GatewayConfig class
POS-supplied configuration for the gateway handoff layer.
Threading model. This is a plain immutable value
object. The POS application builds one and passes it to
MobileReaderSdk.initialize(...) (via ReaderConfig, in a
follow-up branch that wires the field through the
platform-channel adapter). The SDK never mutates it.
Credential boundary. The SDK does not persist
gateway credentials. The POS application is expected to
hold the bearer token / API key / signing material in its
own secure storage and pass it through the
authTokenProvider callback on each handoff. The callback
receives a tokenScope discriminator so the POS can vend
different tokens for sandbox vs production endpoints.
No PCI scope drift. None of the fields on this object carry encrypted card data, KSN, PAN, track, CVV, or ARQC values. The handoff itself transports those (inside the encrypted blob), but the configuration that drives it does not.
Constructors
-
GatewayConfig({GatewayMode mode = GatewayMode.payloadOnly, String? backendBaseUrl, Future<
String?> authTokenProvider(GatewayTokenScope scope)?, Duration requestTimeout = const Duration(seconds: 30), GatewayRetryPolicy retryPolicy = const GatewayRetryPolicy(), Map<String, String> extraHeaders = const {}}) -
const
-
GatewayConfig.fromJson(Map<
String, dynamic> json) -
factory
Properties
-
authTokenProvider
→ Future<
String?> Function(GatewayTokenScope scope)? -
Callback the SDK invokes immediately before each handoff
to obtain an opaque auth token. Returning
nullis allowed when the backend does not require one (e.g. a merchant-side proxy that handles auth itself).final - backendBaseUrl → String?
-
Base URL of the merchant backend. Only consulted in
GatewayMode.gatewayHandoff mode. The SDK does NOT
concatenate paths against this URL itself - the
GatewayClientimplementation owns the route.final -
extraHeaders
→ Map<
String, String> -
POS-supplied extra HTTP headers to attach to every
handoff request. The SDK does NOT inject
Authorizationhere - that goes through authTokenProvider - and it does not allow override ofContent-Type. Sensitive values (bearer tokens, API secrets) MUST NOT live in this map; use authTokenProvider for credentials so they live only for one request.final - hashCode → int
-
The hash code for this object.
no setterinherited
- mode → GatewayMode
-
Whether the SDK forwards the encrypted payload itself
(GatewayMode.gatewayHandoff) or leaves the POS app to
do it (GatewayMode.payloadOnly).
final
- requestTimeout → Duration
-
Per-handoff HTTP request timeout. Production default is
30 s; the POS can shorten it for kiosk UX or lengthen it
for slow gateways.
final
- retryPolicy → GatewayRetryPolicy
-
Retry policy for transient handoff failures. The SDK
only retries failures the policy classifies as
transient (e.g. network drop, 5xx) - it never retries a
completed authorization, because that would risk
double-charging the cardholder.
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Map< String, dynamic> - JSON form intended for the platform channel. Sensitive fields (authTokenProvider is non-serializable; tokens never appear here) are omitted by construction.
-
toString(
) → String -
toString is intentionally terse and redacts both the
auth provider closure (it could close over secrets) and
the contents of extraHeaders (POS apps occasionally
store API keys there even though we forbid it).
override
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited