Cash-in bill timeout: consider auto-finalize vs security trade-off #31

Closed
opened 2026-06-13 22:02:53 +00:00 by padreug · 0 comments
Owner

Migrated from aiolabs/lamassu-next#31 — opened by @padreug on 2026-02-23.\n\n## Problem

When a user inserts bills and walks away, the insertingBills timeout sends them to confirmAbandon. This state has no timeout of its own, so it stays on screen until the next customer taps cancel (→ idle). The walked-away customer loses their cash.

Current behavior (lamassu-next)

insertingBills → TIMEOUT (with bills) → confirmAbandon → hangs until interaction
                                         ├─ CANCEL → idle (next customer clears it)
                                         └─ RETRY → generatingNdebit
  • No bills inserted: TIMEOUT → idle (safe, correct)
  • Bills inserted: TIMEOUT → confirmAbandon (no timeout on this state)
  • confirmAbandon: CANCEL → idle, RETRY → generatingNdebit

Legacy brain.js behavior

  • No bills inserted (acceptingFirstBill): 60s timeout → _idle()
  • Bills inserted (acceptingBills): 60s timeout → _sendCoins() (auto-finalize)
  • Cancel: → _idle() immediately (no confirmation — user loses cash)

Analysis

The brain.js approach (auto-finalize on timeout) seems better for the customer — they'd get their LNURL-withdraw QR generated automatically. However, this creates a security problem: if the customer walked away, the LNURL-withdraw QR code would be displayed on the ATM screen. The next person to walk up could scan it and claim the sats.

Current lamassu-next behavior is actually safer: the confirmAbandon screen doesn't expose any claimable QR. The cash stays in the machine as unclaimed operator funds. The next customer taps cancel to clear the screen.

Possible future improvements

  1. Add a timeout on confirmAbandon → idle (not generatingNdebit) after 60s, so the machine self-recovers without requiring the next customer to interact
  2. Npub-locked receipts (see #36): if the customer scanned their npub before inserting bills, the auto-finalized LNURL-withdraw could be sent as an encrypted DM instead of displayed on screen — solving the security problem
  3. Operator notification: alert operator when cash is abandoned so they can reconcile

Decision

Leave current behavior for now. Revisit after npub scan (#36) is implemented — npub-locked auto-finalize would solve both the UX and security concerns.

Priority

P3 — Current behavior is safe (no money exposed to third parties). The customer who walks away loses cash, but this is an edge case and matches physical cash behavior (leaving money at a counter).

> _Migrated from [aiolabs/lamassu-next#31](https://git.atitlan.io/aiolabs/lamassu-next/issues/31) — opened by @padreug on 2026-02-23._\n\n## Problem When a user inserts bills and walks away, the `insertingBills` timeout sends them to `confirmAbandon`. This state has no timeout of its own, so it stays on screen until the next customer taps cancel (→ idle). The walked-away customer loses their cash. ## Current behavior (lamassu-next) ``` insertingBills → TIMEOUT (with bills) → confirmAbandon → hangs until interaction ├─ CANCEL → idle (next customer clears it) └─ RETRY → generatingNdebit ``` - No bills inserted: TIMEOUT → idle (safe, correct) - Bills inserted: TIMEOUT → confirmAbandon (no timeout on this state) - confirmAbandon: CANCEL → idle, RETRY → generatingNdebit ## Legacy brain.js behavior - No bills inserted (`acceptingFirstBill`): 60s timeout → `_idle()` - Bills inserted (`acceptingBills`): 60s timeout → `_sendCoins()` (auto-finalize) - Cancel: → `_idle()` immediately (no confirmation — user loses cash) ## Analysis The brain.js approach (auto-finalize on timeout) seems better for the customer — they'd get their LNURL-withdraw QR generated automatically. However, **this creates a security problem**: if the customer walked away, the LNURL-withdraw QR code would be displayed on the ATM screen. The next person to walk up could scan it and claim the sats. **Current lamassu-next behavior is actually safer**: the confirmAbandon screen doesn't expose any claimable QR. The cash stays in the machine as unclaimed operator funds. The next customer taps cancel to clear the screen. ## Possible future improvements 1. **Add a timeout on `confirmAbandon`** → idle (not generatingNdebit) after 60s, so the machine self-recovers without requiring the next customer to interact 2. **Npub-locked receipts** (see #36): if the customer scanned their npub before inserting bills, the auto-finalized LNURL-withdraw could be sent as an encrypted DM instead of displayed on screen — solving the security problem 3. **Operator notification**: alert operator when cash is abandoned so they can reconcile ## Decision Leave current behavior for now. Revisit after npub scan (#36) is implemented — npub-locked auto-finalize would solve both the UX and security concerns. ## Priority P3 — Current behavior is safe (no money exposed to third parties). The customer who walks away loses cash, but this is an edge case and matches physical cash behavior (leaving money at a counter).
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/bitspire#31
No description provided.