boltcards/tests
Padreug 4e9cd78b59
Some checks failed
lint.yml / feat(lnurl): /session — one verified tap for a terminal visit (pull_request) Failing after 0s
feat(lnurl): /session — one verified tap for a terminal visit
GET /api/v1/session/{external_id}?p=&c= for bitSpire tap-to-enter. A tap
yields a single-use SUN, so a terminal that verified it at entry could not
reuse the p/c to move sats later. This verifies once (advancing the
counter like /scan), records one hit, and returns what the rest of the
visit needs: the card wallet's balance + fiat equivalent (wallet currency,
then the instance default; display only), the LUD-03 withdraw step
(callback, k1 = hit) and the LUD-06 top-up step (callback), both keyed by
the hit — the same single-use bearer /scan and /pay already hand out.
Withdraw is withheld with a reason once the daily limit is spent, as
/scan would refuse; top-up stays available.

Tests drive the real decrypt/CMAC path with a SUN encrypted under the
card's keys, and pin /verify + /pay behaviour across the helper refactor.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 17:01:14 +02:00
..
__init__.py feat: code quality (#39) 2024-08-29 12:24:15 +02:00
test_init.py feat: code quality (#39) 2024-08-29 12:24:15 +02:00
test_session.py feat(lnurl): /session — one verified tap for a terminal visit 2026-09-20 17:01:14 +02:00