docs: Bolt Card session contract, ADR-003 amendment for verified entry
docs/boltcard-session.md is the /session wire contract (sibling of boltcard-receive-resolver.md), including the trust boundary: the session URL is derived from the card's own host, so open enrollment is still not a security boundary (#91). ADR-003's amendment now records verified entry via /session and the hidden-by-default balance display. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
6779d8ef55
commit
ec2b15c08f
3 changed files with 125 additions and 2 deletions
|
|
@ -99,6 +99,12 @@ wallet …".
|
|||
|
||||
## Notes
|
||||
|
||||
- **Tap-to-enter uses `/session` instead.** When the access gate is on, the
|
||||
card was already verified at entry and the ATM holds the LUD-06 second step
|
||||
from `/session` (see `boltcard-session.md`), so Complete calls `pay.callback`
|
||||
directly and never touches `/pay`. `/pay` remains the path for a card tapped
|
||||
directly on the cash-in screen (gate off, or a second card).
|
||||
|
||||
- **Double-payout:** the cash-in screen still shows the LNURL-withdraw QR as a
|
||||
fallback (customer _pulls_). A tap _pays_ instead. The ATM gates re-entry
|
||||
while a tap is in flight and leaves `displayingQR` on success; the withdraw
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue