Entry now spends the tap's single-use SUN once, on the card server's new /session endpoint (aiolabs/boltcards feat/card-session-endpoint), instead of parsing the lnurlw locally and deferring every check to Complete. The server proves a genuine, non-replayed card and returns the wallet balance plus the hit-keyed LUD-03 withdraw and LUD-06 pay second steps — the same single-use bearer /scan and /pay hand out — so Complete still needs no second tap and the ATM holds no p/c for the visit. - electron/boltcard-session.ts: /scan → /session URL derivation, response parsing, 404 → 'card server does not support sessions'. - lnurl-withdraw / lnurl-pay: the second steps are now callable on their own (executeWithdrawCallback, resolveInvoiceFromPayStep); the tap paths are unchanged and reuse them. - IPC: lnurl:open-card-session, lnurl:withdraw-session, lnurl:pay-session. - store: handleBoltCardEntry opens the session then authorizes the server-returned external_id; the payment handlers take a source (raw tap or session); a withheld withdraw step declines with the server's reason. The boltcard AccessScan no longer carries the lnurlw. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
144 lines
5.8 KiB
TypeScript
144 lines
5.8 KiB
TypeScript
import { describe, it, expect, vi } from 'vitest'
|
|
import { executeLnurlWithdraw, executeWithdrawCallback, lnurlwToHttps } from './lnurl-withdraw'
|
|
|
|
const BOLT11 = 'lnbc10u1p3xyz...'
|
|
const LNURLW =
|
|
'lnurlw://lnbits.l484.com/boltcards/api/v1/scan/abc123?p=DEADBEEFDEADBEEFDEADBEEFDEADBEEF&c=1122334455667788'
|
|
|
|
/** Build a mock fetch that returns the given JSON bodies per call, in order. */
|
|
function mockFetch(bodies: unknown[]) {
|
|
const calls: string[] = []
|
|
const impl = vi.fn(async (url: string | URL) => {
|
|
calls.push(url.toString())
|
|
const body = bodies[calls.length - 1]
|
|
return { json: async () => body } as Response
|
|
})
|
|
return { impl: impl as unknown as typeof fetch, calls }
|
|
}
|
|
|
|
describe('lnurlwToHttps', () => {
|
|
it('maps lnurlw:// and lnurl:// to https://', () => {
|
|
expect(lnurlwToHttps('lnurlw://host/p?x=1')).toBe('https://host/p?x=1')
|
|
expect(lnurlwToHttps('lnurl://host/p')).toBe('https://host/p')
|
|
})
|
|
it('strips a lightning: prefix', () => {
|
|
expect(lnurlwToHttps('lightning:lnurlw://host/p')).toBe('https://host/p')
|
|
})
|
|
it('passes https:// through and trims', () => {
|
|
expect(lnurlwToHttps(' https://host/p ')).toBe('https://host/p')
|
|
})
|
|
it('rejects http://, bech32 lnurl1…, and empty', () => {
|
|
expect(lnurlwToHttps('http://host/p')).toBeNull()
|
|
expect(lnurlwToHttps('LNURL1DP68GURN8GHJ7')).toBeNull()
|
|
expect(lnurlwToHttps('')).toBeNull()
|
|
})
|
|
})
|
|
|
|
describe('executeLnurlWithdraw', () => {
|
|
const withdrawReq = {
|
|
tag: 'withdrawRequest',
|
|
callback: 'https://lnbits.l484.com/boltcards/api/v1/scan/cb',
|
|
k1: 'K1TOKEN',
|
|
minWithdrawable: 1000,
|
|
maxWithdrawable: 5_000_000,
|
|
}
|
|
|
|
it('completes the two-step withdraw and passes k1 + pr to the callback', async () => {
|
|
const { impl, calls } = mockFetch([withdrawReq, { status: 'OK' }])
|
|
const res = await executeLnurlWithdraw(LNURLW, BOLT11, { fetchImpl: impl })
|
|
expect(res).toEqual({ ok: true })
|
|
// First call = the lnurlw as https; second = callback with k1 + pr.
