Commit Graph
2037 Commits
Author SHA1 Message Date
naturallaw777andarena-agent 97990f5092 Make service version metadata less prominent
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 13:49:24 +00:00
Sovran SystemsandGitHub 1c0ef15855 Merge pull request #359 from naturallaw777/arena/019faddd-sovran-systemsos
docs: acknowledge LiveKit and Alby Hub
2026-07-29 07:36:04 -05:00
naturallaw777andarena-agent e9f39a7b21 docs: acknowledge LiveKit and Alby Hub
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 12:35:38 +00:00
Sovran SystemsandGitHub 0283cbb049 Merge pull request #358 from naturallaw777/arena/019fadc2-sovran-systemsos
Improve service version details and naming
2026-07-29 07:18:55 -05:00
naturallaw777andarena-agent 4210ba899f Improve service version details and naming
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 12:18:33 +00:00
Sovran SystemsandGitHub 415a036858 Merge pull request #357 from naturallaw777/arena/019fabe6-sovran-systemsos
docs: add router and ISP port forwarding requirements for Server + Desktop
2026-07-28 22:26:57 -05:00
naturallaw777andarena-agent 236baf66e6 docs: add router and ISP port forwarding requirements for Server + Desktop mode
Add clear guidance in the recommended hardware section explaining that
Server + Desktop mode requires router admin panel access with port
forwarding capability and ISP support for port forwarding. Framed as
empowering guidance rather than barriers to minimize onboarding friction.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 03:26:27 +00:00
Sovran SystemsandGitHub f37654f3ce Merge pull request #356 from naturallaw777/arena/019fabd4-sovran-systemsos
docs: restructure README — tighter, linked, and accurate
2026-07-28 22:18:34 -05:00
naturallaw777andarena-agent fb6bff085e docs: restructure README for clarity, links, and accuracy
- Rework intro to co-headline Bitcoin self-custody and digital sovereignty
- Add table of contents
- Merge overlapping sections (middle-man pitch, day-one tools, differentiators)
  into a single 'Why Sovran_SystemsOS?' section; describe each app once
- Collapse Desktop/Node/Server hardware lists into one comparison table
- Explain sovransystemsos.local once; other sections link to the Hub section
- Compress install guide (7 steps to 6) with collapsible per-OS verify blocks
- Link every upstream project at first mention
- Map features to module files in a table for developers
- Fix clone URL (naturallaw777/Sovran_SystemsOS)
- Remove repo-map rows for docs/wallet-connections.md and role-state.nix;
  note install-time generated files imported by flake.nix
- Add packages/ to repo map; list Alby Hub, Mempool, Haven where relevant
- Fix H1/H2 heading hierarchy and deduplicate footer slogans

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 03:16:53 +00:00
Sovran SystemsandGitHub 020462509d Merge pull request #355 from naturallaw777/arena/019fabce-sovran-systemsos
fix(nwc-wallets): replace incorrect lib.mkIf usage with plain if expressions
2026-07-28 21:59:05 -05:00
naturallaw777andarena-agent 1e4a988ca2 fix(nwc-wallets): replace incorrect lib.mkIf usage with plain if expressions
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 02:58:33 +00:00
Sovran SystemsandGitHub 037a3a00af Merge pull request #354 from naturallaw777/arena/019fabb1-sovran-systemsos
security: harden Lightning Wallet Connections (NWC)
2026-07-28 21:54:23 -05:00
naturallaw777andarena-agent 2e2a9b2d44 security: harden Lightning Wallet Connections (NWC)
- Add rate limiting to public LNURL endpoints (30 req/min per IP)
- Add audit logging for wallet lifecycle events (create, drain, delete, rotate)
- Add Unix socket support for Python ↔ Alby Hub communication
- Add LND macaroon permission documentation/warning
- Add pairing secret rotation API endpoint + CLI command
- Make Nostr relay configurable; auto-use Haven relay when enabled
- Strengthen domain validation (FQDN only, reject localhost/IP)
- Add structured audit log at /var/log/sovran-nwc-audit.log

