Cash-in bill timeout: consider auto-finalize vs security trade-off #31
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
When a user inserts bills and walks away, the
insertingBillstimeout sends them toconfirmAbandon. This state has no timeout of its own, so it stays on screen until the next customer taps cancel (→ idle). The walked-away customer loses their cash.Current behavior (lamassu-next)
Legacy brain.js behavior
acceptingFirstBill): 60s timeout →_idle()acceptingBills): 60s timeout →_sendCoins()(auto-finalize)_idle()immediately (no confirmation — user loses cash)Analysis
The brain.js approach (auto-finalize on timeout) seems better for the customer — they'd get their LNURL-withdraw QR generated automatically. However, this creates a security problem: if the customer walked away, the LNURL-withdraw QR code would be displayed on the ATM screen. The next person to walk up could scan it and claim the sats.
Current lamassu-next behavior is actually safer: the confirmAbandon screen doesn't expose any claimable QR. The cash stays in the machine as unclaimed operator funds. The next customer taps cancel to clear the screen.
Possible future improvements
confirmAbandon→ idle (not generatingNdebit) after 60s, so the machine self-recovers without requiring the next customer to interactDecision
Leave current behavior for now. Revisit after npub scan (#36) is implemented — npub-locked auto-finalize would solve both the UX and security concerns.
Priority
P3 — Current behavior is safe (no money exposed to third parties). The customer who walks away loses cash, but this is an edge case and matches physical cash behavior (leaving money at a counter).