Compare commits

..
Author SHA1 Message Date
Vlad Stan fd3ce06de5 fix: dependencies 2026-07-09 16:36:10 +03:00
Vlad Stan 88da66e4ee refactor: fix deps 2026-07-09 16:36:10 +03:00
Vlad Stan 36958d34f0 refactor: fix some imports 2026-07-09 16:36:10 +03:00
Vlad Stan 220be5cc0b refactor: fix imports 2026-07-09 16:36:10 +03:00
Vlad Stan 1b477f41ad refactor: extract import 2026-07-09 16:36:10 +03:00
Vlad Stan 8ac2cfbd1c refactor: extract permissions component 2026-07-09 16:36:10 +03:00
Vlad Stan 7425f9fa70 chore: clean-up i18n 2026-07-09 16:36:10 +03:00
Vlad Stan 442a272aa5 refactor: separate function 2026-07-09 16:36:10 +03:00
Vlad Stan ebebd781b8 refactor: move function 2026-07-09 16:36:10 +03:00
Vlad Stan 8824ae9fd4 refactor: extract 2026-07-09 16:36:10 +03:00
Vlad Stan ec1a9ac2f4 refactor: is_upgrade_extension 2026-07-09 16:36:10 +03:00
Vlad Stan ba4700b803 chore: make bundle 2026-07-09 16:36:10 +03:00
Vlad Stan 73229c9d0b feat: http.request permissions 2026-07-09 16:36:05 +03:00
Vlad Stan 5f483215d9 chore: lint 2026-07-09 16:36:05 +03:00
Vlad Stan e94a61c279 refactor: remove redundant check 2026-07-09 16:36:05 +03:00
Vlad Stan d9189e62af fix: policies 2026-07-09 16:36:05 +03:00
Vlad Stan 114229fb15 refactor: checks 2026-07-09 16:36:05 +03:00
Vlad Stan 137498740a refactor: move logic out from host.py 2026-07-09 16:36:05 +03:00
Vlad Stan 3ddce73834 fea: nicer permissions 2026-07-09 16:36:05 +03:00
Vlad Stan 597a65c45f feat: ui polish 2026-07-09 16:36:05 +03:00
Vlad Stan 3a5a6713c9 fix: allow no param 2026-07-09 16:36:05 +03:00
Vlad Stan eceb1eba61 fix: start/stop background work 2026-07-09 16:36:05 +03:00
Vlad Stan f186006329 refactor: structure 2026-07-09 16:36:05 +03:00
Vlad Stan 32c782e719 refactor: extract functions 2026-07-09 16:36:05 +03:00
Vlad Stan e45f0cf73d refactor: extract permissions logic 2026-07-09 16:35:53 +03:00
Vlad Stan b5506e7a0b refactor: extract function 2026-07-09 16:35:53 +03:00
Vlad Stan 77d52d3997 chore: clean-up 2026-07-09 16:35:40 +03:00
Vlad Stan 15282ebe23 fix: lint 2026-07-09 16:35:40 +03:00
Vlad Stan 39a148ef51 feat: add camera permissions 2026-07-09 16:35:40 +03:00
Vlad Stan 45a81fe22e feat: pay_invoice 2026-07-09 16:35:40 +03:00
Vlad Stan 4aaab5ca7c fix: icon 2026-07-09 16:35:40 +03:00
Vlad Stan 2add71cf0d refactor: components 2026-07-09 16:35:40 +03:00
Vlad Stan faf3611e2a refactor: better namespace 2026-07-09 16:35:40 +03:00
Vlad Stan 4bcc22d463 feat: add utils 2026-07-09 16:35:40 +03:00
Vlad Stan c094c820ef fix: access to extensions 2026-07-09 16:35:40 +03:00
Vlad Stan 6be509f8f0 feat: call extensions 2026-07-09 16:35:40 +03:00
Vlad Stan 2f74243f2a Revert "feat: public page http calls"
This reverts commit e7c359c1e0e21a8aeea391fd5b2cd6316526d42c.
2026-07-09 16:35:40 +03:00
Vlad Stan 2ff6fe5d3a feat: public page http calls 2026-07-09 16:35:40 +03:00
Vlad Stan 3f281e65f7 fix: user required 2026-07-09 16:35:40 +03:00
Vlad Stan 2286fee5c0 fix: loop issue 2026-07-09 16:35:40 +03:00
Vlad Stan af37caee1b refactor: better imports 2026-07-09 16:35:40 +03:00
Vlad Stan 31d343d220 refactor: split loader from routes 2026-07-09 16:35:40 +03:00
Vlad Stan 42f720cdba fix: typing 2026-07-09 16:35:39 +03:00
alanandVlad Stan 269035d853 chore: make bundle [skip ci] 2026-07-09 16:35:39 +03:00
Vlad Stan c8966d0eaa fix: simplify user check 2026-07-09 16:35:39 +03:00
Vlad Stan 1321c360cc chore: update poetry.lock 2026-07-09 16:35:39 +03:00
Vlad Stan 3ae05ba6e9 feat: ext http request 2026-07-09 16:35:39 +03:00
Vlad Stan 5e48676702 chore: make bundle 2026-07-09 16:35:39 +03:00
Vlad Stan 2cce2f86ef refactor: move code generator to tools 2026-07-09 16:35:34 +03:00
Vlad Stan bca10998bd refactor: remove unused param 2026-07-09 16:35:34 +03:00
Vlad Stan 6400ee985e refactor: move out dispatch_wasm_invoice_paid from tasks 2026-07-09 16:35:34 +03:00
Vlad Stan 61cdfd4662 refactor: remove extra param 2026-07-09 16:35:07 +03:00
Vlad Stan 81e8a08240 refactor: app usage 2026-07-09 16:34:52 +03:00
Vlad Stan 5375055bb7 refactor: simplify 2026-07-09 16:34:44 +03:00
Vlad Stan dbd1e20346 fix: i18n 2026-07-09 16:33:40 +03:00
Vlad Stan 948acb2b73 feat: extra extra 2026-07-09 16:33:39 +03:00
Vlad Stan b8a16e31e7 fix: i18n 2026-07-09 16:33:39 +03:00
Vlad Stan 0fce2481cb fix: owner id 2026-07-09 16:33:39 +03:00
Vlad Stan a2a12a25a5 fix: create row on event 2026-07-09 16:33:22 +03:00
Vlad Stan dab53a70e4 fix: create public invoice 2026-07-09 16:33:09 +03:00
Vlad Stan 003e2e4bb4 feat: create invoice public 2026-07-09 16:33:09 +03:00
Vlad Stan db275afddf feat: public get 2026-07-09 16:33:09 +03:00
Vlad Stan 9081324cda feat: finer grain permissions 2026-07-09 16:33:09 +03:00
Vlad Stan df04f5cc65 fix: permissions 2026-07-09 16:33:09 +03:00
Vlad Stan 21a6bbe73f fix: permissions 2026-07-09 16:33:09 +03:00
Vlad Stan 32c870d71d chore: clean-up 2026-07-09 16:33:09 +03:00
Vlad Stan 0ade5fdc70 fix: navigation 2026-07-09 16:33:09 +03:00
Vlad Stan df5543c280 fix: activate wasm extension 2026-07-09 16:33:09 +03:00
Vlad Stan ebdb95ab89 fix: ui 2026-07-09 16:33:09 +03:00
Vlad Stan e94480f82c feat: ask permission 2026-07-09 16:33:09 +03:00
Vlad Stan 2952e41fd3 feat: permissions 2026-07-09 16:33:09 +03:00
Vlad Stan 2bf50968ba feat: ws bridge 2026-07-09 16:30:18 +03:00
Vlad Stan 52134608f9 chore: clean-up 2026-07-09 16:30:18 +03:00
Vlad Stan 9cc24993ec fix: icons 2026-07-09 16:30:18 +03:00
Vlad Stan 3e30b387b2 fix: import lnbits resources 2026-07-09 16:30:18 +03:00
Vlad Stan d18f225757 feat: pagination 2026-07-09 16:30:18 +03:00
Vlad Stan 3d4202b495 feat: store data 2026-07-09 16:30:18 +03:00
Vlad Stan da76d288ae feat: db operations 2026-07-09 16:30:18 +03:00
Vlad Stan 7f13588705 fix: wallets 2026-07-09 16:30:18 +03:00
Vlad Stan faf436533e feat: create unsafe real invoice 2026-07-09 16:30:18 +03:00
Vlad Stan 15273383ef fix: user bound frame_token 2026-07-09 16:30:18 +03:00
Vlad Stan bdff354d0b fix: links 2026-07-09 16:30:18 +03:00
Vlad Stan 20e3b4c0b4 feat: add wallet list 2026-07-09 16:30:18 +03:00
Vlad Stan f2920e8eb1 fix: postMessage uses '*' 2026-07-09 16:30:18 +03:00
Vlad Stan eed3cb2509 fix: frame in frame 2026-07-09 16:30:18 +03:00
Vlad Stan be2dbd71e9 fix: stricter asset loading 2026-07-09 16:30:18 +03:00
Vlad Stan 3fd08ce223 fix: better error page 2026-07-09 16:30:18 +03:00
Vlad Stan 068cdffb42 fix: allow clipboard copy 2026-07-09 16:30:18 +03:00
Vlad Stan 2dffad917c fix: allow clipboard copy 2026-07-09 16:30:18 +03:00
Vlad Stan 285c0bc92f fix: external iframe access 2026-07-09 16:30:18 +03:00
Vlad Stan a175807188 chore: code format 2026-07-09 16:30:18 +03:00
Vlad Stan f8519c9c60 fix: stricter headers for non-iframe usage 2026-07-09 16:30:18 +03:00
Vlad Stan 951840f50b fix: iframe communication 2026-07-09 16:30:18 +03:00
Vlad Stan 4fccd57595 fix: iframe style 2026-07-09 16:30:18 +03:00
Vlad Stan 15d63fc35a fix: link 2026-07-09 16:30:18 +03:00
Vlad Stan 41db2b2819 feat: serve in iframe 2026-07-09 16:30:18 +03:00
Vlad Stan 4a38d4219c chore: lint 2026-07-09 16:30:18 +03:00
Vlad Stan 6c5bd6f2a1 perf: cache wasm component 2026-07-09 16:30:18 +03:00
Vlad Stan c5c5538a17 fix: REST paths 2026-07-09 16:30:18 +03:00
Vlad Stan 4557910a32 feat: call ext logic 2026-07-09 16:30:17 +03:00
Vlad Stan eec9f8a053 basic extension loading 2026-07-09 16:30:17 +03:00
Vlad Stan da6dbfdcf7 refactor: reorder 2026-07-09 16:30:17 +03:00
Vlad Stan cc4d33c91e fix: remove public context 2026-07-09 16:30:17 +03:00
Vlad Stan 1d7c74b8c1 feat: simpler permissions 2026-07-09 16:30:17 +03:00
Vlad Stan 4943343aa3 feat: dumb 2026-07-09 16:30:17 +03:00
46 changed files with 142 additions and 4115 deletions
-5
View File
@@ -528,11 +528,6 @@ def register_async_tasks() -> None:
task_manager.create_permanent_task(process_next_notification)
task_manager.create_permanent_task(process_next_audit_entry)
async def dispatch_extension_invoice_paid(payment) -> None:
await dispatch_wasm_invoice_paid(payment)
core_app_extra.dispatch_extension_invoice_paid = dispatch_extension_invoice_paid
# server logs for websocket
if settings.lnbits_admin_ui:
server_log_task = initialize_server_websocket_logger()
-2
View File
@@ -18,7 +18,6 @@ from .extensions import (
get_user_extensions,
update_installed_extension,
update_installed_extension_state,
update_installed_extension_wasm_runtime_limits,
update_user_extension,
)
from .payments import (
@@ -157,7 +156,6 @@ __all__ = [
"update_admin_settings",
"update_installed_extension",
"update_installed_extension_state",
"update_installed_extension_wasm_runtime_limits",
"update_migration_version",
"update_payment",
"update_payment_checking_id",
-193
View File
@@ -1,12 +1,7 @@
import json
from datetime import datetime, timedelta, timezone
from lnbits.core.db import db
from lnbits.core.models.extensions import (
InstallableExtension,
UserExtension,
WasmInvocation,
WasmInvocationStats,
)
from lnbits.db import Connection, Database
@@ -16,11 +11,6 @@ async def create_installed_extension(
conn: Connection | None = None,
) -> None:
await (conn or db).insert("installed_extensions", ext)
await update_installed_extension_wasm_runtime_limits(
ext_id=ext.id,
limits=ext.wasm_runtime_limits,
conn=conn,
)
async def update_installed_extension(
@@ -28,11 +18,6 @@ async def update_installed_extension(
conn: Connection | None = None,
) -> None:
await (conn or db).update("installed_extensions", ext)
await update_installed_extension_wasm_runtime_limits(
ext_id=ext.id,
limits=ext.wasm_runtime_limits,
conn=conn,
)
async def update_installed_extension_state(
@@ -46,33 +31,6 @@ async def update_installed_extension_state(
)
async def update_installed_extension_wasm_runtime_limits(
*, ext_id: str, limits: dict, conn: Connection | None = None
) -> None:
