sirius-press/CHANGELOG.md
Silent Mode 8f8c83478e docs(sirius-press): record what the browser found, and what still has not been run
The docs said nobody had clicked the buttons in a browser. Somebody has now,
and it cost two bugs, so testing.md gains a section saying to do it after
touching the auth assets — the HTTP suites cannot see that class of failure.

Also sharpens the honest gap: the Docker stack has not been run anywhere, not
just 'not on a clean Ubuntu box'.
2026-09-22 20:19:42 +02:00

118 lines
5.8 KiB
Markdown

# Changelog
## 0.1.0 — unreleased
First cut. Sirius Press installs, signs people in with a wallet, and publishes
static copies of its pages to a BCNR name.
### Accounts
- Sign in by signing a challenge with a Bitcoin Cash key. The address is
recovered from the signature, so nothing has to be typed but the signature
itself.
- Three ways to produce one: a wallet the browser already exposes (Theseus), a
recovery phrase used once in the page and wiped, or a signature pasted in
from any BIP-137 wallet. The last works with JavaScript disabled.
- One-step registration — the signature is the confirmation, so there is no
email round trip and no pending state.
- Password sign-in stays on by default and can be turned off once every
account has a wallet. The screen that turns it off refuses to do so while it
would lock out the person asking.
- No password reset, and the "lost password" page explains why rather than
pretending otherwise.
- `/sirius-press/v1/confirm` lets any plugin demand a fresh signature before
something irreversible.
### Publishing
- Publishing a post exports it, the home page and its archives to the name's
storage on Sia, signed BNS-SITE1.
- Two signing modes: manual, where the browser signs and the server stores
nothing, and automatic, where an encrypted phrase lets cron publish alone.
Manual is the default.
- Unchanged pages are hashed and skipped rather than re-uploaded.
- Unpublishing a post removes its file from the mirror.
- `wp sirius export` and `wp sirius status` for the command line.
### Compatibility
- Every account carries an unroutable `.invalid` placeholder `user_email`, so
the thousands of ecosystem reads of that field keep returning a string.
- Mail to those placeholders is captured into an in-app inbox. Mail to real
addresses is passed through untouched, so SMTP works normally.
- Shims for WooCommerce, Contact Form 7 and core's admin-email machinery.
### Core
- One change, 75 lines, in `wp-admin/install.php`: the setup wizard asks for a
wallet address instead of an email address, and the address is optional.
- WordPress is vendored at `wordpress/` as a git subtree, already patched.
Upstream releases arrive through `git subtree merge` against
`sirius-press/wordpress-upstream`, a branch of pristine imports, so a
release that touches code near the fork's change is three-way merged rather
than re-derived by hand. `tools/update-wordpress.sh <version>` runs the
whole thing.
- `patches/` is now generated from the tree by `tools/refresh-patches.sh`
(with `--check` for CI) and exists to answer "what does this fork change in
core?" without reading a 3,800-file log. It is documentation, not the build
mechanism.
### Packaging
- `install.sh` for a fresh Ubuntu VPS; Docker stack with MariaDB, PHP-FPM and
nginx. Core lives in the image, so rebuilding is a real upgrade.
- `tools/build.sh --zip` for shared hosting.
- `tools/update-wordpress.sh` to move onto a new upstream release.
- `tools/publish-release.sh` to ship to both mirrors.
### Fixed while testing against a live instance
- **Registration and wallet-linking accepted a signature over the wrong text.**
Public-key recovery always succeeds — it returns a different key rather than
failing — so a mismatched signature silently bound an account to an address
nobody could sign for. Both paths now require the claimed address and
compare it to the recovered one. Sign-in was never exposed to this, because
a wrong address simply matches no account.
- URL rewriting mangled links on any site whose URL carries a port: the
protocol-relative pass matched inside absolute URLs and doubled the scheme,
and a host-only match left the port stranded. Both covered by tests now.
- Translations loaded on `plugins_loaded`, which WordPress 6.7+ warns about on
every request. Moved to `init`.
- The Publishing screen now refuses to be quiet about plain permalinks, which
would collapse an entire site onto one exported file.
- Removed an `is_email()` filter that rested on a false premise: WordPress
validates syntax, not whether a domain can exist, so `.invalid` addresses
already pass and the filter never fired. The documentation said otherwise
and has been corrected.
### Fixed after opening it in a browser
- Wallet sign-in did not work in a browser at all. WordPress marks its
username and password inputs `required`; the wallet path leaves both empty
on purpose, so the form refused to submit a valid signature and pointed a
validation bubble at a field the visitor is not meant to fill in.
- The `hidden` attribute was being overridden by WordPress's own button
styles, so controls this plugin ships hidden were visible regardless —
offering a browser wallet that is not there, and showing a JavaScript-only
button to visitors without JavaScript.
### WordPress 7.1.2
Taken through `tools/update-wordpress.sh` and merged cleanly; upstream did not
touch the one file this fork patches. Two bugs in the update tool surfaced
doing it: a Windows path-subtraction that produced an absolute `--prefix`, and
git-subtree's refusal to run in a repository with any uncommitted file. The
merge now runs in a scratch worktree and a failed run can be retried.
### Known gaps
- `install.sh` and the Docker stack are written and syntax-checked but have
never been run — not on a clean Ubuntu box, and not locally either, since
Docker would not start on the machine this was built on. Largest untested
surface in the project.
- Manual-mode publishing (browser signs and uploads) has not been clicked
through; the server-signing path has.
- Publishing is verified against a transcription of the gateway's own
verification logic, not against `navigate.st` with a registered name.
- Seven of the ten rows in the plugin compatibility matrix are reasoned rather
than tested; the three named in the ship criteria were installed and run.