Files
routstr-core/routstr
9qeklajc c11b6d30c5 fix: verify LNURL invoice amount and destination before reserving
raw_send_to_lnurl asked an LNURL service for an invoice of a specific
amount and then quoted and melted whatever invoice came back, without
ever checking the two agreed. A malicious or compromised payout service
could return an invoice for far more than requested and be paid up to
the value of the selected proofs. The melt quote is the mint's own
reading of the invoice, so it is compared against the requested amount
in the wallet unit before the quote checkpoint and before any proof is
reserved: a mismatch now leaves no durable state behind.

Destinations were equally unguarded. A bech32 LNURL could decode to a
plaintext or internal URL, and both fetches followed redirects blindly,
so a public https origin could bounce the request onto loopback or link
local metadata addresses. Redirects are now followed manually with the
scheme and host re-checked at every hop, and the callback URL taken
from the payRequest body is checked the same way. Error messages no
longer echo service-controlled response bodies into operator logs.

The user refund path reserved proofs and then called raw_send_to_lnurl
without an amount, which the callee rejected before dispatch. Every
such refund failed with the proofs still locked, and the proof rollback
that covers a dispatched melt does not reach that stage. send_to_lnurl
now hands over the unreserved available proofs and the amount, leaving
reservation to happen only after the destination, the invoice amount
and the quote have all been accepted. Pre-dispatch rejection therefore
unwinds cleanly, while an ambiguous dispatch still raises
MeltOutcomeAmbiguousError and keeps the debit for reconciliation.

The missing amount was previously caught by a bare assert, which was
both unreachable for the payout callers and the wrong failure mode for
the refund caller; it is now an explicit validation.
2026-08-24 01:47:07 +02:00
..
2026-08-23 23:25:03 +02:00
2026-08-23 11:06:06 +02:00
2026-08-15 15:09:00 +02:00