fix: consume vss-client 0.5.23 - #673

Merged
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23
Aug 18, 2026
Merged

fix: consume vss-client 0.5.23#673
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23

Conversation

@ovitrif

@ovitrifovitrif commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

This PR bumps vss-rust-client-ffi from 0.5.21 to 0.5.23.

Description

0.5.23 includes synonymdev/vss-rust-client-ffi#20. Unauthenticated client setup now returns AuthError instead of encrypting with a public all-zero key.

Companion Android PR: synonymdev/bitkit-android#1164

Linked Issues/Tasks

Screenshot / Video

N/A

QA Notes

Manual Tests

  • 1.regression: Fresh wallet → backup/Lightning start with current Env LNURL-auth URL: setup still succeeds.

Automated Checks

  • Local Debug simulator build passed against 0.5.23.

@ovitrifovitrif mentioned this pull request Aug 18, 2026
2 tasks
@greptile-apps

Copy link
Copy Markdown

Greptile Summary

This PR upgrades vss-rust-client-ffi to 0.5.23 and makes VSS initialization fail closed when LNURL-auth configuration is blank.

  • Removes unauthenticated backup and Lightning-node VSS fallback paths.
  • Normalizes whitespace in the LNURL-auth URL and adds a dedicated authentication-required error.
  • Updates the Swift package lockfile and adds a security changelog entry.

Confidence Score: 5/5

The PR appears safe to merge, with authenticated VSS initialization consistently replacing the removed unauthenticated fallback.

The changed setup paths reject blank authentication configuration, retain correct failure cleanup, and use the authenticated VSS APIs pinned by the coordinated dependency update; no reachable blocking failure remains.

Important Files Changed

FilenameOverview
Bitkit/Services/LightningService.swiftRemoves fixed-header VSS fallback and requires a nonblank LNURL-auth URL before building the Lightning node.
Bitkit/Services/VssBackupClient.swiftRoutes app and debug VSS setup exclusively through authenticated client initialization.
Bitkit/Utilities/Errors.swiftAdds the dedicated vssAuthRequired service error and its AppError mapping.
Bitkit.xcodeproj/project.pbxprojUpdates the exact vss-rust-client-ffi package requirement to 0.5.23.
Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolvedPins vss-rust-client-ffi 0.5.23 at the corresponding resolved revision.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Backup or Lightning setup] --> B[Read and trim LNURL-auth URL]
B --> C{URL present?}
C -- No --> D[Throw vssAuthRequired]
C -- Yes --> E[Initialize authenticated VSS client]
E --> F[Proceed with backup or Lightning node]
Loading

Reviews (1): Last reviewed commit: "fix: consume vss-client 0.5.23" | Re-trigger Greptile

@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 78f71e8 to 734ffb2CompareAugust 18, 2026 11:12
@ovitrif
ovitrif changed the base branch from master to fix/fail-closed-unauthenticated-vssAugust 18, 2026 11:12
@ovitrifovitrif self-assigned this Aug 18, 2026
@ovitrifovitrif added this to the 2.5.0 milestone Aug 18, 2026
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 734ffb2 to 8a59735CompareAugust 18, 2026 13:03
Base automatically changed from fix/fail-closed-unauthenticated-vss to masterAugust 18, 2026 18:07
Bump vss-rust-client-ffi to 0.5.23 so unauthenticated VSS encryption is rejected in the library.
Related: synonymdev/audit#55, synonymdev/vss-rust-client-ffi#20
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 8a59735 to c56cabaCompareAugust 18, 2026 18:07
@ovitrif
ovitrif merged commit 625b54e into masterAug 18, 2026
11 checks passed
@ovitrif
ovitrif deleted the fix/consume-vss-0.5.23 branch August 18, 2026 20:43
@piotr-iohkpiotr-iohk mentioned this pull request Aug 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ovitrif@ben-kaufman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: consume vss-client 0.5.23 - #673

Merged
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23
Aug 18, 2026
Merged

fix: consume vss-client 0.5.23#673
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23

Conversation

@ovitrif

@ovitrifovitrif commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

This PR bumps vss-rust-client-ffi from 0.5.21 to 0.5.23.

Description

0.5.23 includes synonymdev/vss-rust-client-ffi#20. Unauthenticated client setup now returns AuthError instead of encrypting with a public all-zero key.

Companion Android PR: synonymdev/bitkit-android#1164

Linked Issues/Tasks

Screenshot / Video

N/A

QA Notes

Manual Tests

  • 1.regression: Fresh wallet → backup/Lightning start with current Env LNURL-auth URL: setup still succeeds.

Automated Checks

  • Local Debug simulator build passed against 0.5.23.

@ovitrifovitrif mentioned this pull request Aug 18, 2026
2 tasks
@greptile-apps

Copy link
Copy Markdown

Greptile Summary

This PR upgrades vss-rust-client-ffi to 0.5.23 and makes VSS initialization fail closed when LNURL-auth configuration is blank.

  • Removes unauthenticated backup and Lightning-node VSS fallback paths.
  • Normalizes whitespace in the LNURL-auth URL and adds a dedicated authentication-required error.
  • Updates the Swift package lockfile and adds a security changelog entry.

Confidence Score: 5/5

The PR appears safe to merge, with authenticated VSS initialization consistently replacing the removed unauthenticated fallback.

The changed setup paths reject blank authentication configuration, retain correct failure cleanup, and use the authenticated VSS APIs pinned by the coordinated dependency update; no reachable blocking failure remains.

Important Files Changed

FilenameOverview
Bitkit/Services/LightningService.swiftRemoves fixed-header VSS fallback and requires a nonblank LNURL-auth URL before building the Lightning node.
Bitkit/Services/VssBackupClient.swiftRoutes app and debug VSS setup exclusively through authenticated client initialization.
Bitkit/Utilities/Errors.swiftAdds the dedicated vssAuthRequired service error and its AppError mapping.
Bitkit.xcodeproj/project.pbxprojUpdates the exact vss-rust-client-ffi package requirement to 0.5.23.
Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolvedPins vss-rust-client-ffi 0.5.23 at the corresponding resolved revision.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Backup or Lightning setup] --> B[Read and trim LNURL-auth URL]
B --> C{URL present?}
C -- No --> D[Throw vssAuthRequired]
C -- Yes --> E[Initialize authenticated VSS client]
E --> F[Proceed with backup or Lightning node]
Loading

Reviews (1): Last reviewed commit: "fix: consume vss-client 0.5.23" | Re-trigger Greptile

@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 78f71e8 to 734ffb2CompareAugust 18, 2026 11:12
@ovitrif
ovitrif changed the base branch from master to fix/fail-closed-unauthenticated-vssAugust 18, 2026 11:12
@ovitrifovitrif self-assigned this Aug 18, 2026
@ovitrifovitrif added this to the 2.5.0 milestone Aug 18, 2026
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 734ffb2 to 8a59735CompareAugust 18, 2026 13:03
Base automatically changed from fix/fail-closed-unauthenticated-vss to masterAugust 18, 2026 18:07
Bump vss-rust-client-ffi to 0.5.23 so unauthenticated VSS encryption is rejected in the library.
Related: synonymdev/audit#55, synonymdev/vss-rust-client-ffi#20
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 8a59735 to c56cabaCompareAugust 18, 2026 18:07
@ovitrif
ovitrif merged commit 625b54e into masterAug 18, 2026
11 checks passed
@ovitrif
ovitrif deleted the fix/consume-vss-0.5.23 branch August 18, 2026 20:43
@piotr-iohkpiotr-iohk mentioned this pull request Aug 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ovitrif@ben-kaufman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: consume vss-client 0.5.23 - #673

Merged
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23
Aug 18, 2026
Merged

fix: consume vss-client 0.5.23#673
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23

Conversation

@ovitrif

@ovitrifovitrif commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

This PR bumps vss-rust-client-ffi from 0.5.21 to 0.5.23.

Description

0.5.23 includes synonymdev/vss-rust-client-ffi#20. Unauthenticated client setup now returns AuthError instead of encrypting with a public all-zero key.

Companion Android PR: synonymdev/bitkit-android#1164

Linked Issues/Tasks

Screenshot / Video

N/A

QA Notes

Manual Tests

  • 1.regression: Fresh wallet → backup/Lightning start with current Env LNURL-auth URL: setup still succeeds.

Automated Checks

  • Local Debug simulator build passed against 0.5.23.

@ovitrifovitrif mentioned this pull request Aug 18, 2026
2 tasks
@greptile-apps

Copy link
Copy Markdown

Greptile Summary

This PR upgrades vss-rust-client-ffi to 0.5.23 and makes VSS initialization fail closed when LNURL-auth configuration is blank.

  • Removes unauthenticated backup and Lightning-node VSS fallback paths.
  • Normalizes whitespace in the LNURL-auth URL and adds a dedicated authentication-required error.
  • Updates the Swift package lockfile and adds a security changelog entry.

Confidence Score: 5/5

The PR appears safe to merge, with authenticated VSS initialization consistently replacing the removed unauthenticated fallback.

The changed setup paths reject blank authentication configuration, retain correct failure cleanup, and use the authenticated VSS APIs pinned by the coordinated dependency update; no reachable blocking failure remains.

Important Files Changed

FilenameOverview
Bitkit/Services/LightningService.swiftRemoves fixed-header VSS fallback and requires a nonblank LNURL-auth URL before building the Lightning node.
Bitkit/Services/VssBackupClient.swiftRoutes app and debug VSS setup exclusively through authenticated client initialization.
Bitkit/Utilities/Errors.swiftAdds the dedicated vssAuthRequired service error and its AppError mapping.
Bitkit.xcodeproj/project.pbxprojUpdates the exact vss-rust-client-ffi package requirement to 0.5.23.
Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolvedPins vss-rust-client-ffi 0.5.23 at the corresponding resolved revision.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Backup or Lightning setup] --> B[Read and trim LNURL-auth URL]
B --> C{URL present?}
C -- No --> D[Throw vssAuthRequired]
C -- Yes --> E[Initialize authenticated VSS client]
E --> F[Proceed with backup or Lightning node]
Loading

Reviews (1): Last reviewed commit: "fix: consume vss-client 0.5.23" | Re-trigger Greptile

@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 78f71e8 to 734ffb2CompareAugust 18, 2026 11:12
@ovitrif
ovitrif changed the base branch from master to fix/fail-closed-unauthenticated-vssAugust 18, 2026 11:12
@ovitrifovitrif self-assigned this Aug 18, 2026
@ovitrifovitrif added this to the 2.5.0 milestone Aug 18, 2026
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 734ffb2 to 8a59735CompareAugust 18, 2026 13:03
Base automatically changed from fix/fail-closed-unauthenticated-vss to masterAugust 18, 2026 18:07
Bump vss-rust-client-ffi to 0.5.23 so unauthenticated VSS encryption is rejected in the library.
Related: synonymdev/audit#55, synonymdev/vss-rust-client-ffi#20
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 8a59735 to c56cabaCompareAugust 18, 2026 18:07
@ovitrif
ovitrif merged commit 625b54e into masterAug 18, 2026
11 checks passed
@ovitrif
ovitrif deleted the fix/consume-vss-0.5.23 branch August 18, 2026 20:43
@piotr-iohkpiotr-iohk mentioned this pull request Aug 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ovitrif@ben-kaufman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: consume vss-client 0.5.23 - #673

Merged
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23
Aug 18, 2026
Merged

fix: consume vss-client 0.5.23#673
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23

Conversation

@ovitrif

@ovitrifovitrif commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

This PR bumps vss-rust-client-ffi from 0.5.21 to 0.5.23.

Description

0.5.23 includes synonymdev/vss-rust-client-ffi#20. Unauthenticated client setup now returns AuthError instead of encrypting with a public all-zero key.

Companion Android PR: synonymdev/bitkit-android#1164

Linked Issues/Tasks

Screenshot / Video

N/A

QA Notes

Manual Tests

  • 1.regression: Fresh wallet → backup/Lightning start with current Env LNURL-auth URL: setup still succeeds.

Automated Checks

  • Local Debug simulator build passed against 0.5.23.

@ovitrifovitrif mentioned this pull request Aug 18, 2026
2 tasks
@greptile-apps

Copy link
Copy Markdown

Greptile Summary

This PR upgrades vss-rust-client-ffi to 0.5.23 and makes VSS initialization fail closed when LNURL-auth configuration is blank.

  • Removes unauthenticated backup and Lightning-node VSS fallback paths.
  • Normalizes whitespace in the LNURL-auth URL and adds a dedicated authentication-required error.
  • Updates the Swift package lockfile and adds a security changelog entry.

Confidence Score: 5/5

The PR appears safe to merge, with authenticated VSS initialization consistently replacing the removed unauthenticated fallback.

The changed setup paths reject blank authentication configuration, retain correct failure cleanup, and use the authenticated VSS APIs pinned by the coordinated dependency update; no reachable blocking failure remains.

Important Files Changed

FilenameOverview
Bitkit/Services/LightningService.swiftRemoves fixed-header VSS fallback and requires a nonblank LNURL-auth URL before building the Lightning node.
Bitkit/Services/VssBackupClient.swiftRoutes app and debug VSS setup exclusively through authenticated client initialization.
Bitkit/Utilities/Errors.swiftAdds the dedicated vssAuthRequired service error and its AppError mapping.
Bitkit.xcodeproj/project.pbxprojUpdates the exact vss-rust-client-ffi package requirement to 0.5.23.
Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolvedPins vss-rust-client-ffi 0.5.23 at the corresponding resolved revision.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Backup or Lightning setup] --> B[Read and trim LNURL-auth URL]
B --> C{URL present?}
C -- No --> D[Throw vssAuthRequired]
C -- Yes --> E[Initialize authenticated VSS client]
E --> F[Proceed with backup or Lightning node]
Loading

Reviews (1): Last reviewed commit: "fix: consume vss-client 0.5.23" | Re-trigger Greptile

@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 78f71e8 to 734ffb2CompareAugust 18, 2026 11:12
@ovitrif
ovitrif changed the base branch from master to fix/fail-closed-unauthenticated-vssAugust 18, 2026 11:12
@ovitrifovitrif self-assigned this Aug 18, 2026
@ovitrifovitrif added this to the 2.5.0 milestone Aug 18, 2026
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 734ffb2 to 8a59735CompareAugust 18, 2026 13:03
Base automatically changed from fix/fail-closed-unauthenticated-vss to masterAugust 18, 2026 18:07
Bump vss-rust-client-ffi to 0.5.23 so unauthenticated VSS encryption is rejected in the library.
Related: synonymdev/audit#55, synonymdev/vss-rust-client-ffi#20
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 8a59735 to c56cabaCompareAugust 18, 2026 18:07
@ovitrif
ovitrif merged commit 625b54e into masterAug 18, 2026
11 checks passed
@ovitrif
ovitrif deleted the fix/consume-vss-0.5.23 branch August 18, 2026 20:43
@piotr-iohkpiotr-iohk mentioned this pull request Aug 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ovitrif@ben-kaufman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: consume vss-client 0.5.23 - #673

Merged
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23
Aug 18, 2026
Merged

fix: consume vss-client 0.5.23#673
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23

Conversation

@ovitrif

@ovitrifovitrif commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

This PR bumps vss-rust-client-ffi from 0.5.21 to 0.5.23.

Description

0.5.23 includes synonymdev/vss-rust-client-ffi#20. Unauthenticated client setup now returns AuthError instead of encrypting with a public all-zero key.

Companion Android PR: synonymdev/bitkit-android#1164

Linked Issues/Tasks

Screenshot / Video

N/A

QA Notes

Manual Tests

  • 1.regression: Fresh wallet → backup/Lightning start with current Env LNURL-auth URL: setup still succeeds.

Automated Checks

  • Local Debug simulator build passed against 0.5.23.

@ovitrifovitrif mentioned this pull request Aug 18, 2026
2 tasks
@greptile-apps

Copy link
Copy Markdown

Greptile Summary

This PR upgrades vss-rust-client-ffi to 0.5.23 and makes VSS initialization fail closed when LNURL-auth configuration is blank.

  • Removes unauthenticated backup and Lightning-node VSS fallback paths.
  • Normalizes whitespace in the LNURL-auth URL and adds a dedicated authentication-required error.
  • Updates the Swift package lockfile and adds a security changelog entry.

Confidence Score: 5/5

The PR appears safe to merge, with authenticated VSS initialization consistently replacing the removed unauthenticated fallback.

The changed setup paths reject blank authentication configuration, retain correct failure cleanup, and use the authenticated VSS APIs pinned by the coordinated dependency update; no reachable blocking failure remains.

