fix(access): single-shot loaded card + ADR-003 amendment #92

Merged
padreug merged 2 commits from fix/access-gate-followups into dev 2026-09-20 14:41:45 +00:00
Owner

Two follow-ups to #86.

Loaded card is single-shot. The card loaded at tap-to-enter carries one SUN p/c pair and the boltcards server consumes it on the first GET. After a declined Complete the stored lnurlw could never succeed again but stayed loaded with a Complete button that kept failing. The tap handlers now report skipped / accepted / declined and completeWithCard drops the card after any real attempt, appending "tap your card to try again" to a decline. A fresh tap on the cash screen goes through the normal tap-to-pay/receive path.

Docs match what shipped. ADR-003, .env.example, the access module headers and the provisioning schema still described the npub-QR → UID → serial-reader plan. Added a dated amendment to the ADR (reader, credential, soft entry, open-enrollment forgeability → #91, session semantics, config defaults, audit stub → #90) and removed the never-wired camera and mock readers plus the AccessReader seam and the uid scan variant.

Typecheck clean; machine 92 / state-machine 38 tests pass.

Two follow-ups to #86. **Loaded card is single-shot.** The card loaded at tap-to-enter carries one SUN p/c pair and the boltcards server consumes it on the first GET. After a declined Complete the stored lnurlw could never succeed again but stayed loaded with a Complete button that kept failing. The tap handlers now report skipped / accepted / declined and `completeWithCard` drops the card after any real attempt, appending "tap your card to try again" to a decline. A fresh tap on the cash screen goes through the normal tap-to-pay/receive path. **Docs match what shipped.** ADR-003, `.env.example`, the access module headers and the provisioning schema still described the npub-QR → UID → serial-reader plan. Added a dated amendment to the ADR (reader, credential, soft entry, open-enrollment forgeability → #91, session semantics, config defaults, audit stub → #90) and removed the never-wired camera and mock readers plus the `AccessReader` seam and the `uid` scan variant. Typecheck clean; machine 92 / state-machine 38 tests pass.
The card loaded at tap-to-enter carries one SUN p/c pair, and the
boltcards server bumps the counter on the first GET. After a declined
Complete (limit below amount, callback failure, payment error) the
stored lnurlw can never succeed again, yet it stayed loaded with a
Complete button that would keep failing. The same held on the success
path when the payment never settled (cash-out invoice timeout back to
selectingAmount).

The tap handlers now report skipped / accepted / declined, and
completeWithCard clears the card after any real attempt, appending
'tap your card to try again' to a decline. A skipped outcome (guard
bounced it, no server call) keeps the card. A fresh tap on the cash
screen goes through the normal tap-to-pay/receive path.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
ADR-003, .env.example, the access module's headers and the provisioning
schema still described the planned npub-QR → UID → serial-reader path.
What shipped (#86) is Bolt Card tap-to-enter over the main-process
pcscd reader with external_id as the identity, soft entry and
verify-at-payment. Nothing ever called availableAccessReaders(): the
camera npub-QR reader, the mock reader and the AccessReader seam were
dead, so they go; services/access now holds authorize, the card parser
and the credential types. The unused 'uid' scan variant goes with them;
'npub' (+PIN) and the 'challenge' seam stay.

The ADR gets an amendment section recording the differences, including
that open enrollment is not a security boundary and that the audit is
still a stub (both tracked as issues).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
padreug deleted branch fix/access-gate-followups 2026-09-20 14:41:45 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/bitspire!92
No description provided.