mirror of
https://github.com/Permissionless-Software-Foundation/psf-bch-api.git
synced 2026-09-22 17:12:02 -07:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a959416b10 | ||
|
|
562a196998 | ||
|
|
e006a7ad86 | ||
|
|
f36cd2a8aa | ||
|
|
8b2cf64f1b | ||
|
|
95ae06fada | ||
|
|
188dc939b3 | ||
|
|
7d566beea3 | ||
|
|
6c42f47e15 | ||
|
|
d19a9e64cd | ||
|
|
7c96d72f7b | ||
|
|
7f1770ab70 | ||
|
|
b25f55ce6a | ||
|
|
6e32723b29 | ||
|
|
3b08fc3b62 | ||
|
|
2c1f02d6c7 | ||
|
|
6cf03ca0fe | ||
|
|
5ea7bc9c29 | ||
|
|
39021aba46 | ||
|
|
de34547951 | ||
|
|
b8f34fb40e | ||
|
|
3778894ce2 | ||
|
|
02eb8afd21 | ||
|
|
e708fc1228 | ||
|
|
fed4b2da59 | ||
|
|
f30c2ede04 | ||
|
|
09e05d51e5 | ||
|
|
22cbc54dee | ||
|
|
6fe0e01e8b | ||
|
|
f33b39ef01 | ||
|
|
6d27630393 | ||
|
|
eac4916415 | ||
|
|
baa1170b89 | ||
|
|
23ce276e19 | ||
|
|
f28e2c6a1a | ||
|
|
50a1a83a82 | ||
|
|
eb2dda6955 | ||
|
|
fe8d2ab051 | ||
|
|
66123de679 | ||
|
|
e2860d08b1 | ||
|
|
fa14af624f | ||
|
|
1eb787e0d4 | ||
|
|
ea815868ab | ||
|
|
d17e3aa2d8 |
@@ -25,6 +25,7 @@ PORT=5942
|
|||||||
X402_ENABLED=true
|
X402_ENABLED=true
|
||||||
SERVER_BCH_ADDRESS=bitcoincash:qqlrzp23w08434twmvr4fxw672whkjy0py26r63g3d
|
SERVER_BCH_ADDRESS=bitcoincash:qqlrzp23w08434twmvr4fxw672whkjy0py26r63g3d
|
||||||
FACILITATOR_URL=http://localhost:4345/facilitator
|
FACILITATOR_URL=http://localhost:4345/facilitator
|
||||||
|
X402_PRICE_SAT=200
|
||||||
|
|
||||||
# Basic Authentication required to access this API?
|
# Basic Authentication required to access this API?
|
||||||
USE_BASIC_AUTH=true
|
USE_BASIC_AUTH=true
|
||||||
@@ -1,30 +1,247 @@
|
|||||||
# psf-bch-api
|
# psf-bch-api
|
||||||
|
|
||||||
This is a REST API for communicating with Bitcoin Cash infrastructure. It replaces [bch-api](https://github.com/Permissionless-Software-Foundation/bch-api), and it implements [x402-bch protocol](https://github.com/x402-bch/x402-bch) to handle payments to access the API.
|
[](https://github.com/Permissionless-Software-Foundation/psf-bch-api/blob/master/LICENSE.md)
|
||||||
|
[](https://github.com/feross/standard)
|
||||||
|
|
||||||
|
This is a REST API server for communicating with Bitcoin Cash (BCH) blockchain infrastructure. It is written in node.js JavaScript using the [Express.js](https://expressjs.com/) framework and follows the [Clean Architecture](https://blog.cleancoder.com/uncle-bob/2012/08/13/the-clean-architecture.html) design pattern. It replaces the legacy [bch-api](https://github.com/Permissionless-Software-Foundation/bch-api) and implements the [x402-bch protocol](https://github.com/x402-bch/x402-bch) for optional per-call payments.
|
||||||
|
|
||||||
|
psf-bch-api is the heart of the [Cash Stack](https://cashstack.info), a full software stack for building blockchain-based applications. It creates a single web2 REST API interface that abstracts away the complexity of the underlying blockchain infrastructure, so that application developers can interact with the blockchain through simple HTTP calls.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
psf-bch-api depends on three pieces of back end infrastructure:
|
||||||
|
|
||||||
|
- **[BCHN Full Node](https://cashstack.info/docs/back-end/bchn-full-node)** - the base blockchain node that validates transactions and blocks.
|
||||||
|
- **[Fulcrum Indexer](https://cashstack.info/docs/back-end/fulcrum-indexer)** - an address indexer that tracks balances, transaction histories, and UTXOs.
|
||||||
|
- **[SLP Token Indexer](https://cashstack.info/docs/back-end/slp-indexer/slp-indexer-software)** - tracks all SLP tokens on the blockchain.
|
||||||
|
|
||||||
|
Front-end applications interact with psf-bch-api through libraries such as [bch-js](https://github.com/Permissionless-Software-Foundation/bch-js) or [bch-consumer](https://www.npmjs.com/package/bch-consumer).
|
||||||
|
|
||||||
|
High-level documentation about the full Cash Stack is available at [CashStack.info](https://cashstack.info). Interactive API reference documentation is served by the running server at its root URL (e.g. `http://localhost:5942/`), and a live version can be found at [bch.fullstack.cash](https://bch.fullstack.cash/).