if not await _has_installed_extension_wasm_runtime_limits_column(conn=conn):
return
await (conn or db).execute(
"""
UPDATE installed_extensions
SET wasm_runtime_limits = :limits
WHERE id = :id
""",
{"id": ext_id, "limits": json.dumps(limits)},
)
async def _has_installed_extension_wasm_runtime_limits_column(
conn: Connection | None = None,
) -> bool:
row: dict | None = await (conn or db).fetchone(
"SELECT version FROM dbversions WHERE db = 'core'"
)
if not row:
return False
return int(row["version"] or 0) >= 48
async def delete_installed_extension(
*, ext_id: str, conn: Connection | None = None
) -> None:
@@ -186,154 +144,3 @@ async def get_user_active_extensions_ids(
UserExtension,
)
return [ext.extension for ext in exts]
async def create_wasm_invocation(
invocation: WasmInvocation,
conn: Connection | None = None,
) -> None:
await (conn or db).insert("wasm_invocations", invocation)
async def update_wasm_invocation(
invocation: WasmInvocation,
conn: Connection | None = None,
) -> None:
await (conn or db).update("wasm_invocations", invocation)
async def get_wasm_invocation(
invocation_id: str,
conn: Connection | None = None,
) -> WasmInvocation | None:
return await (conn or db).fetchone(
"SELECT * FROM wasm_invocations WHERE id = :id",
{"id": invocation_id},
model=WasmInvocation,
)
async def get_wasm_invocations(
*,
extension_id: str | None = None,
status: str | None = None,
limit: int = 100,
offset: int = 0,
conn: Connection | None = None,
) -> list[WasmInvocation]:
where: list[str] = []
values: dict = {
"limit": max(1, min(limit, 500)),
"offset": max(offset, 0),
}
if extension_id:
where.append("extension_id = :extension_id")
values["extension_id"] = extension_id
if status:
where.append("status = :status")
values["status"] = status
query = "SELECT * FROM wasm_invocations"
if where:
query += f" WHERE {' AND '.join(where)}"
query += " ORDER BY started_at DESC LIMIT :limit OFFSET :offset"
return await (conn or db).fetchall(query, values, model=WasmInvocation)
async def get_running_wasm_invocations(
conn: Connection | None = None,
) -> list[WasmInvocation]:
return await get_wasm_invocations(status="running", conn=conn)
async def get_wasm_invocation_stats(
*,
extension_id: str | None = None,
since: datetime | None = None,
conn: Connection | None = None,
) -> WasmInvocationStats:
where: list[str] = []
values: dict = {}
if extension_id:
where.append("extension_id = :extension_id")
values["extension_id"] = extension_id
if since:
where.append("started_at >= :since")
values["since"] = since
query = """
SELECT
COUNT(*) AS total,
COALESCE(SUM(CASE WHEN status = 'running' THEN 1 ELSE 0 END), 0)
AS running,
COALESCE(SUM(CASE WHEN status = 'completed' THEN 1 ELSE 0 END), 0)
AS completed,
COALESCE(SUM(CASE WHEN status = 'failed' THEN 1 ELSE 0 END), 0)
AS failed,
COALESCE(SUM(CASE WHEN status = 'stopped' THEN 1 ELSE 0 END), 0)
AS stopped,
COALESCE(SUM(CASE WHEN status = 'timeout' THEN 1 ELSE 0 END), 0)
AS timeout,
COALESCE(AVG(duration_ms), 0) AS avg_duration_ms,
COALESCE(MAX(duration_ms), 0) AS max_duration_ms,
COALESCE(SUM(host_call_count), 0) AS host_call_count,
COALESCE(SUM(http_call_count), 0) AS http_call_count,
COALESCE(SUM(storage_call_count), 0) AS storage_call_count,
COALESCE(SUM(wallet_call_count), 0) AS wallet_call_count
FROM wasm_invocations
"""
if where:
query += f" WHERE {' AND '.join(where)}"
row: dict | None = await (conn or db).fetchone(query, values)
if not row:
return WasmInvocationStats()
return WasmInvocationStats(
total=int(row["total"] or 0),
running=int(row["running"] or 0),
completed=int(row["completed"] or 0),
failed=int(row["failed"] or 0),
stopped=int(row["stopped"] or 0),
timeout=int(row["timeout"] or 0),
avg_duration_ms=float(row["avg_duration_ms"] or 0),
max_duration_ms=int(row["max_duration_ms"] or 0),
host_call_count=int(row["host_call_count"] or 0),
http_call_count=int(row["http_call_count"] or 0),
storage_call_count=int(row["storage_call_count"] or 0),
wallet_call_count=int(row["wallet_call_count"] or 0),
)
async def delete_old_wasm_invocations(
retention_days: int,
conn: Connection | None = None,
) -> int:
if retention_days <= 0:
return 0
cutoff = datetime.now(timezone.utc) - timedelta(days=retention_days)
result = await (conn or db).execute(
"""
DELETE FROM wasm_invocations
WHERE status != 'running' AND started_at < :cutoff
""",
{"cutoff": cutoff},
)
return int(result.rowcount or 0)
async def mark_stale_wasm_invocations(
conn: Connection | None = None,
) -> None:
await (conn or db).execute(
"""
UPDATE wasm_invocations
SET status = 'abandoned',
finished_at = :finished_at,
stop_reason = 'Server restarted before invocation finished.'
WHERE status = 'running'
""",
{"finished_at": datetime.now(timezone.utc)},
)
-59
View File
@@ -824,62 +824,3 @@ async def m046_add_permissions_to_installed_extensions(db: Connection):
await db.execute(
"ALTER TABLE installed_extensions ADD COLUMN permissions TEXT DEFAULT '[]'"
)
async def m047_create_wasm_invocations_table(db: Connection):
"""
Tracks WASM extension invocations for runtime monitoring and controls.
"""
await db.execute(f"""
CREATE TABLE IF NOT EXISTS wasm_invocations (
id TEXT PRIMARY KEY,
extension_id TEXT NOT NULL,
export_name TEXT NOT NULL,
trigger_type TEXT NOT NULL DEFAULT 'unknown',
status TEXT NOT NULL DEFAULT 'running',
started_at TIMESTAMP NOT NULL DEFAULT {db.timestamp_now},
finished_at TIMESTAMP,
duration_ms INT,
user_id TEXT,
wallet_id TEXT,
request_id TEXT,
method TEXT,
path TEXT,
event_type TEXT,
payment_hash TEXT,
checking_id TEXT,
memory_peak_bytes INT,
request_bytes INT,
response_bytes INT,
host_call_count INT NOT NULL DEFAULT 0,
http_call_count INT NOT NULL DEFAULT 0,
storage_call_count INT NOT NULL DEFAULT 0,
wallet_call_count INT NOT NULL DEFAULT 0,
error_type TEXT,
error_message TEXT,
stop_reason TEXT,
"context" TEXT NOT NULL DEFAULT '{{}}'
);
""")
await db.execute("""
CREATE INDEX IF NOT EXISTS idx_wasm_invocations_extension_started
ON wasm_invocations (extension_id, started_at);
""")
await db.execute("""
CREATE INDEX IF NOT EXISTS idx_wasm_invocations_status
ON wasm_invocations (status);
""")
await db.execute("""
CREATE INDEX IF NOT EXISTS idx_wasm_invocations_started
ON wasm_invocations (started_at);
""")
async def m048_add_wasm_runtime_limits_to_installed_extensions(db: Connection):
"""
Adds per-extension WASM runtime limit overrides.
"""
await db.execute(
"ALTER TABLE installed_extensions "
"ADD COLUMN wasm_runtime_limits TEXT DEFAULT '{}'"
)
+5 -67
View File
@@ -6,14 +6,12 @@ import json
import os
import shutil
import zipfile
from collections.abc import Mapping
from datetime import datetime, timezone
from pathlib import Path, PurePosixPath
from pathlib import Path
from typing import Any
import httpx
from loguru import logger
from pydantic import BaseModel, Field, StrictStr
from pydantic import BaseModel, Field
from lnbits.helpers import (
download_url,
@@ -80,13 +78,11 @@ class GitHubRepo(BaseModel):
class ExtensionPermission(BaseModel):
id: StrictStr
description: StrictStr | None = None
id: str
label: str | None = None
description: str | None = None
policies: list[Any] | None = None
class Config:
extra = "ignore"
@staticmethod
def list_from_config(config_json: Mapping[str, Any]) -> list[ExtensionPermission]:
return [
@@ -199,63 +195,6 @@ class Extension(BaseModel):
)
class WasmInvocation(BaseModel):
id: str
extension_id: str
export_name: str
trigger_type: str = "unknown"
status: str = "running"
started_at: datetime = Field(default_factory=lambda: datetime.now(timezone.utc))
finished_at: datetime | None = None
duration_ms: int | None = None
user_id: str | None = None
wallet_id: str | None = None
request_id: str | None = None
method: str | None = None
path: str | None = None
event_type: str | None = None
payment_hash: str | None = None
checking_id: str | None = None
memory_peak_bytes: int | None = None
request_bytes: int | None = None
response_bytes: int | None = None
host_call_count: int = 0
http_call_count: int = 0
storage_call_count: int = 0
wallet_call_count: int = 0
error_type: str | None = None
error_message: str | None = None
stop_reason: str | None = None
context: dict = Field(default_factory=dict)
class WasmInvocationStats(BaseModel):
total: int = 0
running: int = 0
completed: int = 0
failed: int = 0
stopped: int = 0
timeout: int = 0
avg_duration_ms: float = 0
max_duration_ms: int = 0
host_call_count: int = 0
http_call_count: int = 0
storage_call_count: int = 0
wallet_call_count: int = 0
class WasmRuntimeLimitsUpdate(BaseModel):
limits: dict[str, Any] = Field(default_factory=dict)
class WasmRuntimeLimitsInfo(BaseModel):
id: str
name: str
active: bool | None = False
wasm_runtime_limits: dict[str, int] = Field(default_factory=dict)
effective_wasm_runtime_limits: dict[str, int] = Field(default_factory=dict)
class ExtensionRelease(BaseModel):
name: str
version: str
@@ -431,7 +370,6 @@ class InstallableExtension(BaseModel):
stars: int = 0
meta: ExtensionMeta | None = None
permissions: list[ExtensionPermission] = []
wasm_runtime_limits: dict = Field(default_factory=dict, no_database=True)
@property
def hash(self) -> str:
-16
View File
@@ -1,7 +1,6 @@
from __future__ import annotations
from collections.abc import Awaitable, Callable
from pathlib import Path
from typing import Any
from pydantic import BaseModel
@@ -32,16 +31,8 @@ class WasmExtensionRegistry:
self._extensions: dict[str, Any] = {}
def register(self, extension: Any) -> None:
self.require_available(extension)
self._extensions[extension.id] = extension
def require_available(self, extension: Any) -> None:
existing = self._extensions.get(extension.id)
if existing and not _same_wasm_extension_registration(existing, extension):
raise ValueError(
f"WASM extension id '{extension.id}' is already registered."
