bitspire/packages
Padreug 5114619fce fix(access): only accept END_SESSION from idle so the session cap can't strand funds
The root-level END_SESSION let the 10-minute hard cap (and the End Session
button) jump to `locked` from any state, bypassing the money-path guards
the machine already has: confirmAbandon with bills stacked, an in-flight
dispense, an outbound cash-in payment. Cap fires at minute 10 while a
customer's bills sit in the stacker → locked → next unlock resetContext
wipes them unpaid; during dispensingCash the done-event is dropped and
no transaction record is written.

Nothing is lost by scoping it: every transaction terminal state already
targets #atm.locked on this branch, so the machine re-locks on its own
when the transaction ends. END_SESSION now lives on idle.on only, and
useSessionSecurity defers both deadlines until currentState is idle —
an expired session re-locks on the first tick back at the menu.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 14:11:38 +02:00
..
cashu refactor(rename): @lamassu/* → @bitSpire/* package scopes 2026-06-01 19:08:03 +02:00
clink refactor(clink): route CLINK signing + encryption through the Signer 2026-06-19 00:15:17 +02:00
hal chore: scrub "Lamassu" from shipped labels 2026-09-19 09:58:42 +02:00
lnbits feat(lnbits): wrap the create_wallet RPC 2026-09-06 19:24:15 +02:00
nostr-client chore: scrub "Lamassu" from shipped labels 2026-09-19 09:58:42 +02:00
state-machine fix(access): only accept END_SESSION from idle so the session cap can't strand funds 2026-09-20 14:11:38 +02:00
ui-shared chore: scrub "Lamassu" from shipped labels 2026-09-19 09:58:42 +02:00