Commit graph

50 commits

Author SHA1 Message Date
saubyk
a8baba12bb Replace deprecated request/request-promise with axios
request has been deprecated since 2020 with an unfixed SSRF advisory and
pins vulnerable copies of form-data (critical), qs, tough-cookie and
uuid - 8 of the 13 remaining production audit findings, none fixable by
version bumps (issue #1634, item 1).

All 36 backend files that imported request-promise now use a small
compatibility wrapper (server/utils/request.ts) backed by axios, which
is already a production dependency. The wrapper accepts the existing
options shape (qs, form - object or pre-encoded string, body,
baseUrl/uri, rejectUnauthorized, json), resolves with the response body
directly, and rejects with a plain object mirroring request-promise's
StatusCodeError/RequestError shape, so CommonService.handleError works
unchanged (ECONNREFUSED -> 503, Eclair StatusCodeError -> 500, nested
error body extraction). Auth headers are excluded from rejected errors
so they cannot leak into logs. Callers without json: true (block
explorer, currency rates) still get raw text bodies, and LND's
line-delimited /v2/router/send stream still surfaces as a string for
the existing parser.

Only behavioral code change: CLN verifyMessage used request-promise's
callback style and was ported to the same promise style as signMessage;
four Eclair handlers gained explicit returns to satisfy
noImplicitReturns once the import became typed.

Production npm audit drops from 13 findings (2 critical) to 6 low, all
in the crypto-browserify/elliptic chain tracked in #1634.

Verified against the docker regtest fixture with 43 API checks across
LND, Core Lightning and Eclair: reads, invoice creation, a routed LND
payment over the streaming endpoint, cross-implementation payments from
CLN and Eclair, message sign/verify, channel backup to disk, and
bad-invoice/node-unreachable error mapping. Lint and both production
builds are clean.
2026-07-19 22:01:23 -07:00
saubyk
e0fce065d5 Address 2nd review: guard limiter callbacks, CLN postPeer aliases, one-shot done
Follow-up to the second #1629 review:

- F4: the limiter invokes its done callback outside the surrounding .then/.catch,
  so a throw in the response-send body became an unhandled rejection with no
  response (a 500 -> hang regression, notably on LND postPeer where the inner
  .catch was removed). Wrap each converted done body in try/catch that sends the
  error response, guarded by res.headersSent.
- F5: CLN postPeer re-listed peers but never resolved their aliases, so a freshly
  connected CLN peer came back with a raw node id (the frontend uses this response
  directly). Resolve aliases through the same bounded limiter, matching LND postPeer.
- F6: make runWithConcurrencyLimit fire 'done' exactly once via a one-shot guard,
  so multiple synchronous completions (e.g. non-function task elements) can't
  double-send the response.
2026-07-19 22:01:23 -07:00
saubyk
bd74132265 Address review: self-contained CLN getAlias, LND peers bound, limiter guard
Follow-up to the #1501 review (PR #1629):

- F1: CLN getAlias now builds its request from selNode.authentication.options
  instead of the shared module-level 'options'. That coupling meant a cold
  Peers/route lookup dereferenced a null 'options'; with the new limiter
  swallowing per-task throws, that returned 200 with every alias unset. Aliases
  now resolve regardless of call order, with a truncated-id fallback if auth
  options are somehow absent.
- F2: mirror the 20-way concurrency bound to LND peers (getPeers and postPeer),
  which had the same unbounded Promise.all alias fan-out. Eclair resolves
  aliases inline from a bulk nodes list, so it needs no change.
- F3: normalize runWithConcurrencyLimit's start count to at least 1 so a
  non-positive limit can't leave 'done' unfired and hang the response.
2026-07-19 22:01:23 -07:00
saubyk
fbd336a89b Bound CLN alias resolution on peers and route lookups (#1501)
RTL resolves peer aliases by calling listnodes once per peer. A prior fix
(1cec7b1) bounded this to 20 concurrent calls plus a cache for the channel
list, but the peers list and route lookup still used an unbounded Promise.all,
firing one request per peer at once. On nodes with many peers this overwhelms
clnrest and fails with 'Resource temporarily unavailable (os error 11)'
(EAGAIN), so aliases fall back to raw node IDs.