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 02:52:45 +00:00
Sovran SystemsandGitHub 2f46f8994d Merge pull request #353 from naturallaw777/arena/019fabbe-sovran-systemsos
feat: display version numbers on all Hub service tiles
2026-07-28 21:44:46 -05:00
naturallaw777andarena-agent 43764e8c8d feat: display version numbers on all Hub service tiles
Previously only bitcoind.service showed a version on the tile.
Now every service with a parsable Nix store path gets its version
displayed (electrs, btcpayserver, lnd, rtl, mempool, vaultwarden,
matrix-synapse, caddy, tor, etc.).

The existing _get_service_version() helper reads systemctl show
<unit> --property=ExecStart and extracts the version from the Nix
store path. Results are cached for 5 minutes per unit.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 02:44:03 +00:00
Sovran SystemsandGitHub adde78320d Merge pull request #352 from naturallaw777/arena/019fab62-sovran-systemsos
Rename NWC feature to Lightning Wallet Connections and split modal into tabs
2026-07-28 21:02:21 -05:00
naturallaw777andarena-agent aa4ffaa803 Rename NWC feature to Lightning Wallet Connections and split modal into tabs
Naming: user-facing 'Wallet Connections' -> 'Lightning Wallet Connections'
across the Hub, feature registry, tile, and NixOS modules. Internal ids
(nwc-wallets, albyhub.service, /api/nwc/*) are unchanged.

UX: the service-detail modal put status, domain diagnostics, router ports,
the enable/disable toggle, restart, the liquidity guide and the whole wallet
manager in one cramped scrolling column. For this feature the modal is now
980px wide and split into two tabs:

  - Wallets: wallet grid, create/share/verify flows, collapsible liquidity guide
  - Service & Setup: description, status, domain checklist, ports, enable, restart

A status dot and domain chip sit in the tab bar so state is visible from both
tabs, and the modal opens on Setup when the service is off or the Lightning
Address domain is unconfigured. Wallet cards gain a balance chip, pending
badge, a prominent address row, and separated destructive actions.

Non-NWC services keep the original single-column layout and width.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 01:59:28 +00:00
Sovran SystemsandGitHub 7d92026303 Merge pull request #351 from naturallaw777/arena/019fab50-sovran-systemsos
Add NWC Channel & Liquidity Guide UI/UX for LND Nodes
2026-07-28 19:46:09 -05:00
naturallaw777andarena-agent 9ed4409e25 Add NWC channel liquidity guide and UI/UX explanation for new LND nodes
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-29 00:45:06 +00:00
Sovran SystemsandGitHub 57555fc5dd Merge pull request #350 from naturallaw777/arena/019faaea-sovran-systemsos
NWC: downloadable & printable LNURL QR for wallet connections
2026-07-28 18:53:00 -05:00
naturallaw777andarena-agent 5e3432aa89 nwc: add downloadable/printable LNURL QR for wallet connections
Each NWC wallet connection gets its own shareable LNURL QR so the owner
can receive payments from anyone without creating invoices (the core
LNURL value proposition: a static QR that never expires).

Hub UI (service detail modal):
- New 'Share QR' button on every wallet connection card
- Dedicated share view: large QR, Lightning Address + copy, raw bech32
  LNURL + copy
- Download PNG (websites/social), download SVG (vector, print-sharp at
  any size), and a Print button that opens a print-ready payment card
  which auto-invokes the browser print dialog

Backend (FastAPI, session-authenticated):
- GET /api/nwc/wallets/{id}/lnurl -> alias, lightning_address, LNURL
- GET /api/nwc/wallets/{id}/lnurl-qr.png (?download=1, ?scale=)
- GET /api/nwc/wallets/{id}/lnurl-qr.svg (?download=1)
- GET /api/nwc/wallets/{id}/lnurl-qr/print (print-ready HTML card)
- Stdlib bech32 encoder (BIP-173, verified against the official LUD-01
  golden vector); LNURL is uppercased for QR alphanumeric-mode density
  per LUD-01 guidance; QR rendered with the existing qrencode package
- Resolves wallets by app id or pubkey; 404 unknown wallet, 503 when no
  Lightning domain is configured; all routes return 401 unauthenticated

