Compare commits

..
Author SHA1 Message Date
Vlad Stan c5388e23a9 fix: settings reset 2026-02-04 14:05:19 +02:00
Vlad Stan d01893f577 test: one time code 2026-02-04 14:04:25 +02:00
Vlad Stan 1fc15cde81 test: invalid code, reusable code 2026-02-04 13:57:46 +02:00
Vlad Stan c711be4d60 test: no code provided 2026-02-04 13:48:46 +02:00
Vlad Stan ccb9dda164 fix: handle empty strings better 2026-02-04 13:11:40 +02:00
Vlad Stan 100bc45185 chore: code clean-up 2026-02-03 18:11:04 +02:00
Vlad Stan 222d1c8990 fix: remove nostr message 2026-02-03 18:11:04 +02:00
Vlad Stan 69c414fabf feat: better wording 2026-02-03 18:11:04 +02:00
Vlad Stan b33aa41b9a feat: check invitation code 2026-02-03 18:11:04 +02:00
Vlad Stan 68a36dfd18 feat: update settings 2026-02-03 18:11:04 +02:00
Vlad Stan 84a958af6e feat: send invitation code to backend 2026-02-03 18:11:04 +02:00
Vlad Stan 7db645d388 feat: add confirmation options UI 2026-02-03 18:11:04 +02:00
Vlad Stan 30e61eacf3 feat: configure ui 2026-02-03 18:11:04 +02:00
Vlad Stan de496ed9e8 feat: configure activation codes 2026-02-03 18:11:04 +02:00
Vlad Stan 8cb35d9aac feat: add some info 2026-02-03 18:11:04 +02:00
Vlad Stan d662b03370 refactor: reorder fields 2026-02-03 18:11:04 +02:00
Vlad Stan ef78ca7db3 feat: add ui config 2026-02-03 18:11:04 +02:00
Vlad Stan c97c5842ad refactor: better query 2026-02-03 18:10:41 +02:00
Vlad Stan abce6196de refactor: code cleanup 2026-02-03 18:10:41 +02:00
Vlad Stan e7d3be9854 chore: clean-up 2026-02-03 18:10:41 +02:00
Vlad Stan e9dc8c775d chore: bundle 2026-02-03 18:10:41 +02:00
Vlad Stan 31a2d68285 refactor: simplify queries 2026-02-03 18:10:41 +02:00
Vlad Stan bf1ad185b9 refactor: use normal update 2026-02-03 18:10:41 +02:00
Vlad Stan 62de35541c test: add more check 2026-02-03 18:10:41 +02:00
Vlad Stan 1a61435868 test: login after user disabled does not work 2026-02-03 18:10:41 +02:00
Vlad Stan 03ba28d0cb fix: column selection 2026-02-03 18:10:41 +02:00
Vlad Stan 2b260bfdaf fix: better message 2026-02-03 18:10:41 +02:00
Vlad Stan 30ab42c0b2 feat: add back toggle admin 2026-02-03 18:10:41 +02:00
Vlad Stan f603026d5e fix: only fetch keys for activated users 2026-02-03 18:10:41 +02:00
Vlad Stan 84e6b3a9a8 fix: clear cache 2026-02-03 18:10:41 +02:00
Vlad Stan 3aafc0724f feat: clear cache on user deactivation 2026-02-03 18:10:41 +02:00
Vlad Stan b978ce11fc feat: basic account activate/deactivate 2026-02-03 18:10:41 +02:00
dni ⚡andGitHub 656c6cac5b hotfix: websocket with old balance was sent. (#3759) 2026-02-03 12:23:49 +01:00
9 changed files with 203 additions and 42 deletions
+31 -26
View File
@@ -98,19 +98,17 @@ async def get_accounts(
async def get_account(
user_id: str, activated: bool | None = True, conn: Connection | None = None
user_id: str, active_only: bool = True, conn: Connection | None = None
) -> Account | None:
if len(user_id) == 0:
return None
activate_clause = "" if activated is None else "AND activated = :activated"
return await (conn or db).fetchone(
f"""
"""
SELECT * FROM accounts
WHERE id = :id {activate_clause}
""", # noqa: S608
{"id": user_id, "activated": activated},
WHERE id = :id AND (activated = true OR activated = :activated)
""",
{"id": user_id, "activated": active_only},
Account,
)
@@ -136,7 +134,7 @@ async def delete_accounts_no_wallets(
async def get_account_by_username(
username: str, activated: bool = True, conn: Connection | None = None
username: str, active_only: bool = True, conn: Connection | None = None
) -> Account | None:
if len(username) == 0:
return None
@@ -144,28 +142,32 @@ async def get_account_by_username(
return await (conn or db).fetchone(
"""
SELECT * FROM accounts
WHERE LOWER(username) = :username AND activated = :activated
WHERE
LOWER(username) = :username
AND (activated = true OR activated = :activated)
""",
{"username": username.lower(), "activated": activated},
{"username": username.lower(), "activated": active_only},
Account,
)
async def get_account_by_pubkey(
pubkey: str, activated: bool | None = True, conn: Connection | None = None
pubkey: str, active_only: bool = True, conn: Connection | None = None
) -> Account | None:
return await (conn or db).fetchone(
"""
SELECT * FROM accounts
WHERE LOWER(pubkey) = :pubkey AND activated = :activated
WHERE
LOWER(pubkey) = :pubkey
AND (activated = true OR activated = :activated)
""",
{"pubkey": pubkey.lower(), "activated": activated},
