chore: snapshot release workspace
This commit is contained in:
@@ -27,6 +27,7 @@ Allowed RPC methods:
|
||||
|
||||
```text
|
||||
sendrawtransaction
|
||||
submitpackage
|
||||
testmempoolaccept
|
||||
getmempoolinfo
|
||||
getrawmempool
|
||||
@@ -37,6 +38,7 @@ getblockcount
|
||||
getblockhash
|
||||
getblockheader
|
||||
getrawtransaction
|
||||
gettxout
|
||||
decoderawtransaction
|
||||
decodescript
|
||||
estimatesmartfee
|
||||
@@ -113,7 +115,7 @@ The Bitcoin Knots app should add the restricted user only when the secret exists
|
||||
RPC_TXRELAY_AUTH="$(printenv BITCOIN_RPC_TXRELAY_RPCAUTH || true)"
|
||||
RPC_TXRELAY_FLAGS="-rpcwhitelistdefault=0"
|
||||
if [ -n "$RPC_TXRELAY_AUTH" ]; then
|
||||
RPC_TXRELAY_FLAGS="$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblockheader,getrawtransaction,decoderawtransaction,decodescript,estimatesmartfee"
|
||||
RPC_TXRELAY_FLAGS="$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips"
|
||||
fi
|
||||
```
|
||||
|
||||
@@ -245,6 +247,15 @@ curl -sS --user "$BITCOIN_RPC_TXRELAY_USER:$BITCOIN_RPC_TXRELAY_PASSWORD" \
|
||||
Expected result is a Bitcoin RPC validation error such as `TX decode failed`,
|
||||
which confirms the request reached `sendrawtransaction`.
|
||||
|
||||
If a wallet verifies the connection but reports `RPC Forbidden` during
|
||||
broadcast, the credentials authenticated but the broadcast method was outside
|
||||
the loaded `txrelay` whitelist. Restart the active Bitcoin backend after
|
||||
updating the whitelist, then test both `sendrawtransaction` and, for newer
|
||||
package-relay clients, `submitpackage`. Also confirm the public reverse proxy
|
||||
passes the wallet's `Authorization` header through to `127.0.0.1:8332`; do not
|
||||
point public wallet traffic at the Bitcoin UI `/bitcoin-rpc/` helper, because
|
||||
that helper injects the local dashboard credential.
|
||||
|
||||
Check that wallet/admin RPC is blocked:
|
||||
|
||||
```sh
|
||||
|
||||
Reference in New Issue
Block a user