authorizeParkedSend abstract method
AUTHORIZE a parked send NOW (FR-23-b / #361) — sign a send the user already
committed, at this user-present moment, instead of waiting for a background
pass to sign it. Pass BOTH the id AND the createdAt from the ParkedSend.
The package always calls this INSIDE the WalletSendAuthorizer.authorizeSpend
bracket, so a host that stages a per-spend credential has it staged when the
SDK pulls the seed. That is what makes an offline queue drainable at host
custody at all: a background drain has no live user, so it cannot sign — see
walletOfflineQueueSupportedProvider. A host with a BOUND native seed port
stages for THIS row's ParkedSend.binding (FR-17); a stage recorded for any
other row is refused and the send stays parked (funds safe).
ONE ROW PER CALL, ONE CALL PER BRACKET — the row's binding rides the seed pull, so one staged credential serves exactly one row; an "authorize all" affordance LOOPS brackets, it never wraps N rows in one.
Distinct from retryParkedSend, which re-arms a paused row's retry budget and
signs NOTHING. They compose: re-arm first, then authorize.
MONEY-SAFE: it moves only the TIMING of the signature — the payment was
committed when the user queued it. Read ParkedAuthorization's host contract
before writing copy: only signed may be phrased as "sending now", and
stillQueued is NOT a failure (phrasing it as one invites a re-entry, which is
a DOUBLE-PAY). Throws a typed WalletApiError — invalid-state on a closed
handle, watch-only on a structurally seedless wallet, and a seed-required /
seed-mismatch when the credential was not staged (or was staged for another row).
Implementation
Future<ParkedAuthorization> authorizeParkedSend({
required int id,
required int createdAt,
});