WalletSpendIntent class final

The display-facts of the spend being authorized — enough for the host's prompt copy, nothing more. §5.4 never-log values: render them in the prompt, never write them to a log.

Constructors

WalletSpendIntent({required WalletSpendKind kind, int? amountZat, WalletSpendOrigin origin = WalletSpendOrigin.userInitiated, String? recipientAbbrev, String? payoutAbbrev, bool recipientIsSelf = false, int? feeZat, Uint8List? bindingToken, String? machineMemoPurpose})
const

Properties

amountZat → int?
The figure the flow knows at authorization time, in zatoshis — null when nothing honest exists yet (sweep / reclaim discover their totals as they run). PER-KIND semantics (a prompt that renders "Authorize {amount}" must know which claim it makes):
final
bindingToken → Uint8List?
FR-17 (#396): the SDK-minted spend-binding nonce for the EXACT proposal/quote this authorization covers. A host with a native seed port records it at stage time, and its supplier fail-closes a native seed pull presenting anything else — the review↔sign confusion defense. Null for the operations that pull unbound (the shield-to-self sweep / reclaim) and for offline QUEUE-time authorization (the binding is minted at enqueue and surfaced on the parked-send row for a re-stage). NOT key material — but do not log it (it correlates a proposal with its sign moment; §5.4 like every field here).
final
feeZat → int?
The network fee in zatoshis, where the flow holds a proposal that knows it at authorization time; null when signing is deferred (queuedSend) or the fee is discovered later (sweep, reclaim, swap deposit).
final
hashCode → int
The hash code for this object.
no setterinherited
kind → WalletSpendKind
final
machineMemoPurpose → String?
FR-28 — when the payment carries an opaque MACHINE MEMO, the short human-readable purpose whoever attached it supplied. Null for the ordinary case (no machine memo).
final
origin → WalletSpendOrigin
Who initiated this spend — see WalletSpendOrigin. Host policy input; does not change any package-side money behavior.
final
payoutAbbrev → String?
WalletSpendKind.swapDeposit only: an ELIDED display form (via abbreviateWalletAddress) of the user's own FOREIGN payout address — where the provider sends the swapped asset. Unlike recipientAbbrev (the provider's deposit address, which the user has never seen), this is the address the user typed, pasted or scanned and verified in full on the review, so a prompt may show it for the user to match. Kept separate from recipientAbbrev on purpose: the deposit and the payout are different addresses on different chains. Null for every other kind. §5.4: RENDER it, never log it.
final
recipientAbbrev → String?
An ELIDED display form of the recipient (#383 R3 — via abbreviateWalletAddress), so a per-spend prompt can bind confirm→sign to WHAT is signed ("Authorize 1.2 ZEC total, incl. fee, to u1abcd…wxyz?" — phrase totals per the amountZat kind table, never "Send {total} to": the recipient receives total − fee). §5.4: RENDER it in the prompt, never log it — even elided, it correlates on-chain. Null when there is no meaningful external recipient string: the self-transfer kinds (see recipientIsSelf) and a drain-signed WalletSpendKind.queuedSend carry what the flow knows at authorization time, nothing invented.
final
recipientIsSelf → bool
True when the package POSITIVELY knows the funds return to THIS wallet (shield / unshield / sweep / reclaim, and an interactive send whose proposal detected an own-address recipient). False means "external or unknown" — never treat false as a verified-external claim. Lets a host prompt render "internal transfer, funds stay in your wallet" honestly.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited