WalletLocalizations class abstract
Callers can lookup localized strings with an instance of WalletLocalizations
returned by WalletLocalizations.of(context).
Applications need to include WalletLocalizations.delegate() in their app's
localizationDelegates list, and the locales they support in the app's
supportedLocales list. For example:
import 'l10n/wallet_localizations.dart';
return MaterialApp(
localizationsDelegates: WalletLocalizations.localizationsDelegates,
supportedLocales: WalletLocalizations.supportedLocales,
home: MyApplicationHome(),
);
Update pubspec.yaml
Please make sure to update your pubspec.yaml to include the following packages:
dependencies:
# Internationalization support.
flutter_localizations:
sdk: flutter
intl: any # Use the pinned version from flutter_localizations
# Rest of dependencies
iOS Applications
iOS applications define key application metadata, including supported locales, in an Info.plist file that is built into the application bundle. To configure the locales supported by your app, you’ll need to edit this file.
First, open your project’s ios/Runner.xcworkspace Xcode workspace file. Then, in the Project Navigator, open the Info.plist file under the Runner project’s Runner folder.
Next, select the Information Property List item, select Add Item from the Editor menu, then select Localizations from the pop-up menu.
Select and expand the newly-created Localizations item then, for each locale your application supports, add a new item and select the locale you wish to add from the pop-up menu in the Value field. This list should be consistent with the languages listed in the WalletLocalizations.supportedLocales property.
- Implementers
- WalletLocalizationsAr
- WalletLocalizationsDe
- WalletLocalizationsEn
- WalletLocalizationsEs
- WalletLocalizationsFi
- WalletLocalizationsFr
- WalletLocalizationsHe
- WalletLocalizationsIt
- WalletLocalizationsJa
- WalletLocalizationsNb
- WalletLocalizationsNl
- WalletLocalizationsPl
- WalletLocalizationsPt
- WalletLocalizationsRu
- WalletLocalizationsUk
- WalletLocalizationsZh
Constructors
- WalletLocalizations(String locale)
Properties
- hashCode → int
-
The hash code for this object.
no setterinherited
- localeName → String
-
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- securityCustodyBestEffort → String
-
Security screen: the honest erase line for a tier whose key is not held by secure hardware (ADR-0571).
no setter
- securityCustodyHardwareKey → String
-
Security screen: the honest erase line for a hardware-held key tier (no permanence claim, ADR-0571).
no setter
- securityCustodyProbeError → String
-
Security screen: shown when the custody-tier probe fails (e.g. a locked device).
no setter
- securityCustodySectionTitle → String
-
Security screen: section header for where the wallet keys are protected.
no setter
- securityCustodyTierKeychain → String
-
Security screen: custody tier name for the raw Apple keychain fallback.
no setter
- securityCustodyTierNone → String
-
Security screen: custody tier name when the platform has no key vault (desktop).
no setter
- securityCustodyTierSecureEnclave → String
-
Security screen: custody tier name for Apple Secure Enclave.
no setter
- securityCustodyTierSoftware → String
-
Security screen: custody tier name for a software-rooted keystore.
no setter
- securityCustodyTierStrongBox → String
-
Security screen: custody tier name for Android StrongBox.
no setter
- securityCustodyTierTee → String
-
Security screen: custody tier name for an Android TEE-backed keystore.
no setter
- securityCustodyTierUnknown → String
-
Security screen: custody tier name for an unrecognised (newer-core) tier.
no setter
- securityDeleteDialogBody → String
-
Delete-wallet confirmation dialog: body warning.
no setter
- securityDeleteDialogBodyWatchOnly → String
-
Delete-wallet confirmation dialog body for a WATCH-ONLY wallet (#397 §3.7 D5): no recovery phrase, so the copy must not warn about backing one up — it re-imports from its viewing key.
no setter
- securityDeleteDialogCancel → String
-
Delete-wallet confirmation dialog: the cancel action.
no setter
- securityDeleteDialogConfirm → String
-
Delete-wallet confirmation dialog: the destructive confirm action.
no setter
- securityDeleteDialogTitle → String
-
Delete-wallet confirmation dialog: title.
no setter
- securityDeleteFailedSnack → String
-
Security screen: snackbar shown when a delete fault recovered the wallet (no data lost).
no setter
- securityDeleteWalletButton → String
-
Security screen: the destructive button that opens the delete confirmation.
no setter
- securityDeleteWalletSubtitle → String
-
Security screen: subtitle under the delete-wallet button.
no setter
- securityDeleteWalletSubtitleWatchOnly → String
-
Security screen delete subtitle for a WATCH-ONLY wallet (#397 §3.7 D5): it has no recovery phrase, so the copy must not claim 'restorable from your recovery phrase' — it re-imports from its viewing key instead.
no setter
- securityTitle → String
-
Security screen: app bar title.
no setter
-
Security screen: honest body when the host app owns wallet custody (no package provisioner is wired), so the package's custody probe and delete-wallet actions are not available here.
no setter
- walletActivityCatchingUp → String
-
Short activity-section cue shown in place of the empty card on the durable catch-up arm (#380) — the wallet is provably still filling in but the rescan choice is unknown (post-relaunch / post-dismiss / a restore's first sync). HEDGED (review): a fresh create's first sync shares this cue, so it must not assert a history that doesn't exist — 'anything you've received will show up here' is true on the rebuilt, restored, AND empty-new arms.
no setter
- walletActivityEmpty → String
-
Empty-state line when the wallet has no transaction history.
no setter
- walletActivityError → String
-
Honest error line when the transaction-history read fails or times out.
no setter
- walletActivityExpired → String
-
Status of an unmined transaction past its expiry — funds returned to spendable.
no setter
- walletActivityFailed → String
-
Status of a transaction the endpoint rejected.
no setter
- walletActivityLoadMore → String
-
Button at the bottom of the activity list that fetches the next keyset page.
no setter
- walletActivityPending → String
-
Status of a broadcast-but-unmined history row.
no setter
- walletActivityPublicBadge → String
-
Screen-reader words for the activity row’s transparency badge (the visual is a small globe icon), and the value of the tx-detail Visibility row. Direction-neutral: covers sent AND received transparent legs.
no setter
- walletActivityQueued → String
-
Status of a send saved offline, waiting to broadcast.
no setter
- walletActivityRebuilding → String
-
Short activity-section cue shown in place of the empty card while a rescan repopulates.
no setter
- walletActivityReceived → String
-
Title of an incoming (positive net amount) history row.
no setter
- walletActivityRetrying → String
-
Status of a wallet-created, unmined history row the wallet still OWES a broadcast (TxSummary.delivery == retryPending, stage S8 obligation): no endpoint has accepted it yet; the same signed bytes go out again on the next sync pass and after a relaunch. Replaces 'Pending' for that row in the activity list and the detail sheet.
no setter
- walletActivityRowHint → String
-
Screen-reader tap hint on a history row (the row opens the transaction-detail sheet).
no setter
- walletActivitySaved → String
-
Status of a wallet-created, unmined history row whose signed bytes are kept but which the wallet is NOT broadcasting on its own right now (TxSummary.delivery == persisted — a swap deposit held past its quote's window). No promise of automatic sending.
no setter
- walletActivitySent → String
-
Title of an outgoing (negative net amount) history row.
no setter
- walletActivitySyncNotRunning → String
-
Activity-section note replacing 'No activity yet' when history exists but cannot repopulate because no sync pass will run (UX HIGH; #405 widened it from the host policy to the SSOT so a FAILED start is covered too). States the pending fill and its condition; CAUSE-AGNOSTIC — the badge above it names why sync isn't running.
no setter
- walletActivityTitle → String
-
Heading above the transaction-history list on the wallet screen.
no setter
- walletAppearanceMenuItem → String
-
Wallet overflow-menu item that opens the host app's own settings page (the route the host wires; the example puts its theme, Tor and device-log choices there).
no setter
- walletArrivingLabel → String
-
New incoming money that is not yet confirmed. Used in two places: the synced balance card's foot, shown OUTSIDE the balance with a '+' before the amount (maintainer: 'show the actual amount that we have now and pending is a separate part'), and the status of an incoming activity row that is not yet mined. Never for money the user already has.
no setter
- walletAutoShieldIncomplete → String
-
Balance-card cue under the transparent line when the auto-shield loop failed or was denied; the manual Shield button sits right below it.
no setter
- walletAutoShieldToggleLabel → String
-
The auto-shield switch label (default ON; only changeable behind the expert gate).
no setter
- walletBackupBody → String
-
Explanation on the backup screen of what the recovery phrase is and the rules for handling it.
no setter
- walletBackupConfirmCheckbox → String
-
Deliberate confirmation the user toggles before the wallet can become deposit-ready (the money-safety gate).
no setter
- walletBackupContinue → String
-
Action that confirms the backup and opens the wallet for deposits; enabled only once the confirmation box is checked.
no setter
- walletBackupDone → String
-
Action that closes the recovery-phrase backup screen after the words have been viewed (view-only; nothing is saved).
no setter
- walletBackupManagedBody → String
-
Explanation shown when the wallet has no local recovery phrase (a host-managed / raw seed); tells the user their recovery lives with the installing app's account.
no setter
- walletBackupManagedTitle → String
-
Heading of the managed-by-host state, shown when the wallet was set up from a host-supplied seed and has no recovery phrase of its own.
no setter
- walletBackupReauthFailed → String
-
Honest error when the host re-authentication step failed (e.g. a wrong passphrase) before the recovery words were shown; distinct from a device-locked read failure, so it does not tell the user to unlock their device.
no setter
- walletBackupRetryReveal → String
-
Retry action after a failed recovery-phrase reveal.
no setter
- walletBackupReveal → String
-
Deliberate-action button to reveal the recovery words (shoulder-surfing mitigation: words are hidden until tapped).
no setter
- walletBackupRevealFailed → String
-
Honest, plain-language error when the recovery words can't be read (e.g. device locked); no error code.
no setter
- walletBackupRevealing → String
-
Busy label while the recovery words are read from the wallet.
no setter
- walletBackupSaveFailed → String
-
Honest error when persisting the backup confirmation fails; the wallet stays not-yet-ready (the gate stays closed).
no setter
- walletBackupScreenTitle → String
-
App-bar title of the post-onboarding recovery-phrase backup screen.
no setter
- walletBackupSectionTitle → String
-
Section header on the Security settings screen for the recovery-phrase backup entry.
no setter
- walletBackupSecureNoteAndroid → String
-
Security note on Android, where the screen is marked secure (no screenshots).
no setter
- walletBackupSecureNoteOther → String
-
Security note on platforms with no screenshot-block; advises a private setting.
no setter
- walletBackupStartOver → String
-
Understated escape action on the forced-backup screen (#356-F2): deletes the not-yet-backed-up wallet (after a confirm dialog) and returns to the create/restore start, so a user who mis-tapped Create is never cornered into falsely confirming a backup.
no setter
- walletBackupStartOverConfirm → String
-
Destructive confirm action of the Start-over dialog (rendered in the destructive color).
no setter
- walletBackupStartOverConfirmBody → String
-
Body of the Start-over confirmation dialog. Must stay honest for EVERY way of reaching forced backup: a fresh create (nothing deposited via this app), the rare restore stranded here by a confirm-persist failure, AND the residual lost-flag edge on a wallet that was briefly active (review) — hence the hedged 'if this wallet ever held funds' phrase-warning instead of an absolute 'never received anything' claim.
no setter
- walletBackupStartOverConfirmTitle → String
-
Title of the Start-over confirmation dialog on the forced-backup screen.
no setter
- walletBackupStartOverKeep → String
-
Safe cancel action of the Start-over dialog — says what it keeps rather than a bare 'Cancel', so a mis-tap defaults to no loss.
no setter
- walletBackupTileSubtitle → String
-
Subtitle of the settings tile that opens the recovery-phrase backup screen.
no setter
- walletBackupTileTitle → String
-
Title of the settings tile that opens the post-onboarding recovery-phrase backup screen.
no setter
- walletBackupTitle → String
-
Heading on the recovery-phrase backup screen.
no setter
- walletBalanceHiddenAmount → String
-
What a screen reader says in place of an amount the user has hidden with the eye button (the screen shows dots).
no setter
- walletBalanceLabel → String
-
Label above the total wallet balance.
no setter
- walletBalanceStale → String
-
Honest staleness cue shown when the last-known balance is rendered through a failed refresh.
no setter
- walletCatchUpBanner → String
-
Top-of-wallet reassurance banner on the durable catch-up arm (#380): the wallet has never completed a sync pass and is below the chain tip — a relaunch mid-rescan catch-up, a dismissed rescan notice over a rebuilt wallet, or a restore/create's first sync. Generic: unlike the walletRescanRebuilding* family it cannot name what the user chose (the choice does not survive a relaunch). HEDGED funds claim (review, the #356-F7 precedent): a fresh create's first sync — possibly offline, so unbounded — shares this cue, and 'your funds are safe' would assert funds that provably don't exist; 'anything you've received' is conditionally true on every arm.
no setter
- walletCatchUpRescanBanner → String
-
Top-of-wallet reassurance banner on the durable rescan arm (#377 s357b-2): the core's rescan-rebuilding breadcrumb says a rescan rebuild is still catching up, but the in-session choice (which range) did not survive the relaunch — so the copy names the RESCAN (the user's own deliberate action, the stronger 'did I lose funds?' reassurance) without naming the range the walletRescanRebuilding* family can. Same HEDGED funds claim as walletCatchUpBanner ('anything you've received' — a zero-balance wallet rescans too).
no setter
- walletCheckOneTimeMenuItem → String
-
Wallet app-bar overflow-menu item that runs the manual one-time (ephemeral) address check/recovery — always available, covering returns the automatic windowed detect can no longer see (an old return past the detect window, or a re-used one-time address).
no setter
- walletCountdownUnderMinute → String
-
Screen-reader-only countdown magnitude used in the {time} slot of the quote/deposit countdown sentences once under 60 seconds (#364 F9): a per-second live-region announcement was a 1 Hz storm, so the accessible label goes coarse while the visual text keeps ticking.
no setter
- walletCreateButton → String
-
Primary action on the welcome screen: start creating a brand-new wallet.
no setter
- walletDeepScanBannerChecking → String
-
#390 C1 — a dismissible banner on the wallet home while a deep scan the user ran is still surfacing money (pending > 0). Sync-NEUTRAL wording (‘as it’s found’, not ‘as your wallet syncs’) so it stays honest while offline; survives closing the sheet.
no setter
- walletDeepScanBody → String
-
#390 deep-scan sheet explanation. Honest: it CHECKS (does not itself find); results appear via the normal balance as sync proceeds.
no setter
- walletDeepScanCheckButton → String
-
#390 sheet primary action — start (or continue) the deep scan.
no setter
- walletDeepScanCheckDeeperButton → String
-
#390 sheet primary action once a range is already fully checked (covered > 0 and nothing pending) — each run goes deeper.
no setter
- walletDeepScanChecking → String
-
#390 in-flight label — on the sheet button while a scan runs, and on the disabled overflow-menu entry (says why it is disabled).
no setter
- walletDeepScanClose → String
-
#390 sheet dismiss button (the scan continues in the background once started).
no setter
- walletDeepScanCoverage → String
-
#390 sheet coverage line when a range is fully checked (covered > 0, pending == 0). NO count — the address index is not a swap tally, so any number would be false (B2). Offers going deeper.
no setter
- walletDeepScanCoveragePending → String
-
#390 sheet coverage line while the current range is still registering + polling (pending > 0). Sync-NEUTRAL — no ‘while your wallet syncs’ claim, which is false when offline/stalled (B3).
no setter
- walletDeepScanCoverageUnknown → String
-
#390 sheet coverage line fallback while the read is loading or unavailable (never a scary error over a recovery sheet).
no setter
- walletDeepScanFailed → String
-
#390 snackbar when the scan could not start (a transient fault). Reassures nothing changed.
no setter
- walletDeepScanMenuItem → String
-
#390 overflow-menu entry (adjacent to Rescan) opening the deep-scan sheet. CHECK verb, never ‘recover’ — the scan can’t know funds exist. ‘addresses’ not ‘refunds’ — it recovers swap deliveries too.
no setter
- walletDeepScanRan → String
-
#390 inline confirmation after an accepted scan. Honest: it does NOT claim ‘found X’ — money surfaces via the normal balance. Sync-NEUTRAL (no ‘as your wallet syncs’, false when offline; B3).
no setter
- walletDeepScanRefusedDisabled → String
-
#390 snackbar for the swapDisabled refusal (a host kill switch stopped the polling the check depends on).
no setter
- walletDeepScanRefusedOutstanding → String
-
#390 inline message for the checkOutstanding refusal (a prior check is still registering/polling — at most one per ~48h settlement window). B4: names the real horizon (‘up to a couple of days’) instead of ‘a little while’.
no setter
- walletDeepScanRescanBusy → String
-
#390 sheet note while a rescan is running/rebuilding — the deep scan and a rescan both re-poll the transparent set, so they are mutually exclusive.
no setter
- walletDeepScanRestoreNoteBody → String
-
#390 one-time post-restore note body — educates that the situation can happen and how to resolve it, without alarming (‘most wallets need nothing’).
no setter
- walletDeepScanRestoreNoteCheck → String
-
#390 post-restore note action — open the deep-scan sheet.
no setter
- walletDeepScanRestoreNoteDismiss → String
-
#390 post-restore note dismiss action (the note never shows again once displayed).
no setter
- walletDeepScanRestoreNoteTitle → String
-
#390 one-time post-restore note title, shown once after the first restore’s catch-up finishes.
no setter
- walletDeepScanSlow → String
-
#390 rel-H1 inline message when the check exceeds the FFI wedge timeout. The widen MAY have committed (a durable local write), so this must NOT claim 'nothing changed' — it's neutral and says money appears in the balance if it did.
no setter
- walletDeepScanTitle → String
-
#390 deep-scan sheet title.
no setter
- walletDeepScanTorHint → String
-
#390 sheet privacy hint shown when Tor was requested but fell back to clearnet (or is unavailable) — the scan is elective, so recommend deferral. Never blocks the action.
no setter
- walletDeepScanTorUnknownHint → String
-
#390 B5 — softer privacy nudge shown when the connection/transport state hasn’t loaded yet (Tor status unknown), so the privacy hint is never silently dropped. Distinct from walletDeepScanTorHint (a CONFIRMED Tor fallback).
no setter
- walletExpertToggleDescription → String
-
Subtitle under the expert-gate switch. Plain-factual.
no setter
- walletExpertToggleDescriptionNoAutoShield → String
-
The expert-gate description when the HOST declared auto-shield unsupported (#383 R2): walletExpertToggleDescription with ONLY the 'turning automatic shielding off' clause removed — that switch never renders there, so advertising it would promise a control that doesn't appear. Keep the shared clause identical to the sibling key so the two never drift.
no setter
- walletExpertToggleLabel → String
-
The expert-gate switch label (default OFF). Turning it on reveals the auto-shield switch and the move-to-transparent entry in the sheet.
no setter
- walletExportViewingKeyCopied → String
-
Confirmation shown after the viewing key is copied to the clipboard.
no setter
- walletExportViewingKeyCopy → String
-
Button that copies the exported viewing key to the clipboard.
no setter
- walletExportViewingKeyDone → String
-
Action that closes the export-viewing-key screen.
no setter
- walletExportViewingKeyFailed → String
-
Honest error line shown when reading the viewing key for export failed transiently.
no setter
- walletExportViewingKeyQrLabel → String
-
Accessibility label for the QR tile encoding the exported viewing key.
no setter
- walletExportViewingKeyRetry → String
-
Retry action after a failed re-auth or a failed viewing-key read on the export screen.
no setter
- walletExportViewingKeyReveal → String
-
Button that triggers re-authentication and then reveals the viewing key on the export screen.
no setter
- walletExportViewingKeyRevealing → String
-
Loading line shown while the viewing key is being read for export.
no setter
- walletExportViewingKeySecureNoteAndroid → String
-
Note shown on the export-viewing-key screen when screenshot blocking is active.
no setter
- walletExportViewingKeySecureNoteOther → String
-
Note shown on the export-viewing-key screen when screenshot blocking is not available (non-Android).
no setter
- walletExportViewingKeyTileSubtitle → String
-
Subtitle of the export-viewing-key settings tile, summarizing that the exported key is view-only.
no setter
- walletExportViewingKeyTileTitle → String
-
Settings → Security list-tile that opens the viewing-key export screen.
no setter
- walletExportViewingKeyTitle → String
-
App-bar title of the UFVK export screen (#397): the sanctioned surface that reveals the wallet's unified full viewing key for a watch-only or accounting use.
no setter
- walletExportViewingKeyWarning → String
-
The #397 D9 warning copy shown on the export-viewing-key screen. Must state all four facts: (1) it reveals all history in and out, past and future; (2) it cannot spend or recover; (3) share only with someone trusted; (4) the only un-share is moving funds to a new wallet. No softening.
no setter
- walletExportViewingKeyWarningWatchOnly → String
-
The #397 D9 warning for a WATCH-ONLY wallet exporting its own viewing key (UX-M3): identical to walletExportViewingKeyWarning but its final clause states the honest 'once shared it cannot be un-shared', since a watch-only wallet cannot 'move your funds to a new wallet' (no spending keys). Keep the same four facts, no softening.
no setter
- walletGeneratingLabel → String
-
Busy label while the wallet seed is generated and sealed (a local step, no network).
no setter
- walletHideBalance → String
-
Screen-reader label and tooltip of the eye button in the wallet header while amounts are SHOWN: pressing it replaces every amount with dots (FR-49 W-7; maintainer FD-6).
no setter
- walletInFlightReadError → String
-
#308a (S2 §3.5d): shown in place of the in-flight cue (walletInFlightNote) when the in-flight-sends read FAILS, instead of the cue silently vanishing — a vanished cue reads exactly like 'nothing is mid-flight'. The read retries on its own and on every sync/resume edge, so 'Retrying' is true. It must not claim anything IS in flight (we don't know), and must keep the don't-double-pay caution by pointing at the activity list, where the payment's first leg shows as a pending transaction.
no setter
- walletLoadingLabel → String
-
Screen-reader name of a spinner that stands alone, with no label beside it (the wallet's first load, the activity list's first load, the swap token list). S13 §2, maintainer.
no setter
- walletMenuSyncNotRunningHint → String
-
Sub-label under the disabled Rescan / Check-older-swap-addresses menu entries: no sync pass will run, so neither op can ever finish (#405 — widened from the host policy alone to the SSOT walletSyncPassesRunProvider, which also covers a FAILED sync start). CAUSE-AGNOSTIC ON PURPOSE: 'turn syncing on in settings' is the right instruction for a host-off policy and the WRONG one for a failed start, so this states the CONDITION only; the sync badge and the start-failed notice on the same screen own the cause and its remedy. Needed because the explaining badge is occluded behind the open menu and a screen reader would otherwise hear only 'dimmed'.
no setter
- walletMenuTooltip → String
-
Tooltip / screen-reader label for the wallet app-bar overflow menu.
no setter
- walletMoveAlreadyBody → String
-
Body for an already-submitted move (precise: the prior submission moved the funds; never sent twice).
no setter
- walletMoveAlreadyTitle → String
-
The one-shot proposal was already consumed (a double-tap); the funds are never sent twice.
no setter
- walletMoveAutoShieldNote → String
-
Orange note on the move-to-transparent confirm when auto-shield is ON — without it the loop silently reverts the deliberate unshield and burns a second fee.
no setter
- walletMoveBackButton → String
-
Return from the review screen to the amount-entry form.
no setter
- walletMoveCancel → String
-
Dismiss the move-to-transparent sheet from the amount-entry phase.
no setter
- walletMoveClose → String
-
Close the move-to-transparent sheet from a terminal state.
no setter
- walletMoveConfirmButton → String
-
Confirm button that signs + broadcasts the de-shield transaction.
no setter
- walletMoveCouldNotLoad → String
-
The own-address fetch failed or timed out; retryable.
no setter
- walletMoveDeshieldBody → String
-
The §5.1 de-shield warning body, move-specific: the funds + the user's own t-address go public on-chain (no third-party 'recipient' framing).
no setter
- walletMoveDeshieldTitle → String
-
The §5.1 de-shield warning title, move-specific (a self-transfer, not a payment to a third party).
no setter
- walletMoveDestinationLabel → String
-
Label for the read-only destination — the wallet's own transparent address.
no setter
- walletMoveDoneBody → String
-
Body for a successful de-shield broadcast.
no setter
- walletMoveDoneTitle → String
-
Terminal success: the de-shield tx was broadcast.
no setter
- walletMoveFailedTitle → String
-
Terminal failure: nothing was sent; the user can try again.
no setter
- walletMoveLoading → String
-
Transient state while the wallet's own transparent address is loaded.
no setter
- walletMoveMenuItem → String
-
Overflow-menu entry for the Send expert layer's de-shield action (the mirror of Shield).
no setter
- walletMoveNothingBody → String
-
Honest explanation that there is no spendable shielded balance to de-shield.
no setter
- walletMoveNothingCatchingUpBody → String
-
Variant of walletMoveNothingBody while the wallet is still catching up (#381, hardware-proven): the missing shielded balance is UNSCANNED, not unconfirmed, so the default body's 'Once funds confirm' would misattribute the cause. Hedged ('anything you've received') — it must not assert funds exist (#356-F7 precedent).
no setter
- walletMoveNothingTitle → String
-
Shown when there is no shielded balance available to de-shield.
no setter
- walletMoveOwnAddressNote → String
-
Honest, move-specific note: it's the user's own t-addr; the funds can be re-shielded, but the on-chain history of this move is permanent (no self-contradiction).
no setter
- walletMoveOwnAddressNoteStaysPublic → String
-
Variant of walletMoveOwnAddressNote shown when the move leaves the public balance under the shield floor (stage S14): it drops 'You can shield these funds again later', which would be false there.
no setter
- walletMovePreparing → String
-
Transient state while the de-shield proposal is computed (local, no network).
no setter
- walletMoveRetry → String
-
Re-run the move after a recoverable failure.
no setter
- walletMoveReviewButton → String
-
Button that proposes the de-shield and advances to the review screen.
no setter
- walletMoveReviewTitle → String
-
Title of the de-shield confirmation/review screen.
no setter
- walletMoveSavedBody → String
-
Body for a de-shield that was persisted but not yet broadcast. Same #401 R1b posture as walletSendSavedBody: already signed ⇒ the promise holds at every custody tier; pass-dependent ⇒ the render site appends walletSyncPausedMoneyNote when no sync pass will run.
no setter
- walletMoveSavedTitle → String
-
The de-shield tx is persisted but not yet broadcast; it re-sends on a later sync (money-safe). NOT 'when you're online' — the #399 reconnect-promptness rule, folded in by #401 R1b. Mirrors walletSendSavedTitle.
no setter
- walletMoveSheetSubtitle → String
-
Explains what move-to-transparent is for (exchange deposits that reject shielded sources).
no setter
- walletMoveSheetTitle → String
-
Title of the move-to-transparent (de-shield to own address) sheet.
no setter
- walletMoveSubmitting → String
-
Transient state while the de-shield tx is signed and broadcast.
no setter
- walletMoveUnknownBody → String
-
Body for walletMoveUnknownTitle. Must never say whether funds moved. Points at Activity, where the move's real state is shown.
no setter
- walletMoveUnknownTitle → String
-
Title of the move-to-transparent sheet's terminal when the move ran but its answer was lost (MoveOutcomeUnknown): the transaction may already be saved. Neither 'moved' nor 'nothing happened' is true. Body: walletMoveUnknownBody. Only Close is offered, never a retry.
no setter
- walletMoveWalletEnded → String
-
Body for the defensive walletUnavailable terminal — the session dropped mid-sheet (rare).
no setter
- walletNotSetUpBody → String
-
Honest-degradation body for the not-set-up wallet state; states the money-safety reason setup is gated. Only for builds that genuinely ship without the wallet — a failed boot wiring renders walletStartupFailed* instead (#356-F1).
no setter
- walletNotSetUpTitle → String
-
Heading shown when no wallet is provisioned in this build.
no setter
- walletNotSpendableYetLabel → String
-
Balance card breakdown row while the wallet is NOT synced: money the user already has, inside the balance, that cannot be spent until the sync finishes (the wallet cannot yet build what spending it needs). Not new or incoming money — never translate as 'arriving' or 'incoming'.
no setter
- walletOnboardingFailedAlreadyOpen → String
-
Onboarding failure: the wallet's single-instance lock is held (retryable). Honest for BOTH causes — a real second window AND a transient internal straggler finishing up (the device-proven case, where no other window exists).
no setter
- walletOnboardingFailedConfiguration → String
-
Onboarding failure: the host app supplied an invalid wallet configuration (e.g. a rejected data directory). A developer error, not a device/user condition — NON-retryable, and deliberately without an action button (a Retry here would loop the same failure; security review N1).
no setter
- walletOnboardingFailedDeviceLocked → String
-
Onboarding failure: device locked, or the key store did not answer within the SDK's bound (retryable; a wedge clears only on restart).
no setter
- walletOnboardingFailedInterruptedSetup → String
-
Onboarding failure: an interrupted create (remnant); retrying re-probes and resumes the repair via create (open cannot repair it). Retryable, reassuring (the sealed seed is intact).
no setter
- walletOnboardingFailedNeedsRecovery → String
-
Onboarding failure: damaged seal / destroyed key / corrupt storage — restore is the path, not retry. Funds are recoverable from the phrase.
no setter
- walletOnboardingFailedNetwork → String
-
Onboarding failure: a network condition during setup (retryable).
no setter
- walletOnboardingFailedNoVault → String
-
Onboarding failure: no device key vault at all (fail-closed; permanent for this device).
no setter
- walletOnboardingFailedRestoreAction → String
-
Primary action on the needsRecovery failure screen: clears the unreadable wallet and routes to the restore flow (#251 escape hatch).
no setter
- walletOnboardingFailedStorageFull → String
-
Onboarding failure: out of disk space (retryable).
no setter
- walletOnboardingFailedTitle → String
-
Heading on the onboarding failure screen.
no setter
- walletOnboardingFailedUnknown → String
-
Onboarding failure: anything else / a forward-compat kind (retryable; the stable code rides logs).
no setter
- walletOnboardingRecoverConfirmBody → String
-
Body of the confirm dialog: WARN the user they must have their recovery phrase in hand, then reassure funds are safe (phrase-controlled), before the irreversible force-clear.
no setter
- walletOnboardingRecoverConfirmCancel → String
-
Cancel action in the restore-confirm dialog.
no setter
- walletOnboardingRecoverConfirmTitle → String
-
Title of the confirm dialog before the deliberate force-clear + restore.
no setter
- walletOnboardingRetry → String
-
Retry action shown for recoverable onboarding failures.
no setter
- walletOnboardingWelcomeBody → String
-
Body on the wallet onboarding welcome screen; states the money-safety reason backup comes first.
no setter
- walletOnboardingWelcomeTitle → String
-
Heading on the wallet onboarding welcome screen.
no setter
- walletOpeningLabel → String
-
Busy label for the boot probe / open phase — usually brief, but the open lawfully waits out a transiently-held wallet lock for up to ~27.5s, so the wait must be labeled, not a mute spinner.
no setter
- walletParkedAlreadyInProgress → String
-
The notFound outcome of the FR-23-b authorize verb (#401 R2b), split off from walletParkedRetryStale.
notFoundmeans the row is no longer QUEUED — which is EITHER gone (cancelled, completed) OR claimed by the background drain that won the race. In the claimed case the previous copy ('isn't waiting anymore') contradicted the screen itself: the same payment re-renders as PREPARING two lines above, so the user was told a visible row does not exist. The expired outcome keeps walletParkedRetryStale, where 'isn't waiting anymore' is exactly true (the row was deleted). Hedged with 'may' because the surface cannot tell the two apart; points at the two surfaces that can. NEVER invites a re-send — the funds are committed either way and a second send would pay twice.no setter - walletParkedAuthorizeFailed → String
-
Snackbar when the authorize call itself threw (busy / closed wallet / the host's signing credential was unavailable). The saved payment is untouched — same reassurance shape as the other 'unchanged, try again' faults.
no setter
- walletParkedAuthorizeRearmed → String
-
The same not-ready outcome as walletParkedAuthorizeStillWaiting, but for a row that was PAUSED when the user tapped (#400 R5). The authorization re-arms a paused row's retry budget before signing, so even when nothing is signed the row DID change: it is no longer paused, its icon and label change, the paused hint disappears and the reopen-sending prompt may vanish with it. Telling that user their payment is 'unchanged' while the row visibly re-shapes reads as a bug and is simply untrue — so state the re-arm, which is what actually happened. THE SIXTH QUEUE-DRAIN STRING (#403 R3): the previous ending, 'it will be tried again', is the same automatic-drain promise #401 R1(a) swept from five siblings and missed here. A re-armed row is a QUEUED intent, so a background retry needs a sync pass AND a signing credential, and at host custody the unattended pass holds neither. It is the ONLY member of that family a user reaches BY TAPPING THE MONEY BUTTON, and it lands on top of a section whose own note may say these do not send on their own — a promise and its negation four lines apart about one payment. Same rule as walletSendQueuedBody / walletSendQueueHint: promise NO schedule, name the two real actions. Both are on screen by construction here (the re-arm leaves the row Queued, so it renders Send now and Cancel). 'Send now' must match walletParkedSendNow verbatim.
no setter
- walletParkedAuthorizeSent → String
-
Snackbar after a parked send was signed in the authorization bracket (FR-23-b): it is now a real transaction on its way. It leaves the pending-payments list and appears in activity. Present progressive on purpose — reaching the network is still in progress. Used when a sync pass WILL run (
walletSyncPassesRunProvider); otherwise — host policy off OR a failed sync start — use walletParkedAuthorizeSentSyncPaused (#407 R10d: this line said 'the host's sync policy is ON', which stopped being the gate at #401 R5).no setter - walletParkedAuthorizeSentSyncPaused → String
-
The signed-outcome snackbar when NO background sync pass will run (#400 R1, the reliability HIGH; re-keyed by #401 R5). The transaction is signed and the wallet is broadcasting it — but if the broadcast never reaches the network, the wallet's durable re-send only runs on a completed sync pass: without passes the payment would sit signed and unsent with no correction. So the plain 'Sending your payment now.' is not the whole truth here. Renamed from ...SyncOff and made cause-agnostic because it is keyed on the sync DRIVE: a FAILED sync start strands the residual exactly as the host's sync-off policy does, and 'turn syncing back on' is the wrong instruction for it — the screen's own sync notice carries the remedy either way. Never phrase it as a failure (nothing failed) and never invite re-entering the payment — the funds are already committed and a second send would pay twice.
no setter
- walletParkedAuthorizeStillWaiting → String
-
Snackbar when the authorization signed NOTHING and the payment stays saved (not enough spendable balance at this moment, a full one-time-address window, or the wallet's own background pass claimed the row first). MONEY-CRITICAL COPY RULE: this is NOT a failure — never translate it as one. A user who believes the payment failed re-enters it and BOTH send: a double pay. Deliberately promises no retry timing (background retries ride sync passes, which a host may have turned off). Only for a row that was NOT paused — see walletParkedAuthorizeRearmed.
no setter
- walletParkedBlockedByNetworkUpgrade → String
-
Parked-send row detail when ParkedSend.signingBlock is SigningBlock.networkUpgrade — and ONLY then (GRACE-1 §4p G-6): the drain will not sign this row until the app is updated. MUST NOT say 'will send when ready' (it will not, on this version) and MUST NOT say 'failed' (the money is untouched and the intent is intact). Cancel stays offered; retry does not, since retrying changes nothing until the app is updated. A server that merely stopped reporting its network is walletParkedBlockedByServerSilent, never this.
no setter
- walletParkedBlockedByServerSilent → String
-
Parked-send row detail when ParkedSend.signingBlock is SigningBlock.graceExpired (GRACE-1 §4p): this server will not say which network it is on and the wallet's grace for it has run out (or never began), so the drain will not sign this row until a server that reports its network is used. The next step is SWITCH SERVERS. MUST NOT say 'upgraded' or 'update the app' (nothing was upgraded and an update fixes nothing — that is walletParkedBlockedByNetworkUpgrade), MUST NOT say 'will send when ready' and MUST NOT say 'failed'. Cancel stays offered; retry does not.
no setter
- walletParkedBlockedByServerSilentClock → String
-
walletParkedBlockedByServerSilent's variant when the grace ran out on the DEVICE CLOCK (GraceExpiry.clock). The next step is the SAME as the sibling's — a server that reports the network version — and the device clock is a PRECONDITION of it, never an alternative to it (§4p-run fold review row 6, §4r U-5): a corrected clock alone re-permits nothing (the latch holds until a branch-reporting server), so the copy MUST read 'if the date and time are wrong, fix them FIRST — then switch' and MUST NOT read 'switch servers, OR check the date and time'. Same prohibitions as the sibling: never 'upgraded', 'update the app', 'will send when ready' or 'failed'.
no setter
- walletParkedCancel → String
-
Per-row button to cancel (discard) a parked send. The safe counter-affordance — never a re-send.
no setter
- walletParkedCancelAlreadySending → String
-
Snackbar when cancel returned false. The SDK can't yet distinguish 'already gone' from 'began sending', so the copy is hedged ('may') — honest in BOTH cases. NEVER present as cancelled; never invite a re-send — direct the user to the activity list (double-pay safety).
no setter
- walletParkedCancelConfirmBody → String
-
Body of the cancel-parked confirm dialog. Reassures that a queued (not-yet-sent) send moves no funds, while flagging the action is irreversible.
no setter
- walletParkedCancelConfirmDiscard → String
-
Cancel-parked confirm dialog: the irreversible confirm that discards the queued send.
no setter
- walletParkedCancelConfirmKeep → String
-
Cancel-parked confirm dialog: keep the pending payment (dismiss the dialog).
no setter
- walletParkedCancelConfirmTitle → String
-
Title of the confirm dialog before discarding a parked send.
no setter
- walletParkedCancelDone → String
-
Snackbar after a parked send was successfully cancelled.
no setter
- walletParkedCancelFailed → String
-
Snackbar when the cancel call threw (e.g. wallet busy / closed). The queued send is untouched.
no setter
- walletParkedError → String
-
Honest error line when the parked-sends read fails. The surface is shown (not silently hidden) because a parked send is money the user is waiting on.
no setter
- walletParkedErrorRetry → String
-
Inline retry button under the parked-sends read-error line: re-pulls the pending-payments list in place (the home has no pull-to-refresh). SECTION-level, not row-level: the per-row affordance is walletParkedSendNow, which signs one saved payment (#401 R7c — this line named walletParkedRetry, retired by #400). Same 'try again' wording as the other read-error retries (walletReceiveRetry, walletShieldRetry).
no setter
- walletParkedErrorRetryInProgress → String
-
The parked-sends read-error retry button's label WHILE the re-pull is in flight (#407 R5). Load-bearing for a11y, not decoration: the surrounding Semantics(liveRegion:) is flagged on THIS label, so the label CHANGING is what re-fires the announcement when the identical error re-lands. The pre-#407 shape flagged an outer container whose SemanticsData was byte-identical across the flip — measured, it never re-announced, while the code comment claimed it did. Same shape as walletParkedSendNowInProgress. Keep it SHORT — it replaces 'Try again' inside a button beside a spinner.
no setter
- walletParkedPausedHint → String
-
Hint line under a PAUSED parked-send row (#315): the wallet stopped auto-retrying (each retry of a one-time-address send permanently uses up one of a small number of address slots). Must state (a) it will NOT send by itself, (b) funds are safe, (c) the two actions THAT ARE ON SCREEN. #400 R3: the old text said 'Retry it or cancel it' and rendered directly above a button labelled 'Send now' — since FR-23-b that one button both re-arms the row AND signs it, and the separate Retry button no longer exists. Name the visible buttons verbatim (walletParkedSendNow, walletParkedCancel). Never 'will send when ready'.
no setter
- walletParkedPreparingHint → String
-
Hint line under a MID-SIGNATURE parked row (#400 R2) when a sync pass WILL run (
walletSyncPassesRunProvider— #407 R10d corrected this line, which still said 'the host's sync policy is ON' after #401 R5 / #403 R4 re-keyed the site onto the drive-aware SSOT; a FAILED sync start reads policy-ON and runs no passes). Must state (a) work is in progress, (b) the amount may ALREADY be out of the spendable balance — unlike every other row in this section, whose amount is an earmark over the balance, this row can be past the point where the wallet committed the transaction locally and marked its notes spent, so the section's 'their amounts are still part of your balance' is not true of it — (c) funds are safe, (d) it self-recovers: the wallet re-queues an unfinished claim on its next completed sync pass, so the user has nothing to do and must NOT re-enter the payment. Deliberately unspecific about WHEN. Normally NO action is offered on this row (every verb that could act on it requires a still-queued row), so the copy must not name one — with ONE exception (#403 R9e, correcting a claim this file stated absolutely): while the user's OWN authorization bracket is what claimed the row, the section keeps rendering its spinnered Send now, because deleting the cue mid-proof is the dead-app shape the cue exists to prevent. When no pass will run — host policy off OR a failed start — use walletParkedPreparingHintSyncPaused.no setter - walletParkedPreparingHintSyncPaused → String
-
The MID-SIGNATURE row's hint when NO background sync pass will run (#400 R2, re-keyed by #401 R5). Its sibling promises the row 'returns to the list on its own' — true only where sync passes happen, because that self-recovery IS a sync pass. Without passes the row sits there indefinitely and a user told to wait for a self-heal that cannot come re-enters the payment: the double pay this whole section exists to prevent. Renamed from ...SyncOff because it is keyed on the sync DRIVE, not the host policy: a FAILED sync start has the same consequence and 'turn syncing back on' would be the wrong instruction there — so the promise is replaced by a cause-agnostic condition and the screen's own notice carries the remedy. Keep the same first two clauses as the sibling (work in progress; the amount may already be set aside; funds safe). Never phrase it as a failure — nothing failed.
no setter
- walletParkedRetryStale → String
-
Snackbar when retry returned false (the row is gone / began sending / changed). Mirrors the cancel-false contract: never invite a re-send; point at the surfaces.
no setter
- walletParkedSendNow → String
-
Per-row button on a parked send (FR-23-b, #361): sign and send the already-saved payment now, instead of waiting for the wallet's next background pass. A host that authorizes each spend individually prompts here. ONE LABEL FOR BOTH ROW STATES — healthy AND paused (#361 M4): on a paused row it re-arms the retry budget and signs, so it does strictly MORE than on a healthy row and 'Retry' understated it. (The description previously said 'HEALTHY (not paused)' and 'a paused row shows walletParkedRetry instead'; that Retry key is retired — #400 R9 corrects the drift.) Not shown on a row that is already mid-signature (ParkedSend.sending).
no setter
- walletParkedSendNowInProgress → String
-
The Send now button's label while the authorization is in flight (#400 R4): the button is disabled and shows a spinner. Load-bearing, not decoration — at held custody there is no host prompt to look at, and the call runs an unbounded proving step (tens of seconds on a fragmented wallet), so without a cue the user sees a dead button and taps elsewhere or re-enters the payment. Mirrors walletReclaimInProgress.
no setter
- walletParkedSubtitle → String
-
Sub-heading for the parked-sends section. Deliberately NEUTRAL about whether a row will send on its own (#315): a healthy row sends when ready, a PAUSED row never sends until the user retries — the per-row copy carries that split, so this shared line must be true for both. The amounts are an earmark over the balance (still spendable), never added on top nor deducted. Never invite a re-send.
no setter
- walletParkedSubtitlePreparing → String
-
The parked-sends sub-heading when AT LEAST ONE row is mid-signature (#401 R2a). The plain sibling asserts the earmark unconditionally — 'their amounts are still part of your balance' — and that is FALSE for a claimed row: past the engine's create the notes are already locally spent, so the amount has left the spendable set. THE OPENER MUST STAY NEUTRAL (#407 R6 reverted #401 R8a's change to it): this heading renders over the WHOLE section whenever ANY row is sending, and that list may also hold PAUSED rows that never send on their own — 'haven't finished sending' told those users progress was underway and invited them to WAIT instead of tapping Send now, the abandoned-funds harm the paused copy exists to prevent. The progress claim belongs in the except-clause, scoped to the rows it is true of.
no setter
- walletParkedSyncPausedNote → String
-
The parked-sends pause note, replacing the shared walletSyncPausedMoneyNote on THIS surface (#401 R2d + R5). Two changes. (1) It names the ESCAPE: the shared note says only 'paused', and it sits directly above a Send now button that #400 R9 deliberately left working at every custody tier — a user who reads 'paused' and stops looking has abandoned funds they could release with one tap. (2) It is CAUSE-AGNOSTIC and keyed on the sync DRIVE, not the host policy: a failed sync start freezes the queue exactly as a sync-off policy does, and 'in this app's settings' is the wrong instruction for it — the screen's own sync notice carries whichever remedy applies. RENDERED ONLY WHILE THAT ESCAPE EXISTS (#403 R2): Send now is suppressed on a mid-signature row, so a section whose rows are ALL mid-signature falls back to the affordance-free walletSyncPausedMoneyNote instead — a note naming a control that is not on screen is worse than the plain pause it replaced. 'Send now' must match walletParkedSendNow verbatim. Two full standalone sentences; never claims failure.
no setter
- walletParkedTitle → String
-
Heading above the parked-sends section: EVERY queued send that has no on-chain transaction yet and so doesn't appear in the activity list — one-time-address (TEX) sends awaiting their window AND plainly-queued offline sends (#331). The copy is deliberately shape-agnostic; keep it honest for both.
no setter
- walletPendingChangeLabel → String
-
Label for our own change in flight (normal right after a send); shown so the breakdown reconciles to the total.
no setter
- walletPoolAllShielded → String
-
Balance-card pool-clarity line (#389) when the transparent balance is zero: a positive affirmation that EVERY coin is in the shielded (private) pool. Always-on so an all-private wallet gets explicit reassurance, not merely the absence of a transparent line. The '·' (U+00B7 middot) separates the two clauses; keep a real middot with a space on each side. 'shielded' and 'private' as elsewhere on the card.
no setter
- walletPoolIronwood → String
-
The Ironwood shielded pool's name (NU6.3), as the {pool} placeholder of the walletSyncPool* lines. A proper noun: keep it in Latin script unless the locale's Zcash community writes it otherwise.
no setter
- walletPoolOrchard → String
-
The Orchard shielded pool's name, as the {pool} placeholder of the walletSyncPool* lines. A proper noun: keep it in Latin script unless the locale's Zcash community writes it otherwise.
no setter
- walletPoolSapling → String
-
The Sapling shielded pool's name, as the {pool} placeholder of the walletSyncPool* lines. A proper noun: keep it in Latin script unless the locale's Zcash community writes it otherwise.
no setter
- walletPoolTapHint → String
-
Screen-reader tap hint (#389) for the balance-card pool line: read after the button role as 'double tap to
no setter
- walletReceive → String
-
Wallet-surface button + receive screen title.
no setter
- walletReceiveCopied → String
-
Receive screen: snackbar confirmation after copying the address.
no setter
- walletReceiveCopy → String
-
Receive screen: copy-to-clipboard button label.
no setter
- walletReceiveError → String
-
Receive screen: address lookup failed; paired with a Try again button.
no setter
- walletReceiveFreshAddress → String
-
Receive screen (shielded tab): button that mints a fresh diversified address — a new unlinkable address for a contact or invoice that still pays into this wallet.
no setter
- walletReceiveFreshBusy → String
-
Receive screen: snackbar when the fresh-address mint timed out because the wallet is briefly busy (e.g. signing a payment); a retry normally succeeds.
no setter
- walletReceiveFreshCaption → String
-
Receive screen: note shown with a freshly minted diversified address. Must convey all four facts: unlinkable; funds arrive in this wallet; earlier addresses stay valid; the display is one-time (copy before leaving).
no setter
- walletReceiveFreshCopyNow → String
-
Receive screen: the fresh-address note's on-screen state, the last sentence of walletReceiveFreshCaption verbatim; the whole caption moved behind the note's (i) (S13 §1.7: the 'copy it now' state stays on screen).
no setter
- walletReceiveFreshError → String
-
Receive screen: snackbar shown when minting a fresh diversified address fails; the previous address stays on screen.
no setter
- walletReceivePreparing → String
-
Receive screen: honest loading headline while the address derivation is in flight (replaces a bare spinner).
no setter
- walletReceivePreparingHint → String
-
Receive screen: reassuring sub-line under the loading headline. CAUSE-HONEST since #385 (E2E-1): the derivation is LOCAL — the old 'catches up with the network' blamed the network on a fully-synced wallet; the honest cause is the derive queueing behind other wallet work (a heavy sync being one example, not the only one). Avoids 'first sync' since a restore also hits this on a fresh device.
no setter
- walletReceiveQrLabel → String
-
Receive screen: accessibility label for the address QR image.
no setter
- walletReceiveQrLabelTransparent → String
-
Receive screen: accessibility label for the transparent address QR image.
no setter
- walletReceiveRequestAmount → String
-
Receive screen: button that opens the optional amount field; with an amount, the QR, Copy and Share carry a payment request for it (S13, maintainer).
no setter
- walletReceiveRequestAmountLabel → String
-
Receive screen: label of the requested-amount field, in ZEC (S13, maintainer).
no setter
- walletReceiveRetry → String
-
Receive screen: button that re-attempts the address load after a failure.
no setter
-
Receive screen: button that opens the host's share sheet with the address, or the payment request when an amount is set (S13, maintainer). Shown only when the host supplies a share hook.
no setter
- walletReceiveSubtitle → String
-
Receive screen: explains the address is public and shareable.
no setter
- walletReceiveSubtitleTransparent → String
-
Receive screen: subtitle shown when the transparent address is selected.
no setter
- walletReceiveTransparentWarning → String
-
Receive screen: the honest public-address warning shown above the transparent receive address.
no setter
- walletReceiveTypeShielded → String
-
Receive screen: the address-type toggle segment for the private shielded address (the default).
no setter
- walletReceiveTypeTransparent → String
-
Receive screen: the address-type toggle segment for the public transparent address.
no setter
-
Receive screen: shown when there is no live wallet session.
no setter
- walletReclaimButton → String
-
The account-level button that runs the #315 reclaim (reopen a bricked one-time-address send window). Shown only when a send is paused.
no setter
- walletReclaimConfirmAction → String
-
Confirm the reclaim (proceed to authorize + run it).
no setter
- walletReclaimConfirmBody → String
-
Body of the reclaim confirm dialog — the honest-cost disclosure. Must state: the amount is your own and returns; the real cost is a couple of network fees; the moved amount is recovered via the existing action once it confirms. Never imply the funds are lost, and never promise the window reopens instantly. #400 R3: the action is named 'Recover now' (walletRecoverNow) — the old 'Recover funds' was never a button label anywhere in the app.
no setter
- walletReclaimConfirmCancel → String
-
Dismiss the reclaim confirm dialog without acting.
no setter
- walletReclaimConfirmTitle → String
-
Title of the honest-cost disclosure dialog shown before the #315 reclaim runs.
no setter
- walletReclaimExplainer → String
-
#315 slice 2: the line above the 'Reopen sending' button, shown under the parked list when a send is paused. Explains that reopening moves a small amount (your own, returned) — never a fee-only framing that hides the round-trip.
no setter
- walletReclaimFailed → String
-
Snackbar when the reclaim threw a typed error (e.g. seed required / busy / closed handle). The funds are untouched and it is retryable.
no setter
- walletReclaimInProgress → String
-
The reclaim button's label while the reclaim is in flight (button disabled + spinner).
no setter
- walletReclaimNeedsFunds → String
-
Snackbar when the reclaim failed because the shielded balance can't fund the small self-mint (InsufficientFunds).
no setter
- walletReclaimNotBroadcast → String
-
Snackbar when the reclaim mint's broadcast was not acknowledged (ReclaimOutcome.NotBroadcast). Money-safe, but do NOT claim 'nothing was moved': a lost acknowledgement can mean the mint actually landed. Honest about that ambiguity and paces the retry so a rapid re-tap can't double-mint (an extra fee). The principal always returns via the sweep.
no setter
- walletReclaimNothing → String
-
Snackbar when the reclaim found no abandoned reservation to reclaim (ReclaimOutcome.NothingToReclaim) — the window is transient / already clear. No money moved.
no setter
- walletReclaimStarted → String
-
Snackbar after a successful reclaim mint (ReclaimOutcome.Minted). It is INITIATED, not done: the window reopens once the mint confirms (a few minutes) — never claim it is already working. Names the TWO manual follow-ups the user must still do so the flow is not a dead-end. #400 R3: BOTH names were wrong — 'retry the paused send' pointed at a Retry button that FR-23-b replaced with walletParkedSendNow, and 'Recover funds' was never the button's label (it is walletRecoverNow, 'Recover now' — 15 locales had already translated the correct label; EN was the outlier). Every affordance named here must match the visible button label verbatim.
no setter
- walletReclaimUnknown → String
-
Neutral snackbar for a forward-compat reclaim outcome the app does not recognise (ReclaimOutcome.Unknown, only under core/bridge version skew). Never claim success or failure: state it finished and point to the sends + the recover action. Hedge with 'any' since whether an amount moved is unknown. #400 R3: the action is 'Recover now' (walletRecoverNow), matching the visible button.
no setter
- walletRecoverConfirmAction → String
-
Recover confirm dialog: the confirm action that runs the recovery.
no setter
- walletRecoverConfirmBody → String
-
Body of the recover confirm dialog. The action is privacy-positive (into shielded) and idempotent (re-runnable).
no setter
- walletRecoverConfirmCancel → String
-
Recover confirm dialog: dismiss without recovering.
no setter
- walletRecoverConfirmTitle → String
-
Title of the confirm dialog before running the one-time-address recovery (sweep).
no setter
- walletRecoverFailed → String
-
Snackbar when the recovery call threw (e.g. seed required / closed handle). The funds are untouched and re-runnable.
no setter
- walletRecoverInProgress → String
-
The recover button's DISABLED in-progress label while a sweep signs + broadcasts per address (it can take a moment on a slow link). Doubles as the single-flight in-progress cue, so a re-tap can't launch a second concurrent sweep.
no setter
- walletRecoverNothing → String
-
Snackbar when recovery found nothing sweepable (e.g. already recovered on a prior run).
no setter
- walletRecoverNow → String
-
Button to recover funds sitting on one-time (ephemeral) transparent addresses into the shielded balance. Shown only when a successful read reports recoverable funds.
no setter
- walletRecoverRetry → String
-
Snackbar when recovery had per-address faults or hit the per-run cap. The funds stay on-chain and re-runnable — never a loss.
no setter
- walletRecoverTruncated → String
-
Sweep outcome when the per-invocation cap left addresses UNCHECKED and nothing was swept or failed — honest 'incomplete check', never a claim that funds exist (distinct from walletRecoverRetry, which is for per-address faults).
no setter
- walletRescanBlockedSettlingNotice → String
-
Cue shown when the SDK refused a rescan because a broadcast send has not settled yet (rebuilding under it could double-pay); resolution takes hours of online sync.
no setter
- walletRescanBlockedSyncNotRunningNotice → String
-
Rescan refusal notice (#405): the commit-point fence turned the confirm away because no sync pass will run (host policy off OR a failed sync start), so the wipe would strand a zeroed wallet behind a rebuild that cannot execute. Nothing destructive ran, which is why this is the one rescan refusal entitled to say 'your wallet is unchanged' outright (#379 softened walletRescanFailedNotice because a post-rename fault leaves a REBUILT wallet). CAUSE-AGNOSTIC — the badge and the start-failed notice above it carry the cause and the way out.
no setter
- walletRescanBody → String
-
Body of the rescan sheet: what rescan does + the money-safety reassurance.
no setter
- walletRescanCancel → String
-
Dismiss the rescan sheet without rescanning.
no setter
- walletRescanChange → String
-
Button to change an already-chosen rescan start date.
no setter
- walletRescanConfirm → String
-
Confirm button that starts the rescan.
no setter
- walletRescanDatePick → String
-
Help text on the rescan date picker dialog.
no setter
- walletRescanFailedDismiss → String
-
Dismiss the rescan-failed cue.
no setter
- walletRescanFailedNotice → String
-
Honest cue shown when a rescan failed but the wallet was recovered by re-opening. Claims funds-safety only, never 'unchanged' (#379): a fault AFTER the rebuild's atomic rename recovers into the REBUILT lower-birthday wallet, whose balance/history repopulate via the auto-restarted sync.
no setter
- walletRescanMenuItem → String
-
Wallet app-bar overflow-menu item that opens the rescan-recovery sheet.
no setter
- walletRescanNeedsSpaceNotice → String
-
Cue shown when a rescan failed because the device is out of disk space; retrying without freeing space will fail again, so the copy asks for space instead of a retry. Claims funds-safety only, never 'unchanged' (#379): a DiskFull after the rebuild's atomic rename recovers into the REBUILT lower-birthday wallet.
no setter
- walletRescanPick → String
-
Button to choose a rescan start date.
no setter
- walletRescanRangeAll → String
-
Description shown when the rescan will scan the full history (no date).
no setter
- walletRescanRangeDefault → String
-
Description of the DEFAULT rescan range when it is the wallet's own birthday (a wallet younger than a year, where scanning earlier would only cover empty pre-wallet blocks). Does NOT claim completeness of the USER's funds — a too-high restore birthday can leave real deposits below this floor — so it points the recovery user at the earlier-date / scan-all escape hatch (the same nudge the chosen-date arm carries).
no setter
- walletRescanRangeResolving → String
-
Transient description while the wallet's scan-floor read is in flight (sub-millisecond normally; up to the FFI timeout on a wedged bridge). Pick-a-date and Scan-all stay available; only Start waits.
no setter
- walletRescanRangeTitle → String
-
Heading of the date-range control in the rescan sheet.
no setter
- walletRescanRebuildingAll → String
-
Activity-section cue while a full-history rescan repopulates.
no setter
- walletRescanRebuildingDefault → String
-
Activity-section cue while the default rescan (from the wallet's own birthday) repopulates.
no setter
- walletRescanRunning → String
-
Label while the rescan rebuild FFI call is in progress.
no setter
- walletRescanScanAll → String
-
Button to clear the rescan start date and scan the full history.
no setter
- walletRescanSettlingAdvisory → String
-
Rescan sheet advisory shown while in-flight sends exist (#364 M3): the engine's settling-send fence will likely refuse the rescan, and the refusal costs a full quiesce — say so BEFORE Start. Advisory only; the engine stays authoritative, so the copy must hedge ('usually', 'expect') and never promise refusal.
no setter
- walletRescanSwapPointer → String
-
#390 cross-pointer on the Rescan sheet: a rescan re-scans compact blocks (no transparent outputs) and keeps the restore ceiling, so it cannot surface old-swap funds; point the affected user at the deep scan.
no setter
- walletRescanTitle → String
-
Title of the rescan-recovery confirm sheet.
no setter
- walletRescanWarning → String
-
Honest expectation-setting note in the rescan sheet — the duration scales with how far back the chosen date reaches (the ~1-year default measured hours on emulator-class hardware, so 'a few minutes' over-promised).
no setter
- walletRestoreBack → String
-
Secondary action on the restore screen: return to the welcome screen.
no setter
- walletRestoreBirthdayChange → String
-
Action to change an already-chosen creation date.
no setter
- walletRestoreBirthdayClear → String
-
Action to clear the chosen creation date and scan the whole chain instead (money-safe, slower).
no setter
- walletRestoreBirthdayNone → String
-
Shown when the user chose a full scan (no date): money-safe but slower.
no setter
- walletRestoreBirthdayPick → String
-
Action to choose the approximate wallet-creation date.
no setter
- walletRestoreBirthdayTitle → String
-
Heading of the restore starting-point (wallet-creation date) control.
no setter
- walletRestoreBody → String
-
Body on the restore screen explaining what to enter, with an honest note that passphrase-protected ('25th word') wallets can't be imported (a wrong/absent passphrase silently restores a different, empty wallet).
no setter
- walletRestoreButton → String
-
Secondary action on the welcome screen: restore an existing wallet from its recovery phrase.
no setter
- walletRestoreFaultAlreadyExists → String
-
Inline restore error when a completed wallet is already provisioned here.
no setter
- walletRestoreFaultBirthdayTooRecent → String
-
Inline restore error when the chosen creation date is past the chain tip.
no setter
- walletRestoreFaultInvalidPhrase → String
-
Inline restore error when the phrase fails validation with no single offending word (e.g. a checksum failure).
no setter
- walletRestoreFaultSeedMismatch → String
-
Inline restore error when a different phrase is supplied over an interrupted-create remnant.
no setter
- walletRestoreLengthHint → String
-
Hint shown beside the word count when it isn't yet a valid phrase length.
no setter
- walletRestorePhraseHint → String
-
Placeholder hint inside the recovery-phrase field, showing words are space-separated.
no setter
- walletRestoreSubmit → String
-
Primary action on the restore screen: validate the phrase and restore the wallet.
no setter
- walletRestoreTitle → String
-
Heading on the restore (recovery-phrase entry) screen.
no setter
- walletScanOpenSettings → String
-
Scanner, camera refused: opens the app's system settings through the host (S13, maintainer).
no setter
- walletScanOpenSettingsFailed → String
-
Scanner, camera refused: the host's settings opener failed (maintainer).
no setter
- walletSecurityMenuItem → String
-
Wallet overflow menu: opens the Security screen (key custody + delete wallet).
no setter
- walletSendAlreadyBody → String
-
Result body for a re-consumed proposal token (no double-spend).
no setter
- walletSendAlreadyTitle → String
-
Result: the one-shot proposal was already consumed (double-tap).
no setter
- walletSendAmountHint → String
-
Placeholder for the amount field.
no setter
- walletSendAmountLabel → String
-
Label for the amount field.
no setter
- walletSendAnother → String
-
Return to a fresh form after a completed send.
no setter
- walletSendBackButton → String
-
Confirm-screen action that returns to the editable form.
no setter
- walletSendButton → String
-
Entry button on the active wallet surface that opens the send flow.
no setter
- walletSendChangeLabel → String
-
Confirm line: change returned to the wallet (informational).
no setter
- walletSendConfirmButton → String
-
Confirm-screen action that signs + broadcasts.
no setter
- walletSendDeshieldBody → String
-
§5.1 de-shield disclosure body — honest about the public, linkable de-shield.
no setter
- walletSendDeshieldTitle → String
-
§5.1 de-shield disclosure heading: a transparent recipient makes the payment public.
no setter
- walletSendDone → String
-
Leave the send screen after a completed/queued send.
no setter
- walletSendExpiredBody → String
-
Body for walletSendExpiredTitle. States the limit the user hit (the five-second mount grace — keep the number in step with WalletSendEntry's grace if it is ever re-priced), why the wallet refuses (the app already holds a final "nothing was sent" for this request, and paying under it would put a payment on chain with no record of it in the app), and the ONE next step. Never promises the wallet will pay it later; nothing was signed.
no setter
- walletSendExpiredTitle → String
-
Full-screen title when a send screen opened by the app's own entry point (WalletSendEntry.push) appears AFTER the entry's mount grace ran out (stage S8 deadline, R05). The app was already told that nothing was sent, and that answer is final for this request: the screen offers no form and no way to pay it. Terminal, not transient — the user starts again from the app.
no setter
- walletSendFailedBody → String
-
Result body for a sign/build failure (re-propose needed).
no setter
- walletSendFailedTitle → String
-
Result: signing/build failed; no money moved.
no setter
- walletSendFaultAddressInvalid → String
-
Form fault: the recipient address failed to parse.
no setter
- walletSendFaultAmountDecimals → String
-
Form fault: more than 8 fractional digits.
no setter
- walletSendFaultAmountEmpty → String
-
Form fault: the amount field is empty.
no setter
- walletSendFaultAmountNotANumber → String
-
Form fault: the amount isn't a plain decimal number.
no setter
- walletSendFaultAmountNotPositive → String
-
Form fault: the amount parses to zero.
no setter
- walletSendFaultAmountOutOfRange → String
-
Form fault: the amount exceeds max money.
no setter
- walletSendFaultAmountsExpired → String
-
Form fault on the SEND path: the reviewed proposal's anchor went stale between confirm and send (the wallet IS synced; the numbers aged out) — re-propose for fresh figures. Distinct from walletSendFaultNotSynced (the propose-path not-anchorable case).
no setter
- walletSendFaultCouldNotPrepare → String
-
Form fault: a prepare failure with no finer mapping that is DETERMINISTIC on the input (retrying unchanged re-fails), so the honest next step is to check the details. The retryable class has its own key, walletSendFaultCouldNotPrepareTransient — never render this one for it (INC-018 (b)).
no setter
- walletSendFaultCouldNotPrepareTransient → String
-
Form fault: a prepare failure the wallet's OWN state will clear without the user changing anything — a note whose witness the scan has not completed, an anchor not yet recorded, an input a concurrent proposal holds (WalletErrorKind.proposeTransient, INC-018 (b), phase-2 P2-2, maintainer decision 4). MUST NOT say 'check the details': on the device proof the details were correct and the identical send prepared fine two minutes later. 'Just now' + 'in a moment' — a short wait, not a sync-length one (that is walletSendFaultNotSynced).
no setter
- walletSendFaultInsufficientCatchingUp → String
-
Form fault detail under the insufficient-funds message while the wallet is still catching up (#381): the 'you have X' figure is the partial repopulating balance, not a final verdict. Hedged ('may') — it must not promise funds exist.
no setter
- walletSendFaultMemoConflict → String
-
Form fault: the app supplied BOTH a text memo and machine bytes on one payment. A programming error, not a user mistake — the copy must not tell the user to fix or remove their memo, and must say plainly that no money moved.
no setter
- walletSendFaultMemoNotSendable → String
-
Form fault: a reserved/invalid memo.
no setter
- walletSendFaultMemoTooLong → String
-
Form fault: the memo exceeds its length bound.
no setter
- walletSendFaultMemoToTransparent → String
-
Form fault: a memo was given to a transparent recipient.
no setter
- walletSendFaultNetworkMismatch → String
-
Form fault: the address belongs to the other Zcash network.
no setter
- walletSendFaultNetworkUpgrade → String
-
Send fault body under the shared walletSendFailedTitle, for RW-SYNC-002 (networkUpgradeUnsupported): the network is running consensus rules this app version cannot build a valid transaction for, so signing is refused before any proving time is spent. MUST NOT blame the user, MUST NOT imply funds are at risk (they are untouched), MUST NOT promise a timeline we do not control, and MUST NOT promise that receiving still works (INC-016: a build that predates the upgrade can be blind to incoming payments as well). Never shown for a wallet that is merely behind on sync — that is walletSendFaultInsufficientCatchingUp.
no setter
- walletSendFaultNotSynced → String
-
Form fault: not anchorable yet (proposal stale) — offers the queue path. Shown ONLY where the queue affordance actually renders; otherwise walletSendFaultNotSyncedNoQueue.
no setter
- walletSendFaultNotSyncedNoQueue → String
-
The same not-anchorable fault WITHOUT the queue invitation — for surfaces with no offline-queue affordance (the move-to-transparent sheet always; the send form when the host's custody disables the queue, #327). Must stay walletSendFaultNotSynced with ONLY its trailing ', or queue this to send later' clause removed (grammar-mandated closes allowed, e.g. ja 待つ→待ってください) so the two never drift.
no setter
- walletSendFaultNotSyncedSyncNotRunning → String
-
The not-anchorable send fault when no sync pass will run (#405 → the SSOT, so a FAILED start no longer falls through to 'wait for sync to catch up'). The queue clause is gated off by the host policy separately. CAUSE-AGNOSTIC and points at the wallet screen's sync status rather than naming one cause's remedy — the send screen has no ambient badge of its own.
no setter
- walletSendFaultOneTimeAddressLimit → String
-
Send fault: the one-time (ephemeral) address gap-limit ceiling for a multi-step (TEX) send. DUAL-NATURED (#315): slots held by confirming transfers free up on their own; slots used up by sends that never confirmed do NOT — so the copy must promise neither 'just wait' nor doom. Routed back to the form (orange-transient), never the red dead-end.
no setter
- walletSendFaultQueueFull → String
-
Form fault: the durable offline-send queue is at capacity.
no setter
- walletSendFaultStorageFull → String
-
Send fault: the device is out of disk space, so persisting the send hit DiskFull (#373). Retrying without freeing space fails again, so the copy asks for space instead of a plain retry. Funds are untouched — nothing was written or broadcast. Sibling of walletRescanNeedsSpaceNotice and walletOnboardingFailedStorageFull.
no setter
- walletSendFaultUriInvalid → String
-
Form fault: the composed payment URI was rejected.
no setter
- walletSendFaultWalletBusy → String
-
Form fault: the wallet is mid-lifecycle (busy/closing).
no setter
- walletSendFaultWatchOnly → String
-
Inline send-form fault when a watch-only wallet somehow reaches propose/send (defense-in-depth; the SDK refuses the spend).
no setter
- walletSendFeeLabel → String
-
Confirm line: the ZIP-317 fee.
no setter
- walletSendInMotionBody → String
-
Honest in-motion body for a partial TEX two-step send. Must NOT promise auto-completion (the forwarding step can expire into a recoverable strand); only the permanently-true 'don't re-send' plus pointing at the shipped wallet-screen recovery.
no setter
- walletSendInMotionTitle → String
-
Result title for a TEX two-step send with some but not all legs accepted (either order) — funds are in motion on a wallet-controlled one-time address.
no setter
- walletSendKeptBody → String
-
Result body for walletSendKeptTitle. Deliberately makes NO claim either way about automatic sending: it is shown both when the wallet reported a held state (a swap deposit past its quote) and when the reading could not be taken, and must be true in both. Points at Activity, where TxSummary.delivery is rendered.
no setter
- walletSendKeptTitle → String
-
Result: a transaction was signed and kept, but the wallet did NOT report that it will retry it on its own (stage S8 obligation, row 10 — the core's per-transaction delivery state was not retry-pending, or could not be read). No promise of automatic sending; Activity shows the live state. Shared by the send, shield and move result surfaces.
no setter
- walletSendLargeConfirmBoth → String
-
Large-send dialog body when both the relative and absolute large-amount triggers fired (both, and the forward-compat unknown arm).
no setter
- walletSendLargeConfirmCancel → String
-
The cancel action in the large-send dialog — returns to the confirm screen without sending.
no setter
- walletSendLargeConfirmNearTotal → String
-
Large-send dialog body when the amount is a high fraction of the available balance (nearTotalBalance).
no setter
- walletSendLargeConfirmOverThreshold → String
-
Large-send dialog body when the amount is over the absolute large-amount threshold (overAbsoluteThreshold).
no setter
- walletSendLargeConfirmTitle → String
-
Title of the deliberate large-amount confirmation dialog shown before signing when the proposal trips the money-safety check.
no setter
- walletSendLeaveBody → String
-
Dialog body for walletSendLeaveTitle (S13 H2, maintainer).
no setter
- walletSendLeaveConfirm → String
-
Dialog action: leave the send screen; sending continues (S13 H2, maintainer).
no setter
- walletSendLeaveStay → String
-
Dialog action: stay on the send screen (S13 H2, maintainer).
no setter
- walletSendLeaveTitle → String
-
Dialog title when the user presses Back while a payment is being sent (S13 H2, maintainer).
no setter
- walletSendMachineMemoLimit → String
-
The honest limit under the machine-memo disclosure: a purpose label is accountability, not verification. The wallet cannot confirm the sentence describes the bytes.
no setter
- walletSendMachineMemoTitle → String
-
Heading of the per-send disclosure shown at the authorization step when the host attached opaque machine-memo bytes. Never shows the bytes themselves.
no setter
- walletSendMemoHint → String
-
Helper under the memo field — memos can't go to transparent addresses.
no setter
- walletSendMemoLabel → String
-
Label for the optional memo field.
no setter
- walletSendMemoMachineDisabled → String
-
Note under the disabled memo field when the host attached opaque machine-memo bytes (FR-28). One memo per payment, so the written memo field is unavailable.
no setter
- walletSendMemoTransparentDisabled → String
-
Note shown under the memo field when it is disabled because the recipient is a transparent (public) address that cannot receive a memo.
no setter
- walletSendNoSpendableYet → String
-
Honest reason shown under a disabled Send button when the wallet is fully synced but has no spendable funds.
no setter
- walletSendPartialBody → String
-
Result body when some (not all) pool-crossing transactions broadcast. Same #401 R1b posture as walletSendSavedBody: already signed, so the completion promise holds at every custody tier, and the render site appends walletSyncPausedMoneyNote when no sync pass will run.
no setter
- walletSendPaste → String
-
Send form: fills the recipient from the clipboard (S13, maintainer).
no setter
- walletSendPreparing → String
-
Busy label while proposing (local note-selection + fee).
no setter
- walletSendPrivacyShielded → String
-
Send-review visibility statement for a fully shielded payment.
no setter
- walletSendPrivacyTransparent → String
-
Send-review visibility statement when any output is transparent; compact restatement of the de-shield warning.
no setter
- walletSendPublicAckLabel → String
-
Checkbox under the 'not private' warning on a payment to a transparent address, on the review and beside Queue; Send now / Queue stay disabled until it is ticked (maintainer: 'add the Send acknowledgement like Swap', this wording).
no setter
- walletSendQueueButton → String
-
Offline-first secondary action: durably queue the send for the next online sync.
no setter
- walletSendQueuedBody → String
-
Result body for a queued (offline-first) send. It must be true at EVERY custody tier (#400 R9): the previous 'we'll send this automatically the next time your wallet syncs online' is FALSE wherever the wallet holds no signing credential of its own — a host that authorizes each spend individually cannot sign on an unattended background pass at all, and that is exactly the host the offline queue was widened for (FR-23-b). So promise no schedule; name the surface the payment now lives on (keep the wording in step with walletParkedTitle) and the two things the user can actually do there. Never 'as soon as you're online' (the retry schedule can lag a reconnect), and never anything that invites re-entering the payment (a double pay).
no setter
- walletSendQueuedTitle → String
-
Result: the offline send intent was durably stored.
no setter
- walletSendQueueHint → String
-
Honest note under the queue action (#399, retold by #401 R1). NEVER asserts the user is offline (the wallet may be unsynced, or the SERVER may be the unreachable side). It also PROMISES NO SCHEDULE: the previous 'prepared and sent automatically the next time your wallet syncs online' is FALSE at host custody, where the background pass holds no signing credential at all — and that is exactly the host the queue was widened for (FR-23-b). Same rule and same wording family as walletSendQueuedBody, which the user meets ONE TAP LATER: name the surface the payment lives on and the two things they can do there. Keeps the fee-preview honesty (queuing skips it; the fee is computed at signing).
no setter
- walletSendQueuing → String
-
Busy label while durably persisting the queued send intent.
no setter
- walletSendRecipientGetsLabel → String
-
Send review: the amount the recipient receives, fee and change excluded (S13, maintainer).
no setter
- walletSendRecipientHint → String
-
Placeholder for the recipient address field.
no setter
- walletSendRecipientInvalid → String
-
Live recipient-field status: the entered text is not a parseable Zcash address.
no setter
- walletSendRecipientLabel → String
-
Label for the recipient address field / confirm line.
no setter
- walletSendRecipientLocked → String
-
Helper text AND screen-reader label for the recipient field when it is opened read-only (locked) by a prefilled request (from a scanned payment code or the app), so the address can't be edited. Sentence case, no period. Generic — the lock applies whether or not the prefill came from a payment URI.
no setter
- walletSendRecipientShielded → String
-
Live recipient-field status: the entered address is a shielded address, so the payment is private.
no setter
- walletSendRecipientTransparent → String
-
Live recipient-field status: the entered address is a transparent address, so the payment is publicly visible on-chain.
no setter
- walletSendRecipientWrongNetwork → String
-
Live recipient-field status: the address is well-formed but for the wrong network (e.g. a testnet address in a mainnet wallet).
no setter
- walletSendReviewButton → String
-
Primary form action: prepare the send and show the confirm screen.
no setter
- walletSendReviewTitle → String
-
Heading on the confirm screen.
no setter
- walletSendSavedBody → String
-
Result body when no transaction was accepted this attempt — cause-agnostic: a transport miss OR a mempool reject (which can be the already-known race shape with money actually in motion; the wallet-screen in-flight cue owns that window). Money-safe; auto-retry. The automatic promise is TRUE at every custody tier (#401 R1b): this transaction is already SIGNED, and the §6.1 ReBroadcast arm re-sends the raw bytes with no seed — unlike a QUEUED intent, which needs a credential the background pass may not have. It is PASS-dependent though, so the render site appends walletSyncPausedMoneyNote when no pass will run. 'On a later sync' — never 'as soon as you're online' (the #399 reconnect-promptness rule).
no setter
- walletSendSavedTitle → String
-
Result: nothing was accepted this attempt (transport miss or mempool reject); the payment is persisted and will retry.
no setter
- walletSendScanQr → String
-
Send form: opens the camera to scan an address or a zcash: payment request (S13, maintainer).
no setter
- walletSendSelfSendNote → String
-
Passive info note on the confirm screen when the recipient is the wallet's own address — money-safe, just usually unintended. Never a blocker.
no setter
- walletSendSentBody → String
-
Result body for a fully-broadcast send.
no setter
- walletSendSentTitle → String
-
Result: every transaction broadcast successfully.
no setter
- walletSendSubmitting → String
-
Busy label while signing + broadcasting.
no setter
- walletSendSyncNotRunning → String
-
Honest reason under a disabled Send when no sync pass will run (#405 → the SSOT). Wins over any retained status arm: nothing is syncing, stalling, or catching up. CAUSE-AGNOSTIC — the badge names the cause. No trailing period (it renders as a reason line).
no setter
-
Honest reason shown under a disabled Send button when sync is stalled or offline (so it won't progress until connectivity/the fault is resolved) and nothing is spendable.
no setter
- walletSendTitle → String
-
App-bar title of the send screen.
no setter
- walletSendTotalLabel → String
-
Confirm line: total debited (recipient amount + fee).
no setter
- walletSendTryAgain → String
-
Action on a failed-send result that returns to a fresh form.
no setter
-
Honest state when the send screen has no live wallet session (defensive).
no setter
- walletSendUnknownBody → String
-
Body for walletSendUnknownTitle on the SEND path (S7 U1). Must never say whether money moved: the transaction may have been signed and broadcast. Points at Activity, where the payment's real state is shown.
no setter
- walletSendUnknownQueuedBody → String
-
Body for walletSendUnknownTitle on the offline QUEUE path (S7 U1): the payment may have been durably queued to send later. Points at the wallet's pending (parked) payments list.
no setter
- walletSendUnknownTitle → String
-
Title of the send screen's terminal when the payment ran but its answer was lost (S7 U1, SendOutcomeUnknown): the host's own authorization code threw or declined after the spend ran. Neither 'sent' nor 'nothing was sent' is true. Bodies: walletSendUnknownBody / walletSendUnknownQueuedBody. No retry is offered.
no setter
- walletSendWaitingForFunds → String
-
Honest reason shown under a disabled Send button while sync is still catching up and nothing is spendable yet (spend-before-sync). Neutral wording (#356-F7): a zero-fund wallet has no funds for sync to 'reach', so the copy must not imply funds are known to exist.
no setter
- walletSendWatchOnly → String
-
Honest full-screen state when the send screen is reached on a watch-only wallet (no spending keys). Permanent fact, not transient.
no setter
- walletSettingsSaveFailed → String
-
Snackbar shown when persisting a settings toggle failed; the switch stays at its saved value.
no setter
- walletSheetLeaveBody → String
-
Shield / Move sheet: dialog body when Back is pressed while it submits; title walletSendLeaveTitle, actions walletSendLeaveStay / walletSendLeaveConfirm (maintainer).
no setter
- walletShieldAlreadyTitle → String
-
The one-shot shield token was already consumed (a double-tap) — never broadcast twice.
no setter
- walletShieldAmountLabel → String
-
Label for the gross transparent amount being shielded.
no setter
- walletShieldButton → String
-
Action button next to the unshielded balance — moves transparent funds into the private shielded pool (Recv-3).
no setter
- walletShieldClose → String
-
Dismiss the shield sheet after a terminal outcome.
no setter
- walletShieldConfirmButton → String
-
Confirm button that signs + broadcasts the shield transaction.
no setter
- walletShieldDoneBody → String
-
Body for a successful shield broadcast.
no setter
- walletShieldDoneTitle → String
-
Terminal success: the shield tx was broadcast.
no setter
- walletShieldFailedTitle → String
-
The shield could not be prepared or signed; no funds moved.
no setter
- walletShieldFeeLabel → String
-
Label for the ZIP-317 fee on the shield transaction.
no setter
- walletShieldNetLabel → String
-
Label for the net amount that ends up in the shielded balance (gross minus fee).
no setter
- walletShieldNote → String
-
Privacy-positive framing of the shield action (the inverse of a de-shield warning).
no setter
- walletShieldNothingBody → String
-
Honest explanation that the transparent balance is below the shielding threshold.
no setter
- walletShieldNothingTitle → String
-
Shown when the transparent balance is below the shieldable minimum.
no setter
- walletShieldPreparing → String
-
Transient state while the shield proposal is computed (local, no network).
no setter
- walletShieldRetry → String
-
Re-run the shield after a recoverable failure.
no setter
- walletShieldSavedBody → String
-
Honest body for the unbroadcast (saved-for-retry) shield — confirmation is NOT imminent; it re-sends on a later sync. Same #401 R1b posture as walletSendSavedBody (already signed ⇒ custody-independent, pass-dependent ⇒ the render site appends walletSyncPausedMoneyNote), and no 'next time you're online' reconnect promise.
no setter
- walletShieldSavedTitle → String
-
The shield tx is persisted but not yet broadcast; it re-sends on a later sync (money-safe). NOT 'when you're online' (#401 R1b): that is the reconnect-promptness shape #399 forbids — the re-send rides a completed sync pass, which can lag a reconnect and never comes at all while sync is paused. Mirrors walletSendSavedTitle.
no setter
- walletShieldSheetTitle → String
-
Title of the shield confirmation sheet.
no setter
- walletShieldStaleBody → String
-
The wallet isn't synced far enough to anchor the shield yet — retry after sync.
no setter
- walletShieldStorageFullBody → String
-
Shield fault: the device is out of disk space, so preparing/persisting the shield hit DiskFull (#373 follow-up). Retrying without freeing space fails again, so the copy asks for space instead of a plain retry. Funds are untouched. Sibling of walletSendFaultStorageFull.
no setter
- walletShieldSubmitting → String
-
Transient state while the shield tx is signed and broadcast.
no setter
- walletShieldTransientBody → String
-
Shield fault body for the retryable prepare refusal (WalletErrorKind.proposeTransient, INC-018 (b)): a condition the wallet's own state clears — an anchor not yet recorded, an input a concurrent proposal holds, a witness the scan has not completed. The shield sibling of walletSendFaultCouldNotPrepareTransient; MUST NOT claim the wallet is 'still syncing' (that is walletShieldStaleBody — a locked input is not a sync matter) and MUST NOT be title-only (the couldNotPrepare arm's dead-end). No funds moved.
no setter
- walletShieldUnknownBody → String
-
Body for walletShieldUnknownTitle. Must never say whether funds moved. Points at Activity, where the shield's real state is shown.
no setter
- walletShieldUnknownTitle → String
-
Title of the shield sheet's terminal when the shield ran but its answer was lost (ShieldOutcomeUnknown): the transaction may already be saved. Neither 'shielded' nor 'nothing happened' is true. Body: walletShieldUnknownBody. Only Close is offered, never a retry.
no setter
- walletShieldWalletEnded → String
-
Body of the shield sheet’s failure terminal when the wallet session ended mid-sheet; mirrors walletMoveWalletEnded.
no setter
- walletShowBalance → String
-
Screen-reader label and tooltip of the eye button while amounts are HIDDEN: pressing it shows them again (FR-49 W-7; maintainer FD-6).
no setter
-
Honest, recoverable message when the cold snapshot read fails.
no setter
- walletSpendableLabel → String
-
Label for the confirmed, spendable portion of the balance.
no setter
- walletStallBirthdayInFuture → String
-
Stall reason: the wallet's configured starting height (birthday) is above the chain tip THIS SERVER reports and above the newest height the app's bundled data vouches for (StallReason.birthdayInFuture, T0-1c-R2). The wallet cannot tell a server that is behind the chain from a starting height set above the real chain tip, so the copy MUST name BOTH next steps: check the starting block this wallet is set to, or try another server. That height has TWO producers (§4n-review row 7, §4r U-5): the birthday typed at restore AND a rescan from a chosen height (rescan_from) — so the copy says 'the starting block this wallet is set to' and MUST NOT say 'you entered when restoring' (the rescan user typed nothing at restore). MUST NOT say 'check your connection' (the server answered — that is walletStallEndpoint) and MUST NOT suggest restoring from the recovery phrase (nothing on the device is at fault — that is walletStallInternal). The wallet keeps retrying on its own; it clears when the server catches up or the starting block is lowered.
no setter
- walletStallEndpoint → String
-
Stall reason: endpoint unreachable — the normal-offline (caution) arm since #399. Hedged on purpose: a refused dial can mean the SERVER is down while the user's internet is fine, so it must not assert the user's connection is the problem. The wallet retries on its own. Since P3-13 the server IS user-switchable (the sync sheet's Server row opens the picker); the copy still does not promise a switch, because a refused dial cannot say whether it is this server or the user's link that is down.
no setter
- walletStallEndpointMisbehaving → String
-
Stall reason: the server ANSWERED and the answer was wrong (StallReason.endpointMisbehaving — malformed or impossible data, a required pool it does not know, or a root/height that conflicts with what an EARLIER server told this wallet). The mirror image of walletStallInternal: the problem is on the SERVER, so the next step IS 'switch servers'. MUST NOT say 'check your connection' (that is walletStallEndpoint — the link works) and MUST NOT suggest restoring from the recovery phrase (nothing on the device is at fault; the seed is not involved). MAY name a RESCAN as the last resort, after other servers (T0-1d): one member of the class is a conflict with the wallet's own cached record — written from an earlier server — and the conflict alone cannot say which server lied; a rescan rebuilds that record and is the only exit when every server is refused. Uses the same 'rescan your history' vocabulary as walletRescanMenuItem. The wallet keeps retrying on its own.
no setter
- walletStallInternal → String
-
Stall reason: a CORRUPT wallet store, or a local fault the wallet could not diagnose (StallReason.internal; R10 narrowed it) — repair/restore, never switch servers. A busy or briefly unreadable store is walletStallStorageUnavailable, which must never offer the restore.
no setter
- walletStallReorg → String
-
Stall reason: chain reorganization in progress.
no setter
- walletStallStorage → String
-
Stall reason: device storage full.
no setter
-
Stall reason: a TRANSIENT local storage fault (StallReason.storageUnavailable, R10) — the wallet's database was busy past its timeout, or an I/O fault such as a locked iPhone's Data Protection. The store is intact and the wallet retries by itself; the SDK's background sync shows this only at the second local fault before a pass completes. MUST NOT suggest restoring from the recovery phrase (that is walletStallInternal, a corrupt store). MUST NOT say 'check your connection' or 'switch servers' (the network is not involved). Keep it short.
no setter
- walletStallTor → String
-
Stall reason: the private path is GENUINELY DOWN — a dial that failed (refused, unreachable, a dial timeout), nothing registered, a registrant that declared its transport FAILED, or a runtime the SDK cannot drive. TRANSPORT-NEUTRAL by construction (FR-30 (a), C1): this string is rendered from a StallReason, which carries no transport name — every other failing arm names the host's transport, this one cannot, so it names none. It must never say "Tor": a host that registered Shadowsocks reads it too (ADR-0547). TWO CLAIMS IT MAY NOT MAKE (FR-32 (b), stage S1
copy): a StallReason carries no POLICY, so aPreferredwallet reads this sentence too — it can neither say the private path "is required" (a setting that user may never have chosen) nor promise that "nothing was sent in the clear" (onlyRequiredfails closed; its dial plan has no fallback arm at all). Both were in this string until stage S1. NARROWED at stage S1truth: a path that ACCEPTED the dial and then carried nothing no longer reaches this reason — it reads TorState.unanswered, whose sentence claims nothing about which side is at fault.no setter - walletStallUnknown → String
-
Stall reason: forward-compatibility arm — still a stall, never healthy.
no setter
- walletStartupFailedBody → String
-
Body of the boot-wiring failure screen. Must reassure that a boot failure never means fund loss (funds are on-chain), and point at the retry.
no setter
- walletStartupFailedTitle → String
-
Heading of the boot-wiring failure screen (WalletStartupFailedScreen): the app ships the wallet but its startup work (native library load / data directory) failed.
no setter
- walletSwapAckLabel → String
-
Blocking acknowledgment checkbox label — gates the Start swap action (§2.6 disclosures-as-blocking-UX).
no setter
- walletSwapAmountHint → String
-
Placeholder for the swap amount field.
no setter
- walletSwapAmountLabel → String
-
Label for the exact ZEC-in amount field.
no setter
- walletSwapAssetLabel → String
-
Label for the destination-asset dropdown (what the user swaps their ZEC into).
no setter
- walletSwapBackButton → String
-
Review-screen action that returns to the editable form.
no setter
- walletSwapBackToWallet → String
-
Primary button on NON-terminal tracking cards (pending/detected/processing/unknown/not-found), the establish-failure card, and the swap-unavailable screen (#364 F12). 'Done' there read as 'the swap is done' — this label states the navigation honestly. Terminal outcome cards (success/refunded/failed) keep 'Done'.
no setter
- walletSwapButton → String
-
Entry button on the active wallet surface that opens the swap flow (shown only when the host has enabled swap).
no setter
- walletSwapConfirmButton → String
-
Review-screen action that executes the swap (registers intent + queues the deposit).
no setter
- walletSwapDepositAddressLabel → String
-
IntoZec deposit screen: the deposit-address field label.
no setter
- walletSwapDepositAmountCopied → String
-
Snackbar after Copy amount (S13, maintainer).
no setter
- walletSwapDepositBackBody → String
-
IntoZec deposit screen: back-press guard dialog body (the in-flight reassurance).
no setter
- walletSwapDepositBackBodyExpired → String
-
Leave-screen dialog body ONCE THE DEPOSIT WINDOW HAS EXPIRED (#364 F11): the live-window body invites copying the address 'to pay', which post-expiry is exactly what the user must not do — this variant warns off sending instead. HEDGED (review MED): 'should refund', never 'will' — same rule as walletSwapDepositExpired.
no setter
- walletSwapDepositBackLeave → String
-
IntoZec deposit screen: back-press guard — confirm leaving.
no setter
- walletSwapDepositBackStay → String
-
IntoZec deposit screen: back-press guard — stay on the screen.
no setter
- walletSwapDepositBackTitle → String
-
IntoZec deposit screen: back-press guard dialog title.
no setter
- walletSwapDepositCopied → String
-
IntoZec deposit screen: snackbar after copying the deposit address.
no setter
- walletSwapDepositCopy → String
-
IntoZec deposit screen: copy-to-clipboard button.
no setter
- walletSwapDepositCopyAmount → String
-
Swap deposit screen: copies the exact amount to send (S13, maintainer).
no setter
- walletSwapDepositExactNote → String
-
IntoZec deposit screen: the exact-amount honesty note (§4.4).
no setter
- walletSwapDepositExpired → String
-
IntoZec deposit screen: the expired-window message. HEDGED (review MED): 'should refund', never 'will' — a below-minimum/dust late deposit or a GC'd order can make an unconditional promise false on a money screen.
no setter
- walletSwapDepositMemoCopied → String
-
IntoZec deposit screen: snackbar after copying the deposit memo.
no setter
- walletSwapDepositMemoCopy → String
-
IntoZec deposit screen: copy-the-memo-to-clipboard button.
no setter
- walletSwapDepositMemoLabel → String
-
IntoZec deposit screen: label for the required deposit memo value.
no setter
- walletSwapDepositMemoRequired → String
-
IntoZec deposit screen: heading of the required-memo section (some source chains, e.g. XRP/Cosmos, require a destination tag or memo on the deposit).
no setter
- walletSwapDepositMemoWarning → String
-
IntoZec deposit screen: the funds-loss warning above the required deposit memo.
no setter
- walletSwapDepositQrLabel → String
-
IntoZec deposit screen: accessibility label for the deposit-address QR.
no setter
- walletSwapDepositSent → String
-
IntoZec deposit screen: advance-to-tracking affordance.
no setter
- walletSwapDepositTitle → String
-
IntoZec deposit screen: title (§3.3b D7).
no setter
- walletSwapDeshieldBody → String
-
§2.6 disclosure body — honest about the de-shield and the public provider legs.
no setter
- walletSwapDeshieldTitle → String
-
§2.6 disclosure heading: swapping out de-shields ZEC and exposes the provider legs.
no setter
- walletSwapDestinationHint → String
-
Placeholder for the destination address field.
no setter
- walletSwapDestinationLabel → String
-
Label for the foreign receive-address field (where the swapped asset is delivered).
no setter
- walletSwapDestinationScanTooltip → String
-
OutOfZec form: tooltip on the destination-address QR scan button (mobile only).
no setter
- walletSwapDirectionBuy → String
-
Swap form: the IntoZec direction segment (the default) — buy ZEC with another asset.
no setter
- walletSwapDirectionSell → String
-
Swap form: the OutOfZec direction segment — sell ZEC for another asset.
no setter
- walletSwapDiscloseAmounts → String
-
Disclosure item: provider sees both amounts.
no setter
- walletSwapDiscloseCrossLink → String
-
Disclosure item: provider links the two assets to one intent.
no setter
- walletSwapDiscloseDestination → String
-
Disclosure item: provider sees the destination address.
no setter
- walletSwapDiscloseGeneric → String
-
Disclosure item: a forward-compat disclosure line this build can't name.
no setter
- walletSwapDiscloseIp → String
-
Disclosure item: provider sees the caller IP unless on Tor.
no setter
- walletSwapDiscloseProviderLegsPublic → String
-
Disclosure item shown when providerLegsTransparent: the provider's chain legs are public (distinct from our de-shield).
no setter
- walletSwapDiscloseSource → String
-
Disclosure item: provider sees the source address.
no setter
- walletSwapDiscloseTitle → String
-
Heading above the §2.6 provider-disclosure list.
no setter
- walletSwapDone → String
-
Action that leaves the swap screen and returns to the wallet.
no setter
- walletSwapExecuteStillWorking → String
-
Snackbar when the user tries to leave (back gesture/button) while the swap execute is still running — the screen blocks leaving for this bounded step (#367 execute pop-guard). Money is being committed; every outcome screen is leavable.
no setter
- walletSwapExecuting → String
-
Busy label while registering the swap and queuing the deposit.
no setter
- walletSwapFaultAlreadyInFlight → String
-
Form fault: the SDK's one-deposit-in-flight guard refused a second swap while one is still queued/signing/sending/settling. Deliberately does NOT invite a re-quote (re-quoting is the double-deposit door). 'Fully settles … can take a while' is honest about the settlement tail: the guard clears at reorg-final burial (~2 h after the deposit mines) or after quote expiry + tx expiry (review NIT — the earlier copy implied an immediate clear).
no setter
- walletSwapFaultConnection → String
-
Form fault: the swap request to the 1Click service timed out / the connection broke (host-side timeout) — the user's connectivity is the likely cause, distinct from the provider itself being down.
no setter
- walletSwapFaultCouldNotQuote → String
-
Form fault: a generic quote/execute failure with no finer mapping.
no setter
- walletSwapFaultDepositFailed → String
-
Form fault: our side couldn't queue the deposit (no ZEC moved; re-quote).
no setter
- walletSwapFaultDestinationInvalid → String
-
Form fault: the destination was rejected by the SDK.
no setter
- walletSwapFaultDestinationRequired → String
-
Form fault: the destination address was empty (OutOfZec requires it).
no setter
-
Form fault: our side couldn't mint a fresh swap receiving address (IntoZec — the #382 mirror of walletSwapFaultRefundUnavailable; pre-#382 this kind fell through to the generic could-not-quote). Same pre-first-sync dominant cause, same wait-for-sync remedy. 'Receiving address' means the wallet-side ZEC delivery address, NOT the user's typed destination.
no setter
- walletSwapFaultExecuteTimeout → String
-
IntoZec execute overran the host-side timeout (#367, F5): the cause may be transport OR a local stall (a busy store consuming most of the window), so this HEDGES both — unlike walletSwapFaultConnection, it must not firmly blame the user's connection. Money-safe: an IntoZec execute moves no wallet funds; re-quoting is the remedy.
no setter
- walletSwapFaultExpired → String
-
Form fault: the quote deadline lapsed — re-quote.
no setter
- walletSwapFaultForeignAmountRequired → String
-
IntoZec form fault: the source amount was empty.
no setter
- walletSwapFaultOutOfBounds → String
-
Form fault: the quote fell outside the user-anchored bound (protective).
no setter
- walletSwapFaultProviderMisbehaved → String
-
Form fault: the provider broke the protocol contract.
no setter
-
Form fault: provider unreachable/erroring (retryable).
no setter
- walletSwapFaultRefundAddressRequired → String
-
IntoZec form fault: the refund address was empty.
no setter
-
Form fault: our side couldn't mint a fresh refund address (#382 rewrite). The DOMINANT real cause since #368 is a pre-first-sync Sell — the refund mints through the engine, which needs the lazily-provisioned account, and the swap surface is activation-gated — so the copy names the wait-for-sync remedy instead of the pre-#382 bare 'try again' (which looped false hope while lightwalletd was down and the swap provider up). 'Usually' keeps the rare structural tail honest.
no setter
- walletSwapFaultRequestInvalid → String
-
Form fault: not-issued/already-executed/malformed request — re-quote.
no setter
- walletSwapFaultSlippageTooHigh → String
-
Form fault: requested slippage above the SDK ceiling (defensive).
no setter
-
Form fault: our side couldn't persist durable swap state (fail-closed).
no setter
- walletSwapFaultStoreBusyRetry → String
-
Retryable fault (#367): the wallet's own store was momentarily busy and NOTHING was consumed — re-running the same action works. On the review screen it renders inline and Start swap is the retry (the quote is still valid); on the form, tapping Get quote again is the retry. Distinct from walletSwapFaultStateUnavailable (whose remedy is a re-quote).
no setter
- walletSwapFaultSwapOff → String
-
Form fault: swap disabled at this instance (defensive). Also the classifier verdict for the defensively-unreachable watchOnly kind — if that kind ever becomes reachable at quote/execute, promote it to a dedicated permanent-framing key (walletSwapUnavailableWatchOnly is the model).
no setter
- walletSwapFaultTermsDiffer → String
-
Stage S8 (R01): the quote handed to execute names a quote the wallet issued but its terms (address, amounts, memo, refund target, binding) differ from the wallet's own durable record — refused BEFORE the quote's single-use claim, so nothing was consumed and nothing left the wallet. Must state that nothing was sent (true by construction) and point at a fresh quote; must not accuse the provider (the DTO was altered on the way back through the host, not by the provider).
no setter
-
Form fault: no live wallet session (defensive).
no setter
- walletSwapForeignAmountLabelGeneric → String
-
IntoZec form: the foreign amount field label before an asset is picked.
no setter
- walletSwapInFlightRowGeneric → String
-
In-flight swap row line for an unrecognized direction (forward-compat) — neutral, never a guess about who sends what.
no setter
- walletSwapInFlightRowIntoZec → String
-
In-flight swap row line when the USER sends the deposit externally (IntoZec).
no setter
- walletSwapInFlightRowOutOfZec → String
-
In-flight swap row line when the WALLET sends the deposit (OutOfZec).
no setter
- walletSwapInFlightRowOverdue → String
-
In-flight swap row line for an UNRESOLVED record past its settlement window (#382 — such rows now list indefinitely instead of vanishing at 48 h; the wallet keeps watching every sync while unresolved), OUT-OF-ZEC + unknown-direction arm since #385 ('coming back' is refund-shaped, which is exactly the OutOfZec ZEC leg; the IntoZec row has its own delivery-shaped line). MUST stay outcome-neutral ('hasn't reached a confirmed outcome HERE' — review): the swap may in fact have SUCCEEDED unobserved, so 'taking longer than expected' would assert a falsehood over a completed swap. The second sentence is the money promise and covers only ZEC legs — it must not claim anything about a foreign-asset refund, which happens provider-side. ACCEPTED OVERCLAIM (#386, shared with the not-found body): for a pre-#368 upgrade-era record with no recorded watch leg, 'after a sync' is true only of a user-initiated full rescan — upgrade-era-only, shrinking population, documented rather than gated.
no setter
- walletSwapInFlightRowOverdueIntoZec → String
-
The IntoZec arm of the overdue row line (#385 — 'any ZEC coming back' read refund-shaped for a swap whose ZEC leg is the incoming DELIVERY; delivered ZEC never left this wallet's side). Same outcome-neutrality contract as the OutOfZec arm; the money promise covers the ZEC delivery leg only — the foreign deposit's refund, if any, happens provider-side on the source chain. Shares the #386 accepted overclaim documented on the OutOfZec arm (a watchless pre-#368 record's late ZEC is full-rescan-only).
no setter
- walletSwapInFlightRowPastWindow → String
-
In-flight swap row line once the record's deposit window has lapsed (#367, both directions): the present-tense motion lines ('on its way' / 'waiting for your deposit') would be false for the rest of the record's ~48 h life. Neutral — the swap may have settled, refunded, or expired; View swap shows the live truth.
no setter
- walletSwapIntoZecEndsShielded → String
-
IntoZec review: the pinned ends-shielded honesty copy (§3.3b D1).
no setter
- walletSwapIntoZecShieldTitle → String
-
IntoZec review: the positive end-state card title.
no setter
- walletSwapNetworkFeeLabel → String
-
Review line label (OutOfZec only, #367 fee disclosure): the Zcash network fee the deposit transaction will pay ON TOP of the 'You send' amount — without this line the review implied the deposit was the whole debit.
no setter
- walletSwapNetworkFeeValue → String
-
Review line value for the network fee: the exact ZIP-317 fee is computed only when the deposit transaction is signed at execute (there is no swap fee-preview round-trip), so the review honestly discloses the fee's EXISTENCE and timing — never a fabricated number.
no setter
- walletSwapPayoutVerifyAck → String
-
OutOfZec review: the distinct payout-verification acknowledgment (separate from the privacy ack).
no setter
- walletSwapPayoutVerifyTitle → String
-
OutOfZec review: the payout-address verification step title — the user's own foreign address where the swapped asset is sent.
no setter
- walletSwapPendingWindowPassedIntoZec → String
-
Tracking detail when the pending-deposit window already lapsed and the USER was the deposit sender (IntoZec). No refund promise — a deposit that arrived late is the provider's refund flow, handled by other states.
no setter
- walletSwapPendingWindowPassedOutOfZec → String
-
Tracking detail when the pending-deposit window already lapsed and the WALLET was the deposit sender (OutOfZec) — the honest dead-quote line replacing an eternal 'swap started'. Hedged: a late-sent deposit is refunded provider-side, so the claim is only about the not-sent case.
no setter
- walletSwapPickerEmpty → String
-
Token picker: the honest empty state (no assets after filtering).
no setter
- walletSwapPickerError → String
-
Token picker: a first-ever fetch failure with no cache.
no setter
- walletSwapPickerRetry → String
-
Token picker: retry button after a load error.
no setter
- walletSwapPickerSearchHint → String
-
Token picker: placeholder in the search field.
no setter
- walletSwapPickerStale → String
-
Token picker: the L6 serve-stale banner (the live fetch failed; cached data shown).
no setter
- walletSwapPickerTitle → String
-
Token picker sheet title for the IntoZec (Buy) direction — the SOURCE asset the user swaps FROM.
no setter
- walletSwapPickerTitleReceive → String
-
Token picker sheet title for the OutOfZec (Sell) direction — the TARGET asset the user receives (the shared picker is direction-neutral; the caller supplies the framing).
no setter
- walletSwapQuoteButton → String
-
Primary form action: request a bounds-checked quote.
no setter
- walletSwapQuoteExpired → String
-
Review screen: shown when the quote countdown reaches zero; Start swap is disabled.
no setter
- walletSwapQuoteExpiresUnderMinute → String
-
Screen-reader label for the review quote countdown once under 60 seconds (review M4): a dedicated sentence — composing 'less than a minute' into the {time} slot of walletSwapQuoteExpiresIn double-hedged ('about less than a minute') in every locale at the most time-critical spoken moment.
no setter
- walletSwapQuoting → String
-
Busy label while requesting a quote.
no setter
- walletSwapRefundHelper → String
-
IntoZec form: helper text clarifying the refund address is a foreign-chain address.
no setter
- walletSwapRefundHint → String
-
IntoZec form: the refund address field hint.
no setter
- walletSwapRefundInfoBody → String
-
IntoZec form: body of the refund-address explainer dialog (§3.3b D6).
no setter
- walletSwapRefundInfoTitle → String
-
IntoZec form: title of the refund-address explainer dialog.
no setter
- walletSwapRefundLabel → String
-
IntoZec form: the source-chain refund address field label.
no setter
- walletSwapRefundScanTooltip → String
-
IntoZec form: tooltip on the refund-address QR scan button (IZ-4; mobile only).
no setter
- walletSwapRefundVerifyAck → String
-
IntoZec review: the distinct refund-verification acknowledgment (separate from the privacy ack).
no setter
- walletSwapRefundVerifyBody → String
-
IntoZec review: the refund-address verification instruction.
no setter
- walletSwapRefundVerifyTitle → String
-
IntoZec review: the refund-address verification step title (§3.3b D6).
no setter
- walletSwapRemove → String
-
Tooltip/semantics label of the per-row remove affordance on the in-flight swap list (#367).
no setter
- walletSwapRemoveBodyDone → String
-
Confirm-dialog body when the row being removed already shows its pinned terminal outcome (#367) — plain list hygiene, nothing is lost.
no setter
- walletSwapRemoveBodyInFlight → String
-
Confirm-dialog body when the row being removed has NO observed terminal yet, OUT-OF-ZEC arm ONLY since #385 (#367 origin, hedge extended by #382): the watched leg IS this wallet's refund address, so 'stop watching for its refund' and the rescan-recovery claim are true. Removing drops the only re-attach handle AND stops the unresolved-swap watch (the per-sync re-arm keys off this record); a later refund is still recoverable by rescan — never silently lost (the refund address stays registered with the wallet's own engine). The IntoZec/unknown rows use their own bodies — every claim here is FALSE for IntoZec (UX HIGH-1).
no setter
- walletSwapRemoveBodyInFlightIntoZec → String
-
Confirm-dialog body for removing an UNRESOLVED IntoZec row (#385, UX HIGH-1 — the shared body lied to IntoZec users): the watched leg is the DELIVERY destination (this wallet's own engine-minted address), so the watch/rescan claims are about the incoming ZEC delivery; an IntoZec refund is the user's FOREIGN deposit returned on the source chain — this wallet never sees it and rescanning here can never find it, so the copy says where it happens instead.
no setter
- walletSwapRemoveBodyInFlightUnknown → String
-
Confirm-dialog body for removing an UNRESOLVED row whose direction this build doesn't recognize (forward-compat, #385): makes only the direction-independent claims — a watched leg is always one of this wallet's own engine-registered addresses (so the rescan claim holds), and no refund-location claim is made (it differs per direction).
no setter
- walletSwapRemoveCancel → String
-
Confirm-dialog dismiss action for the swap-row remove (#367).
no setter
- walletSwapRemoveConfirm → String
-
Confirm-dialog confirming action for the swap-row remove (#367).
no setter
- walletSwapRemoveTitle → String
-
Confirm-dialog title for removing an in-flight swap row (#367).
no setter
- walletSwapReviewTitle → String
-
Heading on the swap review/confirm screen.
no setter
- walletSwapRowOutcomeFailed → String
-
In-flight swap row line once a FAILED terminal was observed and pinned (#367). Soft wording — a deposited amount settles or refunds provider-side; the row must not assert loss.
no setter
- walletSwapRowOutcomeRefunded → String
-
In-flight swap row line once a REFUNDED terminal was observed and pinned (#367). A named outcome, not an error — details (where the refund went) are on the tracking view.
no setter
- walletSwapRowOutcomeSuccess → String
-
In-flight swap row line once a SUCCESS terminal was observed and pinned (#367) — the row stays until the user removes it or opens tracking and taps Done.
no setter
-
Address QR scanner screen: honest message when the camera can't start (permission denied / no camera) (shared brick).
no setter
- walletSwapScanCancel → String
-
Address QR scanner screen: the close-button tooltip (shared brick).
no setter
- walletSwapScanInstruction → String
-
Address QR scanner screen: the aiming hint / accessible label (shared brick).
no setter
- walletSwapScanManualEntry → String
-
Address QR scanner screen: the always-present escape button that returns to the type/paste field (shared brick).
no setter
- walletSwapScanTitle → String
-
Address QR scanner screen: app-bar title (shared by the IntoZec refund + OutOfZec destination scans).
no setter
- walletSwapsInFlightError → String
-
Honest error line when the durable in-flight swap list can't be read — never a silent hide (this list is the only wallet-side witness of a mid-flight swap).
no setter
- walletSwapsInFlightRetry → String
-
Inline retry button under the in-flight-swaps read-error line: re-pulls the list in place (the home has no pull-to-refresh, and this list is a swap's only wallet-side witness). Same 'try again' wording as the other read-error retries (walletReceiveRetry, walletSwapPickerRetry).
no setter
- walletSwapsInFlightRetryInProgress → String
-
The in-flight-swaps read-error retry button's label WHILE the re-pull is in flight (#407 R5) — the twin of walletParkedErrorRetryInProgress, and load-bearing for the same reason: the label change is what re-announces the retry to a screen reader. Keep it SHORT (it replaces 'Try again' inside a button beside a spinner).
no setter
- walletSwapSlippageCustom → String
-
Swap form: the custom-slippage chip.
no setter
- walletSwapSlippageCustomLabel → String
-
Swap form: the custom-slippage percent field label.
no setter
- walletSwapSlippageLabel → String
-
Swap form: the slippage control label (§3.3b D4).
no setter
- walletSwapSlippageMayFail → String
-
Swap form: advisory for a too-tight slippage tolerance.
no setter
- walletSwapSlippageNormal → String
-
Swap form: advisory for a normal slippage tolerance.
no setter
- walletSwapSlippageRisky → String
-
Swap form: advisory for a wide slippage tolerance.
no setter
- walletSwapSlippageTooHigh → String
-
Swap form: advisory for a slippage beyond the SDK hard ceiling.
no setter
- walletSwapSourceAssetHint → String
-
IntoZec form: the source-asset picker placeholder before an asset is chosen.
no setter
- walletSwapSourceAssetLabel → String
-
IntoZec form: the source-asset picker field label.
no setter
- walletSwapStartAnother → String
-
Secondary action on a still-tracking swap card (W-swap-5): return to the swap form to begin a new swap. The swap being tracked is NOT cancelled — it stays listed on the wallet screen — so the wording is 'another', not 'cancel' or 'new'.
no setter
- walletSwapStatusCheckingTitle → String
-
Tracking: the COLD-attach / first-load busy title, shown while the swap's status is being established and no answer has arrived yet — a fresh re-attach after process death (no carried state), or the moment just after execute before the first poll returns. Neutral BY DESIGN: 'Swap started' (walletSwapStatusPendingTitle) over-claims a state we have not confirmed (the swap may already be further along, or not yet started). The '…' is a real U+2026 ellipsis. (#347, cold-attach label)
no setter
- walletSwapStatusDetectedBody → String
-
Tracking body for the deposit-detected state.
no setter
- walletSwapStatusDetectedTitle → String
-
Tracking: the provider detected the deposit.
no setter
- walletSwapStatusFailedBody → String
-
Tracking body for the failed state (funds-safety honest).
no setter
- walletSwapStatusFailedTitle → String
-
Tracking: terminal failure.
no setter
- walletSwapStatusNotFoundBody → String
-
Tracking body for the not-found terminal (#367; last sentence added by #385, hedge sharpened by #386). Must NOT assert loss: a deposit that landed on an expired order is refunded provider-side to the recorded refund address; 'most likely expired' stays hedged (the provider can no longer tell us anything definitive). Since #385 this card's Done does NOT dismiss the still-unresolved record (MED-1ux — not-found is a heuristic, never pinned, and a silent dismiss voided the watch the overdue row had just promised), so the copy says the swap stays listed + watched and points at the list's Remove (which carries the full disclosure dialog). The watching claim is hedged 'in case it still arrives' (M-1, precision-fixed by #386: 'until it has arrived' PRESUPPOSED an arrival, but this card's own headline case — an expired order whose foreign-coin deposit is refunded provider-side on the source chain — never delivers ZEC here at all); a served leg (money arrived, then shielded/moved) stops the per-pass watch. ACCEPTED OVERCLAIM (#386, documented rather than gated): a pre-#368 upgrade-era record with no recorded watch leg (NULL watch columns, its one-shot backfill window spent) is NOT per-pass watched — its late ZEC is engine-registered and surfaces on a user-initiated full rescan only. That population is upgrade-era-only and shrinking; gating this sentence on watch presence would need a new DTO bit for a corner that retires itself. HEDGED (review M5): 'should refund' — this card's own premise is a GC'd order, the exact case that makes an unconditional refund promise false.
no setter
- walletSwapStatusNotFoundTitle → String
-
Tracking: the SDK's poll policy concluded the provider no longer recognizes this swap (#367 — several consecutive definitive not-found answers; most likely the order expired and was cleaned up provider-side).
no setter
- walletSwapStatusPendingBodyIntoZec → String
-
Tracking body for the pending-deposit state when the USER sends the deposit externally (IntoZec — a foreign coin from their own wallet, never ZEC from this one). Used ONLY within the issuing app run, where the deposit screen showed the instructions; a re-attached swap uses walletSwapStatusPendingBodyIntoZecReattached.
no setter
- walletSwapStatusPendingBodyIntoZecReattached → String
-
Tracking body for a RE-ATTACHED IntoZec pending-deposit swap (#367 — opened from the wallet-screen row after a restart or re-entry). The original body's 'send them before the quote expires' is impossible to follow here: the deposit address/memo are deliberately not stored, and they must NOT be re-shown (a memo-less deposit can lose funds on memo chains). Honest about both arms: already-sent (will be detected) and never-sent (let it expire, start fresh).
no setter
- walletSwapStatusPendingBodyOutOfZec → String
-
Tracking body for the pending-deposit state when the WALLET sends the deposit (OutOfZec). Honest across every state this screen can cover, tightened by #367 (UX MED-4 + reliability MED-2): 'briefly offline' + 'window is short' replace the old unbounded 'once you're back online' promise (false past ~11 min of the 15-min window), and 'stays yours … up to an hour to show as spendable' replaces 'stay in your wallet' (the locked-notes balance dip after a gate-caught miss). Keep both hedges.
no setter
- walletSwapStatusPendingTitle → String
-
Tracking: provider is waiting for the deposit.
no setter
- walletSwapStatusProcessingBody → String
-
Tracking body for the processing state.
no setter
- walletSwapStatusProcessingTitle → String
-
Tracking: the provider is processing the swap.
no setter
- walletSwapStatusRefundedBody → String
-
Tracking body for the refunded state when the USER sent the deposit (IntoZec, #367): the refund goes to the user's own refund address on the SOURCE chain — this wallet never sees it, so the body says where to look instead of the old placeless 'your funds were refunded'.
no setter
- walletSwapStatusRefundedBodyOutOfZec → String
-
Tracking body for the refunded state when the WALLET sent the deposit (OutOfZec; #368 replaced the #367 'may not appear yet' interim): the refund address is watched (refund-index registration), viewing this screen re-arms the watch, and since #382 EVERY sync pass re-arms it while the swap is unresolved — so 'shows up in your balance after the wallet next syncs' is mechanical for ANY absence length, not only within 48 h of executing. Keep the timing hedge ('can take a little while') — the provider's refund transaction must mine and a sync pass must run before the balance moves; never promise instant.
no setter
- walletSwapStatusRefundedTitle → String
-
Tracking: terminal refund (a named outcome, not an error).
no setter
- walletSwapStatusSuccessBody → String
-
Tracking body for the success state.
no setter
- walletSwapStatusSuccessTitle → String
-
Tracking: terminal success.
no setter
- walletSwapStatusUnderBody → String
-
Tracking body for the under-deposited state when the WALLET sent the deposit (OutOfZec) — the user cannot top up a wallet-sent deposit, so the body stays passive (completing or refunding provider-side).
no setter
- walletSwapStatusUnderBodyIntoZec → String
-
Tracking body for the under-deposited state when the USER sends the deposit externally (IntoZec, #367): unlike the OutOfZec arm the user CAN act — top up the missing amount — so the body says so, with the honest refund fallback.
no setter
- walletSwapStatusUnderTitle → String
-
Tracking: only a partial deposit has been received.
no setter
- walletSwapStatusUnknownBody → String
-
Tracking body for the unknown state.
no setter
- walletSwapStatusUnknownTitle → String
-
Tracking: a forward-compat status this build can't name (neutral, never alarming).
no setter
- walletSwapTargetAssetHint → String
-
OutOfZec form: the target-asset picker placeholder before an asset is chosen.
no setter
- walletSwapTitle → String
-
App-bar title of the swap screen.
no setter
- walletSwapTrackingError → String
-
Tracking: an establish-time typed failure (the stream can't be opened).
no setter
- walletSwapTrackingErrorBody → String
-
Body of the tracking ESTABLISH-failure card (review M1): its own body — the failed-status body ('The swap couldn't be completed') contradicted the title on a money claim; an establish failure says nothing about the swap's outcome and must not read as a failure verdict.
no setter
-
Tracking body when the host has killed swap (§3.5 — funds-safety honest). SINCE #382 UNREFERENCED by the package (both directions render their own honest kill body — the IntoZec/OutOfZec siblings); retained for the #347 l10n review to prune rather than churn 16 locales mid-GA.
no setter
-
IntoZec tracking: the §3.3b L8 honest killed-swap message (delivery arrives on the next sync).
no setter
-
OutOfZec tracking: the honest killed-swap message (#382 — the OutOfZec mirror of the IntoZec L8 body). Pre-#382 this arm said funds 'settle or refund on the provider's side' — a misdirect once #368 made refunds land at THIS wallet's own address (the provider would truthfully answer 'we already sent it back'). Mechanics: the kill clears the detection watch, but the refund address stays engine-registered and the unresolved-swap re-arm restores the watch on the first sync after swap is re-enabled — so the promise is mechanical, conditioned on swap being turned back on.
no setter
-
Tracking: swap was turned off, so live tracking stopped (§3.5 host kill state).
no setter
-
Honest state when swap is turned off at this build/instance (§3.5 host kill state).
no setter
-
Honest state when the swap screen has no live wallet session (defensive).
no setter
-
Swap screen reached (host deep-link) on a watch-only wallet (#397 §3.7 D3): the condition is PERMANENT for this wallet, so no 'right now' transience — view-only framing, no retry invitation.
no setter
- walletSwapViewSwap → String
-
Action label that re-opens live tracking for an in-flight swap — on the wallet-screen row and on the 'a swap is already in progress' fault (W-swap-5 #366).
no setter
- walletSwapYouReceiveLabel → String
-
Review line: the minimum guaranteed amount of the destination asset.
no setter
- walletSwapYouSendLabel → String
-
Review line: the exact ZEC amount leaving the wallet.
no setter
- walletSyncBadgeHint → String
-
Screen-reader tap hint on the sync badge row (the row opens the sync-detail sheet; the ⓘ icon carries the same affordance visually).
no setter
- walletSyncCatchingUp → String
-
Shown under the Scanning status during the opaque early phase (percent still rounds to 0) so the wallet reads as actively working, not stuck — explains WHY the sync is slow. No trailing period: it can precede another detail line in the joined a11y label. Says 'a deep initial sync' (not 'first sync') since a restore also hits this on a fresh device.
no setter
- walletSyncConnecting → String
-
Sync status: connecting, no bootstrap percent available.
no setter
- walletSyncDisabled → String
-
Sync badge headline when the HOST app's sync policy is off (#383 R1) — syncing is deliberately not running by the embedding app's own setting. Short; state, not an error.
no setter
- walletSyncDisabledDetail → String
-
Next step under the sync-off badge — points at the HOST app's settings (the package has no sync switch of its own). Keep 'this app's settings' generic; hosts name the screen differently.
no setter
- walletSyncEndpointBehind → String
-
Sync-status headline for SyncStatus.endpointBehind (T0-1c): the wallet scanned to THIS SERVER's reported tip, but that tip is below a block height the network had already passed before this version of the app was built — the server is behind the chain (a node still syncing, stuck or forked, or a server under-reporting its height). MUST NOT read as a plain 'Up to date': the balance shown alongside is current only as of that older block. Distinct from walletSyncUpToDateLimited (this app VERSION — says update) and walletSyncUpToDateDegraded (this server's POOLS — says switch); this one is about this server's HEIGHT and also says switch.
no setter
- walletSyncExplainConnecting → String
-
Sync-detail sheet explanation: the Connecting arm (incl. Tor bootstrap).
no setter
- walletSyncExplainDisabled → String
-
Sync sheet explanation for the sync-off state (#383 R1): says WHO turned it off (the app's settings, deliberately), carries the funds-safe reassurance its not-running siblings (ExplainStartFailed/ExplainOffline) carry, and is honest that the figures are the last synced state — never implies an error or that the package can turn it back on.
no setter
- walletSyncExplainEndpointBehind → String
-
Sync-detail sheet explanation paired with walletSyncEndpointBehind. The next step MUST be 'switch servers': never 'check your connection' (the link works — the pass completed) and never 'update the app' (that is the UpToDateLimited pair). Names both money consequences honestly and without claiming the user holds any: incoming payments after that block are not visible from this server, and a send built against this server's tip carries an expiry the real chain may already be past (it would expire and the funds return, not be lost). MUST NOT say the funds are lost or that anything needs restoring.
no setter
- walletSyncExplainIdle → String
-
Sync-detail sheet explanation: genuinely idle (loop not running, no start failure).
no setter
- walletSyncExplainOffline → String
-
Sync-detail sheet explanation: offline; leads with the funds-are-safe reassurance. The queued-sends clause names the SURFACE, never a drain schedule (#401 R1 — host custody cannot drain on a background pass); keep 'Saved & pending' in step with walletParkedTitle.
no setter
- walletSyncExplainScanning → String
-
Sync-detail sheet explanation: scanning. Reassures the user the app stays usable (maintainer: 'what's going on' behind the badge).
no setter
- walletSyncExplainStalled → String
-
Sync-detail sheet explanation: stalled; the typed walletStall* reason renders as its own paragraph underneath. The endpointUnreachable stall gets walletSyncExplainStalledOffline instead (#399).
no setter
- walletSyncExplainStalledOffline → String
-
Sync-detail sheet explanation for the endpointUnreachable stall only (#399): the calm normal-offline story — funds-safe reassurance, queued-sends-are-normal, automatic retry. Carries BOTH hedges itself ('if you're offline' conditional + the server-side possibility) because the sheet suppresses the walletStallEndpoint detail under this explanation (the near-identical-pair rule); the detail still rides the badge a11y label. The queued-sends clause names the SURFACE and no schedule (#401 R1 — host custody cannot drain on a background pass), and the retry sentence says CONNECTION explicitly so it can never be read as a promise about the send. Hard stalls keep walletSyncExplainStalled.
no setter
- walletSyncExplainStartFailed → String
-
Sync-detail sheet explanation when the sync START command itself failed (#356-F8): replaces the idle arm's 'starts automatically — no action needed', which would contradict the retry notice. Shown above the sheet's Try-again button.
no setter
- walletSyncExplainStarting → String
-
Sync-detail sheet explanation: the loop is up but hasn't reported a batch yet (the silent prep phase).
no setter
- walletSyncExplainUnknown → String
-
Sync-detail sheet explanation: the forward-compat arm — neutral syncing framing, never healthy or alarming.
no setter
- walletSyncExplainUnverified → String
-
Sync-detail sheet explanation paired with walletSyncUnverified; the grace's own line (walletSyncGraceLeft*/walletSyncGraceEnded*) renders beside it and OWNS the sending claim (running: a countdown; ended: a refusal) — this body makes NO claim about sending (fold of the security and crypto angles: it used to say 'sending keeps working for a short grace period', false once the grace has ended). The next step MUST be 'switch servers': never 'check your connection' (the link works — the pass reached the tip) and never 'update the app' (that is the UpToDateLimited pair; nothing was upgraded here). States honestly that the balance IS current (this server serves blocks; only its network claim is missing) — unlike the Limited and Degraded pairs, this is not a balance-is-a-floor state. Under a reported rewinding streak the sheet shows walletSyncExplainUnverifiedStreak instead. MUST NOT say 'upgraded' or 'update'.
no setter
- walletSyncExplainUnverifiedStreak → String
-
Sync-detail sheet explanation paired with walletSyncUnverified when the SDK reports streakReported: true on the grace claim (P3-12, maintainer): the loop has judged this server misbehaving (repeated rewinds — the endpointMisbehaving stall the grace outranks, P2-6). MUST NOT say the balance is current; names the rewinds and their consequence for the balance; makes NO claim about sending (the grace line beside it owns that — fold). The next step MUST be 'switch servers': never 'check your connection', never 'update the app'. MUST NOT say 'upgraded' or 'update'.
no setter
- walletSyncExplainUpToDate → String
-
Sync-detail sheet explanation: up to date.
no setter
- walletSyncExplainUpToDateDegraded → String
-
Sync-detail sheet explanation paired with walletSyncUpToDateDegraded. The next step MUST be 'switch servers': never 'check your connection' (the link works — the pass reached the tip) and never 'update the app' (that is the UpToDateLimited pair). Names the money consequence honestly (unspendable funds in that pool, balance is a floor) without claiming the user holds any. WHICH pool, and how, is the detail line under it — walletSyncPoolUnsupported / walletSyncPoolWithheld / walletSyncPoolHeightViolation / walletSyncPoolUnknown, one per affected pool (§4r U-3).
no setter
- walletSyncExplainUpToDateLimited → String
-
Sync-detail sheet explanation paired with walletSyncUpToDateLimited. Names both consequences honestly — possibly-invisible funds and unavailable memos — because either alone would understate it.
no setter
- walletSyncGraceEndedClock → String
-
The grace ENDED by the DEVICE CLOCK rule (GraceExpiry.clock; GRACE-1 §4p G-6): a day passed on this device's clock since the last confirmation, whatever the server's block height did — the axis a server that freezes its height cannot hold still — or the clock was set back after that day was seen (which does not re-open the grace). Shared by the sync detail line and the send-fault body. ONE next step — a server that reports the network version — with the device clock as its PRECONDITION, never an alternative (§4p-run fold review row 6, §4r U-5): a wrong clock is the one benign cause, but a corrected clock alone re-permits nothing (the latch holds until a branch-reporting server), so the copy MUST read 'if the date and time are wrong, fix them FIRST — then switch' and MUST NOT read 'switch, OR check the date and time'. MUST NOT say 'upgraded' or 'update the app'.
no setter
- walletSyncGraceNeverConfirmed → String
-
The grace never BEGAN (GraceExpiry.neverConfirmed; GRACE-1 §4p): every server this wallet has met withheld the network version, so the app has never confirmed it can send at all. Shared by the sync detail line and the send-fault body; also the forward-compat fallback for a grace shape this UI does not know. NOT the never-synced case (that is walletSendFaultNotSynced — wait for sync). Next step: SWITCH SERVERS. MUST NOT say 'upgraded' or 'update the app'.
no setter
- walletSyncIdle → String
-
Sync status: wallet open, loop about to start (transient — sync auto-starts).
no setter
- walletSyncIdleDetail → String
-
Next step under the idle sync status — sync runs on its own, there is no manual start.
no setter
- walletSyncOffline → String
-
Sync status: no connectivity.
no setter
- walletSyncOfflineDetail → String
-
Next step under the offline sync status; queued sends are normal, not errors. Promises no drain schedule (#401 R1 — the automatic-drain family): a host-custody background pass cannot sign at all, so this names the surface the send is safe on instead. Keep 'Saved & pending' in step with walletParkedTitle.
no setter
- walletSyncPausedMoneyNote → String
-
Shared money-surface qualifier appended to the SAVED-FOR-RETRY result bodies (send / partial / shield / move) when no background sync pass will run (#401 R1b + R5). Those bodies promise the wallet finishes the send on a later sync — true at every custody tier (the transaction is already signed) but only where passes HAPPEN. Deliberately CAUSE-AGNOSTIC: the drive is not running under BOTH the host's sync-off policy AND a failed sync start, and naming one remedy would be wrong for the other — the screen already carries the cause-specific line (the sync-off settings note, or the start-failed retry notice). Plural-safe and standalone (a full sentence); never claims failure, only the pause. Appended through walletSyncPausedJoin, never by a Dart string interpolation. It has a SECOND render site since #403 R2: the parked-sends section falls back to it when every row is mid-signature, because its own note names a Send now that is suppressed on those rows — this one names no affordance, which is exactly why it fits there.
no setter
- walletSyncRetry → String
-
Button on the sync-start-failed notice that re-attempts starting the sync loop.
no setter
- walletSyncScanningEarly → String
-
Sync status: the opaque early phase of a deep first sync where the note-fraction is still ~0 — a number-less headline (paired with an indeterminate bar + the catching-up detail) so a stuck-looking 'Scanning 0%' is never shown.
no setter
- walletSyncServerAppDefault → String
-
Picker: the row label for the host app's default server when it is not among the offered entries (choosing it forgets the remembered choice).
no setter
- walletSyncServerBusy → String
-
Picker refusal copy for WalletErrorKind.walletBusy in another phase (a rescan or a close in flight): retryable, nothing changed.
no setter
- walletSyncServerCancel → String
-
The switch and trust notice dialogs' dismiss action — nothing changes.
no setter
- walletSyncServerCheck → String
-
Picker: the action that probes the typed custom server (one round trip under the wallet's own Tor policy) WITHOUT switching.
no setter
- walletSyncServerChecking → String
-
Picker: the Check button's label while the probe is in flight (15 s budget).
no setter
- walletSyncServerContinue → String
-
The switch notice dialog's confirm action.
no setter
- walletSyncServerCustom → String
-
Picker: the expander that reveals the custom-address field (the maintainer's expert-user path — a regular user never opens it).
no setter
- walletSyncServerCustomHint → String
-
Picker: the custom-address field's hint — the shape the SDK's door accepts (https; http only for a local development server).
no setter
- walletSyncServerInUse → String
-
Picker: the trailing marker on the server row the wallet currently dials.
no setter
- walletSyncServerInvalidUrl → String
-
Picker refusal copy for WalletErrorKind.invalidEndpoint on a custom address (not https, a username or password in it, a path, too long, no host). ONE copy for every reason: the SDK's reason string is a static code the UI never echoes (the FFI rule — no matching on error text).
no setter
- walletSyncServerKeyHeaderLabel → String
-
Picker (ADR-0568): the label of the field for the header name the key goes in (e.g. x-api-key) — shown once a key is typed.
no setter
- walletSyncServerKeyHeaderNeeded → String
-
Picker (ADR-0568): inline copy when a key is typed without its header name.
no setter
- walletSyncServerKeyHide → String
-
Picker (ADR-0568): the key field's toggle — hide the typed key.
no setter
- walletSyncServerKeyInvalid → String
-
Picker refusal copy for WalletErrorKind.invalidEndpointAuth (ADR-0568): the SDK refused the key or its header (a header the transport owns, too long, not printable, padded, or a key for an http:// server). Never the address's copy — the kind tells them apart.
no setter
- walletSyncServerKeyLabel → String
-
Picker (ADR-0568): the label of the optional key field under a custom server's address — the key the user's own server needs. Obscured; never logged.
no setter
- walletSyncServerKeySaved → String
-
Picker (ADR-0568): shown beside the in-use custom server's host when the wallet holds a key for it. The key itself is never shown or returned.
no setter
- walletSyncServerKeyShow → String
-
Picker (ADR-0568): the key field's toggle — show the typed key.
no setter
- walletSyncServerNotOffered → String
-
Picker refusal copy for WalletErrorKind.syncServerNotOffered — a host bug (the picker renders only offered entries), kept honest rather than silent.
no setter
- walletSyncServerSheetTitle → String
-
Title of the sync-server picker sheet (P3-13) and of the switch notice dialog.
no setter
- walletSyncServerSwitching → String
-
Picker: the progress row while the switch runs (the sync loop stops and joins, the choice is written, the session is rebuilt over the same data).
no setter
- walletSyncServerSwitchNotice → String
-
The in-flight notice body while CONNECTING or SCANNING (before ANY switch): the cost (the pass in progress restarts on the new server), the reassurance (no rescan — balance, history and queued sends are untouched), and the honest caveat (the card may read pending until the new server's scan catches up — fold of the walk). At an up-to-date status the sheet shows walletSyncServerSwitchNoticeAtTip instead.
no setter
- walletSyncServerSwitchNoticeAtTip → String
-
The in-flight notice body at an UP-TO-DATE status (nothing is in progress): the switch reconnects; balance and history stay. fold of the walk's observation 2.
no setter
- walletSyncServerTrustNotice → String
-
The trust notice's body: what a sync server LEARNS and what it is TRUSTED with. Shown BEFORE the first probe of a custom server (the probe itself discloses the IP — the crypto audit's MEDIUM moved it from the switch to the Check step), never again for the same host in one picker session. Names the privacy consequence the sync guards cannot judge (IP unless Tor, the birthday range, the transparent addresses the wallet polls — the most wallet-identifying item, even under Tor — the txids it fetches for memo enhancement, the broadcasts; the security review widened it from three items to five) and the honesty consequence they do (balance and history as reported). MUST NOT claim the server can move funds — it cannot (no keys).
no setter
- walletSyncServerTrustNoticeKey → String
-
Trust notice addition (ADR-0568), shown when the user gives a key: a personal key lets the server tie every request, including payments sent on a fresh Tor circuit, to one account. MUST say it links payments to the wallet even over Tor.
no setter
- walletSyncServerTrustTitle → String
-
Title of the trust notice shown before a CUSTOM server is used for the first time (maintainer ruling 1: validate access, then tell the user they are trusting that server).
no setter
- walletSyncServerUnreachable → String
-
Picker refusal copy for WalletErrorKind.syncServerUnreachable when the user TYPED this address (the custom-URL field): the probe could not dial, timed out, or was refused — a gated server rejecting the key lands here too. Hedged like walletStallEndpoint: it MUST NOT say 'check your connection' alone — the server may be the down side. Nothing changed: the wallet stays on its current server. WHY IT NO LONGER STOPS AT 'check the address' (stage S1
copy, from thetruthre-adjudication): probe_oracle (wallet.rs) maps everything that is not a FAILED private dial onto this kind, and since stage S1 a private path that ACCEPTS the dial and then carries nothing no longer reports TorUnavailable — deliberately, because blaming the path for what cannot be separated from a wedged server is the over-claim the stage removed. So a censored path and a wedged server arrive here as the same error and the SDK cannot tell them apart; the address stays the first step (this reader typed it) but it is no longer the ONLY one. Its sibling walletSyncServerUnreachableOffered serves the reader who typed nothing.no setter - walletSyncServerUnreachableOffered → String
-
Picker refusal copy for WalletErrorKind.syncServerUnreachable when the address came from the APP'S OWN LIST (a predefined or default choice) rather than from the user — stage S1
copy. Same error, different reader: 'check the address' is dead advice for someone who typed nothing, and it is the sentence that would meet aRequiredwallet whose private path is being censored, where the address is the one thing that is certainly fine. The either/or is the point and must survive translation — the SDK cannot separate a wedged server from a path that accepts connections and carries nothing, and it does not guess; it names both causes and the two steps the reader can actually take. Names no transport (ADR-0547) and no policy (FR-32 (b)).no setter - walletSyncServerUse → String
-
Picker: the action that switches onto a custom server the probe verified; also the trust dialog's confirm action.
no setter
- walletSyncServerWrongNetwork → String
-
Picker refusal copy for WalletErrorKind.networkMismatch: the server answered and claims another network (testnet under a mainnet wallet). Not recoverable for THAT server; nothing changed.
no setter
- walletSyncSheetBlocksLeft → String
-
Label of the live remaining-blocks row in the sync-detail sheet (exact grouped count — the sheet is WHERE the big number belongs; the badge keeps the compact form).
no setter
- walletSyncSheetClose → String
-
Dismiss button of the sync-detail sheet (sibling of walletShieldClose/walletMoveClose). 'Close', not 'Done' (#356-NIT): the sheet is purely informational — 'Done' implies a completed action.
no setter
- walletSyncSheetConnection → String
-
Sync sheet: section header for HOW the wallet talks to the network (transport privacy + server).
no setter
- walletSyncSheetProgress → String
-
Label of the live scan-percent row in the sync-detail sheet.
no setter
- walletSyncSheetServer → String
-
Sync sheet Connection section: row label for the lightwalletd host the wallet connects to. Since P3-13 the row is a BUTTON when a session exists — it opens the sync-server picker (walletSyncServerRowSemantics is its a11y label).
no setter
- walletSyncSheetSyncedTo → String
-
Label of the tip row in the sync-detail sheet on EVERY reached-tip state (§4r U-2): plain up to date, and the qualified siblings — limited (this app version), degraded (this server's pools), unverified (this server's network claim) and behind (this server's height). The value is the exact grouped height the pass reached; on the behind state it is THIS SERVER's tip, and walletSyncSheetBehindBy follows it.
no setter
- walletSyncSpendableReady → String
-
Shown while scanning when funds are already spendable (spend-before-sync).
no setter
- walletSyncStalled → String
-
Sync status headline for a stalled (typed, renderable) state.
no setter
- walletSyncStartFailed → String
-
Honest, recoverable notice when the background sync loop's start command itself fails (rare); shown with a retry.
no setter
- walletSyncStarting → String
-
Sync status headline when the loop is started but hasn't reported a batch yet (the silent prep phase: reaching the server + fetching the commitment-tree roots and chain tip). Shown instead of the bare Idle 'Not syncing yet' so the wallet reads as actively connecting. NOTE: intentionally identical to walletSyncConnecting in English but a SEMANTICALLY DISTINCT state (host-side driving-Idle prep vs. the SDK's Connecting/Tor-bootstrap arm) — do not merge the two keys in translations.
no setter
- walletSyncStartingDetail → String
-
Detail line under the connecting/starting sync status explaining the prep phase before scanning begins.
no setter
- walletSyncTryNow → String
-
Button on the sync sheet's stalled arm (#399): retry the connection immediately instead of waiting out the automatic retry schedule (restarts the sync loop, which resets its backoff).
no setter
- walletSyncUnknown → String
-
Sync status: forward-compatibility arm rendered as a neutral syncing state.
no setter
- walletSyncUnverified → String
-
Sync-status headline for SyncStatus.upToDateUnverified (GRACE-1 §4p): the wallet scanned to the chain tip, but THIS SERVER will not say which version of the Zcash network it is on, so the app cannot confirm a payment it signs will be accepted; sending works for a short grace and is then refused. MUST NOT read as a plain 'Up to date'. Distinct from walletSyncUpToDateLimited (this app VERSION — says update; MUST NOT be conflated: nothing was upgraded here), walletSyncUpToDateDegraded (this server's POOLS) and walletSyncEndpointBehind (this server's HEIGHT); this one is about the server's NETWORK CLAIM and, like the last two, says switch. MUST NOT contain 'upgraded' or 'update'.
no setter
- walletSyncUnverifiedStreakDetail → String
-
Sync-detail line rendered directly under the grace line when the SDK reports streakReported: true on the grace claim (P3-12 fold, security review MEDIUM 1): the badge's screen-reader label is the headline plus the detail lines, so the streak the grace outranks reaches a user who never opens the sheet. Same next step, 'switch servers'; MUST NOT say 'update' or 'upgraded'.
no setter
- walletSyncUpToDate → String
-
Sync status: fully synced to the chain tip.
no setter
- walletSyncUpToDateDegraded → String
-
Sync-status headline for SyncStatus.upToDateDegraded (T0-1b): the wallet scanned to the chain tip, but THIS SERVER refused, withheld or misreported the subtree roots of one of Zcash's shielded pools, so funds received in that pool cannot be spent through it. MUST NOT read as a plain 'Up to date' — the balance shown alongside is a floor for that pool. Distinct from walletSyncUpToDateLimited (that one is about this app VERSION and says update; this one is about the SERVER and says switch).
no setter
- walletSyncUpToDateLimited → String
-
Sync-status headline for SyncStatus.upToDateLimited: the wallet scanned to the chain tip but this app version could not fully interpret every block, because the network runs consensus rules it does not implement. MUST NOT read as a plain 'Up to date' — the balance shown alongside is a floor, not a total.
no setter
- walletTitle → String
-
Wallet screen title.
no setter
- walletTorActive → String
-
Tor state chip: wallet traffic is riding Tor.
no setter
- walletTorActiveUnattested → String
-
Transport chip for TorRuntimeKind.dialer — an arbitrary byte-stream dialer a Rust host injected, which the SDK (net/dialer.rs) "never knows or names". FR-32 (a): this arm read "Tor active" in the PROTECTED tone until stage S1
copy, asserting onion routing for a path the SDK cannot attest (ADR-0547: the SDK has no predefined transport kinds and renders only what the host declared). It says what IS true — wallet traffic is riding the path the app supplied — and refuses the privacy claim; paired with walletTransportExplainUnverified in the caution tone. A Rust host that KNOWS what it injected says so through WalletHostTransport (label + protection), which wins over any SDK TorState.no setter - walletTorActiveUnverified → String
-
Tor state chip: traffic is on Tor but via a runtime this binding can't attribute; qualified, not a confident protected framing.
no setter
- walletTorBootstrapping → String
-
Transport chip: the private path is starting and wallet traffic waits for it. The NEUTRAL variant, used when the SDK has no name to show (nothing registered, or a runtime with no registry) — walletTorBootstrappingNamed carries the host's own name when there is one. Never says "Tor": the wallet names no transport the host did not name (ADR-0547, FR-30 (a)).
no setter
- walletTorFellBack → String
-
Tor state chip: policy preferred and Tor degraded to clearnet (visible, never silent).
no setter
- walletTorHostDirect → String
-
Transport chip: the host app's registered dialer declared its path EXPOSED (ADR-0547 exposure = exposed: a plain direct connection, or a forward proxy that passes the client address) — not private, the server sees the IP, whatever the host named it and whatever the isolation says. Neutral tone, paired with walletTransportExplainDirect.
no setter
- walletTorHostOtherTransport → String
-
The transport name substituted into walletTorHostPath / walletTorHostPathLinkable when the SDK has NO host name to show (the SDK's own unattributed rendering — an empty name never comes from a host, the crossing refuses it): the wallet never names a transport the host did not name (ADR-0547). Lower-case fragment that reads inside the parentheses.
no setter
- walletTorOff → String
-
Tor state chip: off by configuration.
no setter
- walletTorUnanswered → String
-
Transport CHIP for TorState.unanswered (stage S1
truth, FR-36): the path took the connection and no RPC has come back over it for the maintainer's minute while the wallet was trying. It states the two attested facts — the dial was accepted, nothing has answered — and blames neither side: the SDK cannot tell a blackholed path from a wedged server and never guesses (the either/or is spelled out in the sheet, walletTransportExplainUnanswered). The NEUTRAL variant, used when the SDK has no name to show; walletTorUnansweredNamed carries the host's own name when there is one. Never says "Tor" (ADR-0547). Deliberately NOT walletTorUnavailable's wording: that one means the path is genuinely down.no setter - walletTorUnansweredDirect → String
-
Transport chip for TorState.unanswered on a registered dialer whose descriptor declared its path EXPOSED (ADR-0547 exposure = exposed: the server sees the device's address). FR-44: the unanswered arm inherited Active's payload and not its honesty — it read the plain "connected — nothing coming back" sentence for an exposed path, so a state change silently dropped a privacy loss the Active chip had been disclosing (walletTorHostDirect). The name is discarded here exactly as it is on walletTorHostDirect: what matters is that the path is not private, whatever the host called it and whatever the isolation says. Paired with walletTransportExplainUnansweredDirect, caution tone.
no setter
- walletTorUnansweredUnattested → String
-
Transport chip for TorState.unanswered on the runtimes that declared NOTHING to branch on — TorRuntimeKind.dialer (an arbitrary byte-stream dialer a Rust host injected, which net/dialer.rs says the SDK "never knows or names") and TorRuntimeKind.unknown. It is walletTorUnanswered plus the refusal that walletTorActiveUnattested already makes for the SAME runtime while traffic is flowing. WHY IT EXISTS (crypto audit HIGH + the product pass, found independently): the unanswered arm sent these two runtimes to the bare walletTorUnanswered, so a path the SDK cannot attest read "Private path in use (privacy not verified)" while it carried and the STRONGER "Private path connected" once it went quiet — a user checking privacy at the moment the path stopped carrying read a bigger claim than while it was working. That is FR-44's defect class, sign-identical, on a different runtime; FR-32 (a) is the rule it breaks. Paired with walletTransportExplainUnansweredUnverified, caution tone. ExternalSocks5 keeps the unqualified walletTorUnanswered (the host named Tor by choosing that variant), as does the attested empty-name hostDialer. STILL OPEN, deliberately: whether the noun "private path" over-claims even with the parenthetical — that question is the same for this string and for walletTorActiveUnattested, and they must change together or not at all.
no setter
-
Transport chip: zero traffic — the path is GENUINELY DOWN. NARROWED at stage S1
truthto a dial that FAILED (refused, unreachable, a dial timeout, a NotReady/Retired/FAILED descriptor) plus the cases where there is no path at all (nothing registered, a registrant that declared its transport FAILED — ABI v3 health, ADR-0549). A dial the transport ACCEPTED and then carried nothing is NOT this state: it reads TorState.unanswered, because the SDK cannot separate a blackholed path from a wedged server and this chip would blame the path. The NEUTRAL variant, used when the SDK has no name to show; walletTorUnavailableNamed carries the host's own name when there is one. Never says "Tor" (ADR-0547, FR-30 (a)); names no policy (FR-32 (b)).no setter - walletTorUnknown → String
-
Tor state chip: forward-compatibility arm; privacy rule renders it as not protected.
no setter
- walletTransparentFundsAutoDenied → String
-
The sheet’s automation sentence while the host authorizer has declined automatic shielding for this session (the switch is ON but the loop is paused). Plain-factual; the manual Shield button on the balance card remains the recovery.
no setter
- walletTransparentFundsAutoOff → String
-
The sheet’s conditional automation sentence while auto-shield is OFF (shown even when the expert gate hides the switch, so a persisted OFF is never invisible).
no setter
- walletTransparentFundsIntro → String
-
Plain-factual intro of the transparent-funds sheet: the visibility facts ONLY. The auto-shield claim is the separate CONDITIONAL sentence (walletTransparentFundsAutoOn/Off) so the sheet never states automation that is switched off.
no setter
- walletTransparentFundsMenuItem → String
-
Overflow-menu entry opening the transparent-funds policy sheet (expert gate + auto-shield).
no setter
- walletTransparentFundsTitle → String
-
Title of the transparent-funds policy sheet.
no setter
- walletTransparentLabel → String
-
Label for the transparent (unshielded) portion of the balance — privacy-relevant, shown only when nonzero.
no setter
- walletTransparentNote → String
-
Honest note under a nonzero unshielded balance: BOTH the spendability truth (transparent funds count toward the total but not the spendable figure until shielded — the 'why is my total bigger than spendable' question must be answerable from the card itself, maintainer) AND the privacy truth (publicly visible until shielded).
no setter
- walletTransparentNoteWatchOnly → String
-
The transparent-funds note for a WATCH-ONLY wallet (#397 §3.7 D5): it keeps only the privacy truth (public on-chain) and drops the 'shield these to spend' framing, which a watch-only wallet cannot follow (no spending keys).
no setter
- walletTransportExplainBootstrapping → String
-
Sync sheet Connection explanation: the private path is starting. The NEUTRAL variant (no name to show); walletTransportExplainBootstrappingNamed names the host's transport when the descriptor does.
no setter
- walletTransportExplainDirect → String
-
Sync sheet Connection explanation: no privacy transport — a direct (clearnet) connection.
no setter
- walletTransportExplainFellBack → String
-
Sync sheet Connection explanation: Tor-preferred policy fell back to clearnet.
no setter
- walletTransportExplainHostProxy → String
-
Sync sheet Connection explanation: generic copy for a HOST-provided protective transport (e.g. xray/vless/VPN) when the host supplies no detail of its own.
no setter
- walletTransportExplainTor → String
-
Sync sheet Connection explanation: verified built-in Tor is active.
no setter
- walletTransportExplainUnanswered → String
-
Sync sheet Connection explanation for TorState.unanswered (stage S1
truth, FR-36). The either/or is the POINT and must survive translation: the SDK reports what its own RPCs saw over a connection whose arm it knows, and it never says WHY a ready path is not carrying — a blackholed transport and a wedged server look identical from here. TWO next steps for the two causes (the walletStallBirthdayInFuture discipline): another server for a wedged server, the app's network settings for the path. MUST NOT promise that nothing left in the clear — aPreferredwallet reads this too, and its next dial leaves for clearnet. The NEUTRAL variant (no name to show).no setter - walletTransportExplainUnansweredDirect → String
-
Sync sheet Connection explanation for TorState.unanswered on an EXPOSED registered path (FR-44). Two facts, in this order: the privacy verdict the descriptor decides (walletTransportExplainDirect's sentence, verbatim — the server sees the device's address) and then the unanswered either/or with its two next steps, which survive here unchanged because the state means the same thing whatever the exposure. The subject is "the connection", never "the private path": naming this path private is the FR-44 defect.
no setter
- walletTransportExplainUnansweredUnverified → String
-
Sync sheet Connection explanation for TorState.unanswered on a registered path whose EXPOSURE the host did not declare, or declared with a value this binding cannot read (FR-44). walletTransportExplainUnverified's verdict, verbatim, then the unanswered either/or with its two next steps. The Active family renders walletTransportExplainUnverified alone on the same payload; this is the same verdict with the state's own sentence after it.
no setter
-
Sync sheet Connection explanation: zero traffic — the path is unreachable, unregistered or declared FAILED. Carries the NEXT STEP (ADR-0549 D3) — a failed path is no longer a wait, so the sentence must not read as one. The NEUTRAL variant (no name to show). It says "IS REQUIRED" NOWHERE (FR-32 (b), stage S1
copy): TorState.Unavailable carries no policy and aPreferredwallet reaches it too — a registrant that declared its transport FAILED is a frequent producer — so the sentence states what is true (the path is not available and nothing is connecting) without asserting a setting the user may not have chosen. It makes no claim about clearnet either: since stage S1 aPreferredwallet leaves a FAILED path after the minute, so "nothing was sent in the clear" would be a promise this state cannot keep.no setter - walletTransportExplainUnverified → String
-
Sync sheet Connection explanation: an unverifiable/unknown transport state (privacy rule: never claim protection).
no setter
- walletTxDetailClose → String
-
Dismiss button of the transaction-detail sheet (sibling of walletShieldClose/walletMoveClose).
no setter
- walletTxDetailCopied → String
-
Snackbar confirmation after copying the transaction id.
no setter
- walletTxDetailCopyTxid → String
-
Button that copies the FULL transaction id (the row shows a shortened form).
no setter
- walletTxDetailDate → String
-
Label of the date row in the transaction-detail sheet (absolute, locale-aware).
no setter
- walletTxDetailFee → String
-
Label of the fee row in the transaction-detail sheet (shown only when the fee is known).
no setter
- walletTxDetailHeight → String
-
Label of the mined-height row in the transaction-detail sheet (shown only when mined).
no setter
- walletTxDetailMemo → String
-
Label of the memo row in the transaction-detail sheet (shown only when the tx carries one).
no setter
- walletTxDetailMemoAttached → String
-
Value of the memo row: the tx carries an encrypted memo (content is not yet fetchable through the SDK, so only its presence is shown).
no setter
- walletTxDetailStatus → String
-
Label of the status row in the transaction-detail sheet.
no setter
- walletTxDetailTxid → String
-
Label of the transaction-id row in the transaction-detail sheet.
no setter
- walletTxDetailVisibility → String
-
Label of the tx-detail row stating the transparency fact (value: walletActivityPublicBadge). Rendered only for transactions with a publicly visible output.
no setter
- walletTxExplainConfirmed → String
-
Plain-language explanation of the Confirmed status in the transaction-detail sheet (the depth rides the status row).
no setter
- walletTxExplainExpired → String
-
Plain-language explanation of the Expired status: cancelled, nothing withdrawn (the maintainer's 'what does expired mean' ask). The banner (walletTxFundsKept) carries the headline reassurance; this adds the mechanism.
no setter
- walletTxExplainFailed → String
-
Plain-language explanation of the Failed status: endpoint-rejected, nothing withdrawn.
no setter
- walletTxExplainPending → String
-
Plain-language explanation of the Pending status in the transaction-detail sheet (also the forward-compat Unknown arm, which renders as Pending). Shown for an unmined wallet-created row only once an endpoint ACCEPTED it (TxSummary.delivery accepted/null); a row the wallet is still retrying gets walletTxExplainRetrying instead, because 'sent to the network' is false for it.
no setter
- walletTxExplainQueued → String
-
Plain-language explanation of the Queued status in the transaction-detail sheet. Never 'waiting for a connection' (a send can be queued while ONLINE via the not-synced-yet path, and a queued row can be viewed during a non-network stall). Names NO drain schedule at all (#401 R1): at host custody the background pass holds no signing credential, so it points at the surface and the two real actions instead — the walletSendQueuedBody wording family. LATENT today: history.rs maps Queued rows out of the chain view, so this arm is unreachable; it is kept true so it cannot go live wrong.
no setter
- walletTxExplainRetrying → String
-
Plain-language explanation for a wallet-created, unmined row the wallet still owes a broadcast (TxSummary.delivery == retryPending, stage S8 obligation). Cause-agnostic (a transport miss, a blackholed private path, a kill between signing and sending). 'On each sync' — never 'as soon as you're online' (the #399 reconnect-promptness rule). The expiry clause is true: a transaction past its expiry height is never rebroadcast and the funds free again.
no setter
- walletTxExplainRetryingExpired → String
-
Detail-sheet explanation for a wallet-created row that reads Expired while the wallet still owes the payment (TxSummary.delivery == retryPending, S7 C1): the old transaction expired unmined and the wallet will re-send it once the expiry is safely buried. The row label stays 'Retrying'. The 'don't send it again yourself' clause is the point: a manual re-send pays twice.
no setter
- walletTxExplainSaved → String
-
Plain-language explanation for a wallet-created, unmined row whose bytes are kept without a retry promise (TxSummary.delivery == persisted — a swap deposit held past its quote's window). Makes no claim about automatic sending either way.
no setter
- walletTxExplainUnknown → String
-
Plain-language explanation of the forward-compat Unknown status: neutral — must never AFFIRM a broadcast (unlike walletTxExplainPending) nor claim cancellation, since the binding cannot interpret the state (security review).
no setter
- walletTxFundsKept → String
-
Prominent reassurance for an expired/failed transaction: the money-honest core fact (TxStatus.expired ⇒ funds returned to spendable; failed ⇒ endpoint rejected, nothing spent). Used in the detail-sheet banner and appended to the history row's screen-reader label.
no setter
- walletWatchOnlyAboutBody → String
-
Security-screen explanation for a watch-only wallet: it has no spending keys and nothing to back up.
no setter
- walletWatchOnlyBack → String
-
Return from the watch-only import screen to the welcome screen.
no setter
- walletWatchOnlyBadge → String
-
Short header badge marking a watch-only wallet (no spending keys).
no setter
- walletWatchOnlyBirthdayChange → String
-
Button to change the chosen watch-only start date.
no setter
- walletWatchOnlyBirthdayPick → String
-
Date-picker help text on the watch-only import screen.
no setter
- walletWatchOnlyBirthdayTitle → String
-
Heading of the required creation-date control on the watch-only import screen.
no setter
- walletWatchOnlyBody → String
-
Intro on the watch-only import screen: explains a viewing key gives view-only access and that a start date is needed.
no setter
- walletWatchOnlyButton → String
-
Welcome-screen action (#397) to import a watch-only wallet from a viewing key — it can see balance and history but cannot spend.
no setter
- walletWatchOnlyFaultAlreadyExists → String
-
Inline fault when a wallet already exists and a watch-only import was attempted over it.
no setter
- walletWatchOnlyFaultBirthdayTooRecent → String
-
Inline fault when the chosen watch-only start date is above the chain tip.
no setter
- walletWatchOnlyFaultInvalidKey → String
-
Inline fault when the entered string is not a valid unified viewing key. MODE-NEUTRAL wording: the key may have been pasted OR scanned from a QR, so it must not say 'paste again'.
no setter
- walletWatchOnlyFaultNetworkMismatch → String
-
Inline fault when a well-formed viewing key is for the wrong network (mainnet vs testnet).
no setter
- walletWatchOnlyKeyHint → String
-
Placeholder hint showing the expected viewing-key prefix.
no setter
- walletWatchOnlyKeyLabel → String
-
Label for the text field where the user pastes the unified viewing key.
no setter
-
Shown on the QR reader when the camera cannot start (permission denied / no camera); the manual-entry escape button is always present. Mirrors walletSwapScanCameraUnavailable.
no setter
- walletWatchOnlyScanFilled → String
-
Screen-reader announcement (not visible on screen) made after a QR scan fills the viewing-key field, so a non-sighted user knows the scan landed. NEVER contains the key itself. Keep it short and past-tense.
no setter
- walletWatchOnlyScanHint → String
-
A muted one-line hint under the viewing-key input field, shown only on camera platforms (Android/iOS). Points the user at the scan icon so the QR-scan affordance is discoverable when the body copy is paste-first. Keep it short.
no setter
- walletWatchOnlyScanInstruction → String
-
Aiming hint overlaid on the camera preview when scanning a viewing key. Mirrors walletSwapScanInstruction.
no setter
- walletWatchOnlyScanManualEntry → String
-
The always-present escape button on the viewing-key QR reader — returns to the import form to PASTE the key. The viewing-key counterpart of walletSwapScanManualEntry ('Enter manually'); a viewing key is pasted, not typed, so this must say paste, matching walletWatchOnlyScanCameraUnavailable.
no setter
- walletWatchOnlyScanTitle → String
-
App-bar title of the full-screen QR reader when scanning a viewing key.
no setter
- walletWatchOnlyScanTooltip → String
-
Tooltip/a11y label of the camera-scan icon button on the viewing-key field (mobile only).
no setter
- walletWatchOnlySectionTitle → String
-
Security-screen section header shown instead of the backup section for a watch-only wallet.
no setter
- walletWatchOnlySubmit → String
-
Confirm action that imports the watch-only wallet from the pasted viewing key.
no setter
- walletWatchOnlyTitle → String
-
Heading on the watch-only import screen.
no setter
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
securityDeleteRefusedBusySnack(
int seconds) → String - Security screen: snackbar shown when a delete is REFUSED because a sync-server switch is still in flight (S2 M01 — a delete never races a switch). Names the wait: {seconds} is the switch timeout, after which a delete is accepted again.
-
toString(
) → String -
A string representation of this object.
inherited
-
walletActivityConfirmations(
int count) → String - Confirmation depth of a mined history row.
-
walletAmount(
String amount) → String - A ZEC amount with its unit; amount is pre-formatted by integer math (never a float).
-
walletAutoShieldToggleDescription(
String minZec) → String - Subtitle under the auto-shield switch. {minZec} is the already-formatted minimum amount (e.g. "0.001").
-
walletBalanceHeaderAsOf(
String height) → String - Balance card header when the chain height the balance reflects is known — the as-of block rides IN the header (maintainer), never a separate floating row. The height arrives PRE-GROUPED (exactBlockCount — same format as the sheet's figure rows).
-
walletBalanceHeaderAsOfAt(
String height, String time) → String - Balance card header when BOTH the as-of height and its stamp time are known — one line, never a second row (maintainer: no per-state layout shift). Height arrives pre-grouped; time pre-formatted.
-
walletBalanceHeaderAt(
String time) → String - Balance card caption (maintainer): the time the balance is as of — just the time when today, date and time otherwise. One short line on a small phone; the block height lives in the sync sheet.
-
walletCountdownHoursMinutes(
int hours, String minutes) → String - Countdown magnitude past an hour (e.g. '1h 05m'; {minutes} arrives zero-padded). Localize the unit forms per locale (review F2).
-
walletCountdownMinutes(
int minutes) → String - Countdown magnitude at minute granularity, composed into the countdown sentences' {time} slot (review F2: unit forms live in the ARB so each locale renders its own — the first cut hardcoded Latin 'min' into all 16 locales' spoken labels). Floored minutes — never overstates a money window.
-
walletCountdownSeconds(
int seconds) → String - Countdown magnitude under a minute (visual; the a11y label uses walletCountdownUnderMinute / the dedicated quote sentence). Localize the unit per locale (review F2).
-
walletInFlightNote(
num count, String amount) → String - The durable in-flight two-step cue (#309): first leg broadcast, send not complete — money in motion through a wallet-controlled one-time address. Repeats the permanently-true 'don't re-send' after the result screen is dismissed; cause-agnostic + locational; NO auto-completion promise. Plural: each in-flight send uses its OWN one-time address, so N>=2 must not say 'a one-time address' / 'it'. amount is the pre-formatted aggregate and annotates the same pending payments the activity list shows. TERM (D2, #347): 'set aside for' / 'are set aside' replaced 'committed' — the safety term must NEVER read as blockchain-CONFIRMED, and never as STUCK; the 15 locales were already normalized to reserved/allocated, so EN now ratifies them.
-
walletInFlightNoteSyncPaused(
num count, String amount) → String - walletInFlightNote's variant when NO background sync pass will run (re-keyed and renamed by #403 R4). The second leg forwards only on sync passes, so 'still completing' would claim progress and then negate it — this variant says 'partway through … paused' as one coherent story. Renamed from ...SyncOff and made CAUSE-AGNOSTIC for the same reason as its three re-keyed siblings (walletParkedPreparingHintSyncPaused, walletParkedAuthorizeSentSyncPaused, walletParkedSyncPausedNote): the drive is also not running after a FAILED sync start, where the host policy still reads on and 'syncing is off in this app's settings' is simply the wrong remedy — the screen's own sync notice carries the cause. Match walletSyncPausedMoneyNote's condition wording. Keep the D2 'set aside' term and the identical don't-send-again instruction; same plural rule and placeholders as the sibling.
-
walletInfoButtonLabel(
String label) → String - Screen-reader name of the (i) button after a label; opens the explanation that used to sit on screen (S13). label = the label the button follows, verbatim.
-
walletMoveAvailable(
String amount) → String - Spendable shielded-balance hint above the move amount field; integer-formatted (never a float).
-
walletMoveAvailableCatchingUp(
String amount) → String - Variant of walletMoveAvailable while the wallet is still catching up (#381, the #380 swap-line rule): the spendable figure is the partial repopulating balance, so a low/zero figure must not read as final.
-
walletMoveBelowFloorNote(
String amount, String floor) → String - Orange note on the move-to-transparent review when the move leaves the PUBLIC balance (what is already public at the shield source plus this move) under the core's shield floor (stage S14, maintainer copy): no Shield, manual or automatic, can take it until more arrives. Replaces the auto-shield note in that case.
-
walletParkedCancelSemanticTimed(
String amount, String time) → String - Screen-reader label for a parked row’s Cancel button — binds the action to its amount AND save time so same-amount rows never read identically.
-
walletParkedRowPausedTimed(
String amount, String time) → String - One PAUSED parked-send row (#315): the committed amount plus the locale-formatted save time. The 'paused' word is the row-level honesty split from the healthy 'saved & pending' — a paused payment never sends on its own (walletParkedPausedHint carries the explanation).
-
walletParkedRowPreparingTimed(
String amount, String time) → String - One MID-SIGNATURE parked-send row (#400 R2, ParkedSend.sending): the wallet claimed this payment and is building the transaction — or was, until the app was killed during that step (an OOM while proving is the common mobile case). Before this row existed such a payment was on NO surface at all, which is the double-pay shape the whole section exists to prevent. Say PREPARING: nothing failed (never 'failed') and nothing was broadcast (never 'sent'/'on its way'). walletParkedPreparingHint carries the rest.
-
walletParkedRowTimed(
String amount, String time) → String - One saved & pending (parked) send row: the committed amount plus the locale-formatted save time (the discriminator between two same-amount rows).
-
walletParkedSendNowInProgressSemanticTimed(
String amount, String time) → String - Screen-reader label for the Send now button WHILE its spend bracket is open (#401 R3c). The visible label shortens to 'Sending…', and the in-flight semantic label used to fall back to that bare string — which re-introduces exactly the collision the timed labels exist to prevent: two parked rows with the same amount become two identical 'Sending…' nodes, and the one the user actually authorized is no longer identifiable. Keep the amount + save-time binding through the in-flight state. Present tense, because the signature is happening now.
-
walletParkedSendNowSemanticTimed(
String amount, String time) → String - Screen-reader label for a row’s Send now button — binds the action to its amount AND save time so same-amount rows never read identically (mirrors the Cancel semantic label). Used on healthy AND paused rows alike (see walletParkedSendNow).
-
walletPaymentReceived(
int count) → String - Transient arrival cue (SnackBar; also announced by screen readers) shown when the live incoming-funds stream reports new confirmed arrivals (maintainer decision — the minimal option). DELIBERATELY amount-free: the event payload carries no amount by design (ADR-0536); details are one tap away in the activity list.
-
walletPoolShielded(
String amount) → String - Balance-card pool-clarity line (#389), private-pool segment: the shielded (private) portion of the total, shown always-on directly under the headline so 'how much of my ZEC is private?' is answerable at a glance. amount is a pre-formatted BARE ZEC figure (NO unit) — the unit rides the headline right above, and shielded + transparent sum EXACTLY to it (shielded = total − transparent), so the bare numbers can never disagree with the total. Keep it short: it shares ONE line with the transparent segment. 'Shielded' is the same privacy term used across the card; translate it as the sibling walletTransparentLabel does.
-
walletPoolTransparent(
String amount) → String - Balance-card pool-clarity line (#389), public-pool segment: the transparent (unshielded, publicly-visible-on-chain) portion, rendered in the same privacy-orange the rest of the card uses for transparent funds. amount is pre-formatted BARE ZEC (unit on the headline). Keep it short (shares one line with the shielded segment). Match the 'transparent/unshielded' wording of the sibling walletTransparentLabel.
-
walletRecoverableEphemeralConfirmingNote(
String amount) → String - As walletRecoverableEphemeralNote, but the amount is not yet reorg-final (still confirming) — shown as pending recovery, never settled/ready. amount is pre-formatted.
-
walletRecoverableEphemeralNote(
String amount) → String - Note under the transparent line: part of the unshielded funds sits on a wallet-controlled one-time (ephemeral) address and is reorg-final/recoverable. SUBSET of the balance, never added on top. Cause-agnostic (an exchange return as much as an expired transfer), so never 'stranded'/'bounced'. amount is pre-formatted.
-
walletRecoverableEphemeralNoteWatchOnly(
String amount) → String - The recoverable-ephemeral note for a WATCH-ONLY wallet (#397 §3.7 D3): keeps the locational fact but DROPS the '(recoverable)' claim — recovery mints a self-send (a spend) a watch-only wallet cannot do, and its reclaim affordance is hidden. amount is pre-formatted.
-
walletRecoverDone(
String amount) → String - Snackbar after recovery accepted ALL funds cleanly. The amount is provisional (accepted, not yet confirmed) so the copy says 'recovering'. amount is pre-formatted.
-
walletRecoverDonePartial(
String amount) → String - Snackbar after recovery accepted SOME funds but had per-address faults or hit the per-run cap (swept > 0 AND (failed > 0 OR truncated > 0)). Reports the provisional recovered amount AND honestly flags that work remains — never hides the remainder. amount is pre-formatted.
-
walletRescanEstimate(
String blocks) → String - Size cue under the rescan range control — the approximate number of blocks the chosen range covers, so the duration warning has a visible magnitude. Pre-formatted compact count (e.g. "1.6M").
-
walletRescanRangeChosen(
String date) → String - Description shown when a rescan start date is chosen.
-
walletRescanRebuildingFrom(
String date) → String - Activity-section cue while a dated rescan repopulates.
-
walletRestoreBirthdayChosen(
String date) → String - Shown when a creation date is set (the ~6-months-ago default). States the exclusion as a FACT and names both escape hatches (earlier date / full scan).
-
walletRestoreFaultInvalidWord(
int index) → String - Inline restore error when one word isn't in the BIP39 list; index is 1-based.
-
walletRestorePillSemantics(
int index, String word) → String - Screen-reader label for a recovery-word pill (valid word).
-
walletRestorePillSemanticsInvalid(
int index) → String - Screen-reader label for a recovery-word pill that isn't a BIP39 word. Deliberately OMITS the typed value: an invalid token carries no verification value to read back, and keeping it out of the OS accessibility tree avoids echoing a mistyped recovery word to assistive/automation services (security HARDENING).
-
walletRestoreRemoveWord(
int index) → String - Screen-reader label for the × that removes a recovery-word pill.
-
walletRestoreSomeWordsInvalid(
int count) → String - Live cue when one or more entered words aren't in the BIP39 list (shown as error-coloured pills).
-
walletRestoreWordCount(
int count) → String - Live count of recovery words entered.
-
walletSendAvailable(
String amount) → String - Spendable-balance hint above the send form; amount is integer-formatted (never a float).
-
walletSendAvailableCatchingUp(
String amount) → String - Variant of walletSendAvailable while the wallet is still catching up (#381, the #380 swap-line rule): the spendable figure is the partial repopulating balance, so a low/zero figure (incl. the post-'Send another' refresh) must not read as final.
-
walletSendFaultInsufficient(
String available, String required) → String - Form fault: insufficient funds. Figures are integer-formatted; never logged (§5.4).
-
walletSendFaultInsufficientPending(
String pending) → String - Form fault detail: pending-incoming funds shown alongside an insufficient-funds error. 'Once the wallet catches up', NOT 'once it confirms': the amount is most often a note with thousands of confirmations that is held only until more of the chain is scanned (witness unavailable), so 'confirms' was false for the common case (phase-2 P2-4, maintainer decision 3).
-
walletSendFaultOverCeiling(
String limit) → String - Form fault: the amount exceeds the HOST's policy send ceiling (walletSendCeilingZatProvider, e.g. an alpha roll-out cap). Honest app-policy phrasing — the amount itself is valid.
-
walletSendLargeConfirmAction(
String amount) → String - The irreversible confirm action in the large-send dialog; carries the exact amount so it is unmistakable at the moment of confirming.
-
walletSendMachineMemoPurpose(
String purpose) → String - The host-supplied purpose sentence, rendered verbatim in the machine-memo disclosure.
-
walletSwapAvailable(
String amount) → String - Spendable-balance hint above the swap form; amount is integer-formatted.
-
walletSwapAvailableCatchingUp(
String amount) → String - Variant of walletSwapAvailable while the wallet is still catching up (#380): the spendable figure is the partial repopulating balance, so a low/zero figure must not read as final.
-
walletSwapDepositExpiresIn(
String time) → String - IntoZec deposit screen: the live deadline countdown.
-
walletSwapDepositInstruction(
String amount, String asset, String chain) → String - IntoZec deposit screen: the send instruction.
-
walletSwapDestinationHelperChain(
String chain) → String - OutOfZec form: chain-aware helper for the destination field once a target asset is picked (cross-chain mistakes lose funds).
-
walletSwapDestinationLabelChain(
String chain) → String - OutOfZec form: the destination field label once a target asset is picked, naming its chain.
-
walletSwapFaultInsufficient(
String needed, String spendable) → String - Spendable pre-check refusal at quote review (#367): the deposit plus a conservative network-fee allowance exceeds what is spendable. 'about' is load-bearing — the needed figure includes an allowance, not the exact fee. Amounts are locale-formatted ZEC decimals.
-
walletSwapFaultInsufficientCatchingUp(
String needed, String spendable) → String - The catching-up variant of walletSwapFaultInsufficient (#367): the wallet is mid catch-up/rescan, so the spendable figure may be partial — the closing hedge stops the refusal reading as a final verdict over a partial figure. Keep the hedge conditional ('may'), never a promise.
-
walletSwapFaultOverCeiling(
String limit) → String - Swap form: the host's FR-23 alpha ceiling bounds the swap deposit; stated as an app restriction, never as an invalid amount (#364 S6 — its own key: the send form's 'limits sends' copy misread on a swap form).
-
walletSwapForeignAmountLabel(
String symbol) → String - IntoZec form: the foreign amount field label once an asset is picked.
-
walletSwapForeignValue(
String amount, String asset) → String - Review: a foreign amount + asset, e.g. the IntoZec 'you send' line.
-
walletSwapInFlightStarted(
String time) → String - In-flight swap row time stamp. {time} is a locale-formatted DATE AND TIME (month, day, and clock time — since #382 an UNRESOLVED row is unbounded in age, no longer capped at ~48h, so the date matters), so keep the sentence grammatical with a full datetime, NOT a bare clock time (no preposition that only reads for a time-of-day). Known display bound (#377): the compact format carries no YEAR, so a >1-year-old unresolved row reads year-less — the shared Activity-row idiom.
-
walletSwapIntoZecFloorNote(
String zec, String slippage) → String - IntoZec review: the honest guaranteed-minimum / max-cost line (§3.3b L8).
-
walletSwapPayoutVerifyBody(
String asset) → String - OutOfZec review: the payout-address verification instruction. {asset} is the asset label, e.g. "USDC on Ethereum".
-
walletSwapPendingWindowEndsAt(
String time) → String - Tracking detail under the pending-deposit body (W-swap-5 #366-e): the quote's deposit window, so a pending swap is never open-ended on screen. {time} is a locale-formatted DATE AND TIME (month, day, and clock time — a swap window can cross a day boundary), so keep the sentence grammatical with a full datetime, NOT a bare clock time (e.g. no preposition that only reads for a time-of-day).
-
walletSwapPickerNoMatch(
String query) → String - Token picker: shown when the search query matches no asset.
-
walletSwapQuoteExpiresIn(
String time) → String - Review screen: the live quote countdown while time remains. Since #367 the SDK's expiresAt is the ACTIONABLE deadline (display and the execute gate share one number), so the sentence may promise confirmability up to it; 'about' hedges only device-clock skew. Do NOT use wording that guarantees the quote past the shown time.
-
walletSwapReceiveValue(
String amount, String asset) → String - Formatted receive figure: the provider's decimal min-out amount and the asset label.
-
walletSwapRefundHelperChain(
String chain) → String - IntoZec form: chain-aware helper for the refund field once a source asset is picked.
-
walletSwapRefundLabelChain(
String chain) → String - IntoZec form: the refund field label once a source asset is picked, naming its chain.
-
walletSwapsInFlightTitle(
int count) → String - Wallet-screen section header for the durable in-flight swap list (W-swap-5 #366).
-
walletSwapSlippagePercent(
String value) → String - Swap form: a slippage preset/value rendered as a percent.
-
walletSwapStatusUnderDetail(
String received, String missing, String time) → String - Tracking detail under the under-deposited body (#367 — these DTO fields existed and were never rendered): the provider's received/missing amounts as DECIMAL STRINGS in the deposit asset's units (render verbatim — never re-computed host-side) and the top-up deadline. {time} is a locale-formatted DATE AND TIME (month, day, and clock time — the window can cross a day boundary), so keep the sentence grammatical with a full datetime, NOT a bare clock time (no preposition that only reads for a time-of-day).
-
walletSwapTokenLabel(
String symbol, String chain) → String - Token picker: a source asset's display label (symbol + chain, both uppercased).
-
walletSyncConnectingPercent(
int percent) → String - Sync status: connecting with a Tor bootstrap percent.
-
walletSyncGraceEndedBlocks(
String blocks) → String - The grace ENDED by the block rule (GraceExpiry.blocks; GRACE-1 §4p G-6): the chain advanced a day's worth of blocks since the app last confirmed, with a server that reports its network, that it can send — and this server never said. ONE sentence shared by the sync-status detail line, the send-fault body (RW-SYNC-003) and nothing else, so the three never disagree. blocks is the count since that confirmation, pre-formatted compactly. The next step is SWITCH SERVERS. MUST NOT say 'upgraded' or 'update the app' (that is walletSendFaultNetworkUpgrade — a different fault with a different fix) and MUST NOT imply funds are at risk.
-
walletSyncGraceLeftBlocks(
String blocks) → String - walletSyncGraceLeftHours's variant when the SDK hands NO time — the device clock cannot be trusted for the grace (it reads before the last confirmation), so the block rule alone decides and only the blocks are shown (GRACE-1 §4p G-4; this is the same string set, not a new case). blocks is pre-formatted compactly (e.g. "1.2K"). MUST NOT say 'upgraded' or 'update'.
-
walletSyncGraceLeftHours(
int hours) → String - Detail line under walletSyncUnverified while the grace RUNS and the device clock can be trusted for it: how long sending keeps working. hours is the whole hours left on whichever of the two grace rules (blocks, device clock) runs out FIRST — the SDK already converted the blocks through the network's block spacing, so this is one figure; 0 renders as 'less than an hour'. The next step ('then switch servers') rides in the sentence. MUST NOT say 'upgraded' or 'update'.
-
walletSyncPausedJoin(
String body, String note) → String - THE JOINER, and the separator is the locale's business (#403 R6). walletSyncPausedQualified appends walletSyncPausedMoneyNote to a money body, and doing it with a Dart '$body $note' inserts a U+0020 after a fullwidth full stop (。) in ja and zh, which is wrong typography in both — this package already ADJUDICATED that exact pattern once, in, and abandoned it. TRANSLATORS: this string contains NO words. Emit the two placeholders verbatim in the order the locale's sentence flow requires, with whatever separator that language uses between two complete sentences: a single space for the space-delimited languages, and NOTHING AT ALL for ja/zh (both fragments already end in their own 。). Never add punctuation of your own — both fragments are already terminated. RTL (ar/he) keeps the single space: both fragments are strong-RTL and period-terminated, so the plain join is correct there.
-
walletSyncPoolHeightViolation(
String pool) → String - Sync-detail line for ONE shielded pool whose service was PoolService.heightViolation — this server served subtree completion heights that cannot be true and the wallet refused to record them; the server ANSWERED and the answer was wrong (§4r U-3). Same placement and rules as walletSyncPoolUnsupported. 'Misreporting', matching the explanation's 'misreporting'. MUST NOT say 'empty' or 'unknown pool'.
-
walletSyncPoolUnknown(
String pool) → String - Sync-detail line for ONE shielded pool whose service is PoolService.unknown — the bridge's forward-compatibility arm (a state this version of the UI does not know; only under core/bridge version skew). Rendered as unknown, NEVER as healthy (spec §3.3 unknown handling) — the pool still counts as degraded. Same placement as walletSyncPoolUnsupported.
-
walletSyncPoolUnsupported(
String pool) → String - Sync-detail line (and badge a11y label) for ONE shielded pool whose service on the last pass was PoolService.unsupported — this server does not know the pool at all (an older lightwalletd), so funds received in it cannot be spent through this server (§4r U-3, closing §4j row 8 by rendering). One line per affected pool, under the explanation of walletSyncUpToDateDegraded, walletSyncEndpointBehind or walletSyncUnverified; NO line for a pool served normally. pool is the pool's name (walletPoolSapling / walletPoolOrchard / walletPoolIronwood). 'Refuses', matching walletSyncExplainUpToDateDegraded's 'refusing'. MUST NOT say the pool is empty and MUST NOT say funds are lost; the next step (switch servers) is in the explanation above it.
-
walletSyncPoolWithheld(
String pool) → String - Sync-detail line for ONE shielded pool whose service was PoolService.withheld — this server served FEWER completed subtree roots than the wallet can prove the pool already has (from the signed data the app ships with), so funds received in the part it did not serve cannot be spent through this server (§4r U-3). Same placement and rules as walletSyncPoolUnsupported. 'Withholding', matching the explanation's 'withholding'. MUST NOT say the pool is empty.
-
walletSyncScanning(
int percent) → String - Sync status: scanning blocks, monotonic percent complete.
-
walletSyncScanRemaining(
String count) → String - Compact blocks-left count shown on the SAME ROW as the Scanning percent once a real percent exists (counts down). count is pre-formatted compactly, e.g. "1.6M".
-
walletSyncServerFallbackNotOffered(
String host) → String - Banner on the sync sheet's Server row and the picker when the REMEMBERED choice names a server this app version no longer offers (SyncServerFallback.choiceNotOffered): the default is in use, said, never silent. host = the server now in use.
-
walletSyncServerFallbackRefusedByTransport(
String host) → String - Banner for SyncServerFallback.choiceRefusedByTransport (FR-29 E12): the remembered CUSTOM server is an unencrypted http:// address, which only the SDK's own direct connection may carry — under the app's private path the default is in use, the choice is kept. host = the server now in use.
-
walletSyncServerFallbackUnreadable(
String host) → String - Banner for SyncServerFallback.choiceUnreadable (a malformed remembered choice): the wallet is usable on the default; pick again to replace it. host = the server now in use.
-
walletSyncServerRowSemantics(
String host) → String - Screen-reader label of the sync sheet's Server row when it opens the picker (P3-13). host is the lightwalletd HOST in use (never a full URL).
-
walletSyncServerSwitchFailedRecovered(
String host) → String - Picker notice after a switch failed PAST the point of no return and the wallet was recovered by re-opening (the rescan's recover-by-reopen). Names the server actually in use after the re-open (the new one if the choice landed, the previous one otherwise). Funds and history are untouched either way.
-
walletSyncSheetBehindBy(
int count, String blocks) → String - One-cell figure row in the sync-detail sheet under walletSyncSheetSyncedTo on SyncStatus.endpointBehind (§4m #5, §4r U-2): how far behind the network this server is, AT LEAST. count is newestKnown - tip — the newest height this wallet knows the chain reached (a public constant of the app, or its own last scanned height less the reorg allowance) less this server's tip — which is a LOWER BOUND on the server's lag, never the gap itself, so the copy MUST keep 'at least' in every plural case. blocks is the same number pre-formatted as an exact grouped count (e.g. "12,345" — the sheet's vocabulary; the badge keeps compact forms); count selects the plural case only. Rendered only when count >= 1. MUST NOT read as an error or say the funds are lost: the explanation beside it already names the next step (switch servers).
-
walletTorBootstrappingNamed(
String transport) → String - Transport chip: as walletTorBootstrapping, for a REGISTERED transport whose descriptor names it. transport = the HOST'S OWN name for its transport, verbatim ("Tor", "Shadowsocks", "VLESS via Cloudflare") — the wallet never interprets or translates it.
-
walletTorHostPath(
String transport) → String - Transport chip: wallet traffic rides the dialer the host app registered (FR-29), whose path hides the device's address and honours per-purpose isolation. transport = the HOST'S OWN name for its transport, verbatim (ADR-0547: the wallet has no list of transport kinds), or walletTorHostOtherTransport when the SDK has no name to show. Protected tone.
-
walletTorHostPathLinkable(
String transport) → String - Transport chip: as walletTorHostPath, but the host declared isolation unsupported (or did not declare it) — the wallet's connections can be linked to each other at the proxy — or the host did not declare whether the path hides the device's address (exposure unknown). Caution tone; the state never promises what the host did not declare (ADR-0545, ADR-0547). transport = the host's own name, verbatim.
-
walletTorUnansweredLinkable(
String transport) → String - Transport chip for TorState.unanswered on a registered dialer that is NOT the plainly-private case: the host declared isolation unsupported (or did not declare it), so the wallet's connections can be linked to each other at the proxy — or the host did not declare whether the path hides the device's address (exposure unknown), where the weaker sentence is the honest one (the §3.3 privacy rule: never inherit a benign framing for something the binding cannot attest). The twin of walletTorHostPathLinkable on the Active family. transport = the host's own name, verbatim, or walletTorHostOtherTransport when the SDK has none to show — the sentence leads with the state, not the name, so the unattributed fragment reads inside it. Caution tone.
-
walletTorUnansweredNamed(
String transport) → String - Transport chip: as walletTorUnanswered, for a REGISTERED transport whose descriptor names it — and ONLY for a path the host declared HIDDEN and isolating, since it is the variant that carries no privacy qualifier. transport = the HOST'S OWN name for its transport, verbatim — the wallet never interprets or translates it (ADR-0547).
- Transport chip: as walletTorUnavailable, for a REGISTERED transport whose descriptor names it. transport = the host's own name, verbatim.
-
walletTransparentFundsAutoOn(
String minZec) → String - The sheet’s conditional automation sentence while auto-shield is ON. {minZec} is the already-formatted minimum (e.g. "0.001").
-
walletTransportExplainBootstrappingNamed(
String transport) → String - Sync sheet Connection explanation: as walletTransportExplainBootstrapping, naming the host's own transport verbatim.
-
walletTransportExplainUnansweredNamed(
String transport) → String - Sync sheet Connection explanation: as walletTransportExplainUnanswered, naming the host's own transport verbatim. Only the FIRST clause takes the name — the either/or still says "the path", because naming the host's transport a second time would read as an accusation of it.
- Sync sheet Connection explanation: as walletTransportExplainUnavailable, naming the host's own transport verbatim.
-
walletWatchOnlyBirthdayChosen(
String date) → String - The chosen watch-only start month/year, carrying the honest warning that older funds won't appear (a watch-only import always scans from a floor — no full-scan arm — so the auditor importing an older wallet must not silently see an understated balance). Mirrors walletRestoreBirthdayChosen without the 'Scan all history' clause.
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited
Static Methods
-
of(
BuildContext context) → WalletLocalizations
Constants
-
delegate
→ const LocalizationsDelegate<
WalletLocalizations> -
localizationsDelegates
→ const List<
LocalizationsDelegate> - A list of this localizations delegate along with the default localizations delegates.
-
supportedLocales
→ const List<
Locale> - A list of this localizations delegate's supported locales.