mirror of
https://github.com/Routstr/routstrd.git
synced 2026-10-05 12:28:23 +00:00
Audit of the repo's non-source documentation and ad-hoc scripts.
Deleted (work already shipped, or scratch files):
- IMPLEMENTATION.md — the ~/.cocod → ~/.routstrd/wallet migration plan;
shipped as src/daemon/wallet/{migration,paths}.ts.
- src/TUI refactor.md — plan to move src/cli/usage-tui.ts into src/tui/;
done, src/cli/ no longer exists.
- v1-messages-format-report.md — the Messages-API passthrough bug it
describes is fixed; http/index.ts now forwards path: url.pathname.
- routstr-cost-logging.md — note about the routstr proxy's cost fields vs
pi-ai; not about this codebase.
- refund.js, refund_new.js — one-off scripts with hardcoded Cashu tokens.
- test_box.ts, test_split_box.ts, test_split_box2.ts — manual renderBox
eyeball checks that asserted nothing and bun test never ran.
Moved:
- COCO-2.0.0-MIGRATION-PLAN.md → docs/plans/coco-2.0.0-migration.md, with a
status header. This one is genuinely unexecuted: package.json is still on
coco-core 1.0.1 / coco-cashu-core 1.1.2-rc.50, and its NPC compatibility
gate is unresolved.
Added:
- src/tui/usage/render.test.ts — real assertions for what the three deleted
scratch scripts checked by eye (box width with and without a title, ANSI
padding, side-by-side composition including unequal heights). renderBox
had no coverage before.
Updated:
- SKILL.md — ships in the npm package as the CLI reference but was missing
~15 commands (wallet doctor/cleanup/npc, nwc and auto-refill, history,
ping, providers reviews, service install/uninstall/logs, daemon, local,
update, refund, top, send/receive shortcuts). Also dropped the claim that
onboard installs cocod (the wallet is in-process), removed two orphaned
tables misfiled under `routstrd refresh`, and completed the config and
env-var tables.
- README.md — same cocod correction, points at SKILL.md for the full command
reference, fixes the stale Project Structure tree and the POST / endpoint
description.
- SECURITY.md — drop the stray `## SECURITY.md` line above the real heading.
- package.json — add a `smoke` script so scripts/smoke/chat-completions.sh
stops looking orphaned. Deliberately not wired into CI: it needs a funded
API key.
Note: the Cashu tokens in the deleted refund scripts remain in git history.
They date from March/April 2026 and were being POSTed to refund endpoints, so
they are almost certainly spent — flagging rather than rewriting history.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UW5RBn7pxSuHbDQjtHfQVW
729 B
729 B
Security Policy
Reporting a Vulnerability
Please report suspected security vulnerabilities privately to team@routstr.com.
Do not open a public GitHub issue or disclose the vulnerability publicly until we have had a reasonable opportunity to investigate and coordinate a fix.
Please include, where possible:
- The affected Routstr package and version or commit
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
Do not include real Cashu tokens, seed phrases, private keys, or other secrets.
We will acknowledge your report and coordinate remediation and disclosure with you.
Supported Versions
Security fixes are provided for the latest released version.