Track HTTPS embedded app gate and remaining payment recovery boundaries

This commit is contained in:
archipelago
2026-10-06 14:56:34 -04:00
parent 9771378bfd
commit c3bfbe8519
3 changed files with 43 additions and 0 deletions
+21
View File
@@ -111,3 +111,24 @@ not deserialized as a fresh zero state. The full isolated suite again passes
1,755tests,0failures,5existing ignored in 1,755tests,0failures,5existing ignored in
`/tmp/archy-wallet-recovery-strict-schema-full-tests.log`. No live deployment or `/tmp/archy-wallet-recovery-strict-schema-full-tests.log`. No live deployment or
claim of complete initial-payment recovery is implied. claim of complete initial-payment recovery is implied.
## Additional wallet boundaries found during review (6 October)
Source review of `ecash::melt_tokens`, `swap_between_mints` and
`MintClient::melt_tokens` found further work required before full recovery can
be accepted. The melt path does not currently submit or retain fee-change
outputs, and the caller does not require a PAID response before proceeding.
Cross-mint recovery records are written after the remote operation, leaving an
interruption window. These are source findings, not newly induced live losses.
The implementation must account for NUT-05 quote states and NUT-08 change using
the mint's advertised support, preserve uncertain operations, and verify amount
conservation. Reference specifications:
https://github.com/cashubtc/nuts/blob/main/05.md and
https://github.com/cashubtc/nuts/blob/main/08.md .
Wallet-wide serialization must also include network changes and streaming
revenue writes; a load/save outside the operation lock can overwrite another
mutation. Current empty-wallet-file handling, file permissions and directory
fsync require review as part of durable storage. Counter fail-closed tests do
not establish that this larger transaction journal has been implemented.
+16
View File
@@ -846,3 +846,19 @@ recovery source fails, and atomically flush counter reservations before use.
Rust wallet tests are running only through the required isolated test runner. Rust wallet tests are running only through the required isolated test runner.
No real wallet mutation or additional payment is involved. This prerequisite is No real wallet mutation or additional payment is involved. This prerequisite is
not a completed purchase journal, seller receipt or initial-payment recovery gate. not a completed purchase journal, seller receipt or initial-payment recovery gate.
## Latest continuation: publication lifecycle and HTTPS iframe report
IndeeHub commit `2ec3600` wires the authenticated publication API and bounded
outbox loop, disabled by default. Full backend qualification passes 151 tests
in 17 suites, including actual PostgreSQL/HTTP/local-relay reconstruction.
Final backend production build passes. Disposable database, volume and private
credentials removed; no app deployment or public event/payment occurred.
Archy recovery-counter follow-up `9771378b` passes 1,755 isolated backend
tests with five existing skips. Not deployed; full purchase recovery remains open.
User reports an HTTPS-only embedded app gate while tab mode works. Added task17,
with exact node/app clarification pending. No authentication bypass or live
nginx modification. The private operator report is updated, regenerated and
checked at390/1440px; SCP path remains unchanged.
+6
View File
@@ -372,3 +372,9 @@ as a substitute for repairing the standard public-channel experience.
absolute positioning that overlaps content. Verify tall neighbours, shrinking absolute positioning that overlaps content. Verify tall neighbours, shrinking
results, long labels, keyboard access and mobile/desktop layouts. results, long labels, keyboard access and mobile/desktop layouts.
- Record actual browser geometry checks and deployment acceptance separately. - Record actual browser geometry checks and deployment acceptance separately.
## 17. HTTPS embedded app authentication (reported 6 October)
- User reports opening apps inside an iframe on an HTTPS node shows the app gate, while opening the same app in a separate tab works. Reproduce both modes with the same authenticated session before identifying a cause.
- Trace generated launch origins, cookie attributes and scope, bootstrap redirects, iframe navigation and gate session exchange. Preserve authentication and public-management access restrictions; do not bypass the gate or expose credentials to embedded apps.
- Test HTTPS iframe and tab, HTTP LAN compatibility, desktop/mobile companion, reload, expired sessions, denied access and logout. Record actual-node evidence separately from fixtures. This remains open, not a confirmed diagnosis.