Commit graph

181 commits

Author SHA1 Message Date
saubyk
234956b174
Update project dependencies to resolve Dependabot security alerts
Applies the fixes from the open Dependabot PRs (#1648, #1649, #1650) in a
single pass on the release branch, regenerating the lockfile from scratch.

axios 1.16.0 -> 1.18.1 was the only production exposure (10 advisories).
Transitive deps moved to their fixed in-range versions (fast-uri 3.1.4,
form-data, qs, tough-cookie, tar, del, globby); dev toolchain took safe
bumps (nodemon 3.1.14, eslint 9.39.5, @typescript-eslint 8.65.0).

Drops the unused protractor devDependency: no e2e directory, no config and
no e2e target in angular.json, but 100 packages and the deprecated request
stack behind it. That clears both critical advisories.

npm audit: 50 (2 critical) -> 29 (0 critical); production deps 1 -> 0.
Remaining findings are dev-only tooling needing an Angular 21 migration
rather than a version bump.

Verified: lint, 204 frontend specs, backend + frontend production builds,
and 19 API checks against the docker regtest fixture covering LND, Core
Lightning and Eclair (getinfo, channels, peers, invoices, payments and
forwarding history).
2026-07-28 20:44:46 -07:00
saubyk
785f485019
Update version 0.15.10 2026-07-28 19:33:35 -07:00
saubyk
c5dc49711c Drop crypto-browserify polyfills by moving 2FA TOTP to WebCrypto
The frontend build pulled in crypto-browserify, stream-browserify and
vm-browserify (via tsconfig paths) only because otplib's
@otplib/plugin-crypto requires Node's crypto. That chain carried the
last production npm audit findings - the elliptic advisory
(GHSA-848j-6mx2-7j84, no fixed release) plus browserify-sign/create-ecdh
(issue #1634, item 3).

The two-factor-auth settings dialog is the only browser consumer of
otplib. It now uses a small WebCrypto TOTP service
(src/app/shared/services/totp.service.ts, RFC 6238: HMAC-SHA1, 6 digits,
30s step) instead, so otplib is no longer bundled and the three
polyfills plus their tsconfig path mappings are removed.

The backend still verifies login tokens with otplib, so the new service
must match it exactly - verified byte-for-byte against otplib and the
RFC 6238 test vectors (generateSecret/keyuri/generate/check parity).
Existing authenticator enrollments keep working. token check() is now
async (WebCrypto's digest is promise-based); the dialog's verify handler
was updated to match, and the value was never used for control flow.

Production npm audit now reports zero vulnerabilities (from 13, incl. 2
critical, at the start of this cleanup series). Verified on the docker
fixture: enrolled a 2FA secret from the new service, confirmed the
backend otplib accepts a token it produces at login, rejected
wrong/absent tokens. Unit spec covers RFC 6238 vectors, keyuri parity
and base32 round-trip; both API suites and the full frontend suite (204
specs) pass.
2026-07-19 22:01:23 -07:00
saubyk
e617fbb561 Replace deprecated csurf with csrf-csrf
csurf has been deprecated since 2022 and pins an old cookie release
with a known advisory; npm's only fix is a downgrade (issue #1634,
item 2). csrf-csrf v4 implements the same double-submit-cookie pattern
with an HMAC-signed, session-bound token keyed on the existing boot
secret (common.secret_key).

The frontend contract is unchanged: the token still arrives via the
XSRF-TOKEN cookie/header and is echoed as x-xsrf-token (all token
sources csurf accepted are still read), the signed cookie keeps the
_csrf name (now httpOnly, secure:false to match the session cookie on
plain-HTTP deployments), doubleCsrfProtection attaches req.csrfToken
so app.ts keeps working, and the error code is EBADCSRFTOKEN - already
handled in app.ts. The websocket upgrade check in authCheck.ts now
routes through the shared middleware; upgrade requests are GETs, so
its pass-through semantics are unchanged.

One fix this surfaced: app.ts called req.csrfToken() twice (cookie and
header). Under csurf every token validated against a stable secret;
under csrf-csrf each first-visit call mints a new token, desyncing the
XSRF-TOKEN cookie from the _csrf cookie it must equal. The token is
now generated once per request.

Tokens are session-bound, so a token stolen from one session no longer
validates in another - a check csurf's cookie mode did not perform.

Production npm audit drops from 6 low findings to 4, all in the
crypto-browserify/elliptic chain tracked in #1634.