{"pubkey": pubkey.lower(), "activated": active_only},
Account,
)
async def get_account_by_email(
email: str, activated: bool = True, conn: Connection | None = None
email: str, active_only: bool = True, conn: Connection | None = None
) -> Account | None:
if len(email) == 0:
return None
@@ -173,35 +175,38 @@ async def get_account_by_email(
return await (conn or db).fetchone(
"""
SELECT * FROM accounts
WHERE LOWER(email) = :email AND activated = :activated
WHERE
LOWER(email) = :email
AND (activated = true OR activated = :activated)
""",
{"email": email.lower(), "activated": activated},
{"email": email.lower(), "activated": active_only},
Account,
)
async def get_account_by_username_or_email(
username_or_email: str,
activated: bool = True,
active_only: bool = True,
conn: Connection | None = None,
) -> Account | None:
return await (conn or db).fetchone(
"""
SELECT * FROM accounts
WHERE (LOWER(email) = :value or LOWER(username) = :value)
AND activated = :activated
WHERE
(LOWER(email) = :value or LOWER(username) = :value)
AND (activated = true OR activated = :activated)
""",
{"value": username_or_email.lower(), "activated": activated},
{"value": username_or_email.lower(), "activated": active_only},
Account,
)
async def get_user(
user_id: str, activated: bool | None = True, conn: Connection | None = None
user_id: str, active_only: bool = True, conn: Connection | None = None
) -> User | None:
async with db.reuse_conn(conn) if conn else db.connect() as conn:
account = await get_account(user_id, activated=activated, conn=conn)
account = await get_account(user_id, active_only, conn=conn)
if not account:
return None
return await get_user_from_account(account, conn=conn)
@@ -246,14 +251,14 @@ async def update_user_access_control_list(
async def get_user_access_control_lists(
user_id: str, activated: bool = True, conn: Connection | None = None
user_id: str, active_only: bool = True, conn: Connection | None = None
) -> UserAcls:
user_acls = await (conn or db).fetchone(
"""
SELECT id, access_control_list FROM accounts
WHERE id = :user_id AND activated = :activated
WHERE id = :user_id AND (activated = true OR activated = :activated)
""",
{"user_id": user_id, "activated": activated},
{"user_id": user_id, "activated": active_only},
UserAcls,
)
@@ -261,7 +266,7 @@ async def get_user_access_control_lists(
async def clear_user_id_cache(user_id: str):
user = await get_user(user_id, activated=None)
user = await get_user(user_id, active_only=True)
if user:
clear_user_cache(user)
+13 -2
View File
@@ -776,7 +776,7 @@ async def _pay_internal_invoice(
await update_payment(internal_payment, conn=conn)
logger.success(f"internal payment successful {internal_payment.checking_id}")
send_payment_notification_in_background(wallet, payment)
await _send_payment_notification_in_background(wallet.id, payment, conn=conn)
# notify receiver asynchronously
from lnbits.tasks import internal_invoice_queue
@@ -849,7 +849,8 @@ async def _pay_external_invoice(
payment = await update_payment_success_status(
payment, payment_response, conn=conn
)
send_payment_notification_in_background(wallet, payment)
await _send_payment_notification_in_background(wallet.id, payment, conn=conn)
logger.success(f"payment successful {payment_response.checking_id}")
payment.checking_id = payment_response.checking_id
@@ -1057,3 +1058,13 @@ async def cancel_hold_invoice(payment: Payment) -> InvoiceResponse:
await update_payment(payment)
return response
async def _send_payment_notification_in_background(
wallet_id: str, payment: Payment, conn: Connection | None = None
):
# fetch balance again
wallet = await get_wallet(wallet_id, conn=conn)
if not wallet:
raise PaymentError(f"Could not fetch wallet '{wallet_id}'.", status="failed")
send_payment_notification_in_background(wallet, payment)
+5 -2
View File
@@ -199,8 +199,11 @@ async def init_admin_settings(super_user: str | None = None) -> SuperSettings:
async def check_register_activation_settings(data: RegisterUser):
if not settings.lnbits_require_user_activation:
return None
if settings.lnbits_user_activation_by_invitation_code and data.invitation_code:
code = data.invitation_code.strip()
if settings.lnbits_user_activation_by_invitation_code:
code = data.invitation_code.strip() if data.invitation_code else ""
if len(code) == 0:
raise ValueError("Invitation code cannot be empty.")
