chore: ignore the lnbits runtime data folder

Running the test suite imports lnbits, which creates ./data/ next to the
CWD and drops a real 32-byte .lnbits_auth_key into it. That is precisely
the file class behind the 2026-05-14 leak, and it appears without anyone
asking for it — so it gets ignored before any feature commit can sweep it
up.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018jy52j9GRZ6XKa1Zt21LLj
This commit is contained in:
Padreug 2026-08-31 13:45:21 +02:00
commit 889751a41f

6
.gitignore vendored
View file

@ -8,3 +8,9 @@ node_modules/
.pytest_cache/ .pytest_cache/
.ruff_cache/ .ruff_cache/
.mypy_cache/ .mypy_cache/
# LNbits writes its runtime data folder next to the CWD on import, including
# .lnbits_auth_key — a real instance secret. Importing this package (a test
# run, a REPL) is enough to create it. Never track it.
data/
.lnbits_auth_key