Verified against the docker regtest fixture: both API suites (43
checks across LND, CLN and Eclair) plus a dedicated CSRF battery -
valid-token auth, missing token 403, garbage token 403, cross-session
replay 403, token stability across requests, the XSRF-TOKEN response
header for Quickpay, and the websocket handshake. Lint and build are
clean.
2026-07-19 22:01:23 -07:00
saubyk
a8baba12bb Replace deprecated request/request-promise with axios
request has been deprecated since 2020 with an unfixed SSRF advisory and
pins vulnerable copies of form-data (critical), qs, tough-cookie and
uuid - 8 of the 13 remaining production audit findings, none fixable by
version bumps (issue #1634, item 1).

All 36 backend files that imported request-promise now use a small
compatibility wrapper (server/utils/request.ts) backed by axios, which
is already a production dependency. The wrapper accepts the existing
options shape (qs, form - object or pre-encoded string, body,
baseUrl/uri, rejectUnauthorized, json), resolves with the response body
directly, and rejects with a plain object mirroring request-promise's
StatusCodeError/RequestError shape, so CommonService.handleError works
unchanged (ECONNREFUSED -> 503, Eclair StatusCodeError -> 500, nested
error body extraction). Auth headers are excluded from rejected errors
so they cannot leak into logs. Callers without json: true (block
explorer, currency rates) still get raw text bodies, and LND's
line-delimited /v2/router/send stream still surfaces as a string for
the existing parser.

Only behavioral code change: CLN verifyMessage used request-promise's
callback style and was ported to the same promise style as signMessage;
four Eclair handlers gained explicit returns to satisfy
noImplicitReturns once the import became typed.

Production npm audit drops from 13 findings (2 critical) to 6 low, all
in the crypto-browserify/elliptic chain tracked in #1634.

Verified against the docker regtest fixture with 43 API checks across
LND, Core Lightning and Eclair: reads, invoice creation, a routed LND
payment over the streaming endpoint, cross-implementation payments from
CLN and Eclair, message sign/verify, channel backup to disk, and
bad-invoice/node-unreachable error mapping. Lint and both production
builds are clean.
2026-07-19 22:01:23 -07:00
saubyk
b47e32c88c Bump pdfmake to 0.3.11 to fix its SSRF advisory
The fix is within the pinned 0.3.x line but the exact pin kept npm
update from reaching it. Clears the last high-severity production
vulnerability; frontend build and full spec suite verified.
2026-07-19 22:01:23 -07:00
saubyk
09494dcfc0 Update project dependencies to resolve Dependabot security alerts
Apply the bumps from all 20 open Dependabot security PRs (#1583-#1617)
in one pass on the release branch: axios 1.16.0, ws 8.21.0, the
socket.io server stack, express path-to-regexp, follow-redirects,
lodash and the remaining flagged transitive deps. Angular framework
packages move in lockstep to 20.3.26 and the CLI/build toolchain to
20.3.32, which drops the vulnerable node-forge from the tree entirely.
Also pick up in-range fixes without open PRs (qs, uuid, tough-cookie,
cookie, ajv, bn.js, elliptic, socket.io-parser).

npm audit: 85 vulnerabilities (23 prod) -> 30 (14 prod). The remainder
(request/request-promise, csurf, pdfmake, crypto-browserify chain)
needs code changes, not bumps, and is tracked separately.

Verified: lint, 199 frontend specs, backend + frontend production
builds, and an end-to-end smoke test against the docker regtest
fixture (LND, CLN and Eclair auth/getinfo/channels + WS upgrade).
2026-07-19 22:01:23 -07:00
ShahanaFarooqui
7d676dc940 Update version 0.15.9 2026-07-19 22:01:23 -07:00
ShahanaFarooqui
d038e15bd7 Version Update 2026-02-09 18:13:13 -08:00
ShahanaFarooqui
2f6cdb8fe0 Update project dependencies 2026-02-01 09:06:07 -08:00
3nprob
10fc3368e9 Upgrade nodejs to v22 (#1515) 2026-02-01 09:06:07 -08:00
ShahanaFarooqui
d49124c052 Update Version 2026-02-01 09:06:07 -08:00
ShahanaFarooqui
7340cb390a
Release 0.15.6 (#1506)
Fix for Resource temporarily unavailable error for CLN channel alias list
Security fix for npm vulnerabilities
2025-09-09 02:18:23 -07:00
ShahanaFarooqui
8a0304c162
Release 0.15.5 (#1492)
* Version Updated to 0.15.5-beta

* Fix to show correct experimental-dual-fund configuration from listconfig (#1479)

* feat: boltz swap in refund address (#1490)

require a refund address when creating a swap in and paying it
externally to make sure the swap can be refunded automatically if it
fails.

