walletInFlightSendsReadProvider top-level property
The IN-FLIGHT two-step (TEX) sends (#309) — first leg broadcast, send not yet complete;
money in motion through a wallet-controlled one-time address. Drives the DURABLE
wallet-screen "on its way — don't send it again" cue that survives the dismissible
post-send result screen across the double-pay temptation window. Invalidated on the
SAME edges as walletParkedSendsProvider (the _WalletActive sync listener + resume)
so the cue appears after an interactive partial / a queued drain and CLEARS when the
chain completes, strands (→ the recoverable surface), or requeues the send (every tx
expired unmined → back to the parked surface). Returns EMPTY when no session exists. Additive
CAUTIONARY info like the recoverable subset (the same tx0 is independently visible as
a pending tx in the activity list, so a read failure hides no money — unlike parked,
where the surface is the ONLY witness). The render does NOT self-hide on a failure
(#308a, S2 §3.5d): it says it could not check and is retrying, because a vanished cue
reads as "nothing is mid-flight". The container default retry stays a DELIBERATE
KEEP: the retrying state carries hasError, so the line stands through
the retries and a transient blip heals on its own. Readers that only want the
rows (.value ?? [], the rescan sheet's advisory) stay advisory — the core's
fence refuses a rescan with money in motion. AMOUNT-only (§5.4 — the one-time
address never crosses the bridge).
The identity-scoped READER behind walletInFlightSendsProvider —
invalidate THIS; watch the view.
Implementation
final walletInFlightSendsReadProvider = FutureProvider.autoDispose
.family<List<InFlightSend>, Object?>((ref, identity) {
// Dying-element guard — see walletSnapshotReadProvider.
final superseded = ref.watch(walletIdentityProvider) != identity;
final session = ref.watch(walletSessionProvider);
if (superseded || session == null) {
return Future<List<InFlightSend>>.value(const <InFlightSend>[]);
}
return session.listInFlightSends();
});