2018-09-14 21:31:01 -04:00
|
|
|
{
|
|
|
|
|
"name": "rtl",
|
2026-07-28 19:33:35 -07:00
|
|
|
"version": "0.15.10-beta",
|
2018-09-14 21:31:01 -04:00
|
|
|
"license": "MIT",
|
2021-12-29 18:08:41 -05:00
|
|
|
"type": "module",
|
2019-01-10 23:08:24 -05:00
|
|
|
"scripts": {
|
|
|
|
|
"ng": "ng",
|
2020-12-20 18:36:04 -05:00
|
|
|
"start": "ng serve --open",
|
2022-05-01 14:37:35 -04:00
|
|
|
"prebuildfrontendtest": "node src/prebuild.cjs",
|
2021-12-29 18:08:41 -05:00
|
|
|
"prebuildfrontend": "node src/prebuild.cjs",
|
2024-06-10 12:40:37 -07:00
|
|
|
"watchfrontenddev": "ng build --configuration development --optimization false --watch",
|
2022-12-13 15:53:41 -08:00
|
|
|
"buildfrontendtest": "ng test --watch=false && ng build",
|
|
|
|
|
"buildfrontend": "ng build --configuration production",
|
2026-01-20 16:16:39 -08:00
|
|
|
"buildbackend": "npx tsc --project ./server/tsconfig.server.json",
|
|
|
|
|
"watchbackend": "npx tsc --project ./server/tsconfig.server.json --watch",
|
2022-09-28 18:15:37 -07:00
|
|
|
"server": "set NODE_ENV=development&&nodemon --watch backend --watch server ./rtl.js",
|
2022-09-21 17:19:25 -07:00
|
|
|
"serverUbuntu": "NODE_ENV=development nodemon --watch backend --watch server ./rtl.js",
|
2021-12-29 18:08:41 -05:00
|
|
|
"testdev": "ng test --watch=true --code-coverage",
|
2022-12-27 19:12:27 -08:00
|
|
|
"test": "ng test --watch=false --browsers=ChromeHeadless",
|
2024-06-10 16:41:37 -07:00
|
|
|
"lint": "eslint"
|
2019-01-10 23:08:24 -05:00
|
|
|
},
|
2018-09-14 21:31:01 -04:00
|
|
|
"private": true,
|
|
|
|
|
"dependencies": {
|
2026-01-20 16:16:39 -08:00
|
|
|
"@ngrx/effects": "21.0.1",
|
|
|
|
|
"@ngrx/store": "21.0.1",
|
|
|
|
|
"@swimlane/ngx-charts": "23.1.0",
|
2025-09-09 14:48:23 +05:30
|
|
|
"angular-user-idle": "4.0.0",
|
|
|
|
|
"atob": "2.1.2",
|
Update project dependencies to resolve Dependabot security alerts
Applies the fixes from the open Dependabot PRs (#1648, #1649, #1650) in a
single pass on the release branch, regenerating the lockfile from scratch.
axios 1.16.0 -> 1.18.1 was the only production exposure (10 advisories).
Transitive deps moved to their fixed in-range versions (fast-uri 3.1.4,
form-data, qs, tough-cookie, tar, del, globby); dev toolchain took safe
bumps (nodemon 3.1.14, eslint 9.39.5, @typescript-eslint 8.65.0).
Drops the unused protractor devDependency: no e2e directory, no config and
no e2e target in angular.json, but 100 packages and the deprecated request
stack behind it. That clears both critical advisories.
npm audit: 50 (2 critical) -> 29 (0 critical); production deps 1 -> 0.
Remaining findings are dev-only tooling needing an Angular 21 migration
rather than a version bump.
Verified: lint, 204 frontend specs, backend + frontend production builds,
and 19 API checks against the docker regtest fixture covering LND, Core
Lightning and Eclair (getinfo, channels, peers, invoices, payments and
forwarding history).
2026-07-28 20:44:46 -07:00
|
|
|
"axios": "1.18.1",
|
2026-01-20 16:16:39 -08:00
|
|
|
"buffer": "6.0.3",
|
|
|
|
|
"cookie-parser": "1.4.7",
|
Replace deprecated csurf with csrf-csrf
csurf has been deprecated since 2022 and pins an old cookie release
with a known advisory; npm's only fix is a downgrade (issue #1634,
item 2). csrf-csrf v4 implements the same double-submit-cookie pattern
with an HMAC-signed, session-bound token keyed on the existing boot
secret (common.secret_key).
