fix(access): single-shot loaded card + ADR-003 amendment #92
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/access-gate-followups"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two follow-ups to #86.
Loaded card is single-shot. The card loaded at tap-to-enter carries one SUN p/c pair and the boltcards server consumes it on the first GET. After a declined Complete the stored lnurlw could never succeed again but stayed loaded with a Complete button that kept failing. The tap handlers now report skipped / accepted / declined and
completeWithCarddrops the card after any real attempt, appending "tap your card to try again" to a decline. A fresh tap on the cash screen goes through the normal tap-to-pay/receive path.Docs match what shipped. ADR-003,
.env.example, the access module headers and the provisioning schema still described the npub-QR → UID → serial-reader plan. Added a dated amendment to the ADR (reader, credential, soft entry, open-enrollment forgeability → #91, session semantics, config defaults, audit stub → #90) and removed the never-wired camera and mock readers plus theAccessReaderseam and theuidscan variant.Typecheck clean; machine 92 / state-machine 38 tests pass.