|
||||||
|
|
||||||
|
## The .env File
|
||||||
|
|
||||||
|
All runtime configuration is driven by a `.env` file in the project root. An example is provided at `.env-example`. To get started:
|
||||||
|
|
||||||
|
`cp .env-example .env`
|
||||||
|
|
||||||
|
Then edit `.env` to match your environment. The file is organized into two sections:
|
||||||
|
|
||||||
|
### Infrastructure Setup
|
||||||
|
|
||||||
|
These variables tell psf-bch-api where to find the back end services it depends on:
|
||||||
|
|
||||||
|
- `RPC_BASEURL` - URL of the BCHN full node JSON-RPC interface. Default: `http://127.0.0.1:8332`
|
||||||
|
- `RPC_USERNAME` - RPC username for the full node.
|
||||||
|
- `RPC_PASSWORD` - RPC password for the full node.
|
||||||
|
- `FULCRUM_API` - URL of the Fulcrum indexer REST API.
|
||||||
|
- `SLP_INDEXER_API` - URL of the SLP Token Indexer REST API.
|
||||||
|
- `LOCAL_RESTURL` - The REST API URL used internally for wallet operations. Default: `http://127.0.0.1:5942/v6/`
|
||||||
|
|
||||||
|
### Access Control Settings
|
||||||
|
|
||||||
|
These variables control who can access the API and how they pay for it. The three access-control use cases are described in detail in the [Access Control](#access-control) section below.
|
||||||
|
|
||||||
|
- `PORT` - Port the server listens on. Default: `5942`
|
||||||
|
- `X402_ENABLED` - Enable x402-bch per-call payment middleware. Default: `true`
|
||||||
|
- `SERVER_BCH_ADDRESS` - BCH address that receives x402 payments. Default: `bitcoincash:qqsrke9lh257tqen99dkyy2emh4uty0vky9y0z0lsr`
|
||||||
|
- `FACILITATOR_URL` - URL of the x402-bch facilitator service. Default: `http://localhost:4345/facilitator`
|
||||||
|
- `X402_PRICE_SAT` - Price in satoshis charged per API call via x402. Default: `200`
|
||||||
|
- `USE_BASIC_AUTH` - Enable Bearer token authentication middleware. Default: `false`
|
||||||
|
- `BASIC_AUTH_TOKEN` - The expected Bearer token value.
|
||||||
|
|
||||||
|
## Access Control
|
||||||
|
|
||||||
|
psf-bch-api supports three major access-control configurations. Which one you choose depends on your deployment scenario. The behavior is controlled entirely by the `X402_ENABLED` and `USE_BASIC_AUTH` environment variables.
|
||||||
|
|
||||||
|
### 1. No Rate Limits (Open Access)
|
||||||
|
|
||||||
|
Set both access-control flags to `false`:
|
||||||
|
|
||||||
|
```
|
||||||
|
X402_ENABLED=false
|
||||||
|
USE_BASIC_AUTH=false
|
||||||
|
```
|
||||||
|
|
||||||
|
All API endpoints are publicly accessible without any authentication or payment. This is the simplest configuration, ideal for **local development** or **private, trusted networks** where access control is handled at the network level (e.g. behind a firewall or VPN).
|
||||||
|
|
||||||
|
### 2. Bearer Token Authentication
|
||||||
|
|
||||||
|
Set `USE_BASIC_AUTH=true` and `X402_ENABLED=false`:
|
||||||
|
|
||||||
|
```
|
||||||
|
X402_ENABLED=false
|
||||||
|
USE_BASIC_AUTH=true
|
||||||
|
BASIC_AUTH_TOKEN=my-secret-token
|
||||||
|
```
|
||||||
|
|
||||||
|
Every API request (except `/health` and `/`) must include an `Authorization` header with a valid Bearer token:
|
||||||
|
|
||||||
|
```
|
||||||
|
Authorization: Bearer my-secret-token
|
||||||
|
```
|
||||||
|
|
||||||
|
Requests without a valid token receive an HTTP `401 Unauthorized` response. This is the best option when you want to **restrict access to a known set of users or services** (e.g. an organization's internal apps) without requiring cryptocurrency payments.
|
||||||
|
|
||||||
|
### 3. x402-bch Per-Call Payments
|
||||||
|
|
||||||
|
Set `X402_ENABLED=true`:
|
||||||
|
|
||||||
|
```
|
||||||
|
X402_ENABLED=true
|
||||||
|
SERVER_BCH_ADDRESS=bitcoincash:qqlrzp23w08434twmvr4fxw672whkjy0py26r63g3d
|
||||||
|
FACILITATOR_URL=http://localhost:4345/facilitator
|
||||||
|
X402_PRICE_SAT=200
|
||||||
|
```
|
||||||
|
|
||||||
|
Every API call under the `/v6` prefix requires a BCH micro-payment. When a request arrives without a valid `X-PAYMENT` header, the server responds with HTTP `402 Payment Required` and includes the payment details. Client libraries that support the x402-bch protocol (like [bch-js](https://github.com/Permissionless-Software-Foundation/bch-js)) can handle payments automatically.
|
||||||
|
|
||||||
|
This is the right choice for **public, monetized APIs** where you want to charge per call.
|
||||||
|
|
||||||
|
#### Combined: x402 + Bearer Token
|
||||||
|
|
||||||
|
You can enable both at the same time:
|
||||||
|
|
||||||
|
```
|
||||||
|
X402_ENABLED=true
|
||||||
|
USE_BASIC_AUTH=true
|
||||||
|
BASIC_AUTH_TOKEN=my-secret-token
|
||||||
|
```
|
||||||
|
|
||||||
|
In this mode, requests that present a valid Bearer token bypass the x402 payment requirement. All other requests must pay. This allows you to give **free access to trusted clients** (via the Bearer token) while still **monetizing public access** via x402.
