• Joined on 2025-12-31
padreug opened issue aiolabs/nsecbunkerd#55 2026-10-09 16:47:36 +00:00
Key-at-rest encryption is an unsalted SHA-256 KDF + unauthenticated AES-256-CBC
padreug opened issue aiolabs/nostrclient#7 2026-10-09 16:47:33 +00:00
Public /api/v1/relay websocket: no auth, no frame/subscription/rate limits
padreug opened issue aiolabs/nostrrelay#9 2026-10-09 16:47:27 +00:00
Account allow/block/delete endpoints skip relay ownership check (cross-tenant IDOR)
padreug opened issue aiolabs/nostrmarket#10 2026-10-09 16:47:23 +00:00
Oversell race: stock is checked at invoice time but only decremented at settlement, with no refund path
padreug opened issue aiolabs/withdraw#4 2026-10-09 16:47:22 +00:00
Unique multi-use links can be over-withdrawn: usescsv and used are whole-row read-modify-writes with no serialisation across sub-links
padreug opened issue aiolabs/nostrmarket#9 2026-10-09 16:47:18 +00:00
Inbound Nostr events are dispatched without signature verification
padreug opened issue aiolabs/nostrclient#6 2026-10-09 16:47:17 +00:00
PUT /api/v1/relay/test accepts and echoes a raw Nostr private key
padreug opened issue aiolabs/nostrrelay#8 2026-10-09 16:47:12 +00:00
SQL injection: NostrFilter.to_sql_components interpolates client filter values into SQL
padreug commented on issue aiolabs/bitspire#122 2026-10-09 14:35:02 +00:00
bug(cash-out): a jammed dispense takes the customer's sats, tells the server nothing, over-counts the cassette, and leaves the machine advertising itself as available

Spec'd as ADR-005 — docs/adr/005-cash-out-dispense-outcome.md (on dev, lands with the next push).

padreug commented on issue aiolabs/bitspire#122 2026-10-09 07:20:28 +00:00
bug(cash-out): a jammed dispense takes the customer's sats, tells the server nothing, over-counts the cassette, and leaves the machine advertising itself as available

A fourth gap, surfaced by actually responding to this incident: there is no way to record that a failed dispense was settled off-machine.

padreug opened issue aiolabs/bitspire#122 2026-10-09 07:16:28 +00:00
bug(cash-out): a jammed dispense takes the customer's sats, tells the server nothing, over-counts the cassette, and leaves the machine advertising itself as available
padreug merged pull request aiolabs/webapp#180 2026-10-08 18:46:04 +00:00
fix(auth): don't require a Nostr pubkey to be considered logged in
padreug pushed to dev at aiolabs/webapp 2026-10-08 18:46:04 +00:00
54c1c990e1 Merge pull request 'fix(auth): don't require a Nostr pubkey to be considered logged in' (#180) from fix/auth-guard-no-pubkey-requirement into dev
7497e6b3e5 fix(auth): don't require a Nostr pubkey to be considered logged in
Compare 2 commits »
padreug deleted branch fix/auth-guard-no-pubkey-requirement from aiolabs/webapp 2026-10-08 18:46:04 +00:00
padreug created pull request aiolabs/webapp#180 2026-10-08 18:44:20 +00:00
fix(auth): don't require a Nostr pubkey to be considered logged in
padreug created branch fix/auth-guard-no-pubkey-requirement in aiolabs/webapp 2026-10-08 18:43:59 +00:00
padreug pushed to fix/auth-guard-no-pubkey-requirement at aiolabs/webapp 2026-10-08 18:43:59 +00:00
7497e6b3e5 fix(auth): don't require a Nostr pubkey to be considered logged in
padreug opened issue aiolabs/bitspire#121 2026-10-08 05:34:59 +00:00
A relay outage at boot is misread as a revoked pairing, and latches the machine on the pairing wizard for good
padreug merged pull request aiolabs/bitspire#120 2026-10-06 17:35:43 +00:00
feat(deploy): run the tejo from USB (disk-image-tejo-usb)
padreug pushed to dev at aiolabs/bitspire 2026-10-06 17:35:43 +00:00
695a8bf98d Merge pull request 'feat(deploy): run the tejo from USB (disk-image-tejo-usb)' (#120) from feat/tejo-usb into dev
6042d69356 fix(deploy): tejo had no WireGuard address, so it had no way back in
c3e01c9cd3 feat(deploy): USB-bootable tejo image (disk-image-tejo-usb)
81a001c3d3 refactor(deploy): one USB-image helper for both bootloader shapes
Compare 4 commits »