The frontend contract is unchanged: the token still arrives via the
XSRF-TOKEN cookie/header and is echoed as x-xsrf-token (all token
sources csurf accepted are still read), the signed cookie keeps the
_csrf name (now httpOnly, secure:false to match the session cookie on
plain-HTTP deployments), doubleCsrfProtection attaches req.csrfToken
so app.ts keeps working, and the error code is EBADCSRFTOKEN - already
handled in app.ts. The websocket upgrade check in authCheck.ts now
routes through the shared middleware; upgrade requests are GETs, so
its pass-through semantics are unchanged.
One fix this surfaced: app.ts called req.csrfToken() twice (cookie and
header). Under csurf every token validated against a stable secret;
under csrf-csrf each first-visit call mints a new token, desyncing the
XSRF-TOKEN cookie from the _csrf cookie it must equal. The token is
now generated once per request.
Tokens are session-bound, so a token stolen from one session no longer
validates in another - a check csurf's cookie mode did not perform.
Production npm audit drops from 6 low findings to 4, all in the
crypto-browserify/elliptic chain tracked in #1634.
Verified against the docker regtest fixture: both API suites (43
checks across LND, CLN and Eclair) plus a dedicated CSRF battery -
valid-token auth, missing token 403, garbage token 403, cross-session
replay 403, token stability across requests, the XSRF-TOKEN response
header for Quickpay, and the websocket handshake. Lint and build are
clean.
2026-07-19 17:03:53 -07:00
|
|
|
"csrf-csrf": "4.0.3",
|
2026-01-20 16:16:39 -08:00
|
|
|
"express": "5.2.1",
|
|
|
|
|
"express-session": "1.18.2",
|
2025-09-09 14:48:23 +05:30
|
|
|
"hocon-parser": "1.0.1",
|
2026-01-20 16:16:39 -08:00
|
|
|
"ini": "6.0.0",
|
|
|
|
|
"jsonwebtoken": "9.0.3",
|
|
|
|
|
"ng-qrcode": "21.0.0",
|
2025-09-09 14:48:23 +05:30
|
|
|
"ngx-perfect-scrollbar-next": "10.1.1",
|
|
|
|
|
"otplib": "12.0.1",
|
2026-07-18 18:50:35 -07:00
|
|
|
"pdfmake": "0.3.11",
|
2025-09-09 14:48:23 +05:30
|
|
|
"process": "0.11.10",
|
2026-01-20 16:16:39 -08:00
|
|
|
"rxjs": "7.8.2",
|
2025-09-09 14:48:23 +05:30
|
|
|
"sha256": "0.2.0",
|
2026-01-20 16:16:39 -08:00
|
|
|
"socket.io-client": "4.8.3",
|
|
|
|
|
"tslib": "2.8.1",
|
Update project dependencies to resolve Dependabot security alerts
Apply the bumps from all 20 open Dependabot security PRs (#1583-#1617)
in one pass on the release branch: axios 1.16.0, ws 8.21.0, the
socket.io server stack, express path-to-regexp, follow-redirects,
lodash and the remaining flagged transitive deps. Angular framework
packages move in lockstep to 20.3.26 and the CLI/build toolchain to
20.3.32, which drops the vulnerable node-forge from the tree entirely.
Also pick up in-range fixes without open PRs (qs, uuid, tough-cookie,
cookie, ajv, bn.js, elliptic, socket.io-parser).
npm audit: 85 vulnerabilities (23 prod) -> 30 (14 prod). The remainder
(request/request-promise, csurf, pdfmake, crypto-browserify chain)
needs code changes, not bumps, and is tracked separately.
Verified: lint, 199 frontend specs, backend + frontend production
builds, and an end-to-end smoke test against the docker regtest
fixture (LND, CLN and Eclair auth/getinfo/channels + WS upgrade).
2026-07-18 18:09:06 -07:00
|
|
|
"ws": "8.21.0",
|
2026-01-20 16:16:39 -08:00
|
|
|
"zone.js": "0.16.0"
|
2019-01-10 23:08:24 -05:00
|
|
|
},
|
|
|
|
|
"devDependencies": {
|
Update project dependencies to resolve Dependabot security alerts
Apply the bumps from all 20 open Dependabot security PRs (#1583-#1617)
in one pass on the release branch: axios 1.16.0, ws 8.21.0, the
socket.io server stack, express path-to-regexp, follow-redirects,
lodash and the remaining flagged transitive deps. Angular framework
packages move in lockstep to 20.3.26 and the CLI/build toolchain to
20.3.32, which drops the vulnerable node-forge from the tree entirely.
