From c3bfbe8519f269dfb476a35cad44939041f622c2 Mon Sep 17 00:00:00 2001 From: archipelago Date: Tue, 6 Oct 2026 14:56:34 -0400 Subject: [PATCH] Track HTTPS embedded app gate and remaining payment recovery boundaries --- docs/paid-content-recovery-followup.md | 21 +++++++++++++++++++++ docs/post-1.9.0-progress-20261006.md | 16 ++++++++++++++++ docs/post-1.9.0-work-backlog.md | 6 ++++++ 3 files changed, 43 insertions(+) diff --git a/docs/paid-content-recovery-followup.md b/docs/paid-content-recovery-followup.md index be537864..63015a41 100644 --- a/docs/paid-content-recovery-followup.md +++ b/docs/paid-content-recovery-followup.md @@ -111,3 +111,24 @@ not deserialized as a fresh zero state. The full isolated suite again passes 1,755tests,0failures,5existing ignored in `/tmp/archy-wallet-recovery-strict-schema-full-tests.log`. No live deployment or claim of complete initial-payment recovery is implied. + +## Additional wallet boundaries found during review (6 October) + +Source review of `ecash::melt_tokens`, `swap_between_mints` and +`MintClient::melt_tokens` found further work required before full recovery can +be accepted. The melt path does not currently submit or retain fee-change +outputs, and the caller does not require a PAID response before proceeding. +Cross-mint recovery records are written after the remote operation, leaving an +interruption window. These are source findings, not newly induced live losses. + +The implementation must account for NUT-05 quote states and NUT-08 change using +the mint's advertised support, preserve uncertain operations, and verify amount +conservation. Reference specifications: +https://github.com/cashubtc/nuts/blob/main/05.md and +https://github.com/cashubtc/nuts/blob/main/08.md . + +Wallet-wide serialization must also include network changes and streaming +revenue writes; a load/save outside the operation lock can overwrite another +mutation. Current empty-wallet-file handling, file permissions and directory +fsync require review as part of durable storage. Counter fail-closed tests do +not establish that this larger transaction journal has been implemented. diff --git a/docs/post-1.9.0-progress-20261006.md b/docs/post-1.9.0-progress-20261006.md index a4d42bc0..c0909d75 100644 --- a/docs/post-1.9.0-progress-20261006.md +++ b/docs/post-1.9.0-progress-20261006.md @@ -846,3 +846,19 @@ recovery source fails, and atomically flush counter reservations before use. Rust wallet tests are running only through the required isolated test runner. No real wallet mutation or additional payment is involved. This prerequisite is not a completed purchase journal, seller receipt or initial-payment recovery gate. + +## Latest continuation: publication lifecycle and HTTPS iframe report + +IndeeHub commit `2ec3600` wires the authenticated publication API and bounded +outbox loop, disabled by default. Full backend qualification passes 151 tests +in 17 suites, including actual PostgreSQL/HTTP/local-relay reconstruction. +Final backend production build passes. Disposable database, volume and private +credentials removed; no app deployment or public event/payment occurred. + +Archy recovery-counter follow-up `9771378b` passes 1,755 isolated backend +tests with five existing skips. Not deployed; full purchase recovery remains open. + +User reports an HTTPS-only embedded app gate while tab mode works. Added task17, +with exact node/app clarification pending. No authentication bypass or live +nginx modification. The private operator report is updated, regenerated and +checked at390/1440px; SCP path remains unchanged. diff --git a/docs/post-1.9.0-work-backlog.md b/docs/post-1.9.0-work-backlog.md index f1f55572..6a785873 100644 --- a/docs/post-1.9.0-work-backlog.md +++ b/docs/post-1.9.0-work-backlog.md @@ -372,3 +372,9 @@ as a substitute for repairing the standard public-channel experience. absolute positioning that overlaps content. Verify tall neighbours, shrinking results, long labels, keyboard access and mobile/desktop layouts. - Record actual browser geometry checks and deployment acceptance separately. + +## 17. HTTPS embedded app authentication (reported 6 October) + +- User reports opening apps inside an iframe on an HTTPS node shows the app gate, while opening the same app in a separate tab works. Reproduce both modes with the same authenticated session before identifying a cause. +- Trace generated launch origins, cookie attributes and scope, bootstrap redirects, iframe navigation and gate session exchange. Preserve authentication and public-management access restrictions; do not bypass the gate or expose credentials to embedded apps. +- Test HTTPS iframe and tab, HTTP LAN compatibility, desktop/mobile companion, reload, expired sessions, denied access and logout. Record actual-node evidence separately from fixtures. This remains open, not a confirmed diagnosis.