fix(cash-out): settlement watch missed one-tap payments #99
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/cashout-settlement-race"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
A one-tap Bolt Card Complete settles in about a second. Subscribing took two sequential nostr round trips first, roughly eight seconds against a remote relay, because the watch was armed when the invoice was displayed. The settlement push is ephemeral with no replay, so it fired before anything was listening: the machine sat on a paid invoice until it timed out and the sats were taken with no cash dispensed. On sintra 2026-09-22 this hit both one-tap sells. The old two-tap flow only worked because fumbling with the card covered the window.
The watch is now armed during invoice creation, so the invoice cannot reach the screen unwatched. The payment hash comes from the creation response rather than a decode round trip that was half the window. A settlement that still beats the consumer is latched and replayed, and a get_payment poll runs alongside the subscription so a lost push cannot strand a payment either.
Separately, a card pull that is accepted but never settles now logs the txid and shows a notice on screen instead of returning to the amount screen as though nothing happened.
Typecheck clean; 116 tests including seven covering the race; full Electron build green.