The root-level END_SESSION let the 10-minute hard cap (and the End Session button) jump to `locked` from any state, bypassing the money-path guards the machine already has: confirmAbandon with bills stacked, an in-flight dispense, an outbound cash-in payment. Cap fires at minute 10 while a customer's bills sit in the stacker → locked → next unlock resetContext wipes them unpaid; during dispensingCash the done-event is dropped and no transaction record is written. Nothing is lost by scoping it: every transaction terminal state already targets #atm.locked on this branch, so the machine re-locks on its own when the transaction ends. END_SESSION now lives on idle.on only, and useSessionSecurity defers both deadlines until currentState is idle — an expired session re-locks on the first tick back at the menu. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| cashu | ||
| clink | ||
| hal | ||
| lnbits | ||
| nostr-client | ||
| state-machine | ||
| ui-shared | ||