No new system dependencies.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-28 23:47:37 +00:00
Sovran SystemsandGitHub 5ab2e432f1 Merge pull request #349 from naturallaw777/arena/019faad3-sovran-systemsos
Port-forward UX: remove tile Step 4 and misleading local port 'ready' status
2026-07-28 17:36:45 -05:00
naturallaw777andarena-agent 419680a847 Port-forward UX: drop tile Step 4 and misleading local 'ready' status
The Element Call tile still appended a synthetic 'Step 4: Router Setup
Needed' to the domain diagnostic checklist, and every port table carried a
'Sovran_SystemsOS Status' column with Ready / Not ready yet verdicts.

Both were misleading: port forwarding happens on the router, which this
computer cannot inspect. A local ss/firewall probe can neither prove nor
disprove that forwarding works — and the LiveKit TURN relay range binds on
demand, so it reported 'Not ready yet' even on a perfectly working system.

- server.py: add ROUTER_FORWARD_ONLY_UNITS ({livekit.service}); skip the
  local probe for those units, drop the step-4 append, replace extra_ports
  with router_ports (no status field), and exclude router-only ports from
  both tile health and /api/ports/health so they can't raise false alarms.
- helpers.js: new shared renderPortForwardGuideHtml() — one intro naming the
  internal IP, explicit instructions (same internal/external port, match the
  protocol, use port-range fields for 30000-40000), a colour-coded
  TCP / UDP / TCP+UDP badge per row, and a closing note that the only real
  test is loading the service from a phone on mobile data.
- features.js: enable-time modal uses the shared guide and now always lists
  every port to forward (the old local pre-filter hid ports the user still
  had to open).
- service-detail.js: tile port section uses the same guide; the SSH/non-domain
  branch keeps a small 'not open on this computer yet' hint, which is a real
  local fact, separate from router forwarding.
- onboarding.js: step 3 router note reworded to match (same number for
  internal/external, notes that Element Call adds UDP ports).
- domain-setup.css: styles for the protocol badges and instruction list.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-28 22:34:39 +00:00
Sovran SystemsandGitHub 0e3cab78f8 Merge pull request #348 from naturallaw777/arena/019faa9a-sovran-systemsos
Simplify port-forward UX (drop onboarding step 4) + run Njal.la DDNS on feature enable
2026-07-28 16:41:52 -05:00
naturallaw777andarena-agent a65d977489 Simplify port-forward UX (drop onboarding step 4) + run Njal.la DDNS on feature enable
- Onboarding: remove the redundant/error-prone 'Router Setup' step (5 steps -> 4).
  A compact 80/443 (+22 SSH) note now lives inside Domain Configuration,
  and the Element Call ports are only shown at the moment they matter:
  when enabling the feature, and afterwards on the service tile.
- Onboarding step 3: fix domain prefill bug (API returns {domains: {...}}),
  make /api/network fetch best-effort so it can never block the step.
- Enable-time port modal: streamline copy (one intro + table + pointer to
  the tile's live status view).
- Element Call tile detail: replace 5 repetitive prose blocks with 2 compact
  notes around the live-status port table.
- Njal.la DDNS: run njalla.sh immediately when a DDNS-backed feature is
  enabled (previously only ran on domain save or the 15-min cron tick).
- Harden njalla.sh handling: create the base script (shebang + IP lookup)
  if missing before appending curl lines; invoke via bash explicitly.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-28 21:38:07 +00:00
Sovran SystemsandGitHub 2077cbd0fb Merge pull request #347 from naturallaw777/arena/019faa75-sovran-systemsos
Show NWC manager in Wallet Connections modal
2026-07-28 15:45:48 -05:00
naturallaw777andarena-agent a4f848fc6d Show NWC manager in Wallet Connections modal
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
2026-07-28 20:44:44 +00:00
naturallaw777 1a6e456d06 Updated Contributing 2026-07-27 18:22:40 -05:00
naturallaw777 ccda5e3246 Updated Readme 2026-07-27 18:04:17 -05:00
naturallaw777 aef7582083 Added contributing and updated readme 2026-07-27 17:56:38 -05:00
Sovran SystemsandGitHub c51a762b42 Merge pull request #346 from naturallaw777/staging-dev
Merge into Main
2026-07-27 13:33:56 -05:00
Sovran SystemsandGitHub 91bb49ea13 Merge pull request #345 from naturallaw777/staging-dev
Merge staging-dev into main
2026-07-27 12:21:15 -05:00
naturallaw777 0f8c15e6a1 removed .tests, not needed 2026-07-27 10:35:54 -05:00
naturallaw777 586625f110 removed .github, not needed 2026-07-27 10:34:33 -05:00
naturallaw777 c78370647a removed nix directory, not needed 2026-07-27 10:33:32 -05:00
naturallaw777 e30610ddac removed docs/ai added not necessary 2026-07-27 10:29:34 -05:00
naturallaw777 1503060f7c fixed duplicate systemd lnd strings 2026-07-27 09:40:32 -05:00
Sovran SystemsandGitHub 016ceaa3df Merge pull request #344 from naturallaw777/copilot/fix-wallet-connections-cert-path
Complete Wallet Connections cert-path wiring for interactive `nwc-wallet`
2026-07-27 09:34:03 -05:00
copilot-swe-agent[bot]andGitHub bfa4f2f9e4 Fix NWC wallet cert-path env wiring 2026-07-27 14:29:27 +00:00
copilot-swe-agent[bot]andGitHub f557a6d2db Initial plan 2026-07-27 14:26:00 +00:00
Sovran SystemsandGitHub 69c236d9ca Merge pull request #343 from naturallaw777/copilot/fix-wallet-connections-integration
Use nix-bitcoin `services.lnd.certPath` for Wallet Connections LND setup
2026-07-27 09:18:40 -05:00
copilot-swe-agent[bot]andGitHub d6546bfed8 fix: use nix-bitcoin lnd cert path for wallet connections 2026-07-27 14:16:21 +00:00
copilot-swe-agent[bot]andGitHub d97615db8e Initial plan 2026-07-27 14:13:14 +00:00
Sovran SystemsandGitHub f3c05bf7db Merge pull request #342 from naturallaw777/copilot/fix-lnd-alby-hub-port-collision
Resolve deterministic LND/Alby Hub port collision and enforce loopback-only binding
2026-07-27 13:34:13 +00:00
copilot-swe-agent[bot]andGitHub 004424cc2b Address validation feedback for Nix test and workflow permissions 2026-07-27 12:23:06 +00:00
copilot-swe-agent[bot]andGitHub 37a15afa10 Fix deterministic LND/Alby Hub port collision 2026-07-27 12:21:09 +00:00
copilot-swe-agent[bot]andGitHub fdd9d29db3 Initial plan 2026-07-27 12:13:11 +00:00
Sovran SystemsandGitHub c9458dd73b Merge pull request #341 from naturallaw777/copilot/require-unique-hostname-for-wallet-connections
Require unique hostname for Wallet Connections; add server-side conflict validation
2026-07-27 11:49:44 +00:00
copilot-swe-agent[bot]andGitHub dc98a355e8 Fix redundant backslash escape in hostname regex character class 2026-07-27 11:41:44 +00:00
copilot-swe-agent[bot]andGitHub 154988bbeb Address review feedback: fix hostname regex, use CSS class for NWC warning banner, clarify test comment 2026-07-27 11:39:40 +00:00