Struct payjoin::receive::UncheckedProposal
source · pub struct UncheckedProposal { /* private fields */ }
Expand description
The sender’s original PSBT and optional parameters
This type is used to process the request. It is returned by
UncheckedProposal::from_request()
.
If you are implementing an interactive payment processor, you should get extract the original transaction with extract_tx_to_schedule_broadcast() and schedule, followed by checking that the transaction can be broadcast with check_broadcast_suitability. Otherwise it is safe to call assume_interactive_receive to proceed with validation.
Implementations§
source§impl UncheckedProposal
impl UncheckedProposal
pub fn from_request( body: impl Read, query: &str, headers: impl Headers ) -> Result<Self, RequestError>
sourcepub fn extract_tx_to_schedule_broadcast(&self) -> Transaction
pub fn extract_tx_to_schedule_broadcast(&self) -> Transaction
The Sender’s Original PSBT transaction
sourcepub fn check_broadcast_suitability(
self,
min_fee_rate: Option<FeeRate>,
can_broadcast: impl Fn(&Transaction) -> Result<bool, Error>
) -> Result<MaybeInputsOwned, Error>
pub fn check_broadcast_suitability( self, min_fee_rate: Option<FeeRate>, can_broadcast: impl Fn(&Transaction) -> Result<bool, Error> ) -> Result<MaybeInputsOwned, Error>
Check that the Original PSBT can be broadcasted.
Receiver MUST check that the Original PSBT from the sender
can be broadcast, i.e. testmempoolaccept
bitcoind rpc returns { “allowed”: true,.. }.
Receiver can optionaly set a minimum feerate that will be enforced on the Original PSBT. This can be used to prevent probing attacks and make it easier to deal with high feerate environments.
Do this check if you generate bitcoin uri to receive Payjoin on sender request without manual human approval, like a payment processor. Such so called “non-interactive” receivers are otherwise vulnerable to probing attacks. If a sender can make requests at will, they can learn which bitcoin the receiver owns at no cost. Broadcasting the Original PSBT after some time in the failure case makes incurs sender cost and prevents probing.
Call this after checking downstream.
sourcepub fn assume_interactive_receiver(self) -> MaybeInputsOwned
pub fn assume_interactive_receiver(self) -> MaybeInputsOwned
Call this method if the only way to initiate a Payjoin with this receiver requires manual intervention, as in most consumer wallets.
So-called “non-interactive” receivers, like payment processors, that allow arbitrary requests are otherwise vulnerable to probing attacks.
Those receivers call extract_tx_to_check_broadcast()
and attest_tested_and_scheduled_broadcast()
after making those checks downstream.
Trait Implementations§
source§impl Clone for UncheckedProposal
impl Clone for UncheckedProposal
source§fn clone(&self) -> UncheckedProposal
fn clone(&self) -> UncheckedProposal
1.0.0 · source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source
. Read more