Add k1 session token to ndebit for reliable request matching #23
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
When an ATM displays an ndebit QR code and a customer scans it, the ATM receives the debit request via
GetLiveDebitRequests. However, there's no way to reliably match the incoming request to the specific ATM session that generated the QR.Current ndebit format:
The
pointerfield must be a valid Lightning.Pub account ID (e.g.,"atm"), not a session-specific value. This means all debit requests look identical from the ATM's perspective.Current workaround: Amount-based matching — the ATM matches incoming requests by the sats amount. This works but has edge cases (two customers wanting the same amount simultaneously).
Proposed Solution
Add an optional
k1parameter to ndebit, following the LNURL-withdraw pattern:Flow
k1token per sessionk1in ndebit QRk1in the debit request eventk1inGetLiveDebitRequestsresponsek1— exact session identificationChanges Required
k1param to ndebit encodingencodeNdebit()/decodeNdebit()k1from ndebit, include in debit requestk1inGetLiveDebitRequestsWhy k1?
Related
k1for the same purpose: https://github.com/lnurl/luds/blob/luds/03.mdapps/machine/src/services/lightning.tsServer-side changes tracked in lightning-pub#7
UI code removed pending k1 fix
CLINK ndebit has been disabled in the ATM UI until this issue is resolved. The QR now shows LNURL-withdraw only.
Removed from
CashInView.vueMode selector (Universal/LNURL/CLINK toggle buttons):
Unified QR value (combined lightning + clink):
CLINK Debit by pubkey (manual npub entry):
Once the k1 session token is implemented, re-add these with proper session matching.
Pure CLINK / Lightning.Pub scope — unaffected by the LNbits migration
This issue is about a spec-level change to ndebit (CLINK kind-21002) — adding
k1to the request envelope so debit requests can be correlated to a session token. ndebit and CLINK are Lightning.Pub-only; LNbits has no knowledge of CLINK and thenostr-native-transportwork (see #22) does not change that.So this issue stays:
GetLiveDebitRequestshandler.If LNbits ever grows first-class CLINK support (deferred — see #22 and the LP-vs-LNbits separation memo), this issue's
k1requirement would carry over into that implementation. Until then, treat it as an LP-only spec-and-impl change. The LNbits transport'ssubscribe_payments({wallet_id?, payment_hash?, tag?, link_id?})filter is the outcome-level analog (correlate a settlement to a session bypayment_hashor by an opaqueextra.session_id), but it's not a CLINK feature and doesn't need ak1field.