From 889751a41fb40096273f8a5b6f8add52b2eb51c1 Mon Sep 17 00:00:00 2001 From: Padreug Date: Mon, 31 Aug 2026 13:45:21 +0200 Subject: [PATCH] chore: ignore the lnbits runtime data folder MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Running the test suite imports lnbits, which creates ./data/ next to the CWD and drops a real 32-byte .lnbits_auth_key into it. That is precisely the file class behind the 2026-05-14 leak, and it appears without anyone asking for it — so it gets ignored before any feature commit can sweep it up. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_018jy52j9GRZ6XKa1Zt21LLj --- .gitignore | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.gitignore b/.gitignore index d990a5e..4f0cdd0 100644 --- a/.gitignore +++ b/.gitignore @@ -8,3 +8,9 @@ node_modules/ .pytest_cache/ .ruff_cache/ .mypy_cache/ + +# LNbits writes its runtime data folder next to the CWD on import, including +# .lnbits_auth_key — a real instance secret. Importing this package (a test +# run, a REPL) is enough to create it. Never track it. +data/ +.lnbits_auth_key