Repository navigation
Conversation
This was referenced Sep 27, 2026
This was referenced Sep 27, 2026
Collaborator
Author
|
Superseded by #177. The funding journal chain is parked on the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
The second funding source for an identity: one of the wallet's own Platform addresses, paid straight from its credit balance.
REGISTER_IDENTITY_FROM_PLATFORM_ADDRESSconfirms whatPREPARE_IDENTITY_FUNDINGquoted withsource: 'platform'.IdentityFundingService.platformCandidateslists the wallet's Platform addresses with their balances, derived from the cached account xpub — reading them needs no password.IdentityFundingService.quotePlatformsigns the identity create transition against the address the caller asked for, or the largest one covering the amount, and stores the signed bytes in the journal.GET_IDENTITY_FUNDING_SOURCESnow answers with both sources, each carrying its own error, so an unreachable explorer no longer hides the Platform addresses.Why the bytes are stored instead of rebuilt
The source address's nonce is signed into the transition. A retry therefore sends exactly the stored bytes: re-signing with the same nonce is pointless once the first attempt was accepted, and re-signing with a fresh nonce would pay twice. For the same reason a pending Platform operation blocks
SEND_PLATFORM_TRANSFER,WITHDRAW_PLATFORM_ADDRESS_TO_COREandSHIELD_TO_POOLon that wallet — each of them would move the nonce and leave the quote unusable. Core spends and reads keep running alongside.Top-up from a Platform address, and the shielded-pool source, follow in their own PRs. The legacy
REGISTER_IDENTITY_FROM_ADDRESS/TOP_UP_IDENTITY_FROM_ADDRESSare untouched here and get removed separately, once the UI has moved over.Backend only — no UI changes.
Testing
tsc --noEmit,ts-standardtest/api/private/identities/identityFunding.spec.ts— five new cases: a quote writes nowhere and a repeated prepare returns the same signed bytes; confirming broadcasts exactly those bytes and never touches Core or the proof wait; an address the wallet does not own is refused before anything is reserved; a pending operation holds the address nonce against other spends; both sources are listed with their balances and report failures separately.test/content-script/fundingConflicts.spec.ts— Platform spends are blocked while a Platform operation is pending and run freely while only a Core one is.jest: 44 suites; the only failures are the network-dependent specs that flake ondeveloptoo and pass on a re-run.