if code == settings.lnbits_register_reusable_activation_code:
return None
if code in settings.lnbits_register_one_time_activation_codes:
+5 -3
View File
@@ -98,7 +98,7 @@ async def nostr_login(request: Request) -> JSONResponse:
if not settings.is_auth_method_allowed(AuthMethods.nostr_auth_nip98):
raise HTTPException(HTTPStatus.FORBIDDEN, "Login with Nostr Auth not allowed.")
event = _nostr_nip98_event(request)
account = await get_account_by_pubkey(event["pubkey"])
account = await get_account_by_pubkey(event["pubkey"], active_only=False)
if not account:
account = Account(
id=uuid4().hex,
@@ -106,6 +106,8 @@ async def nostr_login(request: Request) -> JSONResponse:
extra=UserExtra(provider="nostr"),
)
await create_user_account(account)
if not account.activated:
raise HTTPException(HTTPStatus.UNAUTHORIZED, "User is not activated.")
return _auth_success_response(account.username or "", account.id, account.email)
@@ -361,7 +363,7 @@ async def register(data: RegisterUser) -> JSONResponse:
if not is_valid_username(data.username):
raise HTTPException(HTTPStatus.BAD_REQUEST, "Invalid username.")
if await get_account_by_username(data.username):
if await get_account_by_username(data.username, active_only=False):
raise HTTPException(HTTPStatus.BAD_REQUEST, "Username already exists.")
if data.email and not is_valid_email_address(data.email):
@@ -533,7 +535,7 @@ async def _handle_sso_login(userinfo: OpenID, verified_user_id: str | None = Non
raise HTTPException(HTTPStatus.BAD_REQUEST, "Invalid email.")
redirect_path = "/wallet"
account = await get_account_by_email(email)
account = await get_account_by_email(email, active_only=False)
if verified_user_id:
if account:
+2 -2
View File
@@ -74,7 +74,7 @@ async def api_get_users(
summary="Get user by Id",
)
async def api_get_user(user_id: str) -> User:
user = await get_user(user_id, activated=None)
user = await get_user(user_id, active_only=False)
if not user:
raise HTTPException(HTTPStatus.NOT_FOUND, "User not found.")
return user
@@ -242,7 +242,7 @@ async def api_users_toggle_activated(
if settings.is_admin_user(user_id):
settings.lnbits_admin_users.remove(user_id)
user_account = await get_account(user_id, activated=None)
user_account = await get_account(user_id, active_only=False)
if not user_account:
raise HTTPException(
status_code=HTTPStatus.NOT_FOUND,
File diff suppressed because one or more lines are too long
-6
View File
@@ -566,12 +566,6 @@ window.app.component('username-password', {
this.confirmationMethod !== 'code' ||
this.confirmationCode.length > 0
console.log('### disableRegister', {
usernameOK,
passwordOK,
passwordsMatch,
codeOk
})
return !usernameOK || !passwordOK || !passwordsMatch || !codeOk
},
confirmationMethodsCount() {
+142
View File
@@ -297,6 +297,148 @@ async def test_register_ok(http_client: AsyncClient):
), f"Expected 1 default wallet, not {len(user.wallets)}."