Important Files Changed

FilenameOverview
Bitkit/Services/LightningService.swiftRemoves fixed-header VSS fallback and requires a nonblank LNURL-auth URL before building the Lightning node.
Bitkit/Services/VssBackupClient.swiftRoutes app and debug VSS setup exclusively through authenticated client initialization.
Bitkit/Utilities/Errors.swiftAdds the dedicated vssAuthRequired service error and its AppError mapping.
Bitkit.xcodeproj/project.pbxprojUpdates the exact vss-rust-client-ffi package requirement to 0.5.23.
Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolvedPins vss-rust-client-ffi 0.5.23 at the corresponding resolved revision.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Backup or Lightning setup] --> B[Read and trim LNURL-auth URL]
B --> C{URL present?}
C -- No --> D[Throw vssAuthRequired]
C -- Yes --> E[Initialize authenticated VSS client]
E --> F[Proceed with backup or Lightning node]
Loading

Reviews (1): Last reviewed commit: "fix: consume vss-client 0.5.23" | Re-trigger Greptile

@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 78f71e8 to 734ffb2CompareAugust 18, 2026 11:12
@ovitrif
ovitrif changed the base branch from master to fix/fail-closed-unauthenticated-vssAugust 18, 2026 11:12
@ovitrifovitrif self-assigned this Aug 18, 2026
@ovitrifovitrif added this to the 2.5.0 milestone Aug 18, 2026
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 734ffb2 to 8a59735CompareAugust 18, 2026 13:03
Base automatically changed from fix/fail-closed-unauthenticated-vss to masterAugust 18, 2026 18:07
Bump vss-rust-client-ffi to 0.5.23 so unauthenticated VSS encryption is rejected in the library.
Related: synonymdev/audit#55, synonymdev/vss-rust-client-ffi#20
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 8a59735 to c56cabaCompareAugust 18, 2026 18:07
@ovitrif
ovitrif merged commit 625b54e into masterAug 18, 2026
11 checks passed
@ovitrif
ovitrif deleted the fix/consume-vss-0.5.23 branch August 18, 2026 20:43
@piotr-iohkpiotr-iohk mentioned this pull request Aug 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ovitrif@ben-kaufman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: consume vss-client 0.5.23 - #673

Merged
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23
Aug 18, 2026
Merged

fix: consume vss-client 0.5.23#673
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23

Conversation

@ovitrif

@ovitrifovitrif commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

This PR bumps vss-rust-client-ffi from 0.5.21 to 0.5.23.

Description

0.5.23 includes synonymdev/vss-rust-client-ffi#20. Unauthenticated client setup now returns AuthError instead of encrypting with a public all-zero key.

Companion Android PR: synonymdev/bitkit-android#1164

Linked Issues/Tasks

Screenshot / Video

N/A

QA Notes

Manual Tests

  • 1.regression: Fresh wallet → backup/Lightning start with current Env LNURL-auth URL: setup still succeeds.

Automated Checks

  • Local Debug simulator build passed against 0.5.23.

@ovitrifovitrif mentioned this pull request Aug 18, 2026
2 tasks
@greptile-apps

Copy link
Copy Markdown

Greptile Summary

This PR upgrades vss-rust-client-ffi to 0.5.23 and makes VSS initialization fail closed when LNURL-auth configuration is blank.

  • Removes unauthenticated backup and Lightning-node VSS fallback paths.
  • Normalizes whitespace in the LNURL-auth URL and adds a dedicated authentication-required error.
  • Updates the Swift package lockfile and adds a security changelog entry.

Confidence Score: 5/5

The PR appears safe to merge, with authenticated VSS initialization consistently replacing the removed unauthenticated fallback.

The changed setup paths reject blank authentication configuration, retain correct failure cleanup, and use the authenticated VSS APIs pinned by the coordinated dependency update; no reachable blocking failure remains.

Important Files Changed

FilenameOverview
Bitkit/Services/LightningService.swiftRemoves fixed-header VSS fallback and requires a nonblank LNURL-auth URL before building the Lightning node.
Bitkit/Services/VssBackupClient.swiftRoutes app and debug VSS setup exclusively through authenticated client initialization.
Bitkit/Utilities/Errors.swiftAdds the dedicated vssAuthRequired service error and its AppError mapping.
Bitkit.xcodeproj/project.pbxprojUpdates the exact vss-rust-client-ffi package requirement to 0.5.23.
Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolvedPins vss-rust-client-ffi 0.5.23 at the corresponding resolved revision.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Backup or Lightning setup] --> B[Read and trim LNURL-auth URL]
B --> C{URL present?}
C -- No --> D[Throw vssAuthRequired]
C -- Yes --> E[Initialize authenticated VSS client]
E --> F[Proceed with backup or Lightning node]
Loading

Reviews (1): Last reviewed commit: "fix: consume vss-client 0.5.23" | Re-trigger Greptile