---------

Co-authored-by: jackstar12 <62219658+jackstar12@users.noreply.github.com>
2025-07-07 11:36:23 -07:00
ShahanaFarooqui
d51301adde
Release 0.15.4 (#1472)
* Fix for sso access key reading (#1469)
2024-11-18 20:27:51 -08:00
ShahanaFarooqui
a594606d27
Release 0.15.3 (#1467)
* Fix `Unknown command` error when disabling offers on CLN. ([#1443]) (#1451)
* Add missing SSO options to config (#1455)
* Fix for cln logic screen navigation (#1457)
* Transactions destination address display fix (#1458)
* cln delexpiredinvoices deprecation fix (#1459)
* Read LN_IMPLEMENTATION from environment (#1460)
* Add Fee Rate Information on Send Funds Modal (#1461)
* Artifact script fix (#1464)
* Add AMP toggle for LND Send Payments (#1466)

---------

Co-authored-by: Se7enZ <118189041+s373nZ@users.noreply.github.com>
2024-11-10 20:23:52 -08:00
ShahanaFarooqui
125a3b61ae
Release 0.15.2 (#1418)
* Check for authentication obj before delete operation #1415 (#1416)

* Updating version number
2024-06-21 20:09:52 -07:00
ShahanaFarooqui
b6dbd23ae7
Lint Fix (#1408)
Lint bug Fix
2024-06-10 16:41:37 -07:00
ShahanaFarooqui
22ab6d1154
Release 0.15.1 (#1406)
* rm .DS_Store

* Add watchfrontenddev command for npm

* Fix toggle issues in sidenav (pinning and on page refresh)

* Add copy-to-clipboard fallback if navigator.clipboard is not available (#1336)

* add copy-to-clipboard fallback if navigator.clipboard is not available

* amend copy fallback

* clipboard copy lint fixes and frontend build

* fix: add missing boltz state `transaction.lockupFailed` (#1349)

* fix: boltzd docs link (#1354)

* exit gracefully (#1356)

* allow for eclair updated relayed audit format (#1363)

* feat: add boltz service to cln (#1352)

* lint fix

* Request Params Cleanup

* cln: Boltz auto-send (#1366)

* Bug-fix (CLN Boltz): Hide claim tx id and routing fee for non-zero conf reverse swap

* cln: Boltz auto-send

- Added auto send option for Swap In
- Checking compatiblity with v2.0.0 and above

* Test import fixes

* Update help.component.ts (#1379)

Fixed broken link under "Help" -> "Node Settings"

* Backend config fix (#1382)

* Updating Common Application Configuration

* Fixed get RTL Conf

* Update Application Settings

* application and settings case change

* Unified config models

* Default node update

* 2FA and Password reset

* Final application settings update

* Config Settings and Authentication case fixed

* Node Setting Fix

* Fiat currency Symbol fix

* CLN: Fiat symbol fix

* All: Fiat symbol fix

* Update node settings

* Services UI fix

* CLN: Removed child node settings

* All: Removed child node settings

* Test fixes

* mempool links for onchain information (#1383)

* Tests fix

Tests fix

* UI for Block Explorer Configuration (#1385)

* Bump fee with mempool information (#1386)

* Mempool openchannel minfee (#1388)

Open channel model block if min fee is higher

* Show error on login screen if rune is incorrect and getinfo throws error (#1391)

* cln: Removed channel lookup call for update policy (#1392)

* ECL: On-chain Transactions, Invoice and Payments pagination (#1393)

Done most of the UI changes to accommodate pagination on transactions, payments and invoices tables but true pagination cannot be implemented till total number of records are missing from the API response.

Once the issue https://github.com/ACINQ/eclair/issues/2855 is fixed, I will uncomment pagination changes in the frontend.

* lnd: Onchain CPFP (#1394)

- UTXO label bug fix
- Warning on utxo label for "sweep" in text.

