RTL/release-notes/Release-notes-0.15.10.md
Suheb a005b687a7
Release 0.15.10 (#1665)
* Update version 0.15.10

* Update project dependencies to resolve Dependabot security alerts

Applies the fixes from the open Dependabot PRs (#1648, #1649, #1650) in a
single pass on the release branch, regenerating the lockfile from scratch.

axios 1.16.0 -> 1.18.1 was the only production exposure (10 advisories).
Transitive deps moved to their fixed in-range versions (fast-uri 3.1.4,
form-data, qs, tough-cookie, tar, del, globby); dev toolchain took safe
bumps (nodemon 3.1.14, eslint 9.39.5, @typescript-eslint 8.65.0).

Drops the unused protractor devDependency: no e2e directory, no config and
no e2e target in angular.json, but 100 packages and the deprecated request
stack behind it. That clears both critical advisories.

npm audit: 50 (2 critical) -> 29 (0 critical); production deps 1 -> 0.
Remaining findings are dev-only tooling needing an Angular 21 migration
rather than a version bump.

Verified: lint, 204 frontend specs, backend + frontend production builds,
and 19 API checks against the docker regtest fixture covering LND, Core
Lightning and Eclair (getinfo, channels, peers, invoices, payments and
forwarding history).

* Fill in PR number in release note (#1653)

* Harden login request validation (#1654)

Tightens server-side validation of authentication requests, guards the password-reset route behind an authenticated session, and wires the backend regression suite (test/backend/) into npm run test. Users with two-factor authentication enabled are encouraged to update promptly.

Verified: backend specs 12/12, lint green, frontend specs 204/204, and the full authentication matrix end-to-end on the docker regtest fixture.

* Reduce exposure of authentication secrets in logs and config responses (#1659)

* Reduce exposure of authentication secrets in logs and config responses

* Fill in PR number in release note (#1659)

* Harden redaction helpers and secret restore paths

* Pin deployment auth switches server-side and harden settings persistence

* Contain backup file reads and harden config persistence

* Pin backup containment root and preserve config file mode on save

* Update Angular framework packages to 20.3.27 (#1661)

* Update Angular framework packages to 20.3.27

Batches the three Dependabot PRs open against master for the Angular framework
(@angular/core #1658, @angular/compiler #1657, @angular/common #1655) into one
update on the release branch. The framework packages are pinned to exact
versions and their peer ranges require them to move together, so all nine
20.3.26 packages go to 20.3.27: animations, common, compiler, compiler-cli,
core, forms, platform-browser, platform-browser-dynamic and router.

Patch-level upstream fixes only, no advisories. The update stays inside Angular
20 - @angular/build and @angular/cli (20.3.32) and @angular/cdk/@angular/material
(20.2.14) are already at the top of their v20 lines - so it does not pull in the
Angular 21 migration tracked by #1650.

Rebuilt frontend/ for the new framework code. backend/ is unchanged, as no
server/ source moved.

* Fill in PR number in release note (#1661)

* Bound remaining unbounded alias-resolution fan-outs in LND graph.ts and channels.ts   Fixes #1630 (#1651)

* Bound remaining unbounded alias-resolution fan-outs in LND graph.ts and channels.ts

Fixes #1630

* Address review feedback: fix options race, error handling, release notes

* Improve release notes entry to cover full PR scope

* Address review feedback: per-task options copy, exclude qs from alias requests

* Stop logging the eclair auth header at DEBUG level (#1664)

* Stop logging the eclair auth header at DEBUG level

getChannels in the eclair channels controller logged its whole request
options object. Eclair authenticates with HTTP basic auth, so those
options carry the configured lnApiPassword in an authorization header -
raising an eclair node's logLevel to DEBUG wrote
"authorization":"Basic <base64>" into the node log file, which is a
recoverable form of the credential and is routinely shared when
debugging.

The log now carries only the request url and form, matching every other
DEBUG log in the controllers. This was the only site in server/ passing a
whole options object to the logger; the rest log options.form, .url,
.body or .qs, none of which hold credentials.

Present since 0.12.0 and only reachable by opting in to DEBUG (the
default log level is ERROR), but it contradicted the logging guarantee
stated for #1659.

Found by scanning node logs at DEBUG while verifying the 0.15.10 branch
against the regtest fixture. Regression test added in
test/backend/eclair-channels.test.mjs; it fails on the previous code with
"auth header key must not reach the node log".

* Fill in PR number in release note (#1664)

---------

Co-authored-by: Osuji <weezdomosuji@gmail.com>
2026-08-03 22:49:14 -07:00

6.7 KiB

Release Notes — 0.15.10

This document collects the changes that go into the 0.15.10 release. Each PR merged for this release should add its entry under the appropriate section below.

Bug Fixes

  • Auth: harden login request validation (#1654). Tightens server-side validation of authentication requests and adds regression coverage (test/backend/authenticate.test.mjs). Users who have two-factor authentication enabled are encouraged to update promptly.