|
||||||
|
|
||||||
|
## Development
|
||||||
|
|
||||||
|
This is a standard node.js project. To set up a development environment:
|
||||||
|
|
||||||
|
1. Clone the repository:
|
||||||
|
|
||||||
|
`git clone https://github.com/Permissionless-Software-Foundation/psf-bch-api && cd psf-bch-api`
|
||||||
|
|
||||||
|
2. Install dependencies:
|
||||||
|
|
||||||
|
`npm install`
|
||||||
|
|
||||||
|
3. Create your configuration file:
|
||||||
|
|
||||||
|
`cp .env-example .env`
|
||||||
|
|
||||||
|
4. Edit `.env` to point to your back end infrastructure (full node, Fulcrum, SLP indexer). For local development you will likely want to disable access control:
|
||||||
|
|
||||||
|
```
|
||||||
|
X402_ENABLED=false
|
||||||
|
USE_BASIC_AUTH=false
|
||||||
|
```
|
||||||
|
|
||||||
|
5. Start the server:
|
||||||
|
|
||||||
|
`npm start`
|
||||||
|
|
||||||
|
The server will start on port `5942` by default (or whatever you set in `PORT`). API documentation is available at `http://localhost:5942/`.
|
||||||
|
|
||||||
|
### Generating API Docs
|
||||||
|
|
||||||
|
The API reference documentation is generated by [apiDoc](https://apidocjs.com/) from inline annotations in the source code. To regenerate:
|
||||||
|
|
||||||
|
`npm run docs`
|
||||||
|
|
||||||
|
The output is written to the `docs/` directory and served by the running server at its root URL.
|
||||||
|
|
||||||
|
A live version can be found at [bch.fullstack.cash](https://bch.fullstack.cash/).
|
||||||
|
|
||||||
|
## Production (Docker)
|
||||||
|
|
||||||
|
A Docker setup is provided in the `production/docker/` directory for production deployments. The target OS is Ubuntu Linux.
|
||||||
|
|
||||||
|
1. Install [Docker and Docker Compose](https://docs.docker.com/engine/install/ubuntu/).
|
||||||
|
|
||||||
|
2. Navigate to the Docker directory:
|
||||||
|
|
||||||
|
`cd production/docker`
|
||||||
|
|
||||||
|
3. Create and configure the `.env` file. An example is provided:
|
||||||
|
|
||||||
|
`cp .env-example .env`
|
||||||
|
|
||||||
|
Edit `.env` to match your production infrastructure. Note that inside a Docker container, `localhost` refers to the container itself. Use `172.17.0.1` (the default Docker bridge gateway) to reach services running on the host machine:
|
||||||
|
|
||||||
|
```
|
||||||
|
RPC_BASEURL=http://172.17.0.1:8332
|
||||||
|
FULCRUM_API=http://172.17.0.1:3001/v1
|
||||||
|
SLP_INDEXER_API=http://172.17.0.1:5010
|
||||||
|
```
|
||||||
|
|
||||||
|
4. Build the Docker image:
|
||||||
|
|
||||||
|
`docker-compose build --no-cache`
|
||||||
|
|
||||||
|
5. Start the container:
|
||||||
|
|
||||||
|
`docker-compose up -d`
|
||||||
|
|
||||||
|
The container maps host port `5942` to container port `5942`. The `.env` file is mounted into the container as a volume, so you can update configuration without rebuilding.
|
||||||
|
|
||||||
|
To view logs:
|
||||||
|
|
||||||
|
`docker logs -f psf-bch-api`
|
||||||
|
|
||||||
|
To stop the container:
|
||||||
|
|
||||||
|
`docker-compose down`
|
||||||
|
|
||||||
|
A helper script `cleanup-images.sh` is provided to remove dangling Docker images after rebuilds.
|
||||||
|
|
||||||
|
## Testing
|
||||||
|
|
||||||
|
The project includes both unit tests and integration tests. Tests use [Mocha](https://mochajs.org/) as the test runner, [Chai](https://www.chaijs.com/) for assertions, and [Sinon](https://sinonjs.org/) for mocking. Code coverage is provided by [c8](https://github.com/bcoe/c8).
|
||||||
|
|
||||||
|
### Unit Tests
|
||||||
|
|
||||||
|
Unit tests are located in `test/unit/` and cover adapters, controllers, and use cases. They do not require any running infrastructure. To run:
|
||||||
|
|
||||||
|
`npm test`
|
||||||
|
|
||||||
|
This will first lint the code with [Standard](https://standardjs.com/), then execute all unit tests with code coverage.
|
||||||
|
|
||||||
|
To generate an HTML coverage report:
|
||||||
|
|
||||||
|
`npm run coverage`
|
||||||
|
|
||||||
|
The report is written to the `coverage/` directory.
|
||||||
|
|
||||||
|
### Integration Tests
|
||||||
|
|
||||||
|
Integration tests are located in `test/integration/` and require the back end infrastructure (full node, Fulcrum, SLP indexer) to be running. To run:
|
||||||
|
|
||||||
|
`npm run test:integration`
|
||||||
|
|
||||||
|
Integration tests have a 25-second timeout per test to accommodate network calls.
|
||||||
|
|
||||||
|
## Configuration Reference
|
||||||
|
|
||||||
|
All configuration values are read from environment variables (via the `.env` file). The complete list:
|
||||||
|
|
||||||
|
- `PORT` - Server listen port. Default: `5942`
|
||||||
|
- `NODE_ENV` - Environment (`development` or `production`). Default: `development`
|
||||||
|
- `API_PREFIX` - URL prefix for all REST endpoints. Default: `/v6`
|
||||||
|
- `LOG_LEVEL` - Winston logging level. Default: `info`
|
||||||
|
- `RPC_BASEURL` - Full node JSON-RPC URL. Default: `http://127.0.0.1:8332`
|
||||||
|
- `RPC_USERNAME` - Full node RPC username.
