Files
routstrd/docs/nwc-timeouts.md
redshift ad49fbe64c fix(nwc): bound every CLI daemon request with a two-tier deadline
Graft the cleaner daemon-client structure onto the review follow-up:

- Replace the manual AbortController/setTimeout with AbortSignal.timeout;
  the signal stays armed while the body is read, so stalled bodies are
  bounded on all routes, not just /nwc/*.
- 120s default deadline for every route; 600s for value-moving wallet
  routes (/wallet/send/*, /wallet/receive/*) whose mint operations can
  legitimately run longer. A wedged daemon can no longer hang the CLI
  forever on any route. The 'payment outcome is unknown' timeout warning
  now applies on both tiers.
- Rename rebuild log reasons to 'stall': wallet-error replies no longer
  rebuild the connection, so 'timeout' was inaccurate.
- Derive the NWC test client type from WalletAdapterOptions so the tests
  keep compiling when the legacy CocodClient is replaced (#118).
- Rewrite the daemon-client deadline tests around AbortSignal.timeout,
  asserting the requested tier per route and covering stalled bodies on
  long-running routes. Update docs/nwc-timeouts.md to match.
2026-10-02 16:47:09 +08:00

14 lines
1.7 KiB
Markdown

# NWC request timeouts
In `applesauce-wallet-connect@6.2.0`, encryption negotiation waits for a wallet-info event (kind 13194) before starting the response timeout. If a relay subscription stalls before that event arrives, the library request can remain pending indefinitely.
The wallet adapter adds an overall deadline: 15 seconds per read attempt and 45 seconds per payment. Reads can rebuild the relay connection and retry once. Payments are never automatically retried. The library still applies its own 30-second response timeout after negotiation; the 45-second deadline does not extend it.
Normal NIP-47 wallet errors do not rebuild the shared relay connection: a wallet error proves a response arrived, and rebuilding could interrupt unrelated payments. Transport failures and timeouts, including the library's own timeout, still trigger recovery.
Every CLI daemon request has a deadline covering headers and response-body consumption: 120 seconds by default, and 600 seconds for value-moving wallet routes (`/wallet/send/*`, `/wallet/receive/*`), whose mint operations can legitimately run longer. Aborting the CLI request never cancels the daemon-side operation; the longer bound only delays how soon the CLI reports the stall.
A payment timeout is an **unknown outcome**, not proof that no payment occurred. Promise deadlines do not cancel the underlying operation. Check the mint quote, wallet transactions, and Cashu balance before creating and paying another invoice.
The auto-refill loop starts when static configuration or a dynamic configuration getter is supplied, even without an NWC connection at startup. It reads the current wallet and configuration each cycle, so a later connection can activate refills without restarting the daemon.