sirius-press/CHANGELOG.md

95 lines
4.6 KiB
Markdown

# Changelog
## 0.1.0 — unreleased
First cut. Sirius Press installs, signs people in with a wallet, and publishes
static copies of its pages to a BCNR name.
### Accounts
- Sign in by signing a challenge with a Bitcoin Cash key. The address is
recovered from the signature, so nothing has to be typed but the signature
itself.
- Three ways to produce one: a wallet the browser already exposes (Theseus), a
recovery phrase used once in the page and wiped, or a signature pasted in
from any BIP-137 wallet. The last works with JavaScript disabled.
- One-step registration — the signature is the confirmation, so there is no
email round trip and no pending state.
- Password sign-in stays on by default and can be turned off once every
account has a wallet. The screen that turns it off refuses to do so while it
would lock out the person asking.
- No password reset, and the "lost password" page explains why rather than
pretending otherwise.
- `/sirius-press/v1/confirm` lets any plugin demand a fresh signature before
something irreversible.
### Publishing
- Publishing a post exports it, the home page and its archives to the name's
storage on Sia, signed BNS-SITE1.
- Two signing modes: manual, where the browser signs and the server stores
nothing, and automatic, where an encrypted phrase lets cron publish alone.
Manual is the default.
- Unchanged pages are hashed and skipped rather than re-uploaded.
- Unpublishing a post removes its file from the mirror.
- `wp sirius export` and `wp sirius status` for the command line.
### Compatibility
- Every account carries an unroutable `.invalid` placeholder `user_email`, so
the thousands of ecosystem reads of that field keep returning a string.
- Mail to those placeholders is captured into an in-app inbox. Mail to real
addresses is passed through untouched, so SMTP works normally.
- Shims for WooCommerce, Contact Form 7 and core's admin-email machinery.
### Core
- One change, 75 lines, in `wp-admin/install.php`: the setup wizard asks for a
wallet address instead of an email address, and the address is optional.
- WordPress is vendored at `wordpress/` as a git subtree, already patched.
Upstream releases arrive through `git subtree merge` against
`sirius-press/wordpress-upstream`, a branch of pristine imports, so a
release that touches code near the fork's change is three-way merged rather
than re-derived by hand. `tools/update-wordpress.sh <version>` runs the
whole thing.
- `patches/` is now generated from the tree by `tools/refresh-patches.sh`
(with `--check` for CI) and exists to answer "what does this fork change in
core?" without reading a 3,800-file log. It is documentation, not the build
mechanism.
### Packaging
- `install.sh` for a fresh Ubuntu VPS; Docker stack with MariaDB, PHP-FPM and
nginx. Core lives in the image, so rebuilding is a real upgrade.
- `tools/build.sh --zip` for shared hosting.
- `tools/update-wordpress.sh` to move onto a new upstream release.
- `tools/publish-release.sh` to ship to both mirrors.
### Fixed while testing against a live instance
- **Registration and wallet-linking accepted a signature over the wrong text.**
Public-key recovery always succeeds — it returns a different key rather than
failing — so a mismatched signature silently bound an account to an address
nobody could sign for. Both paths now require the claimed address and
compare it to the recovered one. Sign-in was never exposed to this, because
a wrong address simply matches no account.
- URL rewriting mangled links on any site whose URL carries a port: the
protocol-relative pass matched inside absolute URLs and doubled the scheme,
and a host-only match left the port stranded. Both covered by tests now.
- Translations loaded on `plugins_loaded`, which WordPress 6.7+ warns about on
every request. Moved to `init`.
- The Publishing screen now refuses to be quiet about plain permalinks, which
would collapse an entire site onto one exported file.
- Removed an `is_email()` filter that rested on a false premise: WordPress
validates syntax, not whether a domain can exist, so `.invalid` addresses
already pass and the filter never fired. The documentation said otherwise
and has been corrected.
### Known gaps
- `install.sh` and the Docker stack are written and syntax-checked but have
not been run on a clean Ubuntu box.
- Publishing is verified against a transcription of the gateway's own
verification logic, not against `navigate.st` with a registered name.
- Seven of the ten rows in the plugin compatibility matrix are reasoned rather
than tested; the three named in the ship criteria were installed and run.