  • Config & logging: reduce exposure of authentication secrets (#1659). Tightens redaction of authentication material in node logs and configuration API responses, pins deployment-level authentication settings server-side, contains backup file downloads to the node's backup directory, and hardens the settings persistence path. Adds regression coverage (test/backend/common.test.mjs). Users are encouraged to update promptly.

  • Eclair: stop logging the node's auth header at DEBUG level (#1664). getChannels in the Eclair channels controller logged its entire request options object, which for Eclair carries HTTP basic auth — so raising an Eclair node's logLevel to DEBUG wrote authorization: Basic <base64> into the node log, a recoverable form of the configured lnApiPassword. The log now carries only the request url and form, matching every other DEBUG log in the controllers. Present since 0.12.0 and only reachable by opting in to DEBUG (the default level is ERROR), but it contradicted the logging guarantee stated for #1659. Regression coverage added (test/backend/eclair-channels.test.mjs). Found by auditing node logs at DEBUG while verifying this release against the regtest fixture.

Code Health

  • Bound remaining unbounded LND alias-resolution fan-outs (#1651, fixes #1630). Mirrors the runWithConcurrencyLimit(tasks, 20, done) pattern introduced in #1629 across the remaining unbounded Promise.all(map(...)) alias-resolution fan-outs in the LND graph and channels controllers, preventing a large node from firing one alias-lookup request per peer, channel, or hop all at once.

    During review, a related race condition was found and fixed: the module-level options variable in these controllers was reassigned per-request, but getAliasForChannel and getAliasFromPubkey read it by closure rather than receiving it as a parameter. Once alias-resolution tasks were deferred across event-loop turns by the concurrency limiter, a concurrent request to a different node could overwrite options mid-fan-out, causing a task to send with the wrong node's credentials or URL. Both functions now accept an explicit requestOptions parameter, and each handler captures a per-request copy before building the task thunks. The catch blocks inside the concurrency-limit callbacks were also updated to log raw exceptions directly instead of routing them through handleError (which expects an HTTP-error-shaped value), matching the existing pattern used by closeChannel.

  • Batch dependency update resolving the open Dependabot security PRs (#1653). Dependabot had three open security PRs against master (#1648, #1649, #1650). Rather than merging them piecemeal (they conflict with each other on package-lock.json and target the wrong branch for the release flow), the fixes were applied in one pass on the release branch. The only production exposure was axios, carrying ten advisories at 1.16.0 — prototype pollution in request-option merging, formDataToJSON recursion DoS, maxBodyLength bypasses on fetch/HTTP2 uploads, and a NO_PROXY bypass — now on 1.18.1 (a patch above Dependabot's validated 1.18.0, which was superseded during the batch). The lockfile was regenerated from scratch rather than incrementally patched, and the flagged transitive deps were moved to their fixed in-range versions (fast-uri 3.1.4, plus form-data, qs, tough-cookie, tar, del and globby). The dev toolchain took safe patch/minor bumps: nodemon 3.1.14, eslint 9.39.5, and @typescript-eslint/* 8.65.0.

    The unused protractor devDependency was also dropped. It had been dead since the Angular scaffold that introduced it — no e2e/ directory, no protractor.conf.js, and no e2e target in angular.json, leaving a single line in package.json as its only reference — while dragging in 100 packages and the deprecated request stack. Removing it clears both remaining critical advisories (request, form-data) along with fourteen others (adm-zip, selenium-webdriver, webdriver-manager, xml2js, tmp, rimraf and the rest of the webdriver chain).

    npm audit: 50 vulnerabilities (2 critical, 37 high, 10 moderate, 1 low) → 29 (0 critical, 23 high, 6 moderate), and production dependencies are now clean at 0 (from 1 high). Everything still flagged is dev-only build tooling that cannot be fixed by a version bump: the Angular CLI chain (@hono/node-server and @modelcontextprotocol/sdk need Angular 21, i.e. @angular/core ^21 and TypeScript ≥5.9 — a framework migration, not a bump; #1650 is left for that work), the @angular-eslint line, and the karma/jasmine stack. None of it ships in the released bundle.

  • Angular framework patch update to 20.3.27 (#1661). Dependabot opened one PR per package against master for @angular/core (#1658), @angular/compiler (#1657) and @angular/common (#1655). The framework packages are pinned to exact versions and their peer ranges require them to move as a set, so the three were applied as a single batch on the release branch, taking all nine 20.3.26 packages (animations, common, compiler, compiler-cli, core, forms, platform-browser, platform-browser-dynamic, router) to 20.3.27. Upstream fixes only, no advisories: the compiler now disallows i18n event attributes and limits its possible-event-handler check to property names longer than two characters, HttpClient distinguishes repeated transfer-cache params, and platform-server picks up a newer domino.

    This stays inside Angular 20 — the build toolchain (@angular/build, @angular/cli 20.3.32) and @angular/cdk/@angular/material (20.2.14) are already at the top of their v20 lines, so nothing in this batch pulls in the Angular 21 migration still tracked by #1650. frontend/ was rebuilt for the new framework code.