* Bug fixes after testing

* Testing bug fixes (#1401)

* Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too

* lnd: explorer link on pending channels

* Node lookup link on view channel peer pubkey

* Testing bug fixes (#1402)

* Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too

* lnd: explorer link on pending channels

* Node lookup link on view channel peer pubkey

* test fixes

* ng update to v18.0.x

* Updating install with  --legacy-peer-deps

---------

Co-authored-by: Grzegorz Kućmierz <gkucmierz@gmail.com>
Co-authored-by: lacksfish <lacksfish@gmail.com>
Co-authored-by: jackstar12 <62219658+jackstar12@users.noreply.github.com>
Co-authored-by: Kilian <19181985+kilrau@users.noreply.github.com>
Co-authored-by: Taylor King <taylorbradleyking@gmail.com>
Co-authored-by: Fishcake <128653975+fishcakeday@users.noreply.github.com>
Co-authored-by: Ant <72945059+2140data@users.noreply.github.com>
2024-06-10 12:40:37 -07:00
ShahanaFarooqui
475b47b7ea
Release 0.15.0 (#1334)
c-lightning-REST to clnrest migration.
2023-12-05 20:32:05 -08:00
ShahanaFarooqui
e4a2ef9a21 Updated to Angular 16 and removed vulnerabilities 2023-10-06 12:46:33 -07:00
ShahanaFarooqui
aa9bf3549c Typescript Configuration 2023-10-03 17:35:13 -07:00
Shahana Farooqui
9f0d2bfadf Updated Version 2023-06-06 18:34:17 -07:00
Shahana Farooqui
1fcad6306f msatoshi migration without backward compatibility
msatoshi migration without backward compatibility
2023-05-29 12:27:28 -07:00
ShahanaFarooqui
bd72be79bb Lint errors fix
Lint errors fix
2023-03-01 12:22:19 -08:00
ShahanaFarooqui
56e5558bf7 Offers Update #1206 2023-02-20 23:54:28 -08:00
ShahanaFarooqui
a90e35e631 Default Invoice expiry to seven days #1159
Default Invoice expiry to seven days #1159
2023-02-17 18:25:26 -08:00
ShahanaFarooqui
26ebb316be github action test script fix 2022-12-27 19:12:27 -08:00
ShahanaFarooqui
5107c300eb 2FA Fix
2FA Fix
2022-12-27 18:05:42 -08:00
ShahanaFarooqui
1e52024fab temp 2022-12-27 10:11:27 -08:00
ShahanaFarooqui
9db65d9786 Adding request dependency 2022-12-21 11:11:27 -08:00
ShahanaFarooqui
44bb84d6f8 Material Icon and Roboto Fonts 2022-12-14 21:40:10 -08:00
ShahanaFarooqui
6804fc762d Sort refresh bug fix 2022-12-13 15:53:41 -08:00
ShahanaFarooqui
670141a097 Table Sorting Fix 2022-12-12 19:02:07 -08:00
ShahanaFarooqui
251c450431 ngrx, charts and qrcode updates 2022-12-07 21:49:37 -08:00
ShahanaFarooqui
a7dc8c541a ng Material 15 UI adjustments
ng Material 15 UI adjustments
2022-12-02 19:56:41 -08:00
ShahanaFarooqui
439fd68077 Updated cdk 15 2022-12-01 18:46:32 -08:00
ShahanaFarooqui
72140a6d1e ng animations updated 2022-12-01 18:36:27 -08:00
ShahanaFarooqui
9141658976 Downgrading material to 14 due to flex layout
Downgrading material to 14 due to flex layout
2022-12-01 18:27:14 -08:00
ShahanaFarooqui
7e40c4ea30 All Dependencies update 2022-11-28 20:42:17 -08:00
ShahanaFarooqui
be34d70670 ng material v15 update 2022-11-23 19:46:48 -08:00
ShahanaFarooqui
be0d1775d0 ng v15 update 2022-11-23 19:30:45 -08:00
ShahanaFarooqui
86d4d15552 ng material v14 update 2022-11-23 19:23:05 -08:00
ShahanaFarooqui
b4e65e2098 Updated to ng 14 2022-11-23 18:20:23 -08:00
ShahanaFarooqui
411a602727 Version update 2022-11-22 09:06:15 -08:00
ShahanaFarooqui
daa4c735fb
Merge pull request #1070 from erikarvstedt/fix-dependencies
Move dev-only deps to `devDependencies`
2022-10-06 09:58:56 -07:00
ShahanaFarooqui
4d5bb8e3dc Help section update #1112
Help section update #1112
Liquidity Ads LeaseFeeBase unit bug fix
Bitcoind config bug fix
2022-09-28 18:15:37 -07:00
ShahanaFarooqui
72fecba40a Bug fix: Blank invoice preview #1019
Bug fix: Blank invoice preview #1019
2022-09-21 17:19:25 -07:00
ShahanaFarooqui
9f5ee4eb5b Added ChannelType in Open Channel #1093 & Private bug fix #1092
Added ChannelType in Open Channel #1093 & Private bug fix #1092
2022-09-09 18:55:56 -07:00
Erik Arvstedt
c5de2592e6 Move non-runtime deps to devDependencies 2022-08-21 12:50:33 +02:00