Commit graph

72 commits

Author SHA1 Message Date
Håvard Kittelsen
ee43979ba9 Merge branch 'fix/audit-advisories' into 'master'
chore(deps): resolve npm audit advisories

See merge request riftenlabs/lib/wizardconnect!33
2026-08-19 07:05:41 +00:00
Håvard Kittelsen
c2b60b5b3a chore(deps): resolve npm audit advisories
Declared ranges — the lockfile is not published, so these are what consumers
resolve against:

  core                       ws     ^8.18.0 -> ^8.21.3  (prod, vuln 8.0.0-8.20.1)
  core, dapp, wallet, react  vitest ^3.2.3  -> ^3.2.7   (dev,  vuln <3.2.6)

Transitive, lockfile only: vite 7.3.2 -> 7.3.6, postcss 8.5.12 -> 8.5.26,
nanoid 3.3.11 -> 3.3.18, brace-expansion 5.0.5 -> 5.0.9.

npm audit --audit-level=moderate now exits 0. esbuild's low-severity Windows
dev-server advisory is left: needs a major bump behind a peer range.
2026-08-19 09:01:29 +02:00
Håvard Kittelsen
2b004a3f77 Merge branch 'fix/disconnect-race' into 'master'
Deliver the courtesy disconnect before tearing the relay down

See merge request riftenlabs/lib/wizardconnect!32
2026-08-19 06:31:09 +00:00
Håvard Kittelsen
dcda4fce6a fix(wallet): deliver the courtesy disconnect before tearing the relay down
doDisconnect fired the courtesy `disconnect` message without awaiting it, then
tore the relay connection down on the next line:

    conn.client.relay(disconnectMsg).catch(() => {});   // fire and forget
    ...
    conn.cleanup();                                      // closes the pool underneath it

relay() resolves only after `Promise.allSettled(pool.publish(...))` — a real
round trip to every configured relay. cleanup() closed the pool while that
publish was still in flight, so the message usually never left and the dapp went
on believing the wallet was connected until its own liveness timeout fired.
Downstream wallets were patching this out of the published package.

Teardown now splits into two halves with opposite timing requirements.

Registry removal stays synchronous. getConnections() is what a UI renders, and
connect() returns an existing connection for a URI, so leaving this one in the
map while its teardown is pending would hand a caller a dying connection. This
is the one place this differs from !30 and from the downstream patches, which
defer the registry removal along with the teardown.

Relay teardown is deferred until the publish settles, bounded by
DISCONNECT_PUBLISH_TIMEOUT_MS (5s). The bound matters: "the publish never
settles" is exactly the case where a relay is unreachable, and a socket that is
never closed is worse than a courtesy message that is never delivered.

disconnect() keeps its synchronous void signature — not a breaking change.

Why it shipped broken: disconnect.test.ts only covered dapp → wallet. Nothing
exercised wallet → dapp, and the failure is invisible from the wallet's side —
its own state is correct either way, and only the peer notices.
disconnect-delivery.test.ts covers that direction over a live relay, including
the two invariants the deferral must not break (registry cleared immediately,
URI reusable afterwards).

Also fixes a latent hang in the integration harness that the new file exposed.
setupConnection gated both the dapp_ready send and the message handler inside
the keyexchangecomplete callback, so the handshake hung on receiving the wallet's
single wallet_ready for the cycle. Miss it — the dapp's subscription can come up
after the wallet has already published — and key exchange never resolves, the
handler never registers, no dapp_ready is ever sent, and the wallet, guarded by
walletReadySentThisCycle, has nothing prompting it to retry. It now re-announces
dapp_ready(wallet_discovered=false) every 2s until key exchange completes, which
resets that guard and earns another wallet_ready: the recovery path mutual
discovery already specifies, which the harness was not using. Plus retry: 2 on
the integration config, since these tests talk to live relays and a dropped
connection is an environment failure rather than a regression.

docs/wallet.md gains a "Sending disconnect" section for the synchronous/deferred
split and what a caller may rely on. docs/protocol.md gains the sender-side half
of the courtesy-disconnect semantics, which previously read as though "no
acknowledgement" licensed fire-and-forget. That reading is what produced the bug.

The race was diagnosed and first fixed by hantyrram (Ronaldo Ramano) in !30,
which this supersedes — the deferral is their fix; this changes only how it is
scoped.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 16:29:34 +02:00
jakobsn
167ec21474 Merge branch 'revert-e71f76c1' into 'master'
Revert "Merge branch 'randomTradeSummary' into 'master'"

See merge request riftenlabs/lib/wizardconnect!29
2026-05-11 08:48:04 +00:00
jakobsn
d580bb8927 Revert "Merge branch 'randomTradeSummary' into 'master'"
This reverts merge request !27
2026-05-11 08:46:49 +00:00
Dagur Valberg Johannsson
dc01931ad6 Merge branch 'react-dev' into 'master'
Fix issue with restoring session in React dev mode

See merge request riftenlabs/lib/wizardconnect!28
2026-05-09 18:34:46 +00:00
Dagur Valberg Johannsson
c2b13102b9
Fix issue with restoring session in React dev mode 2026-05-09 20:25:45 +02:00
jakobsn
e71f76c1d0 Merge branch 'randomTradeSummary' into 'master'
TxSummary

See merge request riftenlabs/lib/wizardconnect!27
2026-04-29 11:23:23 +00:00
jakobsn
6b6f0ec1d0 TxSummary 2026-04-29 11:23:23 +00:00
jakobsn
201e234bef Merge branch 'cauldron-191-cauldron-and-wizard-connect-thinks-i-am-connected-but-im-not' into 'master'
Active reconnect.

See merge request riftenlabs/lib/wizardconnect!25
2026-04-29 09:06:54 +00:00
jakobsn
443acccb80 Active reconnect. 2026-04-29 09:06:53 +00:00
jakobsn
896871c0d8 Merge branch 'chunk' into 'master'
Add chunk transport extension for oversized messages

See merge request riftenlabs/lib/wizardconnect!24
2026-04-27 13:30:40 +00:00
Dagur Valberg Johannsson
b96cb8e151
Add chunk transport extension for oversized messages
Splits ProtocolMessages exceeding NIP-44's 65,535-byte plaintext ceiling
across multiple gift-wrapped events. Symmetric (both directions),
fire-and-forget, backward-compatible via a new transport-level
\`extensions\` field on \`dapp_ready\` and \`wallet_ready\`. Resolves the
\"Failed to swap: invalid plaintext size\" error on aggregated swap
requests and enables signed-tx responses up to the 1 MB BCH consensus
limit (~2 MB hex).
2026-04-21 14:58:12 +02:00
Dagur Valberg Johannsson
472b9b1ec5 Merge branch 'all-relay' into 'master'
Ensure messages are sent to all relays

See merge request riftenlabs/lib/wizardconnect!23
2026-04-16 11:39:22 +00:00
Dagur Valberg Johannsson
9028384177
Ensure messages are sent to all relays
To be compatible to wallets that only listen on 'relay.cauldron.quest',
we need to make sure we send our messages to all connected relay
servers.
2026-04-16 13:38:28 +02:00
Dagur Valberg Johannsson
053f515b8f Merge branch 'ci-fix' into 'master'
ci: Fix version comparison bug

See merge request riftenlabs/lib/wizardconnect!22
2026-04-14 07:16:18 +00:00
Dagur Valberg Johannsson
994853bf8e
ci: Fix version comparison bug
Auto-publishing had a version comparison bug, causing it to attempt to
republish old versions instead using next avaiable version number.
2026-04-14 09:15:19 +02:00
Dagur Valberg Johannsson
fbac14cd08 Merge branch 'redundant-relay' into 'master'
Add additional default relay

See merge request riftenlabs/lib/wizardconnect!21
2026-04-14 07:03:50 +00:00
Dagur Valberg Johannsson
c8e0a2d7cc
Tests for 22601be4 (tcp zombie) 2026-04-14 08:42:34 +02:00
Dagur Valberg Johannsson
ef56fb198c
Add additional default relay
For improved reliability, this adds an additional relay as a redundancy.
2026-04-14 08:42:34 +02:00
Dagur Valberg Johannsson
f9da868513 Merge branch 'tcp-zombie' into 'master'
Detect stale tcp connections to relay

See merge request riftenlabs/lib/wizardconnect!20
2026-04-08 09:30:09 +00:00
Dagur Valberg Johannsson
a6e4a36db5
npm audit fix 2026-04-08 11:05:16 +02:00
Dagur Valberg Johannsson
22601be42d
Detect stale tcp connections to relay
Enable nostr-tools' internal stale tcp connection detection
2026-04-08 09:47:50 +02:00
Dagur Valberg Johannsson
4bcbef2aae Merge branch 'nicer-react' into 'master'
Add session persistence and refactor dapp manager

See merge request riftenlabs/lib/wizardconnect!19
2026-04-03 15:15:26 +00:00
Dagur Valberg Johannsson
8cd22c34ba
Add session persistence and refactor dapp manager
Keep session persistance by default, such that when reloading a dapp,
the wizardconnect session is kept alive.

Improve signature request interface. Simplify the react API.
2026-04-03 17:11:18 +02:00
Dagur Valberg Johannsson
3af76d5653 Merge branch 'sleepingWizard' into 'master'
Dedup connection: conn.dappDiscovered = false;

See merge request riftenlabs/lib/wizardconnect!17
2026-04-03 12:35:50 +00:00
jakobsn
e852e70a8e Dedup connection: conn.dappDiscovered = false; 2026-04-03 12:35:50 +00:00
Dagur Valberg Johannsson
077236969a Merge branch 'resend-on-ready' into 'master'
Re-send signature request on ready

See merge request riftenlabs/lib/wizardconnect!18
2026-04-03 11:38:12 +00:00
Dagur Valberg Johannsson
3324cac4fb
npm audit fix 2026-04-03 13:22:40 +02:00
Dagur Valberg Johannsson
08ea3da6aa
Re-send signature request on ready
User may need some time to open their wallet to approve signature
request and miss it.

If we have a active request, re-send it if we see a
wallet_ready signal, suggesting the wallet was just opened.
2026-04-03 13:22:40 +02:00
Dagur Valberg Johannsson
72da1758b3 Merge branch 'bcr-stealth-naming' into 'master'
docs: standardize extension names to RPA and BCH Stealth Addresses

See merge request riftenlabs/lib/wizardconnect!16
2026-04-01 09:47:25 +00:00
CyberAshven
d1369f5867 docs: standardize extension names to BCR-agreed standard
Replace placeholder 'bip352' / 'bip47_rpa' with the finalized
extension names from the BCR post and BCH Stealth Protocol spec:

- bip352      → bch_stealth_bip352
- bip47_rpa   → rpa_bip47

Add spend_path / scan_path fields to each extension handshake
object, pointing to the hardened gate paths where the wallet
exports xpubs. Dapps derive the non-hardened /0 child locally.

Add rpa_spend / rpa_scan path names alongside stealth_spend /
stealth_scan in all examples. Update known extensions table with
full path information and BCR reference links.

Spec: https://bitcoincashresearch.org/t/ecdh-stealth-addresses-on-bitcoin-cash-implementation-code/1773/5

I have read the CLA Document and I hereby sign the CLA
2026-03-28 22:39:34 +03:00
Dagur Valberg Johannsson
8b6a2e275f Merge branch 'extensions' into 'master'
Add 'extensions' to hdwalletv1 protocol

See merge request riftenlabs/lib/wizardconnect!15
2026-03-26 12:43:05 +00:00
Dagur Valberg Johannsson
4d1ba8e207
Add 'extensions' to hdwalletv1 protocol
This backward compatible change allows wallets/dapps to add additional
features outside the basic transaction signature support to the
hdwalletv1 protocol.
2026-03-26 10:50:40 +01:00
Dagur Valberg Johannsson
40d5f218fe
npm audit fix 2026-03-26 08:56:48 +01:00
Dagur Valberg Johannsson
fcfcd64d14
Replace nostr-dev-kit -> nostr-tools
The package nostr-dev-kit was using a dependency (tseep) which
downstream would flag as not CSP-safe.