)
def get(self, ext_id: str) -> Any | None:
return self._extensions.get(ext_id)
@@ -49,13 +40,6 @@ class WasmExtensionRegistry:
return list(self._extensions.values())
def _same_wasm_extension_registration(left: Any, right: Any) -> bool:
try:
return Path(left.root_path).resolve() == Path(right.root_path).resolve()
except (AttributeError, TypeError):
return left is right
class ConversionData(BaseModel):
from_: str = "sat"
amount: float
+1 -546
View File
@@ -1,12 +1,5 @@
import asyncio
import importlib
import re
from collections.abc import Mapping
from dataclasses import dataclass
from datetime import datetime, timedelta, timezone
from threading import RLock
from typing import Any
from uuid import uuid4
from loguru import logger
@@ -20,168 +13,22 @@ from lnbits.core.crud import (
update_installed_extension_state,
)
from lnbits.core.crud.extensions import (
create_wasm_invocation,
delete_old_wasm_invocations,
get_installed_extensions,
get_wasm_invocation,
mark_stale_wasm_invocations,
update_installed_extension,
update_installed_extension_wasm_runtime_limits,
update_wasm_invocation,
)
from lnbits.core.crud.extensions import (
get_wasm_invocation_stats as get_wasm_invocation_stats_crud,
)
from lnbits.core.crud.extensions import (
get_wasm_invocations as get_wasm_invocations_crud,
)
from lnbits.core.helpers import migrate_extension_database
from lnbits.core.wasm_ext.api.permissions import validate_wasm_extension_permissions
from lnbits.core.wasm_ext.wasm.loader import is_wasm_extension_id
from lnbits.db import Connection
from lnbits.settings import WasmRuntimeLimits, settings
from lnbits.settings import settings
from ..models.extensions import (
Extension,
ExtensionMeta,
ExtensionPermission,
InstallableExtension,
WasmInvocation,
WasmInvocationStats,
)
_WASM_INVOCATION_CLEANUP_INTERVAL = timedelta(hours=1)
WASM_RUNTIME_LIMIT_FIELDS = tuple(WasmRuntimeLimits.__fields__.keys())
@dataclass
class WasmInvocationHandle:
invocation: WasmInvocation
engine: Any | None = None
store: Any | None = None
runtime_limits: dict[str, int] | None = None
stop_requested: bool = False
stop_reason: str | None = None
_wasm_invocation_lock = RLock()
_wasm_invocation_ready_lock = asyncio.Lock()
_wasm_invocation_handles: dict[str, WasmInvocationHandle] = {}
_wasm_invocations_marked_stale = False
_wasm_invocations_last_cleanup_at: datetime | None = None
def wasm_runtime_limit_defaults() -> dict[str, int]:
return {field: int(getattr(settings, field)) for field in WASM_RUNTIME_LIMIT_FIELDS}
def validate_wasm_runtime_limit_overrides(
limits: Mapping[str, Any] | None,
*,
strict: bool = True,
) -> dict[str, int]:
if not limits:
return {}
validated: dict[str, int] = {}
for field, raw_value in limits.items():
if field not in WASM_RUNTIME_LIMIT_FIELDS:
if strict:
raise ValueError(f"Unknown WASM runtime limit field '{field}'.")
continue
value = _validate_wasm_runtime_limit_value(field, raw_value, strict=strict)
if value is None:
continue
validated[field] = value
return validated
def _validate_wasm_runtime_limit_value(
field: str,
raw_value: Any,
*,
strict: bool,
) -> int | None:
if raw_value is None or raw_value == "":
return None
if isinstance(raw_value, bool):
return _invalid_wasm_runtime_limit(field, strict, "must be an integer")
if isinstance(raw_value, str):
raw_value = raw_value.strip()
if raw_value == "":
return None
if not raw_value.isdecimal():
return _invalid_wasm_runtime_limit(field, strict, "must be an integer")
if isinstance(raw_value, float) and not raw_value.is_integer():
return _invalid_wasm_runtime_limit(field, strict, "must be an integer")
try:
value = int(raw_value)
except (TypeError, ValueError) as exc:
return _invalid_wasm_runtime_limit(
field,
strict,
"must be an integer",
exc=exc,
)
if value < 0:
return _invalid_wasm_runtime_limit(field, strict, "cannot be negative")
return value
def _invalid_wasm_runtime_limit(
field: str,
strict: bool,
message: str,
*,
exc: Exception | None = None,
) -> int | None:
if not strict:
return None
error = ValueError(f"WASM runtime limit '{field}' {message}.")
if exc:
raise error from exc
raise error
def resolve_wasm_runtime_limits(
installed_extension: InstallableExtension | None = None,
) -> dict[str, int]:
limits = wasm_runtime_limit_defaults()
if installed_extension:
limits.update(
validate_wasm_runtime_limit_overrides(
installed_extension.wasm_runtime_limits,
strict=False,
)
)
return limits
async def get_wasm_runtime_limits_for_extension(ext_id: str) -> dict[str, int]:
installed_extension = await get_installed_extension(ext_id)
return resolve_wasm_runtime_limits(installed_extension)
async def update_wasm_extension_runtime_limits(
ext_id: str,
limits: Mapping[str, Any] | None,
) -> dict[str, int]:
installed_extension = await get_installed_extension(ext_id)
if not installed_extension:
raise ValueError(f"Extension '{ext_id}' is not installed.")
if not installed_extension.is_wasm:
raise ValueError(f"Extension '{ext_id}' is not a WASM extension.")
validated_limits = validate_wasm_runtime_limit_overrides(limits)
await update_installed_extension_wasm_runtime_limits(
ext_id=ext_id,
limits=validated_limits,
)
return validated_limits
async def install_extension(
ext_info: InstallableExtension,
@@ -200,8 +47,6 @@ async def install_extension(
installed_ext = await get_installed_extension(ext_info.id)
if installed_ext and installed_ext.meta:
ext_info.meta.payments = installed_ext.meta.payments
if installed_ext:
ext_info.wasm_runtime_limits = installed_ext.wasm_runtime_limits
await check_extensions_limit(installed_ext)
@@ -245,394 +90,6 @@ async def check_extensions_limit(installed_ext: InstallableExtension | None = No
raise ValueError("Max amount of extensions have been installed")
async def ensure_wasm_invocation_monitoring_ready() -> None:
global _wasm_invocations_last_cleanup_at, _wasm_invocations_marked_stale
async with _wasm_invocation_ready_lock:
now = _now()
if not _wasm_invocations_marked_stale:
await mark_stale_wasm_invocations()
_wasm_invocations_marked_stale = True
if (
_wasm_invocations_last_cleanup_at is None
or now - _wasm_invocations_last_cleanup_at
>= _WASM_INVOCATION_CLEANUP_INTERVAL
):
_wasm_invocations_last_cleanup_at = now
await delete_old_wasm_invocations(
settings.lnbits_wasm_invocation_retention_days
)
async def start_wasm_invocation(
*,
extension_id: str,
export_name: str,
trigger_type: str = "unknown",
user_id: str | None = None,
wallet_id: str | None = None,
request_id: str | None = None,
method: str | None = None,
path: str | None = None,
event_type: str | None = None,
payment_hash: str | None = None,
checking_id: str | None = None,
request_bytes: int | None = None,
context: dict | None = None,
runtime_limits: dict[str, int] | None = None,
) -> WasmInvocation:
await ensure_wasm_invocation_monitoring_ready()
_check_wasm_invocation_concurrency(
extension_id=extension_id,
user_id=user_id,
limits=runtime_limits,
)
invocation = WasmInvocation(
id=uuid4().hex,
extension_id=extension_id,
export_name=export_name,
trigger_type=trigger_type,
user_id=user_id,
wallet_id=wallet_id,
request_id=request_id,
method=method,
path=path,
event_type=event_type,
payment_hash=payment_hash,
checking_id=checking_id,
request_bytes=request_bytes,
context=_safe_wasm_invocation_context(context or {}),
)
await create_wasm_invocation(invocation)
with _wasm_invocation_lock:
_wasm_invocation_handles[invocation.id] = WasmInvocationHandle(
invocation,
runtime_limits=runtime_limits,
)
return invocation
def attach_wasm_invocation_runtime(
invocation_id: str,
*,
engine: Any,
store: Any,
) -> None:
with _wasm_invocation_lock:
handle = _wasm_invocation_handles.get(invocation_id)
if not handle:
return
handle.engine = engine
handle.store = store
if handle.stop_requested:
_interrupt_wasm_invocation(handle)
def record_wasm_invocation_host_call(
invocation_id: str | None,
method_id: str,
) -> None:
if not invocation_id:
return
with _wasm_invocation_lock:
handle = _wasm_invocation_handles.get(invocation_id)
if not handle:
return
invocation = handle.invocation
invocation.host_call_count += 1
category = _wasm_host_call_category(method_id)
if category == "http":
invocation.http_call_count += 1
elif category == "storage":
invocation.storage_call_count += 1
elif category == "wallet":
invocation.wallet_call_count += 1
_check_wasm_host_call_limit(invocation, category, handle.runtime_limits)
async def stop_wasm_invocation(
invocation_id: str,
*,
reason: str = "Stopped by admin.",
) -> bool:
interrupted = False
with _wasm_invocation_lock:
handle = _wasm_invocation_handles.get(invocation_id)
if handle:
handle.stop_requested = True
handle.stop_reason = reason
handle.invocation.stop_reason = reason
interrupted = _interrupt_wasm_invocation(handle)
invocation = await get_wasm_invocation(invocation_id)
if invocation and invocation.status == "running":
invocation.stop_reason = reason
await update_wasm_invocation(invocation)
return interrupted
async def stop_wasm_extension_invocations(
extension_id: str,
*,
reason: str = "Extension deactivated.",
) -> int:
with _wasm_invocation_lock:
invocation_ids = [
invocation_id
for invocation_id, handle in _wasm_invocation_handles.items()
if handle.invocation.extension_id == extension_id
]
for invocation_id in invocation_ids:
await stop_wasm_invocation(invocation_id, reason=reason)
return len(invocation_ids)
def wasm_invocation_stop_requested(invocation_id: str) -> bool:
with _wasm_invocation_lock:
handle = _wasm_invocation_handles.get(invocation_id)
return bool(handle and handle.stop_requested)
def get_wasm_invocation_stop_reason(invocation_id: str) -> str | None:
with _wasm_invocation_lock:
handle = _wasm_invocation_handles.get(invocation_id)
return handle.stop_reason if handle else None
async def finish_wasm_invocation(
invocation_id: str,
*,
status: str,
response_bytes: int | None = None,
memory_peak_bytes: int | None = None,
error_type: str | None = None,
error_message: str | None = None,
stop_reason: str | None = None,
) -> None:
with _wasm_invocation_lock:
handle = _wasm_invocation_handles.pop(invocation_id, None)
invocation = (
handle.invocation if handle else await get_wasm_invocation(invocation_id)
)
if not invocation:
return
reason = stop_reason or (handle.stop_reason if handle else None)
if handle and handle.stop_requested and status == "failed":
status = "stopped"
reason = reason or "Stopped by admin."
