Key-at-rest encryption is an unsalted SHA-256 KDF + unauthenticated AES-256-CBC
Public /api/v1/relay websocket: no auth, no frame/subscription/rate limits
Account allow/block/delete endpoints skip relay ownership check (cross-tenant IDOR)
Oversell race: stock is checked at invoice time but only decremented at settlement, with no refund path
Unique multi-use links can be over-withdrawn:
usescsv and used are whole-row read-modify-writes with no serialisation across sub-links
Inbound Nostr events are dispatched without signature verification
PUT /api/v1/relay/test accepts and echoes a raw Nostr private key
SQL injection: NostrFilter.to_sql_components interpolates client filter values into SQL
bug(cash-out): a jammed dispense takes the customer's sats, tells the server nothing, over-counts the cassette, and leaves the machine advertising itself as available
Spec'd as ADR-005 — docs/adr/005-cash-out-dispense-outcome.md (on dev, lands with the next push).
bug(cash-out): a jammed dispense takes the customer's sats, tells the server nothing, over-counts the cassette, and leaves the machine advertising itself as available
A fourth gap, surfaced by actually responding to this incident: there is no way to record that a failed dispense was settled off-machine.
bug(cash-out): a jammed dispense takes the customer's sats, tells the server nothing, over-counts the cassette, and leaves the machine advertising itself as available
fix(auth): don't require a Nostr pubkey to be considered logged in
padreug
deleted branch 2026-10-08 18:46:04 +00:00
fix/auth-guard-no-pubkey-requirement from aiolabs/webapp
fix(auth): don't require a Nostr pubkey to be considered logged in
padreug
created branch fix/auth-guard-no-pubkey-requirement in aiolabs/webapp
2026-10-08 18:43:59 +00:00
A relay outage at boot is misread as a revoked pairing, and latches the machine on the pairing wizard for good
feat(deploy): run the tejo from USB (disk-image-tejo-usb)