|
|
expect(calls[0]).toContain('https://lnbits.l484.com/boltcards/api/v1/scan/abc123')
|
|
expect(calls[1]).toContain('k1=K1TOKEN')
|
|
expect(calls[1]).toContain(`pr=${encodeURIComponent(BOLT11)}`)
|
|
})
|
|
|
|
it('rejects a non-lnurlw tag', async () => {
|
|
const { impl } = mockFetch([])
|
|
const res = await executeLnurlWithdraw('http://nope', BOLT11, { fetchImpl: impl })
|
|
expect(res.ok).toBe(false)
|
|
expect(res.reason).toMatch(/not a valid Bolt Card/i)
|
|
})
|
|
|
|
it('rejects when there is no invoice', async () => {
|
|
const { impl } = mockFetch([])
|
|
const res = await executeLnurlWithdraw(LNURLW, '', { fetchImpl: impl })
|
|
expect(res).toMatchObject({ ok: false, reason: 'no invoice to charge' })
|
|
})
|
|
|
|
it('surfaces an ERROR from the withdraw request', async () => {
|
|
const { impl } = mockFetch([{ status: 'ERROR', reason: 'spent today limit' }])
|
|
const res = await executeLnurlWithdraw(LNURLW, BOLT11, { fetchImpl: impl })
|
|
expect(res).toMatchObject({ ok: false, reason: 'spent today limit' })
|
|
})
|
|
|
|
it('rejects a response that is not a withdrawRequest', async () => {
|
|
const { impl } = mockFetch([{ tag: 'payRequest', callback: 'x' }])
|
|
const res = await executeLnurlWithdraw(LNURLW, BOLT11, { fetchImpl: impl })
|
|
expect(res).toMatchObject({ ok: false })
|
|
expect(res.reason).toMatch(/withdraw voucher/i)
|
|
})
|
|
|
|
it('rejects (without calling the callback) when the amount exceeds the card limit', async () => {
|
|
const { impl, calls } = mockFetch([{ ...withdrawReq, maxWithdrawable: 2000 }])
|
|
const res = await executeLnurlWithdraw(LNURLW, BOLT11, { fetchImpl: impl, amountMsat: 5000 })
|
|
expect(res).toMatchObject({ ok: false, reason: 'card limit is below this amount' })
|
|
expect(calls).toHaveLength(1) // callback never hit
|
|
})
|
|
|
|
it('surfaces an ERROR from the callback (card declined)', async () => {
|
|
const { impl } = mockFetch([withdrawReq, { status: 'ERROR', reason: 'insufficient funds' }])
|
|
const res = await executeLnurlWithdraw(LNURLW, BOLT11, { fetchImpl: impl })
|
|
expect(res).toMatchObject({ ok: false, reason: 'insufficient funds' })
|
|
})
|
|
|
|
it('handles a network failure gracefully', async () => {
|
|
const impl = vi.fn(async () => {
|
|
throw new Error('ECONNREFUSED')
|
|
}) as unknown as typeof fetch
|
|
const res = await executeLnurlWithdraw(LNURLW, BOLT11, { fetchImpl: impl })
|
|
expect(res.ok).toBe(false)
|
|
expect(res.reason).toMatch(/could not reach the card/i)
|
|
})
|
|
})
|
|
|
|
describe('executeWithdrawCallback (session second step, no tap)', () => {
|
|
const step = {
|
|
callback: 'https://lnbits.l484.com/boltcards/api/v1/lnurl/cb/hit1',
|
|
k1: 'hit1',
|
|
maxWithdrawable: 5_000_000,
|
|
}
|
|
|
|
it('hands the invoice straight to the callback with k1', async () => {
|
|
const f = mockFetch([{ status: 'OK' }])
|
|
const out = await executeWithdrawCallback(step, BOLT11, { fetchImpl: f.impl })
|
|
expect(out).toEqual({ ok: true })
|
|
expect(f.calls).toHaveLength(1)
|
|
expect(f.calls[0]).toContain('k1=hit1')
|
|
expect(f.calls[0]).toContain('pr=' + BOLT11)
|
|
})
|
|
|
|
it('refuses an amount above the step limit without calling out', async () => {
|
|
const f = mockFetch([])
|
|
const out = await executeWithdrawCallback(step, BOLT11, {
|
|
fetchImpl: f.impl,
|
|
amountMsat: 6_000_000,
|
|
})
|
|
expect(out).toEqual({ ok: false, reason: 'card limit is below this amount' })
|
|
expect(f.calls).toHaveLength(0)
|
|
})
|
|
|
|
it('surfaces a callback decline', async () => {
|
|
const f = mockFetch([{ status: 'ERROR', reason: 'Payment already claimed.' }])
|
|
const out = await executeWithdrawCallback(step, BOLT11, { fetchImpl: f.impl })
|
|
expect(out).toEqual({ ok: false, reason: 'Payment already claimed.' })
|
|
})
|
|
|
|
it('rejects a missing invoice', async () => {
|
|
const f = mockFetch([])
|
|
expect(await executeWithdrawCallback(step, '', { fetchImpl: f.impl })).toEqual({
|
|
ok: false,
|
|
reason: 'no invoice to charge',
|
|
})
|
|
})
|
|
})
|