Feature: Hold Invoices for Safe Dispensing #3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
For cash-out, the current flow has a risk window: user pays invoice, but if dispenser jams, user loses funds. Hold invoices solve this by delaying settlement until cash is physically dispensed.
Status: Achievable with Hybrid Approach
Complexity: High
Dependencies: LND hold invoices, Lightning.Pub extension or direct LND access
Problem: Current Flow (Risky)
Solution: Hold Invoice Flow (Safe)
Technical Background
LND supports hold invoices via:
AddHoldInvoice: Create invoice with known preimage hashSettleInvoice: Release funds (ATM provides preimage)CancelInvoice: Return funds to payerLightning.Pub Status
Lightning.Pub's codebase includes LND protobuf definitions for hold invoices:
However: These are not currently exposed in Lightning.Pub's HTTP/Nostr API.
Implementation Options
Option A: Lightning.Pub Extension (Recommended)
Contribute hold invoice support to Lightning.Pub:
Pros: Clean integration, benefits entire ecosystem
Cons: Requires upstream contribution, timeline uncertain
Option B: Hybrid Approach
ATM uses Lightning.Pub for accounting but connects to LND directly for hold invoices:
Pros: Works today, no upstream changes needed
Cons: More complex, two connections to manage
Option C: Escrow Account
Use Lightning.Pub's internal accounts as escrow:
Pros: Works within Lightning.Pub model
Cons: Requires user to have Lightning.Pub account for refund
Recommended Approach: Lightning.Pub Contribution
We will contribute hold invoice support directly to Lightning.Pub (Option A). This:
Action Item: Open PR to Lightning.Pub exposing hold invoice methods via Nostr RPC (kind 21000).
Cash-Out Flow with Hold Invoices
Timeout Handling
Priority
P2 - High effort, critical for production safety
References
[reserved] migration number alignmentto Feature: Hold Invoices for Safe DispensingMoved to lightning-pub repo: aiolabs/lightning-pub#2
This issue requires extending Lightning.Pub's API to expose hold invoice functionality and belongs in that repository.
Re-opening this, need to update for new bitspire infra (no longer using lightning.pub)