Nostr-transport create/update bypass the HTTP validation; fiat links created over the transport are served at 1/100 of the configured price #3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
handle_lnurlp_create(transport_rpcs.py:44-51) doesCreatePayLinkData(**body)→create_pay_link(data)and skips the whole validation block ofapi_link_create_or_update(views_api.py:120-170). The concrete money bug: the HTTP path stores fiat amounts in minor units (data.min *= data.fiat_base_multiplier,views_api.py:151-153) and the serving path divides back (views_lnurl.py:54-56,:165-167). A link created over the transport withcurrency: "EUR", min: 5, max: 10is stored as 5/10 and served as 0.05–0.10 EUR. Also skipped:min > max, the full-satoshi rule,webhook_headers/webhook_bodyJSON validity (whichsend_webhooklaterjson.loads), thesuccess_urlscheme, and the username regex.handle_lnurlp_update(:103-105) does rawsetattron a pydantic v1 model, so even theCreatePayLinkDatafield constraints (min >= 0.01,comment_chars <= 799,fiat_base_multiplier >= 1) don't apply on update. The transport is the path lamassu-next uses to manage links.Fix direction: extract the validation (including fiat scaling) into one helper called from both the HTTP handler and the transport handlers; in update, rebuild through
CreatePayLinkDatarather thansetattr. Tests: fiat create over the transport → stored min/max in cents and LNURL response matches the configured price;min > maxrejected; malformedwebhook_headersrejected.Found during reforge run #1 (sandbox lnurlp#9).