|
||||||
|
- `RPC_PASSWORD` - Full node RPC password.
|
||||||
|
- `RPC_TIMEOUT_MS` - Full node RPC request timeout in ms. Default: `15000`
|
||||||
|
- `FULCRUM_API` - Fulcrum indexer REST API URL.
|
||||||
|
- `FULCRUM_TIMEOUT_MS` - Fulcrum API request timeout in ms. Default: `15000`
|
||||||
|
- `SLP_INDEXER_API` - SLP Token Indexer REST API URL.
|
||||||
|
- `SLP_INDEXER_TIMEOUT_MS` - SLP Indexer API request timeout in ms. Default: `15000`
|
||||||
|
- `LOCAL_RESTURL` - Internal REST URL for wallet operations. Default: `http://127.0.0.1:5942/v6/`
|
||||||
|
- `IPFS_GATEWAY` - IPFS gateway hostname. Default: `p2wdb-gateway-678.fullstack.cash`
|
||||||
|
- `X402_ENABLED` - Enable x402-bch payment middleware. Default: `true`
|
||||||
|
- `SERVER_BCH_ADDRESS` - BCH address for x402 payments. Default: `bitcoincash:qqsrke9lh257tqen99dkyy2emh4uty0vky9y0z0lsr`
|
||||||
|
- `FACILITATOR_URL` - x402-bch facilitator service URL. Default: `http://localhost:4345/facilitator`
|
||||||
|
- `X402_PRICE_SAT` - Satoshis charged per API call via x402. Default: `200`
|
||||||
|
- `USE_BASIC_AUTH` - Enable Bearer token authentication. Default: `false`
|
||||||
|
- `BASIC_AUTH_TOKEN` - Expected Bearer token value.
|
||||||
|
|
||||||
## License
|
## License
|
||||||
|
|
||||||
[MIT](./LICENSE.md)
|
[MIT](./LICENSE.md)
|
||||||
|
|
||||||
## x402-bch Payments
|
|
||||||
|
|
||||||
All REST endpoints exposed under the `/v6` prefix are protected by the [`x402-bch-express`](https://www.npmjs.com/package/x402-bch-express) middleware. Each API call requires a BCH payment authorization for **2000 satoshis**. The middleware advertises payment requirements via HTTP 402 responses and validates incoming `X-PAYMENT` headers with a configured Facilitator.
|
|
||||||
|
|
||||||
### Configuration
|
|
||||||
|
|
||||||
Environment variables control the payment flow:
|
|
||||||
|
|
||||||
- `X402_ENABLED` — set to `false` (case-insensitive) to disable the middleware. Defaults to enabled.
|
|
||||||
- `SERVER_BCH_ADDRESS` — BCH cash address that receives funding transactions. Defaults to `bitcoincash:qqlrzp23w08434twmvr4fxw672whkjy0py26r63g3d`.
|
|
||||||
- `FACILITATOR_URL` — Root URL of the facilitator service (e.g., `http://localhost:4345/facilitator`).
|
|
||||||
- `X402_PRICE_SAT` — Optional; override the satoshi price per call (defaults to `2000`).
|
|
||||||
|
|
||||||
When `X402_ENABLED=false`, the server continues to operate without payment headers for local development or trusted deployments.
|
|
||||||
|
|
||||||
### Manual Verification
|
|
||||||
|
|
||||||
1. Start or point to an `x402-bch` facilitator service (the example facilitator listens at `http://localhost:4345/facilitator`).
|
|
||||||
2. Run the API server with the default configuration: `npm start`.
|
|
||||||
3. Call a protected endpoint without an `X-PAYMENT` header, e.g. `curl -i http://localhost:5942/v6/full-node/control/getNetworkInfo`. The server will respond with HTTP `402` and include payment requirements.
|
|
||||||
4. Restart the server with `X402_ENABLED=false npm start` to confirm that the same request now bypasses the middleware (useful for local development without payments).
|
|
||||||
|
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 25 KiB |
+37
-2
@@ -74,6 +74,19 @@ class Server {
|
|||||||
allowedHeaders: ['Content-Type', 'Authorization', 'X-Requested-With']
|
allowedHeaders: ['Content-Type', 'Authorization', 'X-Requested-With']
|
||||||
}))
|
}))
|
||||||
|
|
||||||
|
// URL normalization middleware - collapse multiple slashes
|
||||||
|
app.use((req, res, next) => {
|
||||||
|
if (req.url && req.url.includes('//')) {
|
||||||
|
// Split URL into path and query string
|
||||||
|
const [path, queryString] = req.url.split('?')