Also pick up in-range fixes without open PRs (qs, uuid, tough-cookie,
cookie, ajv, bn.js, elliptic, socket.io-parser).
npm audit: 85 vulnerabilities (23 prod) -> 30 (14 prod). The remainder
(request/request-promise, csurf, pdfmake, crypto-browserify chain)
needs code changes, not bumps, and is tracked separately.
Verified: lint, 199 frontend specs, backend + frontend production
builds, and an end-to-end smoke test against the docker regtest
fixture (LND, CLN and Eclair auth/getinfo/channels + WS upgrade).
2026-07-18 18:09:06 -07:00
|
|
|
"@angular-devkit/build-angular": "20.3.32",
|
2026-01-20 16:16:39 -08:00
|
|
|
"@angular-eslint/builder": "20.7.0",
|
|
|
|
|
"@angular-eslint/eslint-plugin": "20.7.0",
|
|
|
|
|
"@angular-eslint/eslint-plugin-template": "20.7.0",
|
|
|
|
|
"@angular-eslint/schematics": "20.7.0",
|
|
|
|
|
"@angular-eslint/template-parser": "20.7.0",
|
Update project dependencies to resolve Dependabot security alerts
Apply the bumps from all 20 open Dependabot security PRs (#1583-#1617)
in one pass on the release branch: axios 1.16.0, ws 8.21.0, the
socket.io server stack, express path-to-regexp, follow-redirects,
lodash and the remaining flagged transitive deps. Angular framework
packages move in lockstep to 20.3.26 and the CLI/build toolchain to
20.3.32, which drops the vulnerable node-forge from the tree entirely.
Also pick up in-range fixes without open PRs (qs, uuid, tough-cookie,
cookie, ajv, bn.js, elliptic, socket.io-parser).
npm audit: 85 vulnerabilities (23 prod) -> 30 (14 prod). The remainder
(request/request-promise, csurf, pdfmake, crypto-browserify chain)
needs code changes, not bumps, and is tracked separately.
Verified: lint, 199 frontend specs, backend + frontend production
builds, and an end-to-end smoke test against the docker regtest
fixture (LND, CLN and Eclair auth/getinfo/channels + WS upgrade).
2026-07-18 18:09:06 -07:00
|
|
|
"@angular/animations": "20.3.26",
|
|
|
|
|
"@angular/build": "20.3.32",
|
2026-01-20 16:16:39 -08:00
|
|
|
"@angular/cdk": "20.2.14",
|
Update project dependencies to resolve Dependabot security alerts
Apply the bumps from all 20 open Dependabot security PRs (#1583-#1617)
in one pass on the release branch: axios 1.16.0, ws 8.21.0, the
socket.io server stack, express path-to-regexp, follow-redirects,
lodash and the remaining flagged transitive deps. Angular framework
packages move in lockstep to 20.3.26 and the CLI/build toolchain to
20.3.32, which drops the vulnerable node-forge from the tree entirely.
Also pick up in-range fixes without open PRs (qs, uuid, tough-cookie,
cookie, ajv, bn.js, elliptic, socket.io-parser).
npm audit: 85 vulnerabilities (23 prod) -> 30 (14 prod). The remainder
(request/request-promise, csurf, pdfmake, crypto-browserify chain)
needs code changes, not bumps, and is tracked separately.
Verified: lint, 199 frontend specs, backend + frontend production
builds, and an end-to-end smoke test against the docker regtest
fixture (LND, CLN and Eclair auth/getinfo/channels + WS upgrade).
2026-07-18 18:09:06 -07:00
|
|
|
"@angular/cli": "20.3.32",
|
|
|
|
|
"@angular/common": "20.3.26",
|
|
|
|
|
"@angular/compiler": "20.3.26",
|
|
|
|
|
"@angular/compiler-cli": "20.3.26",
|
|
|
|
|
"@angular/core": "20.3.26",
|
2025-09-09 14:48:23 +05:30
|
|
|
"@angular/flex-layout": "15.0.0-beta.42",
|
Update project dependencies to resolve Dependabot security alerts
Apply the bumps from all 20 open Dependabot security PRs (#1583-#1617)
in one pass on the release branch: axios 1.16.0, ws 8.21.0, the
socket.io server stack, express path-to-regexp, follow-redirects,
lodash and the remaining flagged transitive deps. Angular framework
packages move in lockstep to 20.3.26 and the CLI/build toolchain to
20.3.32, which drops the vulnerable node-forge from the tree entirely.
