The singular outgoing_chan_id query parameter on LND's QueryRoutes is
deprecated as of lnd 0.20.0 in favor of the plural outgoing_chan_ids.
The code path was unreachable in RTL anyway: no caller of the
GetQueryRoutes action ever populated outgoingChanId, so the query
parameter was never sent. Drop the unused field, the effect's
conditional URL builder, and the server-side passthrough.
Two non-blocking review points on #1644:
- createHmacKey's comment claimed "exact parity" with otplib, but
otplib's totpPadSecret under-repeats to 18 bytes for 1- and 9-byte
secrets where this service pads to 20. Unreachable in RTL (secrets are
always 10 bytes from generateSecret, field is read-only), and
replicating the otplib bug has negative value - so the comment is
corrected to state parity holds for the 10-byte secrets used here
rather than universally.
- onVerifyToken's token check is now async, so two fast clicks on Verify
could dispatch updateApplicationSettings twice (was synchronous
before). Payload is idempotent so it was harmless, but guarded with an
in-flight flag to restore the single-dispatch behavior.
Frontend/backend artifacts rebuilt; TOTP spec and lint pass.
The frontend build pulled in crypto-browserify, stream-browserify and
vm-browserify (via tsconfig paths) only because otplib's
@otplib/plugin-crypto requires Node's crypto. That chain carried the
last production npm audit findings - the elliptic advisory
(GHSA-848j-6mx2-7j84, no fixed release) plus browserify-sign/create-ecdh
(issue #1634, item 3).
The two-factor-auth settings dialog is the only browser consumer of
otplib. It now uses a small WebCrypto TOTP service
(src/app/shared/services/totp.service.ts, RFC 6238: HMAC-SHA1, 6 digits,
30s step) instead, so otplib is no longer bundled and the three
polyfills plus their tsconfig path mappings are removed.
The backend still verifies login tokens with otplib, so the new service
must match it exactly - verified byte-for-byte against otplib and the
RFC 6238 test vectors (generateSecret/keyuri/generate/check parity).
Existing authenticator enrollments keep working. token check() is now
async (WebCrypto's digest is promise-based); the dialog's verify handler
was updated to match, and the value was never used for control flow.
Production npm audit now reports zero vulnerabilities (from 13, incl. 2
critical, at the start of this cleanup series). Verified on the docker
fixture: enrolled a 2FA secret from the new service, confirmed the
backend otplib accepts a token it produces at login, rejected
wrong/absent tokens. Unit spec covers RFC 6238 vectors, keyuri parity
and base32 round-trip; both API suites and the full frontend suite (204
specs) pass.
Session-bound tokens broke re-login after logout: logoutUser destroys
the session, but the SPA navigated to the login page without a
document reload, so the surviving _csrf/XSRF-TOKEN cookies stayed
bound to the destroyed session id and the next login POST failed with
403 until a manual refresh. Hit both manual logout and the idle-timer
auto-logout.
Two coordinated fixes:
1. Frontend: the logout effect now performs a full document navigation
to the login page (after the server logout completes, so the
request is not aborted by the reload), which re-runs the handshake
and mints a token bound to the fresh session. The logout reason
previously travelled on the NgRx action stream, which cannot
survive a reload - it is now handed over via sessionStorage (set
after clearAll) and picked up and cleared by the login component.
The SSO branch is unchanged (it already left the document).
2. Backend: the EBADCSRFTOKEN error path now re-mints the token for
the current session before responding 403, so any client holding a
stale token (e.g. after a server restart rotates the boot secret)
self-heals on retry instead of looping on 403.
Verified on the fixture: reviewer's repro now shows login 200 ->
logout 200 -> stale-token login 403 (binding intact) with re-minted
cookies on the 403 -> retry 200; and the reload path (fresh GET /
after logout, what the full navigation does) logs in on the first
attempt. Both API suites, the CSRF battery, rtl.effects specs and the
full frontend suite pass; frontend and backend artifacts rebuilt.
