chore: scaffold payroll extension

Repo tooling and LNbits extension metadata only — no runtime code yet, so
this lands separately from the feature work per the workspace commit rules
(cross-cutting concerns commit first).

- MIT licence, .gitignore, README
- Makefile + pyproject wired for the standard aio fork lint pipeline
  (black + ruff + mypy) and pytest
- config.json declaring id/version/tile so the extension is installable
  from the aiolabs catalog once there is something to install

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018jy52j9GRZ6XKa1Zt21LLj
This commit is contained in:
Padreug 2026-08-31 13:36:32 +02:00
commit a211a8ab8b
7 changed files with 191 additions and 0 deletions

42
README.md Normal file
View file

@ -0,0 +1,42 @@
# Payroll
Scheduled recurring payouts between LNbits wallets, driven by the instance
**super user**.
Pick a user from the account directory, point the payout at one of their
wallets, set an amount + currency, a start date, how often it pays and how
many times — Payroll then moves the money on schedule, from a source wallet
you control, and keeps a ledger of every attempt.
## Status
Early. Built for `aiolabs` LNbits instances; see `docs/` for the data model
and operational notes.
## Who can use it
Everything under `/payroll/api/v1/` that reads the account directory or
touches a contract is gated on `check_super_user` — payroll moves money
between accounts the operator does not own, so wallet-level admin keys are
deliberately *not* enough. (`require_admin_key` authorises writes to your
own wallet only; it is not instance-admin. See the auth table in the
workspace `CLAUDE.md`.)
Add `payroll` to `LNBITS_ADMIN_EXTENSIONS` so the extension is hidden from
ordinary users in the UI as well.
## Development
```
make # black + ruff + mypy
make test # pytest
```
The dev LNbits compose mounts `~/dev/shared/extensions/` at `/shared` with
`LNBITS_EXTENSIONS_PATH=/shared`, so this checkout *is* the installed
extension. FakeWallet is enough — no regtest needed for anything except
end-to-end Lightning behaviour.
## Licence
MIT