finished_at = _now()
invocation.status = status
invocation.finished_at = finished_at
invocation.duration_ms = max(
0, int((finished_at - invocation.started_at).total_seconds() * 1000)
)
invocation.response_bytes = response_bytes
invocation.memory_peak_bytes = memory_peak_bytes
invocation.error_type = error_type
invocation.error_message = _safe_wasm_error_message(error_message)
invocation.stop_reason = reason
await update_wasm_invocation(invocation)
def get_current_wasm_invocations(
extension_id: str | None = None,
) -> list[WasmInvocation]:
with _wasm_invocation_lock:
invocations = []
for handle in _wasm_invocation_handles.values():
if extension_id and handle.invocation.extension_id != extension_id:
continue
invocation = handle.invocation.copy(deep=True)
if handle.stop_requested and invocation.status == "running":
invocation.status = "stopping"
invocation.stop_reason = handle.stop_reason
invocations.append(invocation)
return sorted(
invocations, key=lambda invocation: invocation.started_at, reverse=True
)
def _check_wasm_invocation_concurrency(
*,
extension_id: str,
user_id: str | None,
limits: dict[str, int] | None,
) -> None:
if not limits:
return
with _wasm_invocation_lock:
handles = list(_wasm_invocation_handles.values())
if _wasm_limit_exceeded(
limits["wasm_runtime_max_concurrent_invocations"],
len(handles) + 1,
):
raise ValueError("WASM runtime has too many active invocations.")
extension_invocations = sum(
1 for handle in handles if handle.invocation.extension_id == extension_id
)
if _wasm_limit_exceeded(
limits["wasm_runtime_max_concurrent_invocations_per_extension"],
extension_invocations + 1,
):
raise ValueError(
f"WASM extension '{extension_id}' has too many active invocations."
)
if not user_id:
return
user_invocations = sum(
1 for handle in handles if handle.invocation.user_id == user_id
)
if _wasm_limit_exceeded(
limits["wasm_runtime_max_concurrent_invocations_per_user"],
user_invocations + 1,
):
raise ValueError("WASM user has too many active invocations.")
def _check_wasm_host_call_limit(
invocation: WasmInvocation,
category: str,
limits: dict[str, int] | None,
) -> None:
if not limits:
return
if _wasm_limit_exceeded(
limits["wasm_runtime_max_host_calls"],
invocation.host_call_count,
):
raise ValueError("WASM host call limit exceeded.")
category_limits = {
"http": (
limits["wasm_runtime_max_http_calls"],
invocation.http_call_count,
),
"storage": (
limits["wasm_runtime_max_storage_calls"],
invocation.storage_call_count,
),
"wallet": (
limits["wasm_runtime_max_wallet_calls"],
invocation.wallet_call_count,
),
}
category_limit = category_limits.get(category)
if category_limit and _wasm_limit_exceeded(*category_limit):
raise ValueError(f"WASM {category} host call limit exceeded.")
def _wasm_limit_exceeded(limit: int, value: int) -> bool:
return limit > 0 and value > limit
async def get_wasm_invocation_history(
*,
extension_id: str | None = None,
status: str | None = None,
limit: int = 100,
offset: int = 0,
) -> list[WasmInvocation]:
await ensure_wasm_invocation_monitoring_ready()
return await get_wasm_invocations_crud(
extension_id=extension_id,
status=status,
limit=limit,
offset=offset,
)
async def get_wasm_invocation_summary(
*,
extension_id: str | None = None,
hours: int = 24,
) -> WasmInvocationStats:
await ensure_wasm_invocation_monitoring_ready()
since = _now() - timedelta(hours=max(1, min(hours, 24 * 30)))
return await get_wasm_invocation_stats_crud(
extension_id=extension_id,
since=since,
)
def _interrupt_wasm_invocation(handle: WasmInvocationHandle) -> bool:
if not handle.store or not handle.engine:
return False
try:
handle.store.set_epoch_deadline(1)
handle.engine.increment_epoch()
return True
except Exception as exc:
logger.warning(
f"Failed to interrupt WASM invocation '{handle.invocation.id}': {exc}"
)
return False
def _wasm_host_call_category(method_id: str) -> str:
if method_id.startswith("http.") or method_id.startswith("extension.api."):
return "http"
if method_id.startswith("storage."):
return "storage"
if method_id.startswith("wallet."):
return "wallet"
return "host"
def _safe_wasm_invocation_context(context: dict) -> dict:
safe_context: dict = {}
for key, value in context.items():
if not isinstance(key, str):
continue
if value is None or isinstance(value, (bool, int, float)):
safe_context[key[:64]] = value
elif isinstance(value, str):
safe_context[key[:64]] = value[:256]
return safe_context
def _safe_wasm_error_message(message: str | None) -> str | None:
if not message:
return None
safe_message = message[:500]
redactions = [
(
r"(?i)(api[-_ ]?key|token|authorization|password|secret|preimage)"
r"\s*[:=]\s*[^\s,;]+",
r"\1=[redacted]",
),
(r"(?i)bearer\s+[A-Za-z0-9._~+/=-]+", "Bearer [redacted]"),
(r"\b[a-fA-F0-9]{64}\b", "[redacted-hex]"),
]
for pattern, replacement in redactions:
safe_message = re.sub(pattern, replacement, safe_message)
return safe_message
def _now() -> datetime:
return datetime.now(timezone.utc)
async def uninstall_extension(ext_id: str):
await stop_extension_background_work(ext_id)
@@ -656,8 +113,6 @@ async def activate_extension(ext: Extension):
async def deactivate_extension(ext_id: str):
if is_wasm_extension_id(ext_id):
await stop_wasm_extension_invocations(ext_id, reason="Extension deactivated.")
settings.deactivate_extension_paths(ext_id)
await update_installed_extension_state(ext_id=ext_id, active=False)
await stop_extension_background_work(ext_id)
-2
View File
@@ -18,7 +18,6 @@ from lnbits.core.crud import (
)
from lnbits.core.crud.users import get_user
from lnbits.core.crud.wallets import get_wallet
from lnbits.core.db import core_app_extra
from lnbits.core.models import Payment, Wallet
from lnbits.core.models.notifications import (
NOTIFICATION_TEMPLATES,
@@ -245,7 +244,6 @@ async def dispatch_payment_notification(payment: Payment) -> None:
wallet = await get_wallet(payment.wallet_id)
if wallet:
await send_payment_notification(wallet, payment)
await core_app_extra.dispatch_extension_invoice_paid(payment)
async def dispatch_webhook(payment: Payment):
+1
View File
@@ -6,6 +6,7 @@ from lnbits.core.crud import create_audit_entry
from lnbits.core.crud.payments import get_payments_status_count
from lnbits.core.crud.users import get_accounts
from lnbits.core.crud.wallets import get_wallets_count
from lnbits.core.db import core_app_extra
from lnbits.core.models.audit import AuditEntry
from lnbits.core.models.extensions import InstallableExtension
from lnbits.core.models.notifications import NotificationType
-111
View File
@@ -29,10 +29,6 @@ from lnbits.core.models.extensions import (
ReleasePaymentInfo,
UserExtension,
UserExtensionInfo,
WasmInvocation,
WasmInvocationStats,
WasmRuntimeLimitsInfo,
WasmRuntimeLimitsUpdate,
wasm_extension_icon_url,
)
from lnbits.core.models.users import Account, AccountId
@@ -40,17 +36,10 @@ from lnbits.core.services import check_transaction_status, create_invoice
from lnbits.core.services.extensions import (
activate_extension,
deactivate_extension,
get_current_wasm_invocations,
get_valid_extension,
get_valid_extensions,
get_wasm_invocation_history,
get_wasm_invocation_summary,
install_extension,
resolve_wasm_runtime_limits,
stop_wasm_invocation,
uninstall_extension,
update_wasm_extension_runtime_limits,
validate_wasm_runtime_limit_overrides,
)
from lnbits.core.wasm_ext.api.permissions import validate_extension_permissions
from lnbits.db import Page
@@ -143,106 +132,6 @@ async def api_install_extension(data: CreateExtension):
) from exc
@extension_router.get(
"/wasm/invocations/current",
dependencies=[Depends(check_admin)],
)
async def api_get_current_wasm_invocations(
extension_id: str | None = None,
) -> list[WasmInvocation]:
return get_current_wasm_invocations(extension_id=extension_id)
@extension_router.get(
"/wasm/invocations",
dependencies=[Depends(check_admin)],
)
async def api_get_wasm_invocations(
extension_id: str | None = None,
status: str | None = None,
limit: int = 100,
offset: int = 0,
) -> list[WasmInvocation]:
return await get_wasm_invocation_history(
extension_id=extension_id,
status=status,
limit=limit,
offset=offset,
)
@extension_router.get(
"/wasm/invocations/stats",
dependencies=[Depends(check_admin)],
)
async def api_get_wasm_invocation_stats(
extension_id: str | None = None,
hours: int = 24,
) -> WasmInvocationStats:
return await get_wasm_invocation_summary(extension_id=extension_id, hours=hours)
@extension_router.post(
"/wasm/invocations/{invocation_id}/stop",
dependencies=[Depends(check_admin)],
)
async def api_stop_wasm_invocation(invocation_id: str) -> SimpleStatus:
await stop_wasm_invocation(invocation_id, reason="Stopped by admin.")
return SimpleStatus(success=True, message="WASM invocation stop requested.")
