Financial intent
What exactly is being proposed, and how does it move?
| # | Lesson | You will attack |
|---|---|---|
| 4 | Payment destinations and settlement rails | a mistyped address; the wrong network |
| 5 | Invoice revisions and the financial payload | changing an amount after submission |
| 6 | Financial state machines | approving a draft; writing state |
| 7 | Idempotency and retries | replaying a request with a different payload |
These lessons turn a proposal into immutable financial intent. A payment
destination stores a public receiving address and its network, and it is
retired rather than edited. Each invoice revision seals its financial payload
with a SHA-256 hash. The lifecycle is a state machine with no writable state
attribute. A retried proposal with the same idempotency key and the same
payload returns the original; the same key with a different payload is
refused.
Part II reaches the same idempotency question from the other side, in R7 · Side effects and idempotency: what a runtime must assume about tools when it replays a step after a crash.