|
||||||
|
// Collapse multiple consecutive slashes into a single slash
|
||||||
|
const normalizedPath = path.replace(/\/+/g, '/')
|
||||||
|
// Reconstruct req.url with normalized path (req.path is read-only and will auto-update)
|
||||||
|
req.url = queryString ? `${normalizedPath}?${queryString}` : normalizedPath
|
||||||
|
}
|
||||||
|
next()
|
||||||
|
})
|
||||||
|
|
||||||
// Apply basic auth middleware if enabled
|
// Apply basic auth middleware if enabled
|
||||||
// This must run before x402 middleware to set req.locals.basicAuthValid
|
// This must run before x402 middleware to set req.locals.basicAuthValid
|
||||||
if (basicAuthSettings.enabled) {
|
if (basicAuthSettings.enabled) {
|
||||||
@@ -83,8 +96,10 @@ class Server {
|
|||||||
|
|
||||||
// Apply x402 middleware based on configuration
|
// Apply x402 middleware based on configuration
|
||||||
// Logic:
|
// Logic:
|
||||||
// - If X402_ENABLED=false OR USE_BASIC_AUTH=false: Don't apply x402 (no rate limits)
|
|
||||||
// - If X402_ENABLED=true AND USE_BASIC_AUTH=true: Apply x402 conditionally (bypass if basic auth valid)
|
// - If X402_ENABLED=true AND USE_BASIC_AUTH=true: Apply x402 conditionally (bypass if basic auth valid)
|
||||||
|
// - If X402_ENABLED=true AND USE_BASIC_AUTH=false: Apply x402 unconditionally (no basic auth bypass)
|
||||||
|
// - If X402_ENABLED=false AND USE_BASIC_AUTH=true: Require basic auth only
|
||||||
|
// - If X402_ENABLED=false AND USE_BASIC_AUTH=false: No access control
|
||||||
|
|
||||||
// Apply access control middleware based on configuration
|
// Apply access control middleware based on configuration
|
||||||
if (x402Settings.enabled && basicAuthSettings.enabled) {
|
if (x402Settings.enabled && basicAuthSettings.enabled) {
|
||||||
@@ -112,6 +127,21 @@ class Server {
|
|||||||
}
|
}
|
||||||
|
|
||||||
app.use(conditionalX402Middleware)
|
app.use(conditionalX402Middleware)
|
||||||
|
} else if (x402Settings.enabled && !basicAuthSettings.enabled) {
|
||||||
|
// X402_ENABLED=true AND USE_BASIC_AUTH=false: Apply x402 unconditionally (no basic auth bypass)
|
||||||
|
const routes = buildX402Routes(this.config.apiPrefix)
|
||||||
|
const facilitatorOptions = x402Settings.facilitatorUrl
|
||||||
|
? { url: x402Settings.facilitatorUrl }
|
||||||
|
: undefined
|
||||||
|
|
||||||
|
wlogger.info(`x402 middleware enabled (basic auth disabled); enforcing ${x402Settings.priceSat} satoshis per request`)
|
||||||
|
|
||||||
|
// Apply x402 middleware unconditionally - no basic auth bypass
|
||||||
|
app.use(x402PaymentMiddleware(
|
||||||
|
x402Settings.serverAddress,
|
||||||
|
routes,
|
||||||
|
facilitatorOptions
|
||||||
|
))
|
||||||
} else if (basicAuthSettings.enabled && !x402Settings.enabled) {
|
} else if (basicAuthSettings.enabled && !x402Settings.enabled) {
|
||||||
// USE_BASIC_AUTH=true AND X402_ENABLED=false: Require basic auth, reject unauthenticated requests
|
// USE_BASIC_AUTH=true AND X402_ENABLED=false: Require basic auth, reject unauthenticated requests
|
||||||
wlogger.info('Basic auth enforcement enabled (x402 disabled)')
|
wlogger.info('Basic auth enforcement enabled (x402 disabled)')
|
||||||
@@ -144,7 +174,7 @@ class Server {
|
|||||||
|
|
||||||
// Endpoint logging middleware
|
// Endpoint logging middleware
|
||||||
app.use((req, res, next) => {
|
app.use((req, res, next) => {
|
||||||
console.log(`Endpoint called: ${req.method} ${req.path}`)
|
console.log(`Endpoint called: ${req.method} ${req.path} by ${req.ip}`)
|
||||||
res.on('finish', () => {
|
res.on('finish', () => {
|
||||||
console.log(`Endpoint responded: ${req.method} ${req.path} - ${res.statusCode}`)
|
console.log(`Endpoint responded: ${req.method} ${req.path} - ${res.statusCode}`)
|
||||||
})
|
})
|
||||||
@@ -216,6 +246,11 @@ class Server {
|
|||||||
wlogger.info(`Server started on port ${this.config.port}`)
|
wlogger.info(`Server started on port ${this.config.port}`)
|
||||||
})
|
})
|
||||||
|
|
||||||
|
// Explicit timeout settings reduce stale keep-alive socket reuse races.
