Skip to content

feat: register an identity from one of the wallet's own Platform addresses - #171

Closed
LexxXell wants to merge 3 commits into
developfrom
feat/identityFundingFromPlatform
Closed

LexxXell wants to merge 3 commits into
developfrom
feat/identityFundingFromPlatform

Conversation

@LexxXell

Copy link
Copy Markdown
Collaborator

Draft. Sits on #168: it reuses that PR's funding journal, service and execute flow, so until #168 is merged this diff contains its commits too and CI fails the same way (calculateMinRequiredFee needs #167). Both shrink to this PR's own three files' worth of changes once the queue moves.

Changes

The second funding source for an identity: one of the wallet's own Platform addresses, paid straight from its credit balance. REGISTER_IDENTITY_FROM_PLATFORM_ADDRESS confirms what PREPARE_IDENTITY_FUNDING quoted with source: 'platform'.

  • IdentityFundingService.platformCandidates lists the wallet's Platform addresses with their balances, derived from the cached account xpub — reading them needs no password.
  • IdentityFundingService.quotePlatform signs the identity create transition against the address the caller asked for, or the largest one covering the amount, and stores the signed bytes in the journal.
  • The execute flow gains a fork: the asset lock stage belongs to the Core source only. A Platform operation already holds a signed transition, so confirming it broadcasts that and waits for Platform to create the identity.
  • GET_IDENTITY_FUNDING_SOURCES now answers with both sources, each carrying its own error, so an unreachable explorer no longer hides the Platform addresses.

Why the bytes are stored instead of rebuilt

The source address's nonce is signed into the transition. A retry therefore sends exactly the stored bytes: re-signing with the same nonce is pointless once the first attempt was accepted, and re-signing with a fresh nonce would pay twice. For the same reason a pending Platform operation blocks SEND_PLATFORM_TRANSFER, WITHDRAW_PLATFORM_ADDRESS_TO_CORE and SHIELD_TO_POOL on that wallet — each of them would move the nonce and leave the quote unusable. Core spends and reads keep running alongside.

Top-up from a Platform address, and the shielded-pool source, follow in their own PRs. The legacy REGISTER_IDENTITY_FROM_ADDRESS / TOP_UP_IDENTITY_FROM_ADDRESS are untouched here and get removed separately, once the UI has moved over.

Backend only — no UI changes.

Testing

  • tsc --noEmit, ts-standard
  • test/api/private/identities/identityFunding.spec.ts — five new cases: a quote writes nowhere and a repeated prepare returns the same signed bytes; confirming broadcasts exactly those bytes and never touches Core or the proof wait; an address the wallet does not own is refused before anything is reserved; a pending operation holds the address nonce against other spends; both sources are listed with their balances and report failures separately.
  • test/content-script/fundingConflicts.spec.ts — Platform spends are blocked while a Platform operation is pending and run freely while only a Core one is.
  • jest: 44 suites; the only failures are the network-dependent specs that flake on develop too and pass on a re-run.

@LexxXell

LexxXell commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator Author

Superseded by #177. The funding journal chain is parked on the archive/identityFundingJournal branch.

@LexxXell LexxXell closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant