mirror of
https://github.com/minibits-cash/minibits_wallet.git
synced 2026-10-05 19:28:26 +00:00
WalletStore.receive pre-loaded keys for every keyset that signed an incoming token's proofs, because cashu-ts DLEQ-verifies each input proof carrying a DLEQ and threw "Undefined key for amount N in keyset X" when those keys were absent. That bites after a mint migration, where the keyset that signed all existing ecash goes inactive and getKeys() — which returns ACTIVE keysets only, per NUT-01 — stops returning it. cashu-ts 4.9 made the loop redundant. Traced in the shipped bundle: wallet.receive -> prepareSwapToReceive calls _ensureOperableKeysets over the token's own proof ids, and it runs BEFORE the DLEQ loop that used to throw. With fetchKeys unset it filters to exactly the input keysets lacking keys and calls the same keyChain.ensureKeysetKeys the loop called, then additionally repairs ids it does not recognise at all via loadMint(true) — which the loop could not do, since ensureKeysetKeys only resolves keysets already known. inactiveKeysetKeys.test.ts is re-pointed accordingly. Its KeyChain-level tests stay, reframed as the mechanism cashu-ts uses internally rather than as the fix the wallet relies on, and a new describe supplies the evidence that licenses the deletion: a Wallet loaded from an active-keys-only cache — what WalletStore.getWallet really builds — is handed a token signed by the inactive keyset, and prepareSwapToReceive is shown to fetch that keyset by id, land the keys in the keychain, and prepare without throwing. That block also pins the precondition the deletion depends on: _ensureOperableKeysets returns early when the wallet has no mint info, so on such a wallet there is no safety net at all. WalletStore.getWallet always loads mint info first, via loadMintFromCache or loadMint, which is what makes removing the loop safe — asserted so the invariant cannot break silently. Not reachable on a device: it needs proofs signed by a keyset the mint has retired, which a mint will not issue on request. The unit test is the coverage. Verified: tsc --noEmit unchanged against baseline (89 pre-existing, none new), 47 suites / 642 tests pass. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>