features/wallet/shield/shield_state
library
Classes
-
ShieldDone
-
Terminal result of the shield's
send — the reused SendOutcome (the shield
IS a send of the retained token, §3.3a Recv-3).
-
ShieldIdle
-
Initial / reset — nothing prepared yet.
-
ShieldNothingToShield
-
proposeShield returned null — the transparent balance is below the
shieldable minimum (the fee would outweigh the benefit). An honest no-op the
sheet explains, NEVER an error.
-
ShieldOutcomeUnknown
-
The shield's spend STARTED and its answer was lost (R13 §4.3):
send threw a
kind that can follow persistence (singleStepSendErrorPrecedesPersistence
does not accept it), or the host's code threw or declined after the spend
ran. The transaction may already be saved, so neither "shielded" nor
"couldn't shield" is true — the sheet points at Activity and offers Close
only. A Try again here would re-propose over a saved shield. Carries no
error: nothing renders a throw's text.
-
ShieldPreparing
-
proposeShield in flight — deterministic + local (note-selection/fee), no
network. Transient; a spinner.
-
ShieldReady
-
The confirm sheet: the EXACT numbers — gross transparent (
proposal.totalZat),
fee (proposal.feeZat), net that lands shielded (proposal.changeZat) — then
ShieldController.confirm signs + broadcasts. Holds the display proposal
(its opaque token is consumed by id on confirm).
-
ShieldState
-
The shield flow's states (Recv-3), a sealed family the sheet renders with an
exhaustive
switch. The flow is: open → (proposeShield) → ready | nothing,
then ready → (send) → done. Rendering layer ONLY — every transition runs
through ShieldController; no money state is stored here (design invariant 1).
-
ShieldSubmitting
-
send (sign + broadcast the shield tx) in flight. Transient; a spinner. Holds
the proposal so the sheet can keep showing the figures.
-
ShieldUnavailable
-
A recoverable prepare/confirm fault that did NOT move money: the wallet isn't
synced far enough to anchor the shield (
notSyncedYet), is mid-lifecycle
(walletBusy), has no live session (walletUnavailable), or the shield could
not be prepared/signed for a reason with no finer mapping (couldNotPrepare).
The sheet offers "try again" (re-prepare) or honest copy — never a code (§6).
Enums
-
ShieldFaultReason
-
The payload-free shield-fault categories (the honest message axis; no codes).
Functions
-
classifyShieldPrepareFailure(Object error)
→ ShieldState
-
Map a
proposeShield failure to a ShieldState. Reads the typed
WalletApiError.kind ONLY (never a payload — §5.4); a non-FRB error is the
generic ShieldFaultReason.couldNotPrepare. Pure + total, unit-tested at its
boundary without a device.
-
classifyShieldSendFailure(Object error)
→ ShieldState
-
Map a shield
send (sign+broadcast) failure to the next ShieldState. A
consumed token is the honest "already submitted" (the notes are never
broadcast twice, §6.3); a stale anchor routes to re-prepare; everything else
is a no-money-moved sign failure. Reads kind only (§5.4) — mirrors the send
flow's classifySendFailure, projected onto the shield states.