add the bitcoin wallet sidecar and ui
the owner's work, committed as one unit rather than split: the registration
files (App.tsx, Dock, AppRegistry, hono.ts, the schema and db barrels,
ecosystem.config.cjs) all reference modules under src/servers/{api,sidecar}/wallet
and src/workspaces/officerdev/src/apps/Wallet, so committing the shared plumbing
on its own would leave a commit that does not build.
officer-wallet is a new pm2 peer holding seed material sealed under an owner
passphrase on top of VAULT_STORE_KEY, with an unlock ttl after which the root key
is wiped from memory. five backends: on-chain via esplora, and lnd, clnrest,
lndhub and nwc for lightning. bolt11 encode/decode is implemented in-tree.
no secrets in the diff — the key-shaped literals under sidecar/wallet are the
bolt11 spec vectors and the bip39 "abandon … about" vector. .env.example gains
placeholders only. bun test src/servers/sidecar/wallet: 38 pass, 0 fail.
not reviewed line by line; assembled and verified to build, not audited.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -63,3 +63,17 @@ VAULT_STORE_KEY="<generate with: openssl rand -base64 32>"
|
||||
# HEADSCALE_URL=https://headscale.example.com
|
||||
# HEADSCALE_API_KEY="<headscale admin api key>"
|
||||
# HEADSCALE_USER=officer
|
||||
|
||||
# ── Bitcoin wallet (officer-wallet) ─────────────────────────────────────────────────────────────
|
||||
# Chain data source for the self-custodial on-chain wallet. Any Esplora-compatible API works —
|
||||
# mempool.space by default, or point it at your own node's esplora/electrs when you run one.
|
||||
# WALLET_ESPLORA_URL=https://mempool.space/api
|
||||
# WALLET_NETWORK=bitcoin # bitcoin | testnet | signet | regtest
|
||||
#
|
||||
# How long an unlocked wallet stays unlocked, in seconds. Default 900 (15 min). The root key is held
|
||||
# in the sidecar's memory for exactly this long after an unlock, then wiped. Shorter is safer.
|
||||
# WALLET_UNLOCK_TTL_SEC=900
|
||||
#
|
||||
# NOTE: seed material is encrypted with VAULT_STORE_KEY (above) on top of the owner passphrase that
|
||||
# seals it. Both are required to spend. If you lose VAULT_STORE_KEY, every stored seed is
|
||||
# unrecoverable — back up the mnemonics separately, offline.
|
||||
|
||||
Reference in New Issue
Block a user