2.4 KiB
BML QR Pay
Handles BML gateway QR payments — scanning a merchant QR code and completing the 3-step TOTP-authenticated payment flow.
Fragment — BmlQrPayFragment
Opened via:
- Scanning a BML plain URL QR in
PayMvQrFragment - Scanning a combined Fahipay/PayMV QR that embeds a BML gateway URL
- The
OPEN_PAY_WITH_CARDintent action
Step 1 — Resolve QR
The fragment receives a BML gateway URL (e.g., https://pay.bml.com.mv/app/<base64>).
It calls the BML payrequest lookup API (see QR Payment) to resolve the URL to merchant details:
- Merchant name (narrative1)
- Merchant address (narrative2, narrative3)
- Amount (
"0.00"for static QRS, or preset amount for QRR) - Currency
The resolved details are displayed on screen for the user to review before paying.
Source Account Selection
A dropdown lists all BML accounts. The selected account's internal UUID (internalId) is used as debitAccount in the payment request.
Amount Entry
- If the QR is a static QRS (amount
"0.00"), the amount field is editable and required - If the QR is a dynamic QRR, the amount is pre-filled and read-only
Step 2 — TOTP Payment
The payment uses the standard 3-step BML TOTP flow:
2a — Initiate
POST to /walletpayments/pay with action: "approve", debitAccount, requestId (the trxn_hash), amount, currency. Expected response: code: 99 (OTP required).
This step may be skipped if the gateway already indicates OTP is required.
2b — Request OTP Channel
Same POST with channel: "token" added. Expected response: code: 22 (OTP generated and sent to the authenticator).
2c — Confirm with TOTP
The fragment presents an OTP input dialog. The user opens the OTP Screen or reads the TOTP from their authenticator app, then enters the 6-digit code.
Same POST with channel: "token" and otp: "<code>". On success: code: 0 with merchant and amount in payload.
Success
On successful payment a confirmation card is shown:
- Merchant name
- Amount paid
- Currency
A Done button dismisses the fragment.
Error Handling
Failed payments (success: false) display the message field from the API response. The user may retry with a fresh TOTP code.
← PayMV QR Screen Next → Financing