Additionally nostr-tools footprint is much smaller.
2026-03-26 08:46:26 +01:00
Dagur Valberg Johannsson
95bbf96065 Merge branch 'qr-dialog' into 'master'
QR dialog: Give "Copied!" feedback

See merge request riftenlabs/lib/wizardconnect!14
2026-03-23 08:27:38 +00:00
Dagur Valberg Johannsson
676512ea8d
QR dialog: Give "Copied!" feedback
Clicking anywhere on the URI row copies to clipboard (not just the icon).
Shows "Copied!" text for 2 seconds replacing the copy icon.
2026-03-23 09:26:18 +01:00
Dagur Valberg Johannsson
9593332525 Merge branch 'ser-helpers' into 'master'
Add serialization helpers to @wizardconnect/core

See merge request riftenlabs/lib/wizardconnect!13
2026-03-23 08:16:42 +00:00
Dagur Valberg Johannsson
889dd566d1
Add serialization helpers to @wizardconnect/core
Canonical encoding for BigInt (<bigint: Xn>) and Uint8Array (hex or
<Uint8Array: 0x...>) used in the relay protocol. Provides both
serialization (sourceOutputToRelay, transactionToHex) and deserialization
(parseExtendedJson, toUint8Array, toBigInt) so dapps and wallets
don't have to implement this independently.
2026-03-23 08:59:02 +01:00
Dagur Valberg Johannsson
a22d98a6b2 Merge branch 'doc-xpub' into 'master'
doc: An article on xpub sharing

See merge request riftenlabs/lib/wizardconnect!8
2026-03-23 07:45:38 +00:00
Dagur Valberg Johannsson
930f09a167 Merge branch 'session-path' into 'master'
Add proper auto-reconnect with @wizardconnect/react

See merge request riftenlabs/lib/wizardconnect!12
2026-03-23 07:44:43 +00:00
Dagur Valberg Johannsson
68581a4929
up to date, audited 269 packages in 1s
106 packages are looking for funding
  run `npm fund` for details

found 0 vulnerabilities
2026-03-23 08:43:44 +01:00
Dagur Valberg Johannsson
acab94dc68
ci: Build before running tests 2026-03-23 08:43:00 +01:00
Dagur Valberg Johannsson
cb4f1ee598
bug: Pass pubkey to initiateRelay on reconnect
Pass the pubkey if we already know it.
2026-03-23 08:34:51 +01:00
Dagur Valberg Johannsson
8467856975
Persist xpub paths in session storage for offline pubkey derivation
The useWizardConnect hook now saves PathXpub[] from wallet_ready into
the localStorage session. On auto-reconnect, restoreSessionPaths() is
called so getPubkey() works immediately without waiting for the wallet.
Corrupt cached paths are cleared with a warning.
2026-03-23 08:32:17 +01:00
Dagur Valberg Johannsson
add06b6476
Add getSessionPaths() and restoreSessionPaths() to DappConnectionManager
Allows dapps to cache the raw PathXpub[] from wallet_ready and restore
them on subsequent page loads. restoreSessionPaths decodes the xpub strings
and populates pubkeyState so getPubkey() works without waiting for the
wallet to reconnect. Throws on invalid xpub data.
2026-03-23 08:26:12 +01:00
Dagur Valberg Johannsson
33c45596ef Merge branch 'pkg-react' into 'master'
Add 'react' package with QR code and modal dialog

See merge request riftenlabs/lib/wizardconnect!11
2026-03-18 15:41:30 +00:00
Dagur Valberg Johannsson
45fd9f4cb5
Add 'react' package with QR code and modal dialog
Makes it easier for dapp developers to integrate WizardConnect and have
consistent user interface for it across dapps.
2026-03-18 16:34:41 +01:00