feat(machine): consume get_machine_config over the transport (#71)

Source the operator pubkey + fee config from LNbits via the get_machine_config
kind-21000 RPC (spirekeeper#41) right after list_wallets, instead of the
operator pubkey coming only from VITE_OPERATOR_PUBKEYS (env). A seed-only
machine (blank .env) had an empty operator allowlist → the fees/operator-config
services disabled themselves → permanent "awaiting configuration". Now it pulls
its config over the already-authenticated channel and configures itself with
zero per-machine provisioning — closing bitspire#70 P1.

- LnbitsClient.getMachineConfig() → sendRpc('get_machine_config') + the
  MachineConfigResponse / FeeConfigWire types.
- lightning.ts, only when VITE_OPERATOR_PUBKEYS is empty (env override still
  wins): set CONFIG.operatorPubkeys from operator_pubkey (re-enables the
  services), and persist fee_config via the existing applyFeeConfig IPC (mapping
  snake_case → camelCase) so atm.ts's awaiting-fees gate clears immediately —
  robust to the replaceable kind-30078 not being fetchable from the relay. The
  live kind-30078 subscription still handles mid-run fee updates.
- Soft-fail: older spirekeeper (no RPC) or a transport error falls back to the
  env/kind-30078 path.

lnbits + machine typecheck clean; lnbits suite 29 pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-07-02 22:00:49 +02:00 • committed by padreug
commit fdb9a507c2
3 changed files with 79 additions and 0 deletions

View file

@ -37,6 +37,7 @@ import type {
CreateInvoiceBody,
PayInvoiceBody,
WalletInfo,
MachineConfigResponse,
SubscribePaymentsBody,
SubscribeAck,
PaymentPushCallback,
@ -210,6 +211,17 @@ export class LnbitsClient {
return data ?? []
}
/** Pull server-delivered machine config (operator pubkey + fee config) over
* the authenticated transport — spirekeeper's `get_machine_config` RPC
* (bitspire#70 P1). Lets a seed-only ATM configure itself with no per-machine
* env provisioning. Rejects (LnbitsRpcError) if the server hasn't registered
* the RPC (older spirekeeper) — callers should soft-fall-back. */
async getMachineConfig(): Promise<MachineConfigResponse> {
return this.idempotent(() =>
this.sendRpc<MachineConfigResponse>('get_machine_config', {}),
)
}
// ============================================================================
// Invoices
// ============================================================================

View file

@ -274,3 +274,30 @@ export type PaymentPushCallback = (payment: LnbitsPayment) => void
/** Called when the subscription has been closed (by TTL or explicit unsubscribe). */
export type SubscriptionCloseCallback = (reason: 'ttl' | 'unsubscribed') => void
// ============================================================================
// get_machine_config RPC (spirekeeper#41 / bitspire#70 P1)
// ============================================================================
/** Fee-config wire shape inside `get_machine_config` — mirrors spirekeeper's
* `FeeConfigPayload.to_wire_dict()` (snake_case). */
export interface FeeConfigWire {
schema_version: number
cash_in_fee_fraction: number
cash_out_fee_fraction: number
components?: Record<string, number>
}
/** Response of the `get_machine_config` RPC: the operator pubkey + fee config
* (+ fiat, ids) LNbits delivers to a paired ATM over the authenticated
* transport, so a seed-only machine needs no per-machine env provisioning.
* `fee_config` is null until the operator has a super-config. */
export interface MachineConfigResponse {
operator_pubkey: string
fee_config: FeeConfigWire | null
fiat_code: string
machine_npub: string
wallet_id: string
/** Freshness watermark (unix s) for the consumer's fee-config replay guard. */
created_at: number
}