- peers.ts and network.ts getRoute now resolve aliases via
  runWithConcurrencyLimit(tasks, 20, ...), matching the channel list.
- Harden runWithConcurrencyLimit to call done() immediately for an empty task
  list; otherwise an empty peers/route set would never send a response.
- Give the alias cache a 6h TTL and a max size (evicting oldest) so aliases
  refresh without an RTL restart and the cache can't grow unbounded.
2026-07-19 22:01:23 -07:00
saubyk
f518488ecb Clarify connected-mirror comment and pin the fixture rune path
Address review F7/F8 on #1625:

F7 (verification): the onchain.ts `connected === false` branch reads /v1/listfunds
(CLN's own connected field) and only buckets balance as inactive — it is not the
listPeerChannels mirror and does no close logic, so the coercion activates nothing
there. Reword the mirror comment, which inaccurately implied onchain.ts consumes it;
the mirror simply keeps the documented backward-compat `connected` field defined.

F8: hardcode the rune path in create-rune.sh to /root/.lightning/rtl.rune so it
matches the volume mount, healthcheck and RTL runePath instead of deriving it from
${LIGHTNINGD_DATA}, removing the silent-divergence risk.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-19 22:01:23 -07:00
saubyk
512aea96e5 Coerce mirrored peer_connected to a boolean
Address review feedback on #1625: copy peer_connected onto the legacy
`connected` field as a real boolean (!!), so strict-equality readers such as
onchain.ts's `connected === false` behave correctly when peer_connected is
absent, instead of leaving `connected` undefined.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-19 22:01:23 -07:00
saubyk
16d48417d8 Fix CLN channel connection status shown inconsistently (#1606)
CLN's listpeerchannels reports connection state as peer_connected, but the
open/pending channel list columns read the legacy `connected` field, which the
backend never populated. It was therefore always empty, so the list always
rendered "Disconnected" while the detail panel (which reads peer_connected)
showed the true state — the contradiction reported in #1606.

Normalize `connected = peer_connected` in the backend listPeerChannels response
so legacy consumers stay in sync, and point the list columns at peer_connected
directly. Add regression specs asserting the connected column follows
peer_connected even when the legacy field disagrees.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-19 22:01:23 -07:00
ShahanaFarooqui
e9e33da14d Fix page load bug due to zero connected channels (#1529) 2026-02-01 09:06:07 -08:00
ShahanaFarooqui
7340cb390a
Release 0.15.6 (#1506)
Fix for Resource temporarily unavailable error for CLN channel alias list
Security fix for npm vulnerabilities
2025-09-09 02:18:23 -07:00
ShahanaFarooqui
a594606d27
Release 0.15.3 (#1467)
* Fix `Unknown command` error when disabling offers on CLN. ([#1443]) (#1451)
* Add missing SSO options to config (#1455)
* Fix for cln logic screen navigation (#1457)
* Transactions destination address display fix (#1458)
* cln delexpiredinvoices deprecation fix (#1459)
* Read LN_IMPLEMENTATION from environment (#1460)
* Add Fee Rate Information on Send Funds Modal (#1461)
* Artifact script fix (#1464)
* Add AMP toggle for LND Send Payments (#1466)

---------

Co-authored-by: Se7enZ <118189041+s373nZ@users.noreply.github.com>
2024-11-10 20:23:52 -08:00
ShahanaFarooqui
b6dbd23ae7
Lint Fix (#1408)
Lint bug Fix
2024-06-10 16:41:37 -07:00
ShahanaFarooqui
22ab6d1154
Release 0.15.1 (#1406)
* rm .DS_Store

* Add watchfrontenddev command for npm

* Fix toggle issues in sidenav (pinning and on page refresh)

* Add copy-to-clipboard fallback if navigator.clipboard is not available (#1336)

* add copy-to-clipboard fallback if navigator.clipboard is not available

* amend copy fallback

* clipboard copy lint fixes and frontend build

* fix: add missing boltz state `transaction.lockupFailed` (#1349)

* fix: boltzd docs link (#1354)

* exit gracefully (#1356)

* allow for eclair updated relayed audit format (#1363)

* feat: add boltz service to cln (#1352)

* lint fix

* Request Params Cleanup

* cln: Boltz auto-send (#1366)

* Bug-fix (CLN Boltz): Hide claim tx id and routing fee for non-zero conf reverse swap

