features/wallet/started_spend library

The started-spend bookkeeping every money controller shares (R13 §4.2): whether the spend closure ever reached the SDK call, what that call returned, and whether the error that came back is the SDK's own. One copy, used by send's confirm and queue and by the shield and move confirms.

NOT exported: the controllers' own seam to the host's authorizer.

Classes

SpendAnswerLost<T>
The spend started and the answer was lost: the SDK threw a kind that may follow persistence, or something else threw or declined after the closure ran, or the authorizer returned without the SDK's result. error is null in that last case. The flow lands on its "outcome unknown" state.
SpendLanded<T>
The SDK call returned value. errorAfter is anything thrown after it landed (the host's code, a later read) — the landing still stands: "unknown" means only that the answer was lost, and here it was not.
SpendNotStarted<T>
The closure never reached the SDK call: nothing was signed or queued. error is what the authorizer threw (a decline, the identity fence, a refusal before entering), or null when it returned without running the closure.
SpendRefusedBeforePersist<T>
The SDK call itself threw error, and the flow's precedes-persistence predicate accepts it: the core's own answer, raised before anything was saved. The flow's classifier routes it as before.
StartedSpend<T>
What became of one spend, read from the SDK's own record — never from what the host's authorizer returned.

Functions

runStartedSpend<T>({required Future<T> authorize(SpendStart<T> start), required bool precedesPersistence(Object error), required String atMostOnceMessage, void onEntered()?}) → Future<StartedSpend<T>>
Run one spend through the host's authorizer and say what became of it.

Typedefs

SpendStart<T> = Future<T> Function(Future<T> sdkCall(), {void beforeEnter()?})
Hand the SDK call to runStartedSpend's bookkeeping, from INSIDE the spend closure the host's authorizer runs. Call it as the closure's last step, after the identity fence. beforeEnter runs after the at-most-once check and before the spend counts as started — a refusal thrown there is not a started spend.