1. Shell injection in readHexBlock/readHexTx (PyBlock.py):
- Validate user input with hex-only regex before use
- Replace shell=True pipe chain with subprocess list + piped stdin
- Same fix for OP_RETURN loop TX decoding
2. Shell injection in weather commands (ppi.py):
- Replace curl shell commands with requests.get()
- User input (city, lang, unit) no longer touches shell
- Upgraded from HTTP to HTTPS
3. Runtime crash in SPV/spvblock.py:
- os.path.isfile() called with 2 args (TypeError)
- Fixed to use 'and' for two separate checks
4. Config files added to .gitignore:
- pybitblock/config/*.conf (RPC creds, API keys, tokens)
- pybitblock/SPV/config/*.conf
- *.log files
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Replace all uses of 'list' as a variable name for shell command strings
with 'cmd' to avoid shadowing Python's built-in list type.
Affects ppi.py, PyBlock.py, SPV/ppi.py, and SPV/spvblock.py.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- PyBlock.py: Replace 14 star imports with explicit named imports,
remove unused `from art import *` and `from SPV.spvblock import *`
- ppi.py: Replace star imports, remove unused art/nodeconnection imports,
remove duplicate `import requests` and dead lnpay_py comments
- nodeconnection.py: Replace star imports, remove unused art import
This improves code clarity, prevents namespace pollution, and makes
dependencies between modules explicit and traceable.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Replace open() without context managers with `with` statements across all modified files
- Change bare `except:` to `except Exception:` for safer exception handling
- Move Whale Alert API key from hardcoded to environment variable
- Use raw strings for ASCII art to prevent escape sequence issues
- Simplify image file handling in nodeconnection.py
- Convert unsafe shell subprocess calls to list-based format
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Replace insecure patterns that exposed the application to command injection,
arbitrary code execution, and data interception attacks.
- Replace os.popen/os.system with subprocess.run using argument lists
- Migrate pickle config serialization to JSON format
- Replace bare except: blocks with specific exception types
- Fix insecure HTTP URLs to HTTPS (opreturnbot.com, ascii.live)
- Replace shell curl commands with requests library calls
- Add migrate_config.py script for pickle-to-JSON config migration
- Convert existing SPV config files to JSON format
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>