GatewayTransactionRequest class
Normalized request the SDK hands to a GatewayClient when forwarding an encrypted payload to the merchant backend.
Strict allow-list. This object carries only the fields below; there is no extras map, no escape hatch, no "passthrough TLV". The backend reconstructs anything else it needs from the encrypted blob (which it can decrypt; the SDK cannot).
- encryptedPayload — opaque encrypted blob produced by the reader (hex-encoded). The SDK never decodes this.
- ksn — opaque DUKPT key serial number. The SDK never uses this to derive a key.
- entryMode —
chip/tap/swipe/manual. The backend uses this to route to the right processor adapter. - amountMinorUnits, currency — what was asked for at
startTransactiontime. The backend authoritatively verifies against its own expectation. - reader — device metadata (id, vendor, modelKey,
transport, serial, battery) for the backend's audit
trail. Provided as a
Map<String, dynamic>so the gateway layer does not have to depend on the ReaderDevice model. - transactionMetadata — POS-supplied per-transaction metadata (order id, ticket id, ...). Opaque to the SDK.
- idempotencyKey — caller-supplied key from the originating TransactionRequest. The backend MUST dedupe on this.
Banned fields. This object MUST NOT carry:
- PAN / masked PAN / last4,
- cardholder name,
- track 1 / track 2 / track 3,
- CVV / CVC / CID,
- expiry,
- service code,
- discretionary data,
- ARQC plaintext,
- plaintext EMV tags.
The constructor accepts only the named fields above. There
is no Map<String, dynamic> field for "everything else" -
adding banned data would require modifying this class,
which makes the audit boundary the class signature itself.
Constructors
-
GatewayTransactionRequest({required String encryptedPayload, required String ksn, required String entryMode, required int amountMinorUnits, required String currency, required String idempotencyKey, Map<
String, dynamic> ? reader, Map<String, dynamic> ? transactionMetadata}) -
const
-
GatewayTransactionRequest.fromJson(Map<
String, dynamic> json) -
Parse from JSON. Validates that no banned-key surfaces
were smuggled in. Throws ArgumentError when a banned
key is found - the gateway layer translates that into a
structured
payloadInvalidfailure.factory
Properties
- amountMinorUnits → int
-
Amount in minor units; mirrors the originating
TransactionRequest.final - currency → String
-
ISO 4217 currency code (e.g.
USD).final - encryptedPayload → String
-
Sensitive. Encrypted card-data blob. Opaque to the
SDK; the backend decrypts it. Never logged.
final
- entryMode → String
-
chip/tap/swipe/manual.final - hashCode → int
-
The hash code for this object.
no setterinherited
- idempotencyKey → String
-
Caller-supplied idempotency key. The backend dedupes on
this value; the SDK MUST NOT modify it.
final
- ksn → String
-
Sensitive. Key Serial Number for DUKPT decryption.
Opaque to the SDK. Never logged.
final
-
reader
→ Map<
String, dynamic> ? -
Reader-device metadata. Strict allow-list:
id,vendor,modelKey,transport,serialNumber,batteryPercent. The factory constructor on the bridge layer (GatewayTransactionRequestBuilder) enforces this.final - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
transactionMetadata
→ Map<
String, dynamic> ? -
POS-supplied transaction metadata (order id, etc.).
Opaque to the SDK; passed through verbatim.
final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Map< String, dynamic> - JSON form sent over the transport. The map preserves insertion order so the on-wire shape is deterministic for tests / signing.
-
toString(
) → String -
Intentionally redacts the encrypted payload and KSN.
Subscribers that log a request MUST use this form, not
the raw map.
override
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited
Static Methods
-
bannedKeysForTest(
) → Set< String> - Public for tests; downstream callers should not iterate.