Files
redshift d1feddbd21 chore(deps): patch all Dependabot security alerts
Closes 29 of 30 open Dependabot alerts (all 3 critical, all 17 high):

Python (uv.lock):
- litellm 1.83.0 -> 1.84.10  (CVE-2026-49468, CVE-2026-42208 criticals
  + 8 more high/med/low)
- starlette 0.46.2 -> 1.6.0  (CVE-2026-54283, CVE-2026-48818,
  CVE-2026-48817, CVE-2026-48710, CVE-2025-62727, CVE-2025-54121)
- cryptography 43.0.3 -> 50.0.1  (CVE-2026-69249, CVE-2026-26007,
  CVE-2026-34073, CVE-2024-12797)
- h11 0.14.0 -> 0.16.0  (CVE-2025-43859 critical)
- fastapi 0.115.14 -> 0.141.1  (starlette 1.x support)
- httpx 0.25.2 -> 0.28.1, setuptools 75.9.1 -> 84.0.0,
  wheel 0.41.3 -> 0.48.0

cashu 0.20.x pins conservative upper bounds (httpx<0.26, h11<0.15,
fastapi<0.116, cryptography<44, setuptools<76, wheel<0.42,
importlib-metadata<7) that conflict with every patched version, so the
gated packages are lifted via [tool.uv] override-dependencies. routstr
only imports cashu's wallet-side modules, not its mint/fastapi server
paths. starlette is forced via constraint-dependencies since fastapi
0.141 permits the old in-range 0.46.2.

Code changes required by the bumps:
- httpx 0.28 removed `proxies=`: use `proxy=` in
  routstr/nostr/discovery.py (Tor .onion health fetches) and
  examples/tor.py. The discovery.py path was untested and would have
  raised TypeError at runtime on any .onion provider check.
- tests/integration/test_admin_pricing_rate_validation.py: httpx 0.28
  refuses to encode NaN/Inf client-side (allow_nan=False); send raw
  JSON bytes so the bare NaN/Infinity literals still reach the server,
  which is the behavior under test.

UI (pnpm-lock.yaml):
- browserslist 4.28.1 -> 4.28.9  (CVE-2026-73089, CVE-2026-73088)
- @humanfs/node 0.16.7 -> 0.16.8

Remaining alert: ecdsa (GHSA-wj6h-64fc-37mp, Minerva timing attack) is
already at the latest release 0.19.2 with no fix available upstream;
cashu pins ecdsa<0.20. Deferred until cashu migrates off python-ecdsa.

Verified: 1336 unit + 439 integration tests pass, mypy, ruff, UI lint /
format-check / build all clean. 2 unit test failures
(test_provider_slugs) are pre-existing environment leaks (python-dotenv
loads the parent checkout's .env containing TINFOIL_API_KEY and fail
identically on main.
EOF
)
2026-09-07 20:14:28 +02:00
..
2026-03-07 18:15:29 +08:00
2026-03-07 18:15:29 +08:00
2025-10-21 22:07:47 +02:00
2026-03-07 18:15:29 +08:00
2026-07-07 17:22:48 +02:00
2026-07-07 17:22:48 +02:00
2026-03-07 18:15:29 +08:00
2026-05-10 11:18:27 +02:00
2026-08-26 00:38:15 +02:00
2026-08-26 00:38:15 +02:00
2025-10-21 22:07:47 +02:00
2026-03-07 18:15:29 +08:00

Routstr node admin UI

A Next.js app (App Router, static export) that provides the admin dashboard for a routstr-core node: login, settings, providers, balances, transactions, usage, and logs.

There is no separate web server in production. next build produces a fully static export (next.config.ts sets output: 'export'), and the FastAPI backend serves it directly from ../ui_out/ (see routstr/core/main.py). So the UI and the API are served from the same origin in production.

Developing the UI (hot reload)

The everyday loop runs two processes side by side — you do not rebuild the static export while developing:

  1. Start the backend on :8000 — from the repo root: make docker-up (or uvicorn routstr.core.main:app --reload).
  2. Start the Next.js dev server on :3000 — from the repo root: make ui-dev (or cd ui && pnpm dev). Edits hot-reload instantly.

Open http://localhost:3000. With no NEXT_PUBLIC_API_URL set, the UI falls back to http://127.0.0.1:8000 in development (see lib/api/services/configuration.ts), so it talks to the local backend out of the box.

Because dev is cross-origin (:3000 → :8000), it relies on the backend's CORS allowing the UI origin. The default cors_origins is ["*"]; if you tighten CORS, keep http://localhost:3000 allowed for development.

Building the integrated/static UI (what production serves)

To produce the bundle that FastAPI serves from ../ui_out/:

  • make ui-build — builds with local Node/pnpm (scripts/build-ui.sh), then moves ui/out/* to ../ui_out/.
  • make ui-build-docker — same, but inside Docker (no local Node needed).

NEXT_PUBLIC_* variables are read from the repo-root .env at build time and baked in. For a same-origin deployment leave NEXT_PUBLIC_API_URL empty (relative paths); the UI uses window.location.origin at runtime. After building, start the backend and open http://localhost:8000 — the dashboard is served at / and /admin.

If ../ui_out/ does not exist, the backend logs a warning at startup and serves the API only (hitting a UI route returns a small JSON fallback instead of the dashboard).