@extension_router.get(
"/wasm/runtime-limits/extensions",
dependencies=[Depends(check_admin)],
)
async def api_get_wasm_runtime_limit_extensions() -> list[WasmRuntimeLimitsInfo]:
installed_extensions = await get_installed_extensions()
return [
WasmRuntimeLimitsInfo(
id=extension.id,
name=extension.name,
active=extension.active,
wasm_runtime_limits=validate_wasm_runtime_limit_overrides(
extension.wasm_runtime_limits,
strict=False,
),
effective_wasm_runtime_limits=resolve_wasm_runtime_limits(extension),
)
for extension in installed_extensions
if extension.is_wasm
]
@extension_router.put(
"/wasm/runtime-limits/{ext_id}",
dependencies=[Depends(check_admin)],
)
async def api_update_wasm_runtime_limits(
ext_id: str,
data: WasmRuntimeLimitsUpdate,
) -> WasmRuntimeLimitsInfo:
try:
wasm_runtime_limits = await update_wasm_extension_runtime_limits(
ext_id, data.limits
)
extension = await get_installed_extension(ext_id)
if not extension:
raise ValueError(f"Extension '{ext_id}' is not installed.")
extension.wasm_runtime_limits = wasm_runtime_limits
return WasmRuntimeLimitsInfo(
id=extension.id,
name=extension.name,
active=extension.active,
wasm_runtime_limits=wasm_runtime_limits,
effective_wasm_runtime_limits=resolve_wasm_runtime_limits(extension),
)
except ValueError as exc:
raise HTTPException(
status_code=HTTPStatus.BAD_REQUEST,
detail=str(exc),
) from exc
@extension_router.get("/{ext_id}/details")
async def api_extension_details(
ext_id: str,
+1 -6
View File
@@ -189,9 +189,6 @@ admin_ui_checks = [Depends(check_admin), Depends(check_admin_ui)]
@generic_router.get("/audit", dependencies=admin_ui_checks)
@generic_router.get("/node", dependencies=admin_ui_checks)
@generic_router.get("/admin", dependencies=admin_ui_checks)
@generic_router.get("/admin/extensions/wasm", dependencies=admin_ui_checks)
@generic_router.get("/admin/extensions/wasm/limits", dependencies=admin_ui_checks)
@generic_router.get("/admin/extensions/wasm/{ext_id}", dependencies=admin_ui_checks)
@generic_router.get(
"/extensions/builder", dependencies=[Depends(check_extension_builder)]
)
@@ -199,9 +196,7 @@ admin_ui_checks = [Depends(check_admin), Depends(check_admin_ui)]
"/extensions/builder/preview", dependencies=[Depends(check_extension_builder)]
)
async def index(
request: Request,
ext_id: str | None = None,
user: User = Depends(check_user_exists),
request: Request, user: User = Depends(check_user_exists)
) -> HTMLResponse:
return template_renderer().TemplateResponse(
request,
+8 -50
View File
@@ -50,11 +50,6 @@ from .registry import extension_api_method
logger = logging.getLogger("lnbits.extensions")
def _looks_like_lnurl_pay_target(payment_request: str) -> bool:
normalized = payment_request.strip().lower()
return normalized.startswith(("lnurl", "lightning:lnurl")) or "@" in normalized
class ExtensionHostAPI:
def __init__(
self,
@@ -65,9 +60,6 @@ class ExtensionHostAPI:
access_token: str | None = None,
context: str = "user",
owner_id: str | None = None,
wallet_id: str | None = None,
invocation_id: str | None = None,
runtime_limits: dict[str, int] | None = None,
) -> None:
self.extension_id = extension_id
self.permissions, self.permission_policies = self._permission_data(permissions)
@@ -75,9 +67,6 @@ class ExtensionHostAPI:
self.access_token = access_token
self.context = context
self.owner_id = sha256s(user_id) if user_id else owner_id
self.wallet_id = wallet_id
self.invocation_id = invocation_id
self.runtime_limits = runtime_limits or {}
from .utils import ExtensionAPIUtils
self.utils = ExtensionAPIUtils(self.extension_id, self.permissions)
@@ -374,48 +363,29 @@ class ExtensionHostAPI:
async def wallet_pay_invoice(
self, request: PayInvoiceRequest
) -> PayInvoiceResponse:
from lnurl import LnurlResponseException
from lnbits.core.crud.wallets import get_wallet
from lnbits.core.services.lnurl import get_pr_from_lnurl
from lnbits.core.services.payments import pay_invoice
from lnbits.exceptions import PaymentError
wallet = await get_wallet(request.wallet_id)
if wallet is None:
raise PermissionError("Paying invoices from this wallet is not allowed.")
if self.user_id:
if wallet.user != self.user_id:
raise PermissionError(
"Paying invoices from this wallet is not allowed."
)
elif not (self.context == "event" and request.wallet_id == self.wallet_id):
if not self.user_id:
raise PermissionError(
"Paying an invoice requires an authenticated user context."
)
wallet = await get_wallet(request.wallet_id)
if wallet is None or wallet.user != self.user_id:
raise PermissionError("Paying invoices from this wallet is not allowed.")
try:
payment_request = request.payment_request
if _looks_like_lnurl_pay_target(payment_request):
if request.max_sat is None:
return PayInvoiceResponse(
ok=False,
error="max_sat is required for LNURL payments.",
)
payment_request = await get_pr_from_lnurl(
payment_request,
request.max_sat * 1000,
request.description or None,
)
payment = await pay_invoice(
wallet_id=request.wallet_id,
payment_request=payment_request,
payment_request=request.payment_request,
max_sat=request.max_sat,
extra={"tag": self.extension_id, **request.extra},
description=request.description,
tag=self.extension_id,
)
except (PaymentError, ValueError, LnurlResponseException) as exc:
except (PaymentError, ValueError) as exc:
return PayInvoiceResponse(ok=False, error=str(exc))
return PayInvoiceResponse(
@@ -443,15 +413,7 @@ class ExtensionHostAPI:
from ..client.http import send_extension_http_request
policies = self.permission_policies.get("http.request") or []
return await send_extension_http_request(
self.extension_id,
policies,
request,
timeout_ms=self.runtime_limits.get("wasm_runtime_http_timeout_ms"),
max_response_bytes=self.runtime_limits.get(
"wasm_runtime_max_http_response_bytes"
),
)
return await send_extension_http_request(self.extension_id, policies, request)
@extension_api_method(
method_id="extension.api.request",
@@ -472,10 +434,6 @@ class ExtensionHostAPI:
self.user_id,
self.access_token,
request,
timeout_ms=self.runtime_limits.get("wasm_runtime_http_timeout_ms"),
max_response_bytes=self.runtime_limits.get(
"wasm_runtime_max_http_response_bytes"
),
)
@extension_api_method(
+10 -201
View File
@@ -3,18 +3,6 @@ from typing import Any
from lnbits.core.models.extensions import ExtensionPermission, InstallableExtension
from lnbits.core.wasm_ext.api.registry import extension_api_permission_ids
from lnbits.core.wasm_ext.client.http import _request_origin
from lnbits.core.wasm_ext.wasm.config import (
WasmExtensionConfig,
parse_wasm_extension_config,
)
_POLICY_AWARE_PERMISSION_IDS = {
"ext.storage.read_public",
"extension.api.request",
"http.request",
"wallet.create_invoice_public",
}
def validate_extension_permissions(
@@ -32,7 +20,7 @@ def validate_extension_permissions(
unknown_ids.append(permission.id)
if strict:
continue
normalized_permissions.append(permission.copy())
normalized_permissions.append(permission.copy(update={"label": None}))
if unknown_ids and strict:
raise ValueError(
@@ -46,17 +34,14 @@ def validate_extension_permissions(
def validate_wasm_extension_permissions(
ext_info: InstallableExtension,
granted_permissions: list[ExtensionPermission] | None,
extension_config: dict[str, Any] | WasmExtensionConfig,
extension_config: dict[str, Any],
) -> list[ExtensionPermission]:
if isinstance(extension_config, WasmExtensionConfig):
config = extension_config
elif extension_config.get("extension_type") != "wasm":
if extension_config.get("extension_type") != "wasm":
return []
else:
config = parse_wasm_extension_config(ext_info.id, extension_config)
requested_permissions = validate_extension_permissions(
ext_info.id, config.permissions
ext_info.id,
ExtensionPermission.list_from_config(extension_config),
)
if not requested_permissions:
return []
@@ -64,187 +49,11 @@ def validate_wasm_extension_permissions(
if granted_permissions is None:
raise ValueError(f"Extension '{ext_info.id}' requires permission approval.")
granted_permissions = validate_extension_permissions(
ext_info.id,
granted_permissions,
)
requested_by_id = _permission_index(ext_info.id, requested_permissions, "requested")
granted_by_id = _permission_index(ext_info.id, granted_permissions, "granted")
extra_granted_ids = sorted(set(granted_by_id) - set(requested_by_id))
if extra_granted_ids:
requested_ids = {permission.id for permission in requested_permissions}
granted_ids = {permission.id for permission in granted_permissions}
if requested_ids != granted_ids:
raise ValueError(
f"Extension '{ext_info.id}' was granted unrequested permissions: "
+ ", ".join(extra_granted_ids)
f"Extension '{ext_info.id}' was not granted all requested permissions."
)
effective_permissions: list[ExtensionPermission] = []
for permission_id, granted_permission in granted_by_id.items():
requested_permission = requested_by_id[permission_id]
if not _permission_grant_is_subset(requested_permission, granted_permission):
raise ValueError(
f"Extension '{ext_info.id}' was granted broader policies for "
f"permission '{permission_id}'."
)
effective_permissions.append(
requested_permission.copy(update={"policies": granted_permission.policies})
)
return effective_permissions
def _permission_index(
ext_id: str,
permissions: Iterable[ExtensionPermission],
source: str,
) -> dict[str, ExtensionPermission]:
indexed: dict[str, ExtensionPermission] = {}
duplicate_ids: list[str] = []
for permission in permissions:
if permission.id in indexed:
duplicate_ids.append(permission.id)
continue
indexed[permission.id] = permission
if duplicate_ids:
raise ValueError(
f"Extension '{ext_id}' has duplicate {source} permissions: "
+ ", ".join(sorted(set(duplicate_ids)))
)
return indexed
def _permission_grant_is_subset(
requested: ExtensionPermission,
granted: ExtensionPermission,
) -> bool:
if requested.id != granted.id:
return False
if requested.id not in _POLICY_AWARE_PERMISSION_IDS:
return True
if requested.id == "http.request":
return _http_request_grant_is_subset(requested.policies, granted.policies)
if requested.id == "extension.api.request":
return _extension_api_grant_is_subset(requested.policies, granted.policies)
if requested.id == "ext.storage.read_public":
return _public_storage_grant_is_subset(requested.policies, granted.policies)
if requested.id == "wallet.create_invoice_public":
return _public_invoice_grant_is_subset(requested.policies, granted.policies)
return False
def _policy_list(policies: list[Any] | None) -> list[Any]:
return policies if isinstance(policies, list) else []
def _http_request_grant_is_subset(
requested_policies: list[Any] | None,
granted_policies: list[Any] | None,
) -> bool:
return _http_origins(granted_policies).issubset(_http_origins(requested_policies))
def _http_origins(policies: list[Any] | None) -> set[str]:
origins: set[str] = set()
for policy in _policy_list(policies):
host = policy.get("host") if isinstance(policy, dict) else policy
if not isinstance(host, str) or not host:
continue
try:
origins.add(_request_origin(host))
except PermissionError:
continue
return origins
def _extension_api_grant_is_subset(
requested_policies: list[Any] | None,
granted_policies: list[Any] | None,
) -> bool:
requested_targets = _extension_api_targets(requested_policies)
granted_targets = _extension_api_targets(granted_policies)
for extension_id, granted_access in granted_targets.items():
requested_access = requested_targets.get(extension_id)
if requested_access is None or not granted_access.issubset(requested_access):
return False
return True
def _extension_api_targets(policies: list[Any] | None) -> dict[str, set[str]]:
targets: dict[str, set[str]] = {}
for policy in _policy_list(policies):
extension_id: str | None = None
access: list[Any] = []
if isinstance(policy, str):
extension_id = policy
access = ["read"]
elif isinstance(policy, dict):
raw_extension_id = policy.get("id")
raw_access = policy.get("access")
if isinstance(raw_extension_id, str) and isinstance(raw_access, list):
extension_id = raw_extension_id
access = raw_access
if not extension_id or extension_id in targets:
continue
clean_access = {
item
for item in access
if isinstance(item, str) and item in {"read", "write"}
}
if clean_access:
targets[extension_id] = clean_access
return targets
def _public_storage_grant_is_subset(
requested_policies: list[Any] | None,
granted_policies: list[Any] | None,
) -> bool:
requested_tables = _public_storage_tables(requested_policies)
granted_tables = _public_storage_tables(granted_policies)
for table_name, granted_fields in granted_tables.items():
requested_fields = requested_tables.get(table_name)
if requested_fields is None or not granted_fields.issubset(requested_fields):
return False
return True
def _public_storage_tables(policies: list[Any] | None) -> dict[str, set[str]]:
tables: dict[str, set[str]] = {}
for policy in _policy_list(policies):
if not isinstance(policy, dict):
continue
table_name = policy.get("table_name")
public_fields = policy.get("public_fields")
if (
not isinstance(table_name, str)
or table_name in tables
or not isinstance(public_fields, list)
):
continue
fields = {field for field in public_fields if isinstance(field, str) and field}
if fields:
tables[table_name] = fields
return tables
def _public_invoice_grant_is_subset(
requested_policies: list[Any] | None,
granted_policies: list[Any] | None,
) -> bool:
return _public_invoice_sources(granted_policies).issubset(
_public_invoice_sources(requested_policies)
)
def _public_invoice_sources(policies: list[Any] | None) -> set[tuple[str, str]]:
sources: set[tuple[str, str]] = set()
for policy in _policy_list(policies):
if not isinstance(policy, dict):
continue
table = policy.get("table")
wallet_field = policy.get("wallet_field")
if isinstance(table, str) and table and isinstance(wallet_field, str):
sources.add((table, wallet_field))
return sources
return requested_permissions
-3
View File
@@ -31,9 +31,6 @@ class ExtensionAPIHost:
payload: Mapping[str, Any] | BaseModel | None = None,
) -> dict[str, Any]:
method = self._require_method(host_name)
from lnbits.core.services.extensions import record_wasm_invocation_host_call
record_wasm_invocation_host_call(self.api.invocation_id, method.method_id)
request = self._request_model(method, payload)
handler = _resolve_attr_path(self.api, method.python_name)
response = handler(request)
+4 -27
View File
@@ -35,9 +35,6 @@ async def send_extension_api_request(
user_id: str | None,
access_token: str | None,
request: ExtensionApiRequest,
*,
timeout_ms: int | None = None,
max_response_bytes: int | None = None,
) -> HttpResponse:
if not user_id:
raise PermissionError("Extension API requests require authentication.")
