machineMemoPurpose property

String? machineMemoPurpose
final

FR-28 — when the payment carries an opaque MACHINE MEMO, the short human-readable purpose whoever attached it supplied. Null for the ordinary case (no machine memo).

The package already discloses this itself — on the form (which is where the OFFLINE QUEUE commits, without ever passing a review) and again on the review — per send and non-dismissible, so a host prompt that ignores it is not hiding anything. It is offered because a credential prompt IS the authorization moment for a per-spend-credential host, and a user asked to approve a spend should be able to see everything that spend attaches without leaving the prompt.

RENDER it, never log it (§5.4) — and render it as what it is: an attacker-controllable string. The wallet cannot check that it describes the bytes; a label is accountability, not verification.

Implementation

final String? machineMemoPurpose;