|
||||||
|
this.server.keepAliveTimeout = this.config.serverKeepAliveTimeoutMs
|
||||||
|
this.server.headersTimeout = this.config.serverHeadersTimeoutMs
|
||||||
|
this.server.requestTimeout = this.config.serverRequestTimeoutMs
|
||||||
|
|
||||||
this.server.on('error', (err) => {
|
this.server.on('error', (err) => {
|
||||||
console.error('Server error:', err)
|
console.error('Server error:', err)
|
||||||
wlogger.error('Server error:', err)
|
wlogger.error('Server error:', err)
|
||||||
|
|||||||
Generated
+842
-459
File diff suppressed because it is too large
Load Diff
+4
-4
@@ -15,17 +15,17 @@
|
|||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"description": "REST API proxy to Bitcoin Cash infrastructure",
|
"description": "REST API proxy to Bitcoin Cash infrastructure",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@psf/bch-js": "7.1.0",
|
"@psf/bch-js": "7.1.14",
|
||||||
"axios": "1.7.7",
|
"axios": "1.7.7",
|
||||||
"cors": "2.8.5",
|
"cors": "2.8.5",
|
||||||
"dotenv": "16.3.1",
|
"dotenv": "16.3.1",
|
||||||
"express": "5.1.0",
|
"express": "5.1.0",
|
||||||
"minimal-slp-wallet": "7.0.1",
|
"minimal-slp-wallet": "7.1.5",
|
||||||
"psffpp": "1.2.0",
|
"psffpp": "1.2.1",
|
||||||
"slp-token-media": "1.2.10",
|
"slp-token-media": "1.2.10",
|
||||||
"winston": "3.11.0",
|
"winston": "3.11.0",
|
||||||
"winston-daily-rotate-file": "4.7.1",
|
"winston-daily-rotate-file": "4.7.1",
|
||||||
"x402-bch-express": "1.1.1"
|
"x402-bch-express": "2.0.0"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"apidoc": "1.2.0",
|
"apidoc": "1.2.0",
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
|
||||||
@@ -9,10 +9,10 @@ RPC_PASSWORD=password
|
|||||||
FULCRUM_API=http://172.17.0.1:3001/v1
|
FULCRUM_API=http://172.17.0.1:3001/v1
|
||||||
|
|
||||||
# SLP Indexer
|
# SLP Indexer
|
||||||
SLP_INDEXER_API=http://localhost:5010
|
SLP_INDEXER_API=http://172.17.0.1:5020
|
||||||
|
|
||||||
# REST API URL for wallet operations
|
# REST API URL for wallet operations
|
||||||
LOCAL_RESTURL=http://localhost:5942/v6
|
LOCAL_RESTURL=http://172.17.0.1:5942/v6
|
||||||
|
|
||||||
# END INFRASTRUCTURE SETUP
|
# END INFRASTRUCTURE SETUP
|
||||||
|
|
||||||
@@ -22,13 +22,16 @@ LOCAL_RESTURL=http://localhost:5942/v6
|
|||||||
PORT=5942
|
PORT=5942
|
||||||
|
|
||||||
# x402 payments required to access this API?
|
# x402 payments required to access this API?
|
||||||
X402_ENABLED=true
|
X402_ENABLED=false
|
||||||
SERVER_BCH_ADDRESS=bitcoincash:qqlrzp23w08434twmvr4fxw672whkjy0py26r63g3d
|
#X402_ENABLED=true
|
||||||
FACILITATOR_URL=http://localhost:4345/facilitator
|
#SERVER_BCH_ADDRESS=bitcoincash:qqlrzp23w08434twmvr4fxw672whkjy0py26r63g3d
|
||||||
|
#FACILITATOR_URL=http://localhost:4345/facilitator
|
||||||
|
#X402_PRICE_SAT=200
|
||||||
|
|
||||||
# Basic Authentication required to access this API?
|
# Basic Authentication required to access this API?
|
||||||
USE_BASIC_AUTH=true
|
USE_BASIC_AUTH=false
|
||||||
BASIC_AUTH_TOKEN=some-random-token
|
#USE_BASIC_AUTH=true
|
||||||
|
#BASIC_AUTH_TOKEN=some-random-token
|
||||||
|
|
||||||
# END ACCESS CONTROL
|
# END ACCESS CONTROL
|
||||||
|
|
||||||
@@ -51,6 +51,8 @@ RUN git clone https://github.com/Permissionless-Software-Foundation/psf-bch-api
|
|||||||
# and `stage` has the most up-to-date changes.
|
# and `stage` has the most up-to-date changes.
|
||||||
WORKDIR /home/safeuser/psf-bch-api
|
WORKDIR /home/safeuser/psf-bch-api
|
||||||
|
|
||||||
|
RUN git checkout ct-unstable
|
||||||
|
|
||||||
# Install dependencies
|
# Install dependencies
|
||||||
RUN npm install
|
RUN npm install
|
||||||
RUN npm install minimal-slp-wallet
|
RUN npm install minimal-slp-wallet
|
||||||
@@ -58,7 +60,7 @@ RUN npm install minimal-slp-wallet
|
|||||||
# Generate the API docs
|
# Generate the API docs
|
||||||
RUN npm run docs
|
RUN npm run docs
|
||||||
|
|
||||||
COPY .env-local .env
|
COPY .env .env
|
||||||
|
|
||||||
|
|
||||||
CMD ["npm", "start"]
|
CMD ["npm", "start"]
|
||||||
|
|||||||
@@ -17,4 +17,6 @@ services:
|
|||||||
volumes:
|
volumes:
|
||||||
#- ./start-rest2nostr.sh:/home/safeuser/REST2NOSTR/start-rest2nostr.sh
|
#- ./start-rest2nostr.sh:/home/safeuser/REST2NOSTR/start-rest2nostr.sh
|
||||||
- ./.env:/home/safeuser/.env
|
- ./.env:/home/safeuser/.env
|
||||||
|
- ../data:/home/safeuser/psf-bch-api/production/data
|
||||||
|
- ../data/logs:/home/safeuser/psf-bch-api/logs
|
||||||
restart: always
|
restart: always
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
npm start
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
// Simple Node.js app that prints 'hello world' every 10 seconds
|
|
||||||
|
|
||||||
setInterval(() => {
|
|
||||||
console.log('hello world')
|
|
||||||
}, 10000)
|
|
||||||
|
|
||||||
console.log('Timer started. Printing "hello world" every 10 seconds...')
|
|
||||||
Vendored
+7
-2
@@ -26,10 +26,10 @@ const normalizeBoolean = (value, defaultValue) => {
|
|||||||
return defaultValue
|
return defaultValue
|
||||||
}
|
}
|
||||||
|
|
||||||
// By default, the price per API call is 2000 satoshis.
|
// By default, the price per API call is 200 satoshis.
|
||||||
// But the user can override this value by setting the X402_PRICE_SAT environment variable.
|
// But the user can override this value by setting the X402_PRICE_SAT environment variable.