@@ -58,7 +55,7 @@ async def send_extension_api_request(
try:
async with httpx.AsyncClient(
follow_redirects=False,
timeout=_timeout_seconds(timeout_ms, EXTENSION_API_TIMEOUT_SECONDS),
timeout=EXTENSION_API_TIMEOUT_SECONDS,
trust_env=False,
) as client:
async with client.stream(
@@ -67,10 +64,7 @@ async def send_extension_api_request(
headers={"Authorization": f"Bearer {access_token}"},
content=body,
) as response:
response_body = await _read_limited_response(
response,
max_response_bytes=max_response_bytes,
)
response_body = await _read_limited_response(response)
return HttpResponse(
status_code=response.status_code,
headers=_response_headers(dict(response.headers)),
@@ -183,34 +177,17 @@ def _extension_api_path(path: str) -> str:
return urlunsplit(("", "", parts.path, parts.query, ""))
async def _read_limited_response(
response: httpx.Response,
*,
max_response_bytes: int | None = None,
) -> bytes:
limit = (
EXTENSION_API_MAX_RESPONSE_BYTES
if max_response_bytes is None
else max_response_bytes
)
async def _read_limited_response(response: httpx.Response) -> bytes:
chunks: list[bytes] = []
size = 0
async for chunk in response.aiter_bytes():
size += len(chunk)
if limit > 0 and size > limit:
if size > EXTENSION_API_MAX_RESPONSE_BYTES:
raise ValueError("Extension API response is too large.")
chunks.append(chunk)
return b"".join(chunks)
def _timeout_seconds(timeout_ms: int | None, default: float) -> float | None:
if timeout_ms is None:
return default
if timeout_ms <= 0:
return None
return timeout_ms / 1000
def _response_headers(headers: dict[str, str]) -> dict[str, str]:
return {
key: value
+4 -25
View File
@@ -32,9 +32,6 @@ async def send_extension_http_request(
extension_id: str,
policies: list[Any],
request: HttpRequest,
*,
timeout_ms: int | None = None,
max_response_bytes: int | None = None,
) -> HttpResponse:
allowed_origins = _allowed_origins(policies)
origin = _request_origin(request.url)
@@ -52,7 +49,7 @@ async def send_extension_http_request(
try:
async with httpx.AsyncClient(
follow_redirects=False,
timeout=_timeout_seconds(timeout_ms, HTTP_REQUEST_TIMEOUT_SECONDS),
timeout=HTTP_REQUEST_TIMEOUT_SECONDS,
trust_env=False,
) as client:
async with client.stream(
@@ -61,10 +58,7 @@ async def send_extension_http_request(
headers=headers,
content=body,
) as response:
response_body = await _read_limited_response(
response,
max_response_bytes=max_response_bytes,
)
response_body = await _read_limited_response(response)
return HttpResponse(
status_code=response.status_code,
headers=_response_headers(dict(response.headers)),
@@ -170,32 +164,17 @@ def _request_headers(headers: dict[str, str]) -> dict[str, str]:
return clean
async def _read_limited_response(
response: httpx.Response,
*,
max_response_bytes: int | None = None,
) -> bytes:
limit = (
HTTP_MAX_RESPONSE_BYTES if max_response_bytes is None else max_response_bytes
)
async def _read_limited_response(response: httpx.Response) -> bytes:
chunks: list[bytes] = []
size = 0
async for chunk in response.aiter_bytes():
size += len(chunk)
if limit > 0 and size > limit:
if size > HTTP_MAX_RESPONSE_BYTES:
raise ValueError("HTTP response is too large.")
chunks.append(chunk)
return b"".join(chunks)
def _timeout_seconds(timeout_ms: int | None, default: float) -> float | None:
if timeout_ms is None:
return default
if timeout_ms <= 0:
return None
return timeout_ms / 1000
def _response_headers(headers: dict[str, str]) -> dict[str, str]:
return {
key: value
+18 -111
View File
@@ -2,46 +2,32 @@ from __future__ import annotations
import json
import re
from dataclasses import dataclass
from typing import Annotated, Any
from fastapi import Depends, FastAPI, HTTPException, Request
from lnbits.core.models import Account
from lnbits.core.services.extensions import get_wasm_runtime_limits_for_extension
from lnbits.decorators import check_access_token, check_account_exists
from lnbits.settings import settings
from ..wasm.config import WasmAPIRouteConfig
from ..wasm.invoke import invoke_wasm_extension_export
from ..wasm.loader import WasmExtension
class WasmRequestBodyTooLargeError(ValueError):
pass
@dataclass(frozen=True)
class WasmRoutePayload:
data: dict[str, Any]
request_bytes: int | None
def register_wasm_extension_api_routes(app: FastAPI, extension: WasmExtension) -> None:
for route_config in extension.config.api_routes:
for route_config in extension.config.get("api_routes") or []:
_add_wasm_extension_api_route(app, extension, route_config)
def _add_wasm_extension_api_route(
app: FastAPI,
extension: WasmExtension,
route_config: WasmAPIRouteConfig,
route_config: dict[str, Any],
) -> None:
method = _wasm_extension_api_method(extension, route_config.method)
route_path = _wasm_extension_api_path(extension, route_config.path)
export_name = _wasm_extension_api_export(extension, route_config.export)
path_params = route_config.path_params
auth = _wasm_extension_route_auth(extension, route_config.auth)
method = _wasm_extension_api_method(extension, route_config.get("method"))
route_path = _wasm_extension_api_path(extension, route_config.get("path"))
export_name = _wasm_extension_api_export(extension, route_config.get("export"))
path_params = route_config.get("path_params") or {}
auth = _wasm_extension_route_auth(extension, route_config.get("auth"))
if _has_route(app, route_path, method):
return
@@ -52,27 +38,14 @@ def _add_wasm_extension_api_route(
access_token: str | None = None,
) -> dict[str, Any]:
try:
limits = await get_wasm_runtime_limits_for_extension(extension.id)
payload = await _read_api_payload(
request,
path_params,
max_body_bytes=limits["wasm_runtime_max_request_bytes"],
)
payload = await _read_api_payload(request, path_params)
return await invoke_wasm_extension_export(
extension.id,
export_name,
payload.data,
payload,
user=account,
access_token=access_token,
trigger_type="http",
method=request.method,
path=request.url.path,
request_id=request.headers.get("x-request-id"),
request_bytes=payload.request_bytes,
context_data={"origin": _request_origin(request)},
)
except WasmRequestBodyTooLargeError as exc:
raise HTTPException(status_code=413, detail=str(exc)) from exc
except KeyError as exc:
raise HTTPException(status_code=404, detail=str(exc)) from exc
except PermissionError as exc:
@@ -106,70 +79,22 @@ def _add_wasm_extension_api_route(
async def _read_api_payload(
request: Request,
path_params: dict[str, str],
*,
max_body_bytes: int,
) -> WasmRoutePayload:
) -> dict[str, Any]:
payload = _read_api_path_params(request, path_params)
payload.update(_read_api_query_params(request))
request_bytes: int | None = None
if request.method in {"POST", "PUT", "PATCH"}:
body, request_bytes = await _read_json_object_with_size(
request,
max_body_bytes=max_body_bytes,
)
payload.update(body)
return WasmRoutePayload(payload, request_bytes)
payload.update(await _read_json_object(request))
return payload
async def _read_json_object(
request: Request,
*,
max_body_bytes: int | None = None,
) -> dict[str, Any]:
body, _ = await _read_json_object_with_size(
request,
max_body_bytes=(
settings.wasm_runtime_max_request_bytes
if max_body_bytes is None
else max_body_bytes
),
)
return body
async def _read_json_object_with_size(
request: Request,
*,
max_body_bytes: int,
) -> tuple[dict[str, Any], int]:
body = await _read_limited_body(request, max_body_bytes=max_body_bytes)
async def _read_json_object(request: Request) -> dict[str, Any]:
body = await request.body()
if not body:
return {}, 0
return {}
value = json.loads(body)
if not isinstance(value, dict):
raise TypeError("WASM extension API payload must be a JSON object.")
return value, len(body)
async def _read_limited_body(request: Request, *, max_body_bytes: int) -> bytes:
content_length = _request_content_length(request)
if _wasm_request_too_large(content_length, max_body_bytes):
raise WasmRequestBodyTooLargeError(
f"WASM extension request is too large: {content_length} bytes."
)
chunks: list[bytes] = []
size = 0
async for chunk in request.stream():
if not chunk:
continue
size += len(chunk)
if _wasm_request_too_large(size, max_body_bytes):
raise WasmRequestBodyTooLargeError(
f"WASM extension request is too large: {size} bytes."
