lockRecipient property
When true, the recipient field opens READ-ONLY (still selectable, so the
user can verify who they're paying) — for a host that resolved the payee
itself (pay-a-contact) and must not let the address be edited into a
different one. Recipient-ONLY: the amount and memo always stay editable
(the FR-25 contract). Default false — a fully editable prefill.
THE LOCK IS CONDITIONAL, not absolute (host contract):
- It is applied only when the recipient classifies SENDABLE against this
wallet's network at entry. An invalid / wrong-network / unclassifiable
address opens EDITABLE with the inline status explaining why — a
read-only field the user can never correct would be a dead-end. (A
fromUrirequest can't hit this — the parser already network-checked it — only a typed request with a bad address can.) - It is RELEASED if the wallet session flips while the form is open (the identity switch clears the whole draft; a still-locked empty field would be a dead-end). So a host MUST NOT treat the lock as a security guarantee that the typed address will be paid: the binding verification is the review screen's address echo and the host's own authorizer prompt (which receives the abbreviated recipient in its spend intent).
Implementation
final bool lockRecipient;