@pytest.mark.anyio
async def test_register_no_activation_code(
http_client: AsyncClient, settings: Settings
):
settings.lnbits_require_user_activation = True
tiny_id = shortuuid.uuid()[:8]
response = await http_client.post(
"/api/v1/auth/register",
json={
"username": f"u21.{tiny_id}",
"password": "secret1234",
"password_repeat": "secret1234",
"email": f"u21.{tiny_id}@lnbits.com",
},
)
assert response.status_code == 400
assert response.json().get("detail") == "No activation method provided."
settings.lnbits_user_activation_by_invitation_code = True
response = await http_client.post(
"/api/v1/auth/register",
json={
"username": f"u21.{tiny_id}",
"password": "secret1234",
"password_repeat": "secret1234",
"email": f"u21.{tiny_id}@lnbits.com",
},
)
assert response.status_code == 400, "User creation blocked without activation code."
assert response.json().get("detail") == "Invitation code cannot be empty."
@pytest.mark.anyio
async def test_register_invalid_activation_code(
http_client: AsyncClient, settings: Settings
):
settings.lnbits_require_user_activation = True
settings.lnbits_user_activation_by_invitation_code = True
settings.lnbits_register_reusable_activation_code = "foo"
settings.lnbits_register_one_time_activation_codes = ["baz", "qux"]
tiny_id = shortuuid.uuid()[:8]
response = await http_client.post(
"/api/v1/auth/register",
json={
"username": f"u21.{tiny_id}",
"password": "secret1234",
"password_repeat": "secret1234",
"email": f"u21.{tiny_id}@lnbits.com",
"invitation_code": "bar",
},
)
assert response.status_code == 400
assert response.json().get("detail") == "Invalid invitation code."
@pytest.mark.anyio
async def test_register_reusable_activation_code(
http_client: AsyncClient, settings: Settings
):
settings.lnbits_require_user_activation = True
settings.lnbits_user_activation_by_invitation_code = True
settings.lnbits_register_reusable_activation_code = "foo"
tiny_id = shortuuid.uuid()[:8]
response = await http_client.post(
"/api/v1/auth/register",
json={
"username": f"u21.{tiny_id}",
"password": "secret1234",
"password_repeat": "secret1234",
"email": f"u21.{tiny_id}@lnbits.com",
"invitation_code": "foo",
},
)
assert response.status_code == 200, "User created with reusable code."
assert response.json().get("access_token") is not None
# Register again with the same code
tiny_id = shortuuid.uuid()[:8]
response = await http_client.post(
"/api/v1/auth/register",
json={
"username": f"u21.{tiny_id}",
"password": "secret1234",
"password_repeat": "secret1234",
"email": f"u21.{tiny_id}@lnbits.com",
"invitation_code": "foo",
},
)
assert response.status_code == 200, "User created with reusable code."
assert response.json().get("access_token") is not None
@pytest.mark.anyio
async def test_register_one_time_activation_code(
http_client: AsyncClient, settings: Settings
):
settings.lnbits_require_user_activation = True
settings.lnbits_user_activation_by_invitation_code = True
settings.lnbits_register_reusable_activation_code = "foo"
settings.lnbits_register_one_time_activation_codes = ["baz", "qux"]
tiny_id = shortuuid.uuid()[:8]
response = await http_client.post(
"/api/v1/auth/register",
json={
"username": f"u21.{tiny_id}",
"password": "secret1234",
"password_repeat": "secret1234",
"email": f"u21.{tiny_id}@lnbits.com",
"invitation_code": "baz",
},
)
assert response.status_code == 200, "User created with one-time code."
assert response.json().get("access_token") is not None
# Register again with the same code
tiny_id = shortuuid.uuid()[:8]
response = await http_client.post(
"/api/v1/auth/register",
json={
"username": f"u21.{tiny_id}",
"password": "secret1234",
"password_repeat": "secret1234",
"email": f"u21.{tiny_id}@lnbits.com",
"invitation_code": "baz",
},
)
assert response.status_code == 400, "Invalid invitation code."
assert response.json().get("detail") == "Invalid invitation code."
@pytest.mark.anyio
async def test_register_email_twice(http_client: AsyncClient):
tiny_id = shortuuid.uuid()[:8]
+4
View File
@@ -341,3 +341,7 @@ def _settings_cleanup(settings: Settings):
settings.lnbits_max_outgoing_payment_amount_sats = 10_000_000_100
settings.lnbits_max_incoming_payment_amount_sats = 10_000_000_200
settings.stripe_limits = FiatProviderLimits()
settings.lnbits_require_user_activation = False
settings.lnbits_user_activation_by_invitation_code = False
settings.lnbits_register_reusable_activation_code = ""
settings.lnbits_register_one_time_activation_codes = []