|
cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
|
What a sale is paid with and to, and the sale between broadcast and verdict. More...
#include "pos_app.h"Go to the source code of this file.
Functions | |
| token_t * | active_token (pos_chain_t chain) |
| The selection's token, or NULL for a native coin. | |
| static bool | token_parse (token_t *t, bool tron, CW_CryptoProvider &crypto) |
Parse t->str into its dual store, twice and independently. | |
| void | token_load (const token_cfg_t *cfg, CW_CryptoProvider &crypto) |
| Load one token at boot: the operator's contract if one is set and parses, config.h otherwise. | |
| bool | token_decimals_ok (pos_chain_t chain, char *err, size_t err_max) |
| Before the first sale in an operator-set token, read its decimals() and refuse anything but 6. | |
| void | ui_refresh_addresses_for (uint8_t c) |
| Point the UI's address rows at the selected chain. | |
| void | ui_refresh_addresses (void) |
| Implemented by main: repoint those two rows at the selected chain. | |
| const pos_addr_t * | active_dest (void) |
| The reconciled recipient for the chain currently selected. | |
| void | sale_fee_text (char *out, size_t n) |
| The most network fee the customer's card can be charged on top of the sale, for the confirm screen. "" where there is no cap to state: a native TRX transfer burns bandwidth, not a fee limit. | |
| void | inflight_persist (const inflight_t *fl) |
| Write the sale to NVS just before it leaves the terminal. | |
| uint64_t | wall_ms (void) |
| Unix time in ms, 0 while the clock is unset. | |
| void | settle_inflight (void) |
| Poll the in-flight sale for up to 120 s and show what the chain says. | |
| bcast_t | pay_sign_and_broadcast (CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_CryptoProvider &crypto, const pos_amount_t *amount, const char *pin, size_t pin_chars, inflight_t *fl, char *err_out, size_t err_max) |
| Sign and broadcast the reconciled sale on whichever family is selected. The family is read once, here. | |
Variables | |
| const uint8_t | ETH_DERIVE_PATH [20] |
| char | s_payout_eth [SETTINGS_PAYOUT_MAX] = "" |
| char | s_payout_tron [SETTINGS_PAYOUT_MAX] = "" |
| token_t | s_token [POS_CHAIN__COUNT] |
| const token_cfg_t | TOKEN_CFG [] |
| const size_t | TOKEN_CFG_COUNT = sizeof(TOKEN_CFG) / sizeof(TOKEN_CFG[0]) |
| pos_addr_t | s_dest |
| bool | s_payout_bad [2] = { false, false } |
| pos_addr_t | s_tron_dest |
| sale_fee_t | s_sale_fee |
| inflight_t | s_inflight |
What a sale is paid with and to, and the sale between broadcast and verdict.
Definition in file pay.cpp.
| const pos_addr_t * active_dest | ( | void | ) |
The reconciled recipient for the chain currently selected.
Definition at line 188 of file pay.cpp.
References chain_is_tron(), s_dest, and s_tron_dest.
Referenced by app_main(), and settle_inflight().
| token_t * active_token | ( | pos_chain_t | chain | ) |
The selection's token, or NULL for a native coin.
Definition at line 45 of file pay.cpp.
References pos_asset_t::native, pos_asset_of(), POS_CHAIN__COUNT, and s_token.
Referenced by app_main(), evm_balance_ok(), pay_sign_and_broadcast(), sale_fee_text(), sign_and_broadcast(), token_decimals_ok(), and ui_refresh_addresses_for().
| void inflight_persist | ( | const inflight_t * | fl | ) |
Write the sale to NVS just before it leaves the terminal.
So a brownout or panic during the receipt poll does not lose whether the customer paid. Written as "broadcast not known": a record that survives a reset is by definition one whose answer nobody saw. One write per sale.
Definition at line 228 of file pay.cpp.
References inflight_t::active, inflight_t::broadcast_known, and settings_inflight_save().
