Skip to content

feat: fund identity registration and top-up from the wallet's own Core coins - #168

Closed
LexxXell wants to merge 1 commit into
developfrom
feat/identityFundingFromCore
Closed

LexxXell wants to merge 1 commit into
developfrom
feat/identityFundingFromCore

Conversation

@LexxXell

Copy link
Copy Markdown
Collaborator

Draft. Depends on #167 (dash-platform-sdk 1.5.0-dev.10): the fee estimate uses StateTransition.calculateMinRequiredFee() from pshenmic-dpp 2.0.0-dev.29, so this does not compile on develop's SDK yet. Will be rebased once #167 is merged.

Changes

Identity registration and top-up paid from the wallet's own Core coins (BIP44 UTXOs), instead of a deposit to a one-off funding address. Backend only; Platform-address and shielded sources come in later PRs.

The flow is split into a quote and a confirmation, both journaled so that any step can be resumed after a crash, a closed popup or a network timeout without reselecting coins or spending a second asset lock:

  1. PREPARE_IDENTITY_FUNDING selects UTXOs, reserves the DIP-13 index (registration 5'/1'/i, top-up 5'/2'/i), signs the asset lock and estimates the Platform fee. Nothing is broadcast. Returns the operation with Core and Platform fees and the expected net credits.
  2. REGISTER_IDENTITY_FROM_CORE / TOP_UP_IDENTITY_FROM_CORE broadcast the saved asset lock, wait for its InstantLock/ChainLock proof, build and send the identity transition, and wait for Platform to confirm it.
  3. CANCEL_IDENTITY_FUNDING releases a quote that has not been broadcast. GET_IDENTITY_FUNDING_OPERATIONS / GET_IDENTITY_FUNDING_SOURCES list operations and the spendable Core balance.

Backend pieces

  • IdentityFundingRepository — per-wallet journal (identityFunding_<network>_<walletId>), guarded by Web Locks: a short journal lock for writes and a per-operation lock for a whole execution.
  • IdentityFundingService — domain primitives (UTXO loading via dashscan /xpub/utxo, parent tx verification, signing, fee estimate, broadcast, transition building); the handlers orchestrate them.
  • buildAssetLockFromUtxos — multi-input asset lock with change back to the BIP44 change chain (1 duff/byte, 546 dust).
  • Error handling (identityFundingErrors):
    • an unknown outcome (timeout, deadline elapsed, network) keeps the operation pending;
    • a Core tx the network refused releases the coins;
    • a Platform rejection of a transition on an asset lock that is already on L1 retries on the same lock with a ChainLock proof. The Core tx is never rebroadcast after it was accepted.
  • REGISTER_IDENTITY is refused while a registration funding operation is pending.
  • Migration 0010 (schema 10) only bumps the version; the journal lives under new keys.

Testing

  • tsc --noEmit, ts-standard (on dev.10)
  • jest: 361/362 on dev.10 (exportPrivateKey times out only in the full run and passes alone)
  • Live on testnet from the dev console: Core registration and top-up, 13/13 checks; the Core fee matched the quote exactly.

@LexxXell

LexxXell commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator Author

Superseded by #177. The funding journal chain is parked on the archive/identityFundingJournal branch.

@LexxXell LexxXell closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant