The structural fix for bitspire#122. _handle_payment used to spawn process_settlement the instant a cash_out payment landed — before the machine had begun to dispense — so a jam two seconds later found the legs already paid and `processed` was the honest answer. Payment is now the authorization; the machine's report is the capture. A cash_out lands as awaiting_dispense and is not distributed. The new `report_dispense` handler (identity from the VERIFIED transport sender, same as create_withdraw / get_machine_config) stores every report append-only and moves the settlement: dispense_confirmed → pending and distribution runs; some notes out → partial_pending, held whole (ADR-005 Decision 1, one distribution when the shortfall is resolved); nothing out → cash_owed, first on the worklist. A report naming remediates_txid moves the owed settlement it names to pending in full. Already-captured settlements are recorded but never moved — a report cannot un-pay legs. A byte-identical resend is acked without a new row. Both orders of arrival are handled: a report that precedes its payment (hold invoices settle after the dispense; the invoice listener can lag) is stored unlinked and adopted when the settlement is inserted, through the same transition. counts_uncertain on a report mirrors onto the machine immediately rather than at the next heartbeat. The state-event consumer mirrors cash_out_held_* onto dca_machines, including clearing it. Soft-fails like the other RPCs: without register_rpc the settlements sit in awaiting_dispense and surface as dispense_unreported — the honest state.
85 lines
3.3 KiB
Python
85 lines
3.3 KiB
Python
import asyncio
|
|
|
|
from fastapi import APIRouter
|
|
from lnbits.tasks import create_permanent_unique_task
|
|
from loguru import logger
|
|
|
|
from .cashin_transport import register_create_withdraw_rpc
|
|
from .crud import db
|
|
from .dispense_transport import register_dispense_report_rpc
|
|
from .machine_config_transport import register_machine_config_rpc
|
|
from .nostr_transport_roster import register_with_lnbits as register_roster_with_lnbits
|
|
from .tasks import wait_for_cassette_state_events, wait_for_paid_invoices
|
|
from .views import spirekeeper_generic_router
|
|
from .views_api import spirekeeper_api_router
|
|
|
|
logger.info("spirekeeper v2 loaded")
|
|
|
|
|
|
spirekeeper_ext: APIRouter = APIRouter(prefix="/spirekeeper", tags=["DCA Admin"])
|
|
spirekeeper_ext.include_router(spirekeeper_generic_router)
|
|
spirekeeper_ext.include_router(spirekeeper_api_router)
|
|
|
|
spirekeeper_static_files = [
|
|
{
|
|
"path": "/spirekeeper/static",
|
|
"name": "spirekeeper_static",
|
|
}
|
|
]
|
|
|
|
scheduled_tasks: list[asyncio.Task] = []
|
|
|
|
|
|
def spirekeeper_stop():
|
|
for task in scheduled_tasks:
|
|
try:
|
|
task.cancel()
|
|
except Exception as ex:
|
|
logger.warning(ex)
|
|
|
|
|
|
def spirekeeper_start():
|
|
# bitSpire invoice listener — replaces the v1 SSH/PostgreSQL poller.
|
|
invoice_task = create_permanent_unique_task(
|
|
"ext_spirekeeper", wait_for_paid_invoices
|
|
)
|
|
scheduled_tasks.append(invoice_task)
|
|
# Cassette bootstrap consumer (#29 v1) — subscribes to
|
|
# bitspire-cassettes-state events from each active ATM and upserts
|
|
# cassette_configs on receipt. Soft-fails if nostrclient isn't
|
|
# installed (logs + backs off, never crashes).
|
|
cassette_task = create_permanent_unique_task(
|
|
"ext_spirekeeper_cassette_bootstrap", wait_for_cassette_state_events
|
|
)
|
|
scheduled_tasks.append(cassette_task)
|
|
# Path-B wallet-routing hook (#20 / coord-log 2026-05-31T15:25Z):
|
|
# register our ATM-roster resolver with lnbits' nostr-transport so
|
|
# inbound kind-21000 from a known ATM npub routes to the operator's
|
|
# wallet, not an auto-created machine wallet. Soft-fails on lnbits
|
|
# versions that don't yet expose `register_roster_resolver`.
|
|
register_roster_with_lnbits()
|
|
# Secure cash-in (#31): register the `create_withdraw` nostr-transport RPC
|
|
# so the ATM requests a server-priced, server-stamped cash-in withdraw link
|
|
# over the bunker-signed transport — amount/fee/attribution derived
|
|
# server-side, never client-supplied. Soft-fails if `register_rpc` isn't
|
|
# exposed by this lnbits.
|
|
register_create_withdraw_rpc()
|
|
# Server-delivered machine config (#41 / bitspire#70 P1): register the
|
|
# get_machine_config RPC so a paired ATM pulls its operator pubkey + fee
|
|
# config over the transport, leaving "awaiting configuration" with no
|
|
# per-machine env provisioning. Soft-fails if register_rpc isn't exposed.
|
|
register_machine_config_rpc()
|
|
# Dispense outcome capture (bitspire ADR-005 §2 / #122): register the
|
|
# report_dispense RPC. A cash-out settlement now waits in awaiting_dispense
|
|
# until the machine reports; the success report is what distributes it,
|
|
# a failure report puts the customer on the owed-cash worklist.
|
|
register_dispense_report_rpc()
|
|
|
|
|
|
__all__ = [
|
|
"db",
|
|
"spirekeeper_ext",
|
|
"spirekeeper_start",
|
|
"spirekeeper_static_files",
|
|
"spirekeeper_stop",
|
|
]
|