Repository navigation
Blink: warn that a stored custodial API key is readable by the server operator - #152
Conversation
… operator The custodial (API key) path stores the key in the store's Lightning settings on the server, so on a shared or public-registration instance the operator can read it and use it for whatever the key is scoped to — a WRITE key can spend the account's balance. Add a proportionate warning to the setup tab and README: minimize scope (READ+RECEIVE to receive, WRITE only to pay), treat the key as exposed on a server you do not operate, and note it is revocable from the dashboard. The non-custodial ln-address path stores no credential and is unaffected.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Blink README and custodial account setup UI now warn about API-key storage, server-operator access, scopes, ChangesBlink credential security warnings
Estimated code review effort: 1 (Trivial) | ~3 minutes Merge Risk: ⚪ Minimal · up to This PR adds a server-trust warning to the Blink custodial API-key setup guidance and README without changing behavior; no actionable merge-blocking risk remains after normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (2 skipped: 2 unsupported.) ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What
Adds a server-trust warning to the custodial (API key) path in the Blink plugin — on the setup tab and in the README — stating that BTCPay stores the API key in the store's Lightning settings, so whoever operates the server can read it and use it for whatever the key is scoped to (a
WRITEkey can spend the account's balance).The warning is deliberately proportionate. A user consciously selects the key's scopes in the Blink dashboard, so this is not "you didn't know what the key does" — it is a reminder of the server-storage consequence, which is the part that isn't visible at key-creation time: on a shared or public-registration BTCPay instance the key sits on a host the tenant may not operate. It leads with the two mitigations that actually apply here:
READ+RECEIVEto receive; addWRITEonly if BTCPay must also pay invoices. A leaked receive-only key cannot spend.The non-custodial
ln-address=path stores no credential and is explicitly noted as unaffected.Why
BTCPay's Flint (Spark) plugin recently added an equivalent disclosure for the same class of exposure — a server-stored spend credential readable by the instance admin — in sethforprivacy/flint#45 (raised in sethforprivacy/flint#43). This applies the same fiduciary principle to Blink's custodial path. The exposure is genuinely less critical here than in the seed case, because a Blink API key is scope-limitable and revocable where a wallet seed is neither, and the warning says so rather than overstating it.
Changes
Views/Shared/Blink/LNPaymentMethodSetupTab.cshtml— warning alert after the API-key setup instructions.README.md— matching note under the custodial account section.Docs/UI copy only; no behavioural change.
Summary by CodeRabbit
WRITEkeys.