| 2258 | }; |
| 2259 | |
| 2260 | static struct command_result * |
| 2261 | invoice_fetched(struct command *cmd, |
| 2262 | const char *method, |
| 2263 | const char *buf, |
| 2264 | const jsmntok_t *result, |
| 2265 | struct xpay_params *params) |
| 2266 | { |
| 2267 | const char *inv, *err; |
| 2268 | |
| 2269 | inv = json_strdup(tmpctx, buf, json_get_member(buf, result, "invoice")); |
| 2270 | inv = to_canonical_invstr(tmpctx, inv); |
| 2271 | |
| 2272 | /* BOLT #12: |
| 2273 | * - if `invreq_amount` is present: |
| 2274 | * - MUST reject the invoice if `invoice_amount` is not equal to `invreq_amount` |
| 2275 | * - otherwise: |
| 2276 | * - SHOULD confirm authorization if `invoice_amount`.`msat` is not within |
| 2277 | * the amount range authorized. |
| 2278 | */ |
| 2279 | /* invoice_amount is not one of the fields the invoice must copy from our |
| 2280 | * invoice_request, so it is set independently of what we asked for and |
| 2281 | * has to be checked here. We set invreq_amount iff we were given an |
| 2282 | * amount, which selects which of the two rules above applies. */ |
| 2283 | if (params->authorized_msat) { |
| 2284 | struct amount_msat invoice_msat; |
| 2285 | struct tlv_invoice *b12inv |
| 2286 | = invoice_decode(tmpctx, inv, strlen(inv), |
| 2287 | plugin_feature_set(cmd->plugin), |
| 2288 | chainparams, &err); |
| 2289 | if (!b12inv) |
| 2290 | return command_fail(cmd, OFFER_BAD_INVREQ_REPLY, |
| 2291 | "Invalid bolt12 invoice: %s", err); |
| 2292 | /* invoice_decode() has already insisted on invoice_amount. */ |
| 2293 | invoice_msat = amount_msat(*b12inv->invoice_amount); |
| 2294 | if (params->msat) { |
| 2295 | if (!amount_msat_eq(invoice_msat, *params->authorized_msat)) |
| 2296 | return command_fail(cmd, OFFER_BAD_INVREQ_REPLY, |
| 2297 | "Invoice amount is %s, but we asked for %s", |
| 2298 | fmt_amount_msat(tmpctx, invoice_msat), |
| 2299 | fmt_amount_msat(tmpctx, |
| 2300 | *params->authorized_msat)); |
| 2301 | } else if (amount_msat_greater(invoice_msat, |
| 2302 | *params->authorized_msat)) { |
| 2303 | return command_fail(cmd, OFFER_BAD_INVREQ_REPLY, |
| 2304 | "Invoice amount is %s, more than the %s we authorized", |
| 2305 | fmt_amount_msat(tmpctx, invoice_msat), |
| 2306 | fmt_amount_msat(tmpctx, |
| 2307 | *params->authorized_msat)); |
| 2308 | } |
| 2309 | } |
| 2310 | |
| 2311 | return xpay_core(cmd, inv, |
| 2312 | NULL, params->maxfee, params->layers, |
| 2313 | params->retryfor, params->partial, params->maxdelay, |
| 2314 | params->label, NULL, false, false, |
| 2315 | params->includefees_msat); |
| 2316 | } |
| 2317 |
nothing calls this directly
no test coverage detected