ -24,6 +24,7 @@ export interface RuntimeConfig {
validatorDevice?: string
dispenserDevice?: string
cassettes?: string
allowMockFallback: boolean
}
// Expose protected methods to renderer