Referenced by sign_and_broadcast(), and sign_and_broadcast_tron().
| bcast_t pay_sign_and_broadcast | ( | CryptnoxWallet & | wallet, |
| Pn532NfcTransport & | transport, | ||
| CW_CryptoProvider & | crypto, | ||
| const pos_amount_t * | amount, | ||
| const char * | pin, | ||
| size_t | pin_chars, | ||
| inflight_t * | fl, | ||
| char * | err_out, | ||
| size_t | err_max ) |
Sign and broadcast the reconciled sale on whichever family is selected. The family is read once, here.
Definition at line 347 of file pay.cpp.
References active_token(), BCAST_FAILED, chain_is_tron(), s_dest, s_tron_dest, settings_get_chain(), sign_and_broadcast(), sign_and_broadcast_tron(), and token_decimals_ok().
Referenced by app_main().
| void sale_fee_text | ( | char * | out, |
| size_t | n ) |
The most network fee the customer's card can be charged on top of the sale, for the confirm screen. "" where there is no cap to state: a native TRX transfer burns bandwidth, not a fee limit.
Definition at line 201 of file pay.cpp.
References active_token(), chain_is_native_evm(), chain_is_polygon(), chain_is_tron(), fmt_coin(), GAS_LIMIT_NATIVE, s_sale_fee, and TRON_TRC20_FEE_LIMIT_SUN.
Referenced by app_main().
| void settle_inflight | ( | void | ) |
Poll the in-flight sale for up to 120 s and show what the chain says.
Only three answers end a sale: mined and ours (Approved), mined and reverted (nothing moved), or — Tron only — expired without ever being included (nothing can ever move). Everything else, including a receipt that does not match the transfer and a broadcast whose answer was lost, is Unconfirmed: the screen keeps the hash, offers Check again, and never says Declined, because a declined sale is one the merchant charges a second time.
Definition at line 255 of file pay.cpp.
References inflight_t::active, active_dest(), inflight_t::amount, inflight_t::broadcast_known, inflight_t::decided, eth_rpc_get_tx_receipt(), ETH_RPC_RECEIPT_MISMATCH, ETH_RPC_RECEIPT_PENDING, ETH_RPC_RECEIPT_REVERTED, ETH_RPC_RECEIPT_SUCCESS, eth_rpc_select_for(), inflight_t::expiration_ms, expired(), inflight_t::hash, IS_TRUE32, inflight_t::payee, inflight_t::polygon, pos_handle_anomaly(), POS_VERDICT_APPROVED, POS_VERDICT_DECLINED, run_payment_decision(), s_inflight, settings_inflight_clear(), TAG, inflight_t::to, inflight_t::token, inflight_t::tron, tron_receipt_as_eth(), tron_rpc_get_receipt(), ui_set_tx_info(), ui_show_tx_status(), UI_TX_STATE_CONFIRMING, UI_TX_STATE_DONE, UI_TX_STATE_FAILED, UI_TX_STATE_UNCONFIRMED, wall_ms(), and wdt_feed().
Referenced by app_main().
| bool token_decimals_ok | ( | pos_chain_t | chain, |
| char * | err, | ||
| size_t | err_max ) |
Before the first sale in an operator-set token, read its decimals() and refuse anything but 6.
Every amount is signed in 6-decimal base units, so an 18-decimal contract would be charged 10^-12 of the figure on the screen. Checked here rather than when the contract is proposed: the config page runs with the station down, so no node can be asked then. A read that fails refuses the sale too, and the next sale asks again. Once per boot per token.
Definition at line 115 of file pay.cpp.
References active_token(), pos_addr_t::addr, token_t::addr, token_t::checked, ETH_ADDR_LEN, eth_rpc_get_token_decimals(), eth_rpc_select(), eth_rpc_select_for(), pos_chain_is_polygon(), pos_chain_is_tron(), token_t::str, TAG, TRON_ADDR_HEX_LEN, tron_addr_to_hex(), and tron_rpc_get_trc20_decimals().
Referenced by app_main(), and pay_sign_and_broadcast().
| void token_load | ( | const token_cfg_t * | cfg, |
| CW_CryptoProvider & | crypto ) |
Load one token at boot: the operator's contract if one is set and parses, config.h otherwise.
Non-fatal by design: a placeholder or a typo leaves ok false and that one asset is refused when selected, rather than stopping a terminal that charges in something else from booting.