Per LND v0.21.0 release notes, the sat_per_byte option will be removed
in v0.22 across CloseChannel, OpenChannel, SendCoins, SendMany, and
walletrpc.BumpFee. LND already treats sat_per_byte as sat/vbyte
internally, so this is a pure rename with no value conversion. Updates
both the wire-format strings sent to LND and the matching TypeScript
identifiers across the close-channel, open-channel, send-coins, and
bump-fee paths.
The a11y fix in #1609 wrapped the bare Scroll Range mat-select in a
mat-form-field for its label, but the wrapper reserved subscript space
(78.8px vs the date field 56px) and anchored to the row top, leaving
the date picker ~11px lower on every implementation reports screen.
Use subscriptSizing="dynamic" (no hints are used) and center on the
cross axis, restoring the aligned 56px row from v0.15.8 while keeping
the label. Verified headlessly against the regtest fixture: both
fields now render at identical top/height.
Fixes#1635
The accessibility edits dropped the final newline from six form templates.
Add it back so these files end with a newline again (POSIX text-file
convention; keeps diffs clean and avoids no-newline lint noise).
Blocks-till-maturity is critical information for a force-closing channel but
was only visible in the per-channel detail modal. The column and its data
binding already existed in the pending force-closing table (and was selectable
via column settings); it was just missing from the default column selection.
Add blocks_til_maturity to the pending_force_closing default columnSelection
and columnSelectionSM so it is surfaced on the list by default on both desktop
and mobile.
A dependency-update commit in the 0.15.8-beta cycle mechanically renamed
the paginator binding [showFirstLastButtons] to [hidePageSize] on every
mat-paginator while keeping the same 'screenSize === XS ? false : true'
expression. The two properties have opposite polarity, so this inverted
the behavior: on desktop the page-size selector was hidden (locking users
to 10 items per page) and the first/last-page buttons were dropped as
collateral. Revert the ~44 affected paginators back to [showFirstLastButtons]
across the LND, CLN, Eclair and shared tables.
Address review F6 on #1625: the LND channel information modal has the same
unguarded selNode.settings.blockExplorerUrl binding as the CLN one, and it is
opened without selNode from the active-HTLCs and channel-backup tables, so it can
blank out the same way. Guard the explorer link (*ngIf + a no-op click when the
url is absent) so a missing selNode can no longer blank the dialog. Eclair's modal
doesn't use selNode.settings, so it needs no change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Address review F4 on #1625: the new selNode field resolved to the global DOM
Node type because the RTL Node model was not imported. Import Node from
shared/models/RTLconfig so the field, the rootSelectedNode store value, and the
CLNChannelInformationComponent it feeds all agree, restoring type-checking.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The channel information modal renders a block-explorer link from
selNode.settings.blockExplorerUrl, but the pending/inactive channels table
opened the modal without passing selNode. With it undefined, that binding threw
during change detection and blanked every field below it — State, Connected,
Private and the balances all rendered without a value. A disconnected channel
moves to the pending/inactive table, so this is what surfaced on View Info for a
disconnected channel (the symptom in the original report).
Pass selNode from the pending table (matching the open table), and guard the
modal's explorer link (*ngIf + a no-op click when the url is absent) so a missing
selNode can no longer blank the whole dialog. Add a regression test asserting the
pending table passes selNode when opening the modal.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Address review F3 on #1625: the Close-Channel *ngIf still read the legacy
`connected` field while its neighboring column now reads peer_connected. Point
it at peer_connected directly so it no longer depends on the backend mirror,
removing the latent coupling.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CLN's listpeerchannels reports connection state as peer_connected, but the
open/pending channel list columns read the legacy `connected` field, which the
backend never populated. It was therefore always empty, so the list always
rendered "Disconnected" while the detail panel (which reads peer_connected)
showed the true state — the contradiction reported in #1606.
