# Changelog ## 0.1.0 — unreleased First cut. Sirius Press installs, signs people in with a wallet, and publishes static copies of its pages to a BCNR name. ### Accounts - Sign in by signing a challenge with a Bitcoin Cash key. The address is recovered from the signature, so nothing has to be typed but the signature itself. - Three ways to produce one: a wallet the browser already exposes (Theseus), a recovery phrase used once in the page and wiped, or a signature pasted in from any BIP-137 wallet. The last works with JavaScript disabled. - One-step registration — the signature is the confirmation, so there is no email round trip and no pending state. - Password sign-in stays on by default and can be turned off once every account has a wallet. The screen that turns it off refuses to do so while it would lock out the person asking. - No password reset, and the "lost password" page explains why rather than pretending otherwise. - `/sirius-press/v1/confirm` lets any plugin demand a fresh signature before something irreversible. ### Publishing - Publishing a post exports it, the home page and its archives to the name's storage on Sia, signed BNS-SITE1. - Two signing modes: manual, where the browser signs and the server stores nothing, and automatic, where an encrypted phrase lets cron publish alone. Manual is the default. - Unchanged pages are hashed and skipped rather than re-uploaded. - Unpublishing a post removes its file from the mirror. - `wp sirius export` and `wp sirius status` for the command line. ### Compatibility - Every account carries an unroutable `.invalid` placeholder `user_email`, so the thousands of ecosystem reads of that field keep returning a string. - Mail to those placeholders is captured into an in-app inbox. Mail to real addresses is passed through untouched, so SMTP works normally. - Shims for WooCommerce, Contact Form 7 and core's admin-email machinery. ### Core - One patch, 75 lines, against `wp-admin/install.php`: the setup wizard asks for a wallet address instead of an email address, and the address is optional. - WordPress is pinned and verified rather than vendored — `tools/wordpress.lock` plus `patches/`. See docs/upstream-merges.md. ### Packaging - `install.sh` for a fresh Ubuntu VPS; Docker stack with MariaDB, PHP-FPM and nginx. Core lives in the image, so rebuilding is a real upgrade. - `tools/build.sh --zip` for shared hosting. - `tools/update-wordpress.sh` to move onto a new upstream release. - `tools/publish-release.sh` to ship to both mirrors. ### Known gaps - The plugin compatibility matrix in docs is reasoned from each plugin's setup path, not yet confirmed against a running install. - No instance has been stood up end to end against a live chipnet name, so the full publish path is verified by unit and interop tests rather than by a round trip through the gateway.