)
chunks.append(chunk)
return b"".join(chunks)
return value
def _read_api_path_params(
@@ -187,32 +112,14 @@ def _read_api_query_params(request: Request) -> dict[str, Any]:
return {_snake_to_camel(key): value for key, value in request.query_params.items()}
def _request_content_length(request: Request) -> int | None:
content_length = request.headers.get("content-length")
if content_length and content_length.isdigit():
return int(content_length)
return None
def _wasm_request_too_large(size: int | None, max_body_bytes: int) -> bool:
return size is not None and max_body_bytes > 0 and size > max_body_bytes
def _request_origin(request: Request) -> str | None:
origin = request.headers.get("origin")
if not origin:
return None
return origin[:256]
def _wasm_extension_api_export(extension: WasmExtension, export_name: Any) -> str:
if not isinstance(export_name, str) or not export_name:
raise ValueError(f"Invalid API export for WASM extension '{extension.id}'.")
for export in extension.exports:
if export.name != export_name:
if export.get("name") != export_name:
continue
if export.visibility in {"public", "authenticated"}:
if export.get("visibility") in {"public", "authenticated"}:
return export_name
raise PermissionError(f"WASM export '{export_name}' is not callable over HTTP.")
raise KeyError(f"WASM extension '{extension.id}' has no export '{export_name}'.")
-1
View File
@@ -15,7 +15,6 @@ from .ui import register_wasm_extension_ui_routes
def register_wasm_extension(app: FastAPI, ext_id: str) -> WasmExtension:
loaded = load_wasm_extension(ext_id)
core_app_extra.wasm_extension_registry.require_available(loaded)
warm_wasm_extension(loaded)
mount_wasm_extension_static(app, loaded)
+15 -16
View File
@@ -17,7 +17,6 @@ from lnbits.decorators import (
from ..wasm.loader import WasmExtension
from .api import (
WasmRequestBodyTooLargeError,
_has_route,
_path_template_pattern,
_read_json_object,
@@ -38,11 +37,13 @@ from .security import (
def register_wasm_extension_ui_routes(app: FastAPI, extension: WasmExtension) -> None:
_add_wasm_extension_frame_config_route(app, extension)
for route_index, route_config in enumerate(extension.config.ui_routes):
route_path = _wasm_extension_ui_route_path(extension, route_config.path)
entrypoint = _wasm_extension_entrypoint(extension, route_config.entrypoint)
for route_index, route_config in enumerate(extension.config.get("ui_routes") or []):
route_path = _wasm_extension_ui_route_path(extension, route_config.get("path"))
entrypoint = _wasm_extension_entrypoint(
extension, route_config.get("entrypoint")
)
frame_path = f"/ext-frame/{extension.id}/{route_index}"
auth = _wasm_extension_route_auth(extension, route_config.auth)
auth = _wasm_extension_route_auth(extension, route_config.get("auth"))
_add_wasm_extension_frame_route(app, extension, frame_path, entrypoint)
_add_wasm_extension_wrapper_route(
app,
@@ -67,8 +68,6 @@ def _add_wasm_extension_frame_config_route(
) -> dict[str, Any]:
try:
body = await _read_json_object(request)
except WasmRequestBodyTooLargeError as exc:
raise HTTPException(status_code=413, detail=str(exc)) from exc
except (TypeError, ValueError) as exc:
raise HTTPException(status_code=400, detail=str(exc)) from exc
@@ -189,13 +188,13 @@ def _wasm_extension_bridge_api_routes(
public: bool,
) -> list[dict[str, str]]:
routes: list[dict[str, str]] = []
for route_config in extension.config.api_routes:
auth = _wasm_extension_route_auth(extension, route_config.auth)
for route_config in extension.config.get("api_routes") or []:
auth = _wasm_extension_route_auth(extension, route_config.get("auth"))
if public and auth != "public":
continue
method = _wasm_extension_api_method(extension, route_config.method)
path = _wasm_extension_api_path(extension, route_config.path)
_wasm_extension_api_export(extension, route_config.export)
method = _wasm_extension_api_method(extension, route_config.get("method"))
path = _wasm_extension_api_path(extension, route_config.get("path"))
_wasm_extension_api_export(extension, route_config.get("export"))
routes.append(
{
"method": method,
@@ -217,16 +216,16 @@ def _match_wasm_extension_ui_route(
if not isinstance(path, str) or not path.startswith("/"):
raise HTTPException(status_code=404, detail="Not found")
for route_index, route_config in enumerate(extension.config.ui_routes):
route_path = _wasm_extension_ui_route_path(extension, route_config.path)
for route_index, route_config in enumerate(extension.config.get("ui_routes") or []):
route_path = _wasm_extension_ui_route_path(extension, route_config.get("path"))
route_params = _path_template_params(route_path, path)
if route_params is None:
continue
return {
"frame_path": f"/ext-frame/{extension.id}/{route_index}",
"auth": _wasm_extension_route_auth(extension, route_config.auth),
"path_params": route_config.path_params,
"auth": _wasm_extension_route_auth(extension, route_config.get("auth")),
"path_params": route_config.get("path_params") or {},
"route_params": route_params,
}
+4 -27
View File
@@ -5,8 +5,6 @@ from typing import Any
from wasmtime import Config, Engine
from lnbits.settings import settings
from .loader import WasmExtension
@@ -14,37 +12,19 @@ def warm_wasm_extension(extension: WasmExtension) -> None:
_wasm_component(extension)
@lru_cache(maxsize=8)
def _wasm_engine(max_wasm_stack_bytes: int | None = None) -> Any:
@lru_cache(maxsize=1)
def _wasm_engine() -> Any:
config = Config()
config.wasm_component_model = True
config.epoch_interruption = True
config.consume_fuel = True
stack_limit = (
settings.wasm_runtime_max_wasm_stack_bytes
if max_wasm_stack_bytes is None
else max_wasm_stack_bytes
)
if stack_limit > 0:
config.max_wasm_stack = stack_limit
return Engine(config)
def _wasm_component(
extension: WasmExtension,
limits: dict[str, int] | None = None,
) -> Any:
def _wasm_component(extension: WasmExtension) -> Any:
stat = extension.module_path.stat()
max_wasm_stack_bytes = (
limits["wasm_runtime_max_wasm_stack_bytes"]
if limits
else settings.wasm_runtime_max_wasm_stack_bytes
)
return _cached_wasm_component(
str(extension.module_path),
stat.st_mtime_ns,
stat.st_size,
max_wasm_stack_bytes,
)
@@ -53,10 +33,7 @@ def _cached_wasm_component(
module_path: str,
mtime_ns: int,
size: int,
max_wasm_stack_bytes: int,
) -> Any:
from wasmtime import component
return component.Component.from_file(
_wasm_engine(max_wasm_stack_bytes), module_path
)
return component.Component.from_file(_wasm_engine(), module_path)
-115
View File
@@ -1,115 +0,0 @@
from __future__ import annotations
import re
from typing import Any, Literal
from pydantic import (
BaseModel,
Field,
StrictBool,
StrictStr,
ValidationError,
)
from lnbits.core.models.extensions import ExtensionPermission
_EXTENSION_ID_RE = re.compile(r"^[A-Za-z0-9_-]+$")
class _StrictWasmModel(BaseModel):
class Config:
extra = "ignore"
allow_population_by_field_name = True
class WasmExtensionExport(_StrictWasmModel):
name: StrictStr
visibility: Literal["authenticated", "event", "public"]
class WasmRuntimeConfig(_StrictWasmModel):
module: StrictStr
wit: StrictStr | None = None
world: StrictStr = ""
exports: list[WasmExtensionExport] = Field(default_factory=list)
class WasmUIConfig(_StrictWasmModel):
entrypoint: StrictStr | None = None
sandbox: StrictBool | None = None
class WasmSDKConfig(_StrictWasmModel):
frontend_js: StrictStr | None = None
class WasmUIRouteConfig(_StrictWasmModel):
path: StrictStr
entrypoint: StrictStr
auth: Literal["public", "user"]
path_params: dict[str, StrictStr] = Field(default_factory=dict)
class WasmAPIRouteConfig(_StrictWasmModel):
method: Literal["DELETE", "GET", "PATCH", "POST", "PUT"]
path: StrictStr
export: StrictStr
auth: Literal["public", "user"]
path_params: dict[str, StrictStr] = Field(default_factory=dict)
class WasmEventsConfig(_StrictWasmModel):
on_invoice_paid: StrictStr | None = Field(None, alias="onInvoicePaid")
class WasmExtensionConfig(_StrictWasmModel):
id: StrictStr
name: StrictStr
short_description: StrictStr
tile: StrictStr | None = None
version: StrictStr
min_lnbits_version: StrictStr | None = None
max_lnbits_version: StrictStr | None = None
extension_type: Literal["wasm"]
wasm: WasmRuntimeConfig
events: WasmEventsConfig = Field(
default_factory=lambda: WasmEventsConfig.parse_obj({})
)
ui: WasmUIConfig | None = None
sdk: WasmSDKConfig | None = None
ui_routes: list[WasmUIRouteConfig] = Field(default_factory=list)
api_routes: list[WasmAPIRouteConfig] = Field(default_factory=list)
permissions: list[ExtensionPermission] = Field(default_factory=list)
def parse_wasm_extension_config(
ext_id: str,
config: dict[str, Any],
) -> WasmExtensionConfig:
validate_wasm_extension_config_id(ext_id, config)
try:
return WasmExtensionConfig.parse_obj(config)
except ValidationError as exc:
raise ValueError(
f"Invalid WASM extension config for '{ext_id}': {exc}"
) from exc
def validate_wasm_extension_config_id(
ext_id: str,
config: dict[str, Any] | WasmExtensionConfig,
) -> str:
if not _EXTENSION_ID_RE.fullmatch(ext_id):
raise ValueError(f"Invalid WASM extension id '{ext_id}'.")
config_id = (
config.id if isinstance(config, WasmExtensionConfig) else config.get("id")
)
if not isinstance(config_id, str) or not config_id:
raise ValueError(f"WASM extension '{ext_id}' config must define id.")
if config_id != ext_id:
raise ValueError(
f"WASM extension id mismatch: installed as '{ext_id}' "
f"but config declares '{config_id}'."
