feat(docker): add dev.sh with auto-funding and ATM app setup
- Add dev.sh script for managing regtest development environment - Implement cmd_fund to fund ATM app owner via Lightning.Pub API - Add --fund flag to cmd_up for automatic funding on startup - Update setup_atm_app to write VITE_APP_ID to machine .env - Fix Electron IPC to pass appId and extensionApiUrl to renderer - Restructure repo from nested lamassu-next/ to root The dev.sh script now supports: - ./dev.sh up --fund # Start regtest and auto-fund ATM - ./dev.sh fund # Fund existing ATM app - ./dev.sh status # Show environment status - ./dev.sh reset # Clean restart Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
parent
30a2eb2199
commit
c98f126ba7
180 changed files with 2695 additions and 9587 deletions
105
.claude/skills/security.md
Normal file
105
.claude/skills/security.md
Normal file
|
|
@ -0,0 +1,105 @@
|
|||
# /security - Security Review Agent
|
||||
|
||||
## Purpose
|
||||
Perform security audits on code changes, focusing on Bitcoin/Lightning ATM-specific vulnerabilities.
|
||||
|
||||
## Invocation
|
||||
```
|
||||
/security [target]
|
||||
```
|
||||
|
||||
Where `target` can be:
|
||||
- A file path (e.g., `packages/lightning/src/client.ts`)
|
||||
- A directory (e.g., `packages/hal/`)
|
||||
- `--staged` for staged git changes
|
||||
- `--all` for full codebase scan
|
||||
|
||||
## Review Checklist
|
||||
|
||||
### 1. Bitcoin/Lightning Security
|
||||
- [ ] Private keys never logged or exposed
|
||||
- [ ] nsec (Nostr secret keys) protected with proper permissions (0600)
|
||||
- [ ] Invoice amounts validated before payment
|
||||
- [ ] Payment preimages handled securely
|
||||
- [ ] No hardcoded mnemonics, seeds, or keys
|
||||
- [ ] Proper BOLT11/BOLT12 invoice validation
|
||||
|
||||
### 2. Hardware Security (ATM-specific)
|
||||
- [ ] Bill validator amounts cross-checked
|
||||
- [ ] Dispenser commands validated (prevent over-dispensing)
|
||||
- [ ] Hardware error states handled gracefully
|
||||
- [ ] No race conditions in cash handling
|
||||
- [ ] Timeout handling for hardware operations
|
||||
|
||||
### 3. Nostr Security
|
||||
- [ ] NIP-44 encryption used for sensitive messages
|
||||
- [ ] Event signatures verified before processing
|
||||
- [ ] Relay URLs validated (no injection)
|
||||
- [ ] NIP-42 auth implemented for private relay
|
||||
- [ ] No pubkey/npub confusion (proper type safety)
|
||||
|
||||
### 4. General Security
|
||||
- [ ] Input validation on all external data
|
||||
- [ ] SQL injection prevention (parameterized queries)
|
||||
- [ ] No command injection in Bash/shell calls
|
||||
- [ ] Proper error handling (no sensitive data in errors)
|
||||
- [ ] Rate limiting on API endpoints
|
||||
- [ ] HTTPS/WSS enforced in production
|
||||
|
||||
### 5. Rust-specific (HAL)
|
||||
- [ ] No `unsafe` blocks without justification
|
||||
- [ ] Error handling with Result, no unwrap() in production
|
||||
- [ ] Buffer bounds checking for serial communication
|
||||
- [ ] Proper lifetime management
|
||||
|
||||
### 6. TypeScript-specific
|
||||
- [ ] Strict null checks honored
|
||||
- [ ] No `any` types
|
||||
- [ ] Zod validation on external data
|
||||
- [ ] No eval() or dynamic code execution
|
||||
|
||||
## Output Format
|
||||
|
||||
```markdown
|
||||
## Security Review: [target]
|
||||
|
||||
### Critical Issues
|
||||
- [ ] Issue description with file:line reference
|
||||
|
||||
### High Priority
|
||||
- [ ] Issue description with file:line reference
|
||||
|
||||
### Medium Priority
|
||||
- [ ] Issue description with file:line reference
|
||||
|
||||
### Low Priority / Suggestions
|
||||
- [ ] Suggestion with rationale
|
||||
|
||||
### Passed Checks
|
||||
- [x] Check that passed
|
||||
```
|
||||
|
||||
## Example Usage
|
||||
|
||||
```
|
||||
/security packages/lightning/src/client.ts
|
||||
```
|
||||
|
||||
Output:
|
||||
```markdown
|
||||
## Security Review: packages/lightning/src/client.ts
|
||||
|
||||
### Critical Issues
|
||||
None found.
|
||||
|
||||
### High Priority
|
||||
- [ ] `client.ts:45` - Invoice amount not validated before `payInvoice()` call
|
||||
|
||||
### Medium Priority
|
||||
- [ ] `client.ts:78` - Error message includes full stack trace, may leak internal paths
|
||||
|
||||
### Passed Checks
|
||||
- [x] Private keys not exposed in logs
|
||||
- [x] NIP-44 encryption used for DMs
|
||||
- [x] Proper TypeScript strict mode
|
||||
```
|
||||
Loading…
Add table
Add a link
Reference in a new issue