@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 78f71e8 to 734ffb2CompareAugust 18, 2026 11:12
@ovitrif
ovitrif changed the base branch from master to fix/fail-closed-unauthenticated-vssAugust 18, 2026 11:12
@ovitrifovitrif self-assigned this Aug 18, 2026
@ovitrifovitrif added this to the 2.5.0 milestone Aug 18, 2026
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 734ffb2 to 8a59735CompareAugust 18, 2026 13:03
Base automatically changed from fix/fail-closed-unauthenticated-vss to masterAugust 18, 2026 18:07
Bump vss-rust-client-ffi to 0.5.23 so unauthenticated VSS encryption is rejected in the library.
Related: synonymdev/audit#55, synonymdev/vss-rust-client-ffi#20
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 8a59735 to c56cabaCompareAugust 18, 2026 18:07
@ovitrif
ovitrif merged commit 625b54e into masterAug 18, 2026
11 checks passed
@ovitrif
ovitrif deleted the fix/consume-vss-0.5.23 branch August 18, 2026 20:43
@piotr-iohkpiotr-iohk mentioned this pull request Aug 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ovitrif@ben-kaufman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: consume vss-client 0.5.23 - #673

Merged
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23
Aug 18, 2026
Merged

fix: consume vss-client 0.5.23#673
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23

Conversation

@ovitrif

@ovitrifovitrif commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

This PR bumps vss-rust-client-ffi from 0.5.21 to 0.5.23.

Description

0.5.23 includes synonymdev/vss-rust-client-ffi#20. Unauthenticated client setup now returns AuthError instead of encrypting with a public all-zero key.

Companion Android PR: synonymdev/bitkit-android#1164

Linked Issues/Tasks

Screenshot / Video

N/A

QA Notes

Manual Tests

  • 1.regression: Fresh wallet → backup/Lightning start with current Env LNURL-auth URL: setup still succeeds.

Automated Checks

  • Local Debug simulator build passed against 0.5.23.

@ovitrifovitrif mentioned this pull request Aug 18, 2026
2 tasks
@greptile-apps

Copy link
Copy Markdown

Greptile Summary

This PR upgrades vss-rust-client-ffi to 0.5.23 and makes VSS initialization fail closed when LNURL-auth configuration is blank.

  • Removes unauthenticated backup and Lightning-node VSS fallback paths.
  • Normalizes whitespace in the LNURL-auth URL and adds a dedicated authentication-required error.
  • Updates the Swift package lockfile and adds a security changelog entry.

Confidence Score: 5/5

The PR appears safe to merge, with authenticated VSS initialization consistently replacing the removed unauthenticated fallback.

The changed setup paths reject blank authentication configuration, retain correct failure cleanup, and use the authenticated VSS APIs pinned by the coordinated dependency update; no reachable blocking failure remains.

Important Files Changed

FilenameOverview
Bitkit/Services/LightningService.swiftRemoves fixed-header VSS fallback and requires a nonblank LNURL-auth URL before building the Lightning node.
Bitkit/Services/VssBackupClient.swiftRoutes app and debug VSS setup exclusively through authenticated client initialization.
Bitkit/Utilities/Errors.swiftAdds the dedicated vssAuthRequired service error and its AppError mapping.
Bitkit.xcodeproj/project.pbxprojUpdates the exact vss-rust-client-ffi package requirement to 0.5.23.
Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolvedPins vss-rust-client-ffi 0.5.23 at the corresponding resolved revision.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Backup or Lightning setup] --> B[Read and trim LNURL-auth URL]
B --> C{URL present?}
C -- No --> D[Throw vssAuthRequired]
C -- Yes --> E[Initialize authenticated VSS client]
E --> F[Proceed with backup or Lightning node]
Loading

Reviews (1): Last reviewed commit: "fix: consume vss-client 0.5.23" | Re-trigger Greptile

@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 78f71e8 to 734ffb2CompareAugust 18, 2026 11:12
@ovitrif
ovitrif changed the base branch from master to fix/fail-closed-unauthenticated-vssAugust 18, 2026 11:12
@ovitrifovitrif self-assigned this Aug 18, 2026
@ovitrifovitrif added this to the 2.5.0 milestone Aug 18, 2026
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 734ffb2 to 8a59735CompareAugust 18, 2026 13:03
Base automatically changed from fix/fail-closed-unauthenticated-vss to masterAugust 18, 2026 18:07
Bump vss-rust-client-ffi to 0.5.23 so unauthenticated VSS encryption is rejected in the library.
Related: synonymdev/audit#55, synonymdev/vss-rust-client-ffi#20
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 8a59735 to c56cabaCompareAugust 18, 2026 18:07
@ovitrif
ovitrif merged commit 625b54e into masterAug 18, 2026
11 checks passed
@ovitrif
ovitrif deleted the fix/consume-vss-0.5.23 branch August 18, 2026 20:43
@piotr-iohkpiotr-iohk mentioned this pull request Aug 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ovitrif@ben-kaufman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: consume vss-client 0.5.23 - #673