)
return config_id
+14 -37
View File
@@ -1,10 +1,8 @@
import json
from collections.abc import Iterable
from typing import Any
from loguru import logger
from lnbits.core.crud.extensions import get_installed_extension
from lnbits.core.db import core_app_extra
from lnbits.core.wasm_ext.storage.crud import storage_get_row_owner_id
from lnbits.core.wasm_ext.wasm.invoke import invoke_wasm_extension_export
@@ -31,18 +29,12 @@ async def dispatch_wasm_invoice_paid(payment: Any) -> None:
return
try:
owner_id = await _wasm_invoice_paid_owner_id(extension, payment)
await invoke_wasm_extension_export(
extension.id,
export_name,
_wasm_invoice_paid_payload(payment),
context="event",
owner_id=owner_id,
trigger_type="event",
event_type="invoice_paid",
wallet_id=payment.wallet_id,
payment_hash=payment.payment_hash,
checking_id=payment.checking_id,
owner_id=await _wasm_invoice_paid_owner_id(extension, payment),
)
except Exception as exc:
logger.warning(
@@ -62,7 +54,7 @@ def _payment_extension_id(payment: Any) -> str | None:
async def _wasm_invoice_paid_owner_id(extension: Any, payment: Any) -> str | None:
source_id = _payment_source_id(payment)
source_tables = await _wasm_public_invoice_source_tables(extension.id)
source_tables = _wasm_public_invoice_source_tables(extension.config)
if not source_id or not source_tables:
return None
@@ -79,31 +71,14 @@ def _payment_source_id(payment: Any) -> str | None:
return source_id if isinstance(source_id, str) and source_id else None
async def _wasm_public_invoice_source_tables(extension_id: str) -> list[str]:
installed_extension = await get_installed_extension(extension_id)
if not installed_extension:
return []
return _wasm_public_invoice_source_tables_from_permissions(
installed_extension.permissions
)
def _wasm_public_invoice_source_tables_from_permissions(
permissions: Iterable[Any],
) -> list[str]:
def _wasm_public_invoice_source_tables(config: dict[str, Any]) -> list[str]:
permissions = config.get("permissions") or []
for permission in permissions:
permission_id = (
permission.get("id")
if isinstance(permission, dict)
else getattr(permission, "id", None)
)
if permission_id != "wallet.create_invoice_public":
if not isinstance(permission, dict):
continue
policies = (
permission.get("policies")
if isinstance(permission, dict)
else getattr(permission, "policies", None)
)
if permission.get("id") != "wallet.create_invoice_public":
continue
policies = permission.get("policies")
if not isinstance(policies, list):
return []
return [
@@ -116,14 +91,16 @@ def _wasm_public_invoice_source_tables_from_permissions(
return []
def _wasm_invoice_paid_export(config: Any) -> str | None:
return config.events.on_invoice_paid
def _wasm_invoice_paid_export(config: dict[str, Any]) -> str | None:
events = config.get("events") or {}
export_name = events.get("onInvoicePaid")
return export_name if isinstance(export_name, str) and export_name else None
def _is_wasm_event_export(extension: Any, export_name: str) -> bool:
for export in extension.exports:
if export.name == export_name:
return export.visibility == "event"
if export.get("name") == export_name:
return export.get("visibility") == "event"
return False
+23 -183
View File
@@ -9,7 +9,6 @@ from wasmtime import Store, WasiConfig, component
from lnbits.core.crud.extensions import get_installed_extension
from lnbits.core.db import core_app_extra
from lnbits.settings import settings
from ..api.host import ExtensionHostAPI
from ..api.runtime import ExtensionAPIHost
@@ -17,9 +16,6 @@ from .component import _wasm_component, _wasm_engine
from .host import add_extension_host_imports
from .loader import WasmExtension
_WASM_EPOCH_DEADLINE_TICKS = 1_000_000_000
_WASM_UNLIMITED_FUEL = 2**63 - 1
async def invoke_wasm_extension_export(
ext_id: str,
@@ -30,52 +26,9 @@ async def invoke_wasm_extension_export(
access_token: str | None = None,
context: str = "user",
owner_id: str | None = None,
trigger_type: str = "unknown",
request_id: str | None = None,
method: str | None = None,
path: str | None = None,
event_type: str | None = None,
wallet_id: str | None = None,
payment_hash: str | None = None,
checking_id: str | None = None,
request_bytes: int | None = None,
context_data: dict | None = None,
) -> dict[str, Any]:
from lnbits.core.services.extensions import (
finish_wasm_invocation,
get_wasm_invocation_stop_reason,
resolve_wasm_runtime_limits,
start_wasm_invocation,
stop_wasm_invocation,
wasm_invocation_stop_requested,
)
extension = _get_registered_extension(ext_id)
installed_extension = await _active_installed_extension(extension)
permissions = installed_extension.permissions
limits = resolve_wasm_runtime_limits(installed_extension)
payload = payload or {}
payload_size = _json_size(payload)
effective_request_bytes = (
request_bytes if request_bytes is not None else payload_size
)
_check_wasm_request_size(effective_request_bytes, limits)
invocation = await start_wasm_invocation(
extension_id=extension.id,
export_name=export_name,
trigger_type=trigger_type,
user_id=_user_id(user) or owner_id,
wallet_id=wallet_id,
request_id=request_id,
method=method,
path=path,
event_type=event_type,
payment_hash=payment_hash,
checking_id=checking_id,
request_bytes=effective_request_bytes,
context={"host_context": context, **(context_data or {})},
runtime_limits=limits,
)
permissions = await _extension_permissions(extension)
api = ExtensionHostAPI(
extension.id,
permissions,
@@ -83,91 +36,17 @@ async def invoke_wasm_extension_export(
access_token=access_token,
context=context,
owner_id=owner_id,
wallet_id=wallet_id,
invocation_id=invocation.id,
runtime_limits=limits,
)
event_loop = asyncio.get_running_loop()
thread_task = asyncio.create_task(
asyncio.to_thread(
_invoke_wasm_extension_export_sync,
extension,
export_name,
payload,
api,
event_loop,
invocation.id,
limits,
)
return await asyncio.to_thread(
_invoke_wasm_extension_export_sync,
extension,
export_name,
payload or {},
api,
event_loop,
)
max_execution_ms = limits["wasm_runtime_max_execution_ms"]
timed_out = False
finished = False
try:
try:
if max_execution_ms > 0:
result = await asyncio.wait_for(
asyncio.shield(thread_task),
timeout=max_execution_ms / 1000,
)
else:
result = await thread_task
except asyncio.TimeoutError as exc:
timed_out = True
stop_reason = "WASM execution time limit exceeded."
await stop_wasm_invocation(invocation.id, reason=stop_reason)
try:
result = await asyncio.wait_for(
asyncio.shield(thread_task),
timeout=2,
)
except asyncio.TimeoutError:
await finish_wasm_invocation(
invocation.id,
status="timeout",
error_type="TimeoutError",
error_message=stop_reason,
stop_reason=stop_reason,
)
finished = True
raise TimeoutError(stop_reason) from exc
status = (
"timeout"
if timed_out
else (
"stopped"
if wasm_invocation_stop_requested(invocation.id)
else "completed"
)
)
await finish_wasm_invocation(
invocation.id,
status=status,
response_bytes=_json_size(result),
stop_reason=get_wasm_invocation_stop_reason(invocation.id),
)
finished = True
return result
except Exception as exc:
if not finished:
await finish_wasm_invocation(
invocation.id,
status=(
"timeout"
if timed_out
else (
"stopped"
if wasm_invocation_stop_requested(invocation.id)
else "failed"
)
),
error_type=exc.__class__.__name__,
error_message=str(exc),
stop_reason=get_wasm_invocation_stop_reason(invocation.id),
)
raise
def _invoke_wasm_extension_export_sync(
@@ -176,24 +55,17 @@ def _invoke_wasm_extension_export_sync(
payload: Mapping[str, Any],
api: ExtensionHostAPI,
event_loop: asyncio.AbstractEventLoop,
invocation_id: str,
limits: dict[str, int],
) -> dict[str, Any]:
from lnbits.core.services.extensions import attach_wasm_invocation_runtime
engine = _wasm_engine(limits["wasm_runtime_max_wasm_stack_bytes"])
engine = _wasm_engine()
store = Store(engine)
_set_store_limits(store, limits)
_set_store_fuel(store, limits)
store.set_epoch_deadline(_WASM_EPOCH_DEADLINE_TICKS)
attach_wasm_invocation_runtime(invocation_id, engine=engine, store=store)
store.set_wasi(WasiConfig())
linker = component.Linker(engine)
linker.add_wasip2()
add_extension_host_imports(linker, ExtensionAPIHost(api), event_loop)
wasm_component = _wasm_component(extension, limits)
wasm_component = _wasm_component(extension)
instance = linker.instantiate(store, wasm_component)
function = instance.get_func(store, export_name)
if not function:
@@ -203,17 +75,21 @@ def _invoke_wasm_extension_export_sync(
result = function(store, json.dumps(payload))
function.post_return(store)
return _parse_wasm_export_result(result, limits)
return _parse_wasm_export_result(extension, result)
def _parse_wasm_export_result(value: Any, limits: dict[str, int]) -> dict[str, Any]:
def _parse_wasm_export_result(extension: WasmExtension, value: Any) -> dict[str, Any]:
if isinstance(value, bytes):
value = value.decode()
if not isinstance(value, str):
return {"ok": True, "data": value}
max_response_bytes = limits["wasm_runtime_max_response_bytes"]
if max_response_bytes > 0:
max_response_bytes = (
(extension.config.get("wasm") or {})
.get("resource_limits", {})
.get("max_response_bytes")
)
if isinstance(max_response_bytes, int):
response_size = len(value.encode())
if response_size > max_response_bytes:
raise ValueError(
@@ -233,48 +109,12 @@ def _get_registered_extension(ext_id: str) -> WasmExtension:
raise RuntimeError(f"WASM extension '{ext_id}' is not registered.")
async def _active_installed_extension(extension: WasmExtension) -> Any:
async def _extension_permissions(extension: WasmExtension) -> list[Any]:
installed_extension = await get_installed_extension(extension.id)
if (
not installed_extension
or settings.lnbits_extensions_deactivate_all
or not installed_extension.active
):
raise PermissionError(f"WASM extension '{extension.id}' is deactivated.")
return installed_extension
if not installed_extension:
return []
return installed_extension.permissions
def _user_id(user: Any | None) -> str | None:
return getattr(user, "id", None) if user else None
def _set_store_limits(store: Any, limits: dict[str, int]) -> None:
store.set_limits(
memory_size=_wasm_limit(limits["wasm_runtime_max_memory_bytes"]),
table_elements=_wasm_limit(limits["wasm_runtime_max_table_elements"]),
instances=_wasm_limit(limits["wasm_runtime_max_instances"]),
tables=_wasm_limit(limits["wasm_runtime_max_tables"]),
memories=_wasm_limit(limits["wasm_runtime_max_memories"]),
)
def _set_store_fuel(store: Any, limits: dict[str, int]) -> None:
store.set_fuel(
limits["wasm_runtime_max_fuel"]
if limits["wasm_runtime_max_fuel"] > 0
else _WASM_UNLIMITED_FUEL
)
def _check_wasm_request_size(request_bytes: int, limits: dict[str, int]) -> None:
max_request_bytes = limits["wasm_runtime_max_request_bytes"]
if max_request_bytes > 0 and request_bytes > max_request_bytes:
raise ValueError(f"WASM extension request is too large: {request_bytes} bytes.")
def _wasm_limit(value: int) -> int:
return value if value > 0 else -1
def _json_size(value: Any) -> int:
return len(json.dumps(value, default=str).encode())
+18 -25
View File
@@ -5,11 +5,6 @@ from dataclasses import dataclass
from pathlib import Path
from typing import Any
from lnbits.core.wasm_ext.wasm.config import (
WasmExtensionConfig,
WasmExtensionExport,
parse_wasm_extension_config,
)
from lnbits.settings import settings
@@ -22,13 +17,13 @@ class WasmExtension:
module_path: Path
wit_path: Path | None
world: str
exports: list[WasmExtensionExport]
config: WasmExtensionConfig
host_api: str
exports: list[dict[str, Any]]
config: dict[str, Any]
def is_wasm_extension_id(ext_id: str) -> bool:
ext_dir = Path(settings.lnbits_extensions_path, "extensions", ext_id)
config = _load_json(ext_dir / "config.json")
config = load_wasm_extension_config(ext_id)
return bool(config and config.get("extension_type") == "wasm")
@@ -37,38 +32,36 @@ def is_wasm_extension_dir(ext_dir: Path) -> bool:
return bool(config and config.get("extension_type") == "wasm")
def load_wasm_extension_config(ext_id: str) -> WasmExtensionConfig | None:
def load_wasm_extension_config(ext_id: str) -> dict[str, Any] | None:
ext_dir = Path(settings.lnbits_extensions_path, "extensions", ext_id)
config = _load_json(ext_dir / "config.json")
if not config or config.get("extension_type") != "wasm":
return None
return parse_wasm_extension_config