Also pick up in-range fixes without open PRs (qs, uuid, tough-cookie,
cookie, ajv, bn.js, elliptic, socket.io-parser).
npm audit: 85 vulnerabilities (23 prod) -> 30 (14 prod). The remainder
(request/request-promise, csurf, pdfmake, crypto-browserify chain)
needs code changes, not bumps, and is tracked separately.
Verified: lint, 199 frontend specs, backend + frontend production
builds, and an end-to-end smoke test against the docker regtest
fixture (LND, CLN and Eclair auth/getinfo/channels + WS upgrade).
2026-07-18 18:09:06 -07:00
|
|
|
"@angular/forms": "20.3.26",
|
2026-01-20 16:16:39 -08:00
|
|
|
"@angular/material": "20.2.14",
|
Update project dependencies to resolve Dependabot security alerts
Apply the bumps from all 20 open Dependabot security PRs (#1583-#1617)
in one pass on the release branch: axios 1.16.0, ws 8.21.0, the
socket.io server stack, express path-to-regexp, follow-redirects,
lodash and the remaining flagged transitive deps. Angular framework
packages move in lockstep to 20.3.26 and the CLI/build toolchain to
20.3.32, which drops the vulnerable node-forge from the tree entirely.
Also pick up in-range fixes without open PRs (qs, uuid, tough-cookie,
cookie, ajv, bn.js, elliptic, socket.io-parser).
npm audit: 85 vulnerabilities (23 prod) -> 30 (14 prod). The remainder
(request/request-promise, csurf, pdfmake, crypto-browserify chain)
needs code changes, not bumps, and is tracked separately.
Verified: lint, 199 frontend specs, backend + frontend production
builds, and an end-to-end smoke test against the docker regtest
fixture (LND, CLN and Eclair auth/getinfo/channels + WS upgrade).
2026-07-18 18:09:06 -07:00
|
|
|
"@angular/platform-browser": "20.3.26",
|
|
|
|
|
"@angular/platform-browser-dynamic": "20.3.26",
|
|
|
|
|
"@angular/router": "20.3.26",
|
2026-01-20 16:16:39 -08:00
|
|
|
"@eslint/eslintrc": "3.3.3",
|
|
|
|
|
"@fortawesome/angular-fontawesome": "4.0.0",
|
|
|
|
|
"@fortawesome/fontawesome-svg-core": "7.1.0",
|
|
|
|
|
"@fortawesome/free-regular-svg-icons": "7.1.0",
|
|
|
|
|
"@fortawesome/free-solid-svg-icons": "7.1.0",
|
|
|
|
|
"@ngrx/store-devtools": "21.0.1",
|
|
|
|
|
"@types/jasmine": "5.1.15",
|
|
|
|
|
"@types/node": "20.19.30",
|
Update project dependencies to resolve Dependabot security alerts
Applies the fixes from the open Dependabot PRs (#1648, #1649, #1650) in a
single pass on the release branch, regenerating the lockfile from scratch.
axios 1.16.0 -> 1.18.1 was the only production exposure (10 advisories).
Transitive deps moved to their fixed in-range versions (fast-uri 3.1.4,
form-data, qs, tough-cookie, tar, del, globby); dev toolchain took safe
bumps (nodemon 3.1.14, eslint 9.39.5, @typescript-eslint 8.65.0).
Drops the unused protractor devDependency: no e2e directory, no config and
no e2e target in angular.json, but 100 packages and the deprecated request
stack behind it. That clears both critical advisories.
npm audit: 50 (2 critical) -> 29 (0 critical); production deps 1 -> 0.
Remaining findings are dev-only tooling needing an Angular 21 migration
rather than a version bump.
Verified: lint, 204 frontend specs, backend + frontend production builds,
and 19 API checks against the docker regtest fixture covering LND, Core
Lightning and Eclair (getinfo, channels, peers, invoices, payments and
forwarding history).