|
||||||
const parsedPriceSat = Number(process.env.X402_PRICE_SAT)
|
const parsedPriceSat = Number(process.env.X402_PRICE_SAT)
|
||||||
const priceSat = Number.isFinite(parsedPriceSat) && parsedPriceSat > 0 ? parsedPriceSat : 2000
|
const priceSat = Number.isFinite(parsedPriceSat) && parsedPriceSat > 0 ? parsedPriceSat : 200
|
||||||
|
|
||||||
const x402Defaults = {
|
const x402Defaults = {
|
||||||
enabled: normalizeBoolean(process.env.X402_ENABLED, true),
|
enabled: normalizeBoolean(process.env.X402_ENABLED, true),
|
||||||
@@ -47,6 +47,11 @@ export default {
|
|||||||
// Server port
|
// Server port
|
||||||
port: parseInt(process.env.PORT, 10) || 5942,
|
port: parseInt(process.env.PORT, 10) || 5942,
|
||||||
|
|
||||||
|
// HTTP server connection lifecycle configuration.
|
||||||
|
serverKeepAliveTimeoutMs: Number(process.env.SERVER_KEEPALIVE_TIMEOUT_MS || 3000),
|
||||||
|
serverHeadersTimeoutMs: Number(process.env.SERVER_HEADERS_TIMEOUT_MS || 65000),
|
||||||
|
serverRequestTimeoutMs: Number(process.env.SERVER_REQUEST_TIMEOUT_MS || 120000),
|
||||||
|
|
||||||
// Environment
|
// Environment
|
||||||
env: process.env.NODE_ENV || 'development',
|
env: process.env.NODE_ENV || 'development',
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -26,7 +26,7 @@ export function buildX402Routes (apiPrefix = '/v6') {
|
|||||||
price: config.x402.priceSat,
|
price: config.x402.priceSat,
|
||||||
network: NETWORK,
|
network: NETWORK,
|
||||||
config: {
|
config: {
|
||||||
description: `${DEFAULT_DESCRIPTION} (2000 satoshis)`,
|
description: `${DEFAULT_DESCRIPTION} (${config.x402.priceSat} satoshis)`,
|
||||||
maxTimeoutSeconds: DEFAULT_TIMEOUT_SECONDS
|
maxTimeoutSeconds: DEFAULT_TIMEOUT_SECONDS
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -424,7 +424,20 @@ class FulcrumRESTController {
|
|||||||
|
|
||||||
const cashAddr = this._validateAndConvertAddress(address)
|
const cashAddr = this._validateAndConvertAddress(address)
|
||||||
|
|
||||||
const result = await this.fulcrumUseCases.getTransactions({ address: cashAddr, allTxs })
|
// Extract bearer token from request header if present
|
||||||
|
let bearerToken = null
|
||||||
|
if (req.headers && req.headers.authorization) {
|
||||||
|
const parts = req.headers.authorization.split(' ')
|
||||||
|
if (parts.length === 2 && parts[0] === 'Bearer') {
|
||||||
|
bearerToken = parts[1]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const result = await this.fulcrumUseCases.getTransactions({
|
||||||
|
address: cashAddr,
|
||||||
|
allTxs,
|
||||||
|
bearerToken
|
||||||
|
})
|
||||||
return res.status(200).json(result)
|
return res.status(200).json(result)
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
return this.handleError(err, res)
|
return this.handleError(err, res)
|
||||||
@@ -470,9 +483,19 @@ class FulcrumRESTController {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Extract bearer token from request header if present
|
||||||
|
let bearerToken = null
|
||||||
|
if (req.headers && req.headers.authorization) {
|
||||||
|
const parts = req.headers.authorization.split(' ')
|
||||||
|
if (parts.length === 2 && parts[0] === 'Bearer') {
|
||||||
|
bearerToken = parts[1]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
const result = await this.fulcrumUseCases.getTransactionsBulk({
|
const result = await this.fulcrumUseCases.getTransactionsBulk({
|
||||||
addresses: validatedAddresses,
|
addresses: validatedAddresses,
|
||||||
allTxs
|
allTxs,
|
||||||
|
bearerToken
|
||||||
})
|
})
|
||||||
return res.status(200).json(result)
|
return res.status(200).json(result)
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
|
|||||||
@@ -6,7 +6,15 @@ import wlogger from '../adapters/wlogger.js'
|
|||||||
import BCHJS from '@psf/bch-js'
|
import BCHJS from '@psf/bch-js'
|
||||||
import config from '../config/index.js'
|
import config from '../config/index.js'
|
||||||
|
|
||||||
const bchjs = new BCHJS({ restURL: config.restURL })
|
// Use RESTURL (from test) or REST_URL (from psf-bch-api config) or fallback to config
|
||||||
|
const restURL = process.env.RESTURL || process.env.REST_URL || process.env.LOCAL_RESTURL || config.restURL
|
||||||
|
// Use BCHJSBEARERTOKEN (from test) or BASIC_AUTH_TOKEN (from psf-bch-api config) or fallback to config
|
||||||
|
const bearerToken = process.env.BCHJSBEARERTOKEN || process.env.BASIC_AUTH_TOKEN || config.basicAuth.token
|
||||||
|
|
||||||
|
const bchjs = new BCHJS({
|
||||||
|
restURL,
|
||||||
|
bearerToken
|
||||||
|
})
|
||||||
|
|
||||||
class FulcrumUseCases {
|
class FulcrumUseCases {
|
||||||
constructor (localConfig = {}) {
|
constructor (localConfig = {}) {
|
||||||
@@ -56,7 +64,7 @@ class FulcrumUseCases {
|
|||||||
async getTransactionDetails ({ txid }) {
|
async getTransactionDetails ({ txid }) {
|
||||||
try {
|
try {
|
||||||
const response = await this.fulcrum.get(`electrumx/tx/data/${txid}`)
|
const response = await this.fulcrum.get(`electrumx/tx/data/${txid}`)
|
||||||
console.log(`getTransactionDetails() TXID ${txid}: ${JSON.stringify(response, null, 2)}`)
|
// console.log(`getTransactionDetails() TXID ${txid}: ${JSON.stringify(response, null, 2)}`)
|
||||||
return response
|
return response
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
wlogger.error('Error in FulcrumUseCases.getTransactionDetails()', err)
|
wlogger.error('Error in FulcrumUseCases.getTransactionDetails()', err)
|
||||||
@@ -98,13 +106,24 @@ class FulcrumUseCases {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async getTransactions ({ address, allTxs }) {
|
async getTransactions ({ address, allTxs, bearerToken = null }) {
|
||||||
try {
|
try {
|
||||||
const response = await this.fulcrum.get(`electrumx/transactions/${address}`)
|
const response = await this.fulcrum.get(`electrumx/transactions/${address}`)
|
||||||
|
|
||||||
// Sort transactions in descending order, so that newest transactions are first.
