walletSessionProvider top-level property
The wallet session source — the money-safety gate's single home. A
deposit-capable WalletSession is exposed to the wallet surface ONLY when
onboarding is OnboardingActive, i.e. AFTER the recovery-phrase backup is
confirmed-and-persisted. Every other phase (loading / welcome / generating /
awaiting-backup / confirming / failed / unavailable — including a
provisioned-but-unconfirmed wallet resumed after a crash) yields null, and
the wallet surface renders its honest not-set-up state: never invite a
deposit into a wallet whose seed the user has not backed up.
The whole live-sync graph below hangs off this seam. In this build the
onboarding backend is unwired (walletProvisionerProvider/
onboardingStoreProvider default null → OnboardingUnavailable → null
here), so production still shows not-set-up; the on-device slice overrides
those providers and this derivation goes live with zero rework. Tests
override THIS provider directly with a fake session.
THE SESSION-ONLY HOST CONFIGURATION (a SUPPORTED integration, not just a
test trick): a host with its OWN provisioning/custody model (e.g. a
host-supplied seed staged Rust-side, recovery via the host's own master
secret) overrides THIS provider with a derivation from its own gate —
yielding an FrbWalletSession over its handle when its wallet is ready,
null otherwise — and leaves walletProvisionerProvider unwired. The
active surface then renders fully; the affordances that need the package
provisioner (rescan, the Security screen) hide themselves. RESPONSIBILITY
TRANSFER: overriding this provider REPLACES the backup-confirmed gate — the
host's own gate must guarantee the wallet's funds are recoverable (its own
backup semantics) BEFORE it exposes a session, because every deposit/send
surface lights up the moment this is non-null.
Implementation
final walletSessionProvider = Provider<WalletSession?>((ref) {
final state = ref.watch(onboardingControllerProvider);
return state is OnboardingActive ? state.session : null;
});