2026-07-28 20:44:46 -07:00
|
|
|
"@typescript-eslint/eslint-plugin": "8.65.0",
|
|
|
|
|
"@typescript-eslint/parser": "8.65.0",
|
2026-01-20 16:16:39 -08:00
|
|
|
"dotenv": "17.2.3",
|
Update project dependencies to resolve Dependabot security alerts
Applies the fixes from the open Dependabot PRs (#1648, #1649, #1650) in a
single pass on the release branch, regenerating the lockfile from scratch.
axios 1.16.0 -> 1.18.1 was the only production exposure (10 advisories).
Transitive deps moved to their fixed in-range versions (fast-uri 3.1.4,
form-data, qs, tough-cookie, tar, del, globby); dev toolchain took safe
bumps (nodemon 3.1.14, eslint 9.39.5, @typescript-eslint 8.65.0).
Drops the unused protractor devDependency: no e2e directory, no config and
no e2e target in angular.json, but 100 packages and the deprecated request
stack behind it. That clears both critical advisories.
npm audit: 50 (2 critical) -> 29 (0 critical); production deps 1 -> 0.
Remaining findings are dev-only tooling needing an Angular 21 migration
rather than a version bump.
Verified: lint, 204 frontend specs, backend + frontend production builds,
and 19 API checks against the docker regtest fixture covering LND, Core
Lightning and Eclair (getinfo, channels, peers, invoices, payments and
forwarding history).
2026-07-28 20:44:46 -07:00
|
|
|
"eslint": "9.39.5",
|
2025-09-09 14:48:23 +05:30
|
|
|
"eslint-plugin-deprecation": "3.0.0",
|
2026-01-20 16:16:39 -08:00
|
|
|
"jasmine-core": "5.13.0",
|
2025-09-09 14:48:23 +05:30
|
|
|
"jasmine-spec-reporter": "7.0.0",
|
2026-01-20 16:16:39 -08:00
|
|
|
"karma": "6.4.4",
|
2025-09-09 14:48:23 +05:30
|
|
|
"karma-chrome-launcher": "3.2.0",
|
|
|
|
|
"karma-coverage": "2.2.1",
|
|
|
|
|
"karma-jasmine": "5.1.0",
|
|
|
|
|
"karma-jasmine-html-reporter": "2.1.0",
|
2026-01-20 16:16:39 -08:00
|
|
|
"material-icons": "1.13.14",
|
Update project dependencies to resolve Dependabot security alerts
Applies the fixes from the open Dependabot PRs (#1648, #1649, #1650) in a
single pass on the release branch, regenerating the lockfile from scratch.
axios 1.16.0 -> 1.18.1 was the only production exposure (10 advisories).
Transitive deps moved to their fixed in-range versions (fast-uri 3.1.4,
form-data, qs, tough-cookie, tar, del, globby); dev toolchain took safe
bumps (nodemon 3.1.14, eslint 9.39.5, @typescript-eslint 8.65.0).
Drops the unused protractor devDependency: no e2e directory, no config and
no e2e target in angular.json, but 100 packages and the deprecated request
stack behind it. That clears both critical advisories.
npm audit: 50 (2 critical) -> 29 (0 critical); production deps 1 -> 0.
Remaining findings are dev-only tooling needing an Angular 21 migration
rather than a version bump.
Verified: lint, 204 frontend specs, backend + frontend production builds,
and 19 API checks against the docker regtest fixture covering LND, Core
Lightning and Eclair (getinfo, channels, peers, invoices, payments and
forwarding history).
2026-07-28 20:44:46 -07:00
|
|
|
"nodemon": "3.1.14",
|
2025-09-09 14:48:23 +05:30
|
|
|
"roboto-fontface": "0.10.0",
|
|
|
|
|
"ts-node": "10.9.2",
|
2026-01-20 16:16:39 -08:00
|
|
|
"typescript": "5.8.3"
|
2025-09-09 14:48:23 +05:30
|
|
|
},
|
|
|
|
|
"overrides": {
|
|
|
|
|
"chalk": "4.1.0",
|
|
|
|
|
"strip-ansi": "6.0.1",
|
|
|
|
|
"color-convert": "2.0.1",
|
|
|
|
|
"color-name": "1.1.4",
|
|
|
|
|
"is-core-module": "2.13.0",
|
|
|
|
|
"error-ex": "1.3.2",
|
|
|
|
|
"has-ansi": "2.1.1"
|
2026-01-20 16:16:39 -08:00
|
|
|
}
|
2024-06-10 16:41:37 -07:00
|
|
|
}
|