feat: operator command channel via Nostr (manual dispense, remote management) #38
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Add a Nostr-native operator command channel so authorized operators can remotely manage ATMs — starting with manual dispense to remediate failed transactions.
Operator Identity
New env var
OPERATOR_PUBKEYS— comma-separated list of hex pubkeys authorized to send commands to this machine.The machine subscribes to Kind 21003 (CLINK Manage) events tagged with its own pubkey, filters by sender matching an authorized operator pubkey, and decrypts the command via NIP-44.
This is intentionally separate from
LIGHTNING_PUB_PUBKEY— operator identity should not be coupled to the payment backend. An operator can manage multiple machines across different Lightning.Pub instances from their personal Nostr identity.Commands
Phase 1: Manual Dispense
When
ref_txidis provided, the original failed transaction gets updated:status→remediatedThis closes the loop: operator sees
ERR→ triggers manual dispense → transaction shows asremediatedin TUI/dashboard.New transaction type:
manual_dispense(distinct fromcash_out— no Lightning payment involved).Safety: Machine must be in
idlestate. Response includes full cassette result (provisioned/dispensed/rejected).Phase 2: Remote Management
get_status— machine state, cassette inventory, cashbox, uptimeempty_cashbox— reset cashbox countersreboot— restart the ATM serviceget_transactions— recent transaction list with statusPhase 3: Dashboard Integration
apps/dashboard/sends commands as Kind 21003 events signed by operator's keyERR/PARTIALhighlighting and "Remediate" buttonProtocol Flow
Access Points
Operator commands should be sendable from:
apps/dashboard/) — primary UI, web-basedatm-tui) — local management tool, could also gain Nostr command capabilityTransaction Status Lifecycle
Files to Modify
apps/machine/.env.exampleOPERATOR_PUBKEYSapps/machine/electron/main.tsapps/machine/src/services/operator.tsapps/machine/src/stores/atm.tsapps/machine/electron/state-store.tsremediatedstatus,manual_dispensetype, link remediation txidpackages/state-machine/src/types.tsWhat Does NOT Change