* cln: Boltz auto-send

- Added auto send option for Swap In
- Checking compatiblity with v2.0.0 and above

* Test import fixes

* Update help.component.ts (#1379)

Fixed broken link under "Help" -> "Node Settings"

* Backend config fix (#1382)

* Updating Common Application Configuration

* Fixed get RTL Conf

* Update Application Settings

* application and settings case change

* Unified config models

* Default node update

* 2FA and Password reset

* Final application settings update

* Config Settings and Authentication case fixed

* Node Setting Fix

* Fiat currency Symbol fix

* CLN: Fiat symbol fix

* All: Fiat symbol fix

* Update node settings

* Services UI fix

* CLN: Removed child node settings

* All: Removed child node settings

* Test fixes

* mempool links for onchain information (#1383)

* Tests fix

Tests fix

* UI for Block Explorer Configuration (#1385)

* Bump fee with mempool information (#1386)

* Mempool openchannel minfee (#1388)

Open channel model block if min fee is higher

* Show error on login screen if rune is incorrect and getinfo throws error (#1391)

* cln: Removed channel lookup call for update policy (#1392)

* ECL: On-chain Transactions, Invoice and Payments pagination (#1393)

Done most of the UI changes to accommodate pagination on transactions, payments and invoices tables but true pagination cannot be implemented till total number of records are missing from the API response.

Once the issue https://github.com/ACINQ/eclair/issues/2855 is fixed, I will uncomment pagination changes in the frontend.

* lnd: Onchain CPFP (#1394)

- UTXO label bug fix
- Warning on utxo label for "sweep" in text.

* Bug fixes after testing

* Testing bug fixes (#1401)

* Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too

* lnd: explorer link on pending channels

* Node lookup link on view channel peer pubkey

* Testing bug fixes (#1402)

* Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too

* lnd: explorer link on pending channels

* Node lookup link on view channel peer pubkey

* test fixes

* ng update to v18.0.x

* Updating install with  --legacy-peer-deps

---------

Co-authored-by: Grzegorz Kućmierz <gkucmierz@gmail.com>
Co-authored-by: lacksfish <lacksfish@gmail.com>
Co-authored-by: jackstar12 <62219658+jackstar12@users.noreply.github.com>
Co-authored-by: Kilian <19181985+kilrau@users.noreply.github.com>
Co-authored-by: Taylor King <taylorbradleyking@gmail.com>
Co-authored-by: Fishcake <128653975+fishcakeday@users.noreply.github.com>
Co-authored-by: Ant <72945059+2140data@users.noreply.github.com>
2024-06-10 12:40:37 -07:00
ShahanaFarooqui
475b47b7ea
Release 0.15.0 (#1334)
c-lightning-REST to clnrest migration.
2023-12-05 20:32:05 -08:00
ShahanaFarooqui
14fd866d1a Bug fix: Manage button link filter #1294 and Page Settings Error 2023-10-05 19:04:37 -07:00
ShahanaFarooqui
9768963862 bug fix: id to channel_id 2023-08-15 11:45:54 -07:00
Shahana Farooqui
1fcad6306f msatoshi migration without backward compatibility
msatoshi migration without backward compatibility
2023-05-29 12:27:28 -07:00
Shahana Farooqui
8bce41276b cln channels & transactions msat migration 2023-05-16 19:41:50 -07:00
ShahanaFarooqui
56e5558bf7 Offers Update #1206 2023-02-20 23:54:28 -08:00
ShahanaFarooqui
5107c300eb 2FA Fix
2FA Fix
2022-12-27 18:05:42 -08:00
ShahanaFarooqui
b505931c82 Removing channel type selection 2022-11-15 12:55:44 -08:00
ShahanaFarooqui
f8166e67e8 Offer Update & ECL camelCase Fix 2022-10-28 18:32:52 -07:00
ShahanaFarooqui
4d163a8216 db and ellipsis fix 2022-10-28 14:20:34 -07:00
ShahanaFarooqui
2e54ba92ac Fixed grid paddings 2022-10-28 09:41:38 -07:00
ShahanaFarooqui
eafc7835f8 CLN Peers and Channels Page Layout 2022-10-18 14:51:20 -07:00
ShahanaFarooqui
d98064ca2c CLN Offers and Bookmarks Page Layout
CLN Offers and Bookmarks Page Layout
2022-10-17 18:33:32 -07:00
ShahanaFarooqui
e7b03f4b2f CLN On-chain page settings
CLN On-chain page settings
2022-10-17 16:58:21 -07:00
ShahanaFarooqui
149561dedb CLN Invoices Page Settings
CLN Invoices Page Settings
2022-10-17 09:35:09 -07:00
ShahanaFarooqui
e74c5bc635 CLN Payment Sort 2022-10-17 08:37:58 -07:00
ShahanaFarooqui
772633b0c1 CLN Payment record/page & showcolumns except sort 2022-10-15 22:51:29 -07:00
ShahanaFarooqui
7a0bd37d91 Validate Document First 2022-10-15 17:25:46 -07:00
ShahanaFarooqui
a72f00a97b Page Settings
Page Settings
2022-10-14 13:53:36 -07:00
ShahanaFarooqui
6945d084b4 Base Config Page
Base Config Page
2022-10-12 14:38:21 -07:00
ShahanaFarooqui
e2eeb8b919 CLN Forwarding history filter and lint fixes
CLN Forwarding history filter and lint fixes
2022-08-17 15:48:04 -07:00
ShahanaFarooqui
cd2324944c Liquidity Ads address Type Chips
Liquidity Ads address Type Chips
2022-08-14 11:22:00 -07:00
Shahana Farooqui
a1a507a44d Fixing lint and test errors
Fixing lint and test errors
2022-08-11 03:16:09 -07:00
Shahana Farooqui
9165ae6a58 Removed list forwards from dashboard and pagination
Removed list forwards from dashboard and pagination
2022-08-10 23:43:01 -07:00
Shahana Farooqui
70abf7af25 Removed sorting from CLN paginated list forwards
Removed sorting from CLN paginated list forwards
2022-08-07 16:43:17 -07:00
ShahanaFarooqui
5f873ca50f
CLN Regtest network fix #974 (#1043)
CLN Regtest network fix #974
2022-06-21 20:29:30 -04:00
Shahana Farooqui
b8477e3613 CLN Liq Ads Node Explorer Links
CLN Liq Ads Node Explorer Links
2022-05-26 19:37:33 -04:00
ShahanaFarooqui
7d8a8a15d6
Cln forwards pagination (#1033)
List Forwards Pagination
List Forwards Backward Compatibility
2022-05-24 20:54:57 -04:00
Shahana Farooqui
976b6f0e27 Forwarding events pagination
Forwarding events pagination
2022-05-24 15:53:00 -04:00
Shahana Farooqui
3a9c436c32 Forwarding events pagination incomplete 2
Forwarding events pagination incomplete
2022-05-24 15:53:00 -04:00
Shahana Farooqui
1580c296cd Forwarding events pagination incomplete
Forwarding events pagination incomplete
2022-05-24 15:53:00 -04:00
Shahana Farooqui
c7fd9fad08 Liquidity Ads Page except channel count and capacity filters
Liquidity Ads Page except channel count and capacity filters
2022-05-20 12:11:01 -04:00
Shahana Farooqui
3795851acf Liquidity Ads Page Incomplete
Liquidity Ads Page Incomplete
2022-05-20 12:11:01 -04:00
Shahana Farooqui
346e414181 Liquidity Ads List Display Incomplete
Liquidity Ads List Display Incomplete
2022-05-20 12:11:01 -04:00
Shahana Farooqui
df5f5768c1 Funder Update POST
Funder Update POST
2022-05-16 15:40:16 -04:00
Shahana Farooqui
1e6786a850 Enable/Disable with listConfigs
Enable/Disable with listConfigs
2022-05-16 15:40:16 -04:00
Shahana Farooqui
519c18bafc Funder Policy Update
Funder Policy Update
2022-05-16 15:40:16 -04:00
ShahanaFarooqui
44412d357e
Release 0.12.3 (#1012)
LND Palemoon UX extension panel bug
Cookie file not generated for BTCPayServer #990
ECL Missing fee calculation on Dashboard #975
CLT channel filter on alias bug fix #982
CLightning to Code Lightning #997
Added Infographics for Channel Rebalance
CLN Base fee zero bug fix #987
ECL Query Route bug fix #1007
LND faster initial load
LND Transactions Lookup #1002
LND Bug fix for Routing Fee Calculation
2022-05-01 13:35:20 -04:00