Merged
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23
Aug 18, 2026
Merged

fix: consume vss-client 0.5.23#673
ovitrif merged 1 commit into
masterfrom
fix/consume-vss-0.5.23

Conversation

@ovitrif

@ovitrifovitrif commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

This PR bumps vss-rust-client-ffi from 0.5.21 to 0.5.23.

Description

0.5.23 includes synonymdev/vss-rust-client-ffi#20. Unauthenticated client setup now returns AuthError instead of encrypting with a public all-zero key.

Companion Android PR: synonymdev/bitkit-android#1164

Linked Issues/Tasks

Screenshot / Video

N/A

QA Notes

Manual Tests

  • 1.regression: Fresh wallet → backup/Lightning start with current Env LNURL-auth URL: setup still succeeds.

Automated Checks

  • Local Debug simulator build passed against 0.5.23.

@ovitrifovitrif mentioned this pull request Aug 18, 2026
2 tasks
@greptile-apps

Copy link
Copy Markdown

Greptile Summary

This PR upgrades vss-rust-client-ffi to 0.5.23 and makes VSS initialization fail closed when LNURL-auth configuration is blank.

  • Removes unauthenticated backup and Lightning-node VSS fallback paths.
  • Normalizes whitespace in the LNURL-auth URL and adds a dedicated authentication-required error.
  • Updates the Swift package lockfile and adds a security changelog entry.

Confidence Score: 5/5

The PR appears safe to merge, with authenticated VSS initialization consistently replacing the removed unauthenticated fallback.

The changed setup paths reject blank authentication configuration, retain correct failure cleanup, and use the authenticated VSS APIs pinned by the coordinated dependency update; no reachable blocking failure remains.

Important Files Changed

FilenameOverview
Bitkit/Services/LightningService.swiftRemoves fixed-header VSS fallback and requires a nonblank LNURL-auth URL before building the Lightning node.
Bitkit/Services/VssBackupClient.swiftRoutes app and debug VSS setup exclusively through authenticated client initialization.
Bitkit/Utilities/Errors.swiftAdds the dedicated vssAuthRequired service error and its AppError mapping.
Bitkit.xcodeproj/project.pbxprojUpdates the exact vss-rust-client-ffi package requirement to 0.5.23.
Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolvedPins vss-rust-client-ffi 0.5.23 at the corresponding resolved revision.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Backup or Lightning setup] --> B[Read and trim LNURL-auth URL]
B --> C{URL present?}
C -- No --> D[Throw vssAuthRequired]
C -- Yes --> E[Initialize authenticated VSS client]
E --> F[Proceed with backup or Lightning node]
Loading

Reviews (1): Last reviewed commit: "fix: consume vss-client 0.5.23" | Re-trigger Greptile

@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 78f71e8 to 734ffb2CompareAugust 18, 2026 11:12
@ovitrif
ovitrif changed the base branch from master to fix/fail-closed-unauthenticated-vssAugust 18, 2026 11:12
@ovitrifovitrif self-assigned this Aug 18, 2026
@ovitrifovitrif added this to the 2.5.0 milestone Aug 18, 2026
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 734ffb2 to 8a59735CompareAugust 18, 2026 13:03
Base automatically changed from fix/fail-closed-unauthenticated-vss to masterAugust 18, 2026 18:07
Bump vss-rust-client-ffi to 0.5.23 so unauthenticated VSS encryption is rejected in the library.
Related: synonymdev/audit#55, synonymdev/vss-rust-client-ffi#20
@ovitrif
ovitrifforce-pushed the fix/consume-vss-0.5.23 branch from 8a59735 to c56cabaCompareAugust 18, 2026 18:07
@ovitrif
ovitrif merged commit 625b54e into masterAug 18, 2026
11 checks passed
@ovitrif
ovitrif deleted the fix/consume-vss-0.5.23 branch August 18, 2026 20:43
@piotr-iohkpiotr-iohk mentioned this pull request Aug 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ovitrif@ben-kaufman