fix(auth): don't require a Nostr pubkey to be considered logged in #180
No reviewers
Labels
No labels
app:activities
app:chat
app:chatelet
app:events
app:forum
app:libra
app:market
app:restaurant
app:tasks
app:wallet
app:webapp
bug
enhancement
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
aiolabs/webapp!180
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/auth-guard-no-pubkey-requirement"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Symptom
Logging into the wallet standalone redirects straight back to
/login, forever. Same for accounting. Reproduced on atio.Cause
src/lib/router-helpers.ts:For an account with no Nostr pubkey this is a closed loop: login succeeds, lnbits issues a token,
isAuthenticatedflips true — butpubkeyis empty, soisFullyAuthedstays false andinstallStrictAuthGuardbounces every route back to/login.It bites wallet, chat and accounting (the three strict-guard apps). On atio, 9 of 58 accounts have a Nostr identity; the other 49 are Lightning-only and locked out.
The pubkey check was never about needing an identity. It was added for #36 as a proxy for "
getCurrentUser()actually came back", so a stale token in localStorage couldn't count as a session. Pubkey happened to be a reliable marker — until a population without one showed up.Fix
Key the check on
idinstead. Every account has one, so the #36 protection is preserved exactly (a bare token still doesn't satisfy it) and the incidental identity requirement goes away.Then put the genuine requirement where it actually belongs —
installStrictAuthGuardtakes an optional{ requirePubkey }, and only chat sets it:Chat is Nostr end-to-end and can't function without a key. Wallet and accounting are payment/ledger surfaces, and per ADR-0001 in
aiolabs/lnbits— LNbits is a liquidity service, not an identity provider — core payment flows must not be gated on having an identity. Being unable to see your Lightning balance without a Nostr key is that principle inverted.Verification
nostr-toolsimport isnip19.encodeBytes('lnurl', …)inWalletPage.vue, used for bech32-encoding a pay link into the receive QR — a codec, nothing to do with identity.vue-tsc -bpasses.walletandaccountingare untouched.installLenientAuthGuardsharesisFullyAuthed, so the public standalones'meta.requiresAuthroutes get the same fix for free.Known gap, deliberately not fixed here
A pubkey-less user opening chat still loops at
/logininstead of seeing an "identity required" screen. That loop is now correct behaviour rather than a bug, but it's still a poor way to express it and deserves a proper message. Happy to split that into its own issue.Context
Surfaced while moving atio onto the lnbits dev channel (
aiolabs/lnbits#78). atio is the first instance with a large Lightning-only population, which is why this went unnoticed — every other instance's accounts happen to have pubkeys.