|
// Sort transactions in descending order, so that newest transactions are first.
|
||||||
if (response.transactions && Array.isArray(response.transactions)) {
|
if (response.transactions && Array.isArray(response.transactions)) {
|
||||||
response.transactions = await this.bchjs.Electrumx.sortAllTxs(response.transactions, 'DESCENDING')
|
// Use bearer token from request if provided, otherwise use the default bchjs instance
|
||||||
|
let bchjsInstance = this.bchjs
|
||||||
|
if (bearerToken) {
|
||||||
|
// Create a temporary bchjs instance with the bearer token from the request
|
||||||
|
const restURL = process.env.RESTURL || process.env.REST_URL || process.env.LOCAL_RESTURL || config.restURL
|
||||||
|
bchjsInstance = new BCHJS({
|
||||||
|
restURL,
|
||||||
|
bearerToken
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
response.transactions = await bchjsInstance.Electrumx.sortAllTxs(response.transactions, 'DESCENDING')
|
||||||
|
|
||||||
if (!allTxs) {
|
if (!allTxs) {
|
||||||
// Return only the first 100 transactions of the history.
|
// Return only the first 100 transactions of the history.
|
||||||
@@ -119,16 +138,31 @@ class FulcrumUseCases {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async getTransactionsBulk ({ addresses, allTxs }) {
|
async getTransactionsBulk ({ addresses, allTxs, bearerToken = null }) {
|
||||||
try {
|
try {
|
||||||
const response = await this.fulcrum.post('electrumx/transactions/', { addresses })
|
const response = await this.fulcrum.post('electrumx/transactions/', { addresses })
|
||||||
|
|
||||||
// Sort transactions in descending order for each address entry.
|
// Sort transactions in descending order for each address entry.
|
||||||
if (response.transactions && Array.isArray(response.transactions)) {
|
if (response.transactions && Array.isArray(response.transactions)) {
|
||||||
|
// Use bearer token from request if provided, otherwise use the default bchjs instance
|
||||||
|
let bchjsInstance = this.bchjs
|
||||||
|
|
||||||
|
// console.log('getTransactionsBulk() bearerToken: ', bearerToken)
|
||||||
|
if (bearerToken) {
|
||||||
|
// Create a temporary bchjs instance with the bearer token from the request
|
||||||
|
const restURL = config.restURL
|
||||||
|
|
||||||
|
// console.log('getTransactionsBulk() restURL: ', restURL)
|
||||||
|
bchjsInstance = new BCHJS({
|
||||||
|
restURL,
|
||||||
|
bearerToken
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
for (let i = 0; i < response.transactions.length; i++) {
|
for (let i = 0; i < response.transactions.length; i++) {
|
||||||
const thisEntry = response.transactions[i]
|
const thisEntry = response.transactions[i]
|
||||||
if (thisEntry.transactions && Array.isArray(thisEntry.transactions)) {
|
if (thisEntry.transactions && Array.isArray(thisEntry.transactions)) {
|
||||||
thisEntry.transactions = await this.bchjs.Electrumx.sortAllTxs(thisEntry.transactions, 'DESCENDING')
|
thisEntry.transactions = await bchjsInstance.Electrumx.sortAllTxs(thisEntry.transactions, 'DESCENDING')
|
||||||
|
|
||||||
if (!allTxs && thisEntry.transactions.length > 100) {
|
if (!allTxs && thisEntry.transactions.length > 100) {
|
||||||
// Extract only the first 100 transactions.
|
// Extract only the first 100 transactions.
|
||||||
|
|||||||
@@ -274,7 +274,7 @@ class SlpUseCases {
|
|||||||
// Get transaction data
|
// Get transaction data
|
||||||
console.log('Decoding OP_RETURN for TXID: ', txid)
|
console.log('Decoding OP_RETURN for TXID: ', txid)
|
||||||
const txData = await this.bchjs.Electrumx.txData(txid)
|
const txData = await this.bchjs.Electrumx.txData(txid)
|
||||||
console.log(`TXID ${txid}: ${JSON.stringify(txData, null, 2)}`)
|
// console.log(`TXID ${txid}: ${JSON.stringify(txData, null, 2)}`)
|
||||||
let data = false
|
let data = false
|
||||||
|
|
||||||
// Map the vout of the transaction in search of an OP_RETURN
|
// Map the vout of the transaction in search of an OP_RETURN
|
||||||
|
|||||||
Reference in New Issue
Block a user