Closes gap 2 from coord log 2026-06-01T18:30Z. The LNbits withdraw extension's nostr-transport RPC now populates `link.lnurl` from `settings.lnbits_baseurl` (aiolabs/withdraw#1 / commit e9d911e), so the ATM no longer needs a separate HTTP URL on the wire to compose the LNURL-withdraw callback itself. What goes: - `VITE_LNBITS_HTTP_URL` env var (renderer + Electron main) - `lnbitsHttpUrl` field on `LightningConfig`, `RuntimeConfig`, and the Window mirror in `src/types/electron.d.ts` - The manual `${lnbitsHttpUrl}/withdraw/api/v1/lnurl/${unique_hash}` composition in `generateLnurlWithdraw` - The `encodeLnurl` bech32 helper in `lightning.ts` (LNbits returns bech32-encoded; we just `.toUpperCase()` to match BOLT/LNURL convention) - `@scure/base` dep from `apps/machine/package.json` (only used by the removed helper; clink still uses it directly) - The `lnbitsHttpUrl` option + `LNBITS_HTTP_URL=…` env var + boot echo in `deploy/nixos/bitspire-atm.nix` - Doc references in CLAUDE.md, README.md, deploy/nixos/README.md, docs/architecture-comparison.md, and the lightning-check skill What stays: - `link.lnurl` consumption, with an explicit error if LNbits returns null (which signals `LNBITS_BASEURL` is unset on the server side — better to fail clearly than silently) - The receiver-side bech32 uppercasing (LNbits returns lowercase per the standard library) Why this is a net win: - Removes a config-drift surface — if LNbits's external URL moved (DNS, port, reverse-proxy rewrite), every ATM in the field would stop issuing redeemable LNURL-withdraw QRs until reconfigured. Now LNbits derives its own URL from `settings.lnbits_baseurl`, one source of truth. - Removes an extra provisioning step. No more `LNBITS_HTTP_URL=…` before running `provision-atm.sh`; the relay + server pubkey suffice. - Removes the misleading boot echo that triggered the §`18:30Z` smoke triage confusion ("LNbits HTTP: <url>" read like ATM-→-LNbits connectivity, when it was only ever a URL embedded in customer QRs). Also adds a `# pragma: allowlist secret` marker above the `VITE_ATM_PRIVATE_KEY` doc block in `.env.example` so the global secret scanner stops false-positiving on the documentation prose. Workspace typecheck + 24/24 apps/machine tests still green. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
72 lines
2.9 KiB
Bash
72 lines
2.9 KiB
Bash
# bitSpire ATM Configuration
|
|
# Copy this file to .env and fill in your values
|
|
|
|
# =============================================================================
|
|
# Hardware Configuration
|
|
# =============================================================================
|
|
|
|
# Machine model preset (sintra, gaia, or custom)
|
|
VITE_LAMASSU_MACHINE_MODEL=sintra
|
|
|
|
# Fiat currency code (ISO 4217)
|
|
VITE_LAMASSU_FIAT_CODE=USD
|
|
|
|
# Custom device paths (optional - uses preset defaults if not set)
|
|
# VITE_LAMASSU_VALIDATOR_DEVICE=/dev/ttyJ5
|
|
# VITE_LAMASSU_DISPENSER_DEVICE=/dev/ttyJ7
|
|
|
|
# Cassette configuration (optional - JSON array)
|
|
# VITE_LAMASSU_CASSETTES='[{"denomination":20,"count":100}]'
|
|
|
|
# =============================================================================
|
|
# LNbits Connection (Required) — nostr-native-transport
|
|
# =============================================================================
|
|
|
|
# Nostr relay WebSocket URL — relay LNbits is subscribed to.
|
|
VITE_RELAY_URL=ws://localhost:7777
|
|
|
|
# LNbits nostr-transport server pubkey (hex, 64 chars).
|
|
# Printed by the LNbits server on startup:
|
|
# docker logs lnbits | grep 'nostr_transport pubkey'
|
|
VITE_LNBITS_SERVER_PUBKEY=
|
|
|
|
# (LNbits HTTP URL is no longer needed on the ATM side — the
|
|
# nostr-transport RPC `lnurlw_create_link` now returns `link.lnurl`
|
|
# populated from `settings.lnbits_baseurl` on the LNbits server. See
|
|
# aiolabs/withdraw#1 / commit e9d911e.)
|
|
|
|
# =============================================================================
|
|
# ATM Identity
|
|
# =============================================================================
|
|
|
|
# pragma: allowlist secret
|
|
# ATM's Nostr private key (hex format, 64 characters). This signing
|
|
# key IS the credential — LNbits derives the account from it on first
|
|
# contact (issue aiolabs/lnbits#9 alignment).
|
|
# Generate with: openssl rand -hex 32
|
|
# If not set, generates ephemeral identity on each restart (dev only).
|
|
VITE_ATM_PRIVATE_KEY=
|
|
|
|
# =============================================================================
|
|
# Operator Identity
|
|
# =============================================================================
|
|
|
|
# Comma-separated list of Nostr hex pubkeys authorized to send operator commands
|
|
# (manual dispense, remote management).
|
|
# VITE_OPERATOR_PUBKEYS=abcd1234...,ef567890...
|
|
|
|
# =============================================================================
|
|
# Maintenance Mode
|
|
# =============================================================================
|
|
|
|
# Show "Under Service" screen and block all transactions
|
|
# VITE_MAINTENANCE_MODE=true
|
|
|
|
# =============================================================================
|
|
# Mock Fallback (Production Safety)
|
|
# =============================================================================
|
|
|
|
# Allow fallback to mock services when hardware/Lightning fails (default: false)
|
|
# Set to 'true' for development/demo environments only
|
|
# When false (production default), initialization failures show a maintenance screen
|
|
# VITE_ALLOW_MOCK_FALLBACK=true
|