Normalize `connected = peer_connected` in the backend listPeerChannels response
so legacy consumers stay in sync, and point the list columns at peer_connected
directly. Add regression specs asserting the connected column follows
peer_connected even when the legacy field disagrees.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Version Updated to 0.15.5-beta
* Fix to show correct experimental-dual-fund configuration from listconfig (#1479)
* feat: boltz swap in refund address (#1490)
require a refund address when creating a swap in and paying it
externally to make sure the swap can be refunded automatically if it
fails.
---------
Co-authored-by: jackstar12 <62219658+jackstar12@users.noreply.github.com>
* rm .DS_Store
* Add watchfrontenddev command for npm
* Fix toggle issues in sidenav (pinning and on page refresh)
* Add copy-to-clipboard fallback if navigator.clipboard is not available (#1336)
* add copy-to-clipboard fallback if navigator.clipboard is not available
* amend copy fallback
* clipboard copy lint fixes and frontend build
* fix: add missing boltz state `transaction.lockupFailed` (#1349)
* fix: boltzd docs link (#1354)
* exit gracefully (#1356)
* allow for eclair updated relayed audit format (#1363)
* feat: add boltz service to cln (#1352)
* lint fix
* Request Params Cleanup
* cln: Boltz auto-send (#1366)
* Bug-fix (CLN Boltz): Hide claim tx id and routing fee for non-zero conf reverse swap
* cln: Boltz auto-send
- Added auto send option for Swap In
- Checking compatiblity with v2.0.0 and above
* Test import fixes
* Update help.component.ts (#1379)
Fixed broken link under "Help" -> "Node Settings"
* Backend config fix (#1382)
* Updating Common Application Configuration
* Fixed get RTL Conf
* Update Application Settings
* application and settings case change
* Unified config models
* Default node update
* 2FA and Password reset
* Final application settings update
* Config Settings and Authentication case fixed
* Node Setting Fix
* Fiat currency Symbol fix
* CLN: Fiat symbol fix
* All: Fiat symbol fix
* Update node settings
* Services UI fix
* CLN: Removed child node settings
* All: Removed child node settings
* Test fixes
* mempool links for onchain information (#1383)
* Tests fix
Tests fix
* UI for Block Explorer Configuration (#1385)
* Bump fee with mempool information (#1386)
* Mempool openchannel minfee (#1388)
Open channel model block if min fee is higher
* Show error on login screen if rune is incorrect and getinfo throws error (#1391)
* cln: Removed channel lookup call for update policy (#1392)
* ECL: On-chain Transactions, Invoice and Payments pagination (#1393)
Done most of the UI changes to accommodate pagination on transactions, payments and invoices tables but true pagination cannot be implemented till total number of records are missing from the API response.
Once the issue https://github.com/ACINQ/eclair/issues/2855 is fixed, I will uncomment pagination changes in the frontend.
* lnd: Onchain CPFP (#1394)
- UTXO label bug fix
- Warning on utxo label for "sweep" in text.
* Bug fixes after testing
* Testing bug fixes (#1401)
* Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too
* lnd: explorer link on pending channels
* Node lookup link on view channel peer pubkey
* Testing bug fixes (#1402)
* Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too
* lnd: explorer link on pending channels
* Node lookup link on view channel peer pubkey
* test fixes
* ng update to v18.0.x
* Updating install with --legacy-peer-deps
---------
Co-authored-by: Grzegorz Kućmierz <gkucmierz@gmail.com>
Co-authored-by: lacksfish <lacksfish@gmail.com>
Co-authored-by: jackstar12 <62219658+jackstar12@users.noreply.github.com>
Co-authored-by: Kilian <19181985+kilrau@users.noreply.github.com>
Co-authored-by: Taylor King <taylorbradleyking@gmail.com>
Co-authored-by: Fishcake <128653975+fishcakeday@users.noreply.github.com>
Co-authored-by: Ant <72945059+2140data@users.noreply.github.com>