Definition at line 84 of file pay.cpp.
References token_cfg_t::chain, token_t::checked, token_cfg_t::main, token_cfg_t::name, pos_asset_t::net, pos_asset_of(), pos_chain_is_tron(), pos_net_info(), s_token, settings_get_contract(), settings_net_str(), token_t::str, TAG, token_cfg_t::test, pos_asset_t::ticker, and token_parse().
Referenced by pos_boot().
|
static |
Parse t->str into its dual store, twice and independently.
EVM: eth_addr_parse, which also runs the EIP-55 checksum. Tron: base58check, decoded twice by the SDK, so a mistyped contract is refused here rather than charged against the wrong asset.
Definition at line 57 of file pay.cpp.
References pos_addr_t::addr, token_t::addr, pos_addr_t::addr_echo, ETH_ADDR_LEN, eth_addr_parse(), token_t::ok, and token_t::str.
Referenced by token_load().
| void ui_refresh_addresses | ( | void | ) |
Implemented by main: repoint those two rows at the selected chain.
The asset picker switches the chain on the UI task and rebuilds the page immediately, so it asks for the new pair here rather than posting an event and racing its own redraw. main owns the per-chain contract and payout strings; this only reads them.
Definition at line 170 of file pay.cpp.
References settings_get_chain(), and ui_refresh_addresses_for().
Referenced by app_main(), btn_event_cb(), and pos_boot().
| void ui_refresh_addresses_for | ( | uint8_t | chain | ) |
Point the UI's address rows at the selected chain.
Same, for any chain (a pos_chain_t) rather than the one sales use.
Called on every entry to the confirm screen and from the asset picker, since the chain can be switched while this task is parked on its queue (see ui.h).
Point the UI's address rows at the selected chain.
The admin Tx tab browses another asset's contract and payout without switching what the terminal charges in.
Definition at line 155 of file pay.cpp.
References active_token(), pos_chain_is_polygon(), pos_chain_is_tron(), s_payout_eth, s_payout_tron, token_t::str, and ui_set_addresses().
Referenced by build_settings(), and ui_refresh_addresses().
| uint64_t wall_ms | ( | void | ) |
Unix time in ms, 0 while the clock is unset.
Definition at line 237 of file pay.cpp.
Referenced by app_main(), and settle_inflight().
| const uint8_t ETH_DERIVE_PATH[20] |
Definition at line 16 of file pay.cpp.
Referenced by card_read_payouts(), and sign_and_broadcast().
| pos_addr_t s_dest |
Definition at line 177 of file pay.cpp.
Referenced by active_dest(), pay_sign_and_broadcast(), and resolve_evm_payout().
| inflight_t s_inflight |
Definition at line 219 of file pay.cpp.
Referenced by app_main(), and settle_inflight().
| bool s_payout_bad[2] = { false, false } |
Definition at line 182 of file pay.cpp.
Referenced by app_main(), and pos_boot().
| char s_payout_eth[SETTINGS_PAYOUT_MAX] = "" |
Definition at line 27 of file pay.cpp.
Referenced by app_main(), pos_boot(), resolve_evm_payout(), and ui_refresh_addresses_for().
| char s_payout_tron[SETTINGS_PAYOUT_MAX] = "" |
Definition at line 28 of file pay.cpp.
Referenced by app_main(), pos_boot(), and ui_refresh_addresses_for().
| sale_fee_t s_sale_fee |
Definition at line 192 of file pay.cpp.
Referenced by app_main(), evm_balance_ok(), sale_fee_text(), and sign_and_broadcast().
| token_t s_token[POS_CHAIN__COUNT] |
Definition at line 30 of file pay.cpp.
Referenced by active_token(), auth_post(), has_token(), prov_auth_resolve(), prov_pair_code(), prov_start(), prov_stop(), and token_load().
| pos_addr_t s_tron_dest |
Definition at line 185 of file pay.cpp.
Referenced by active_dest(), pay_sign_and_broadcast(), and pos_boot().
| const token_cfg_t TOKEN_CFG[] |
Definition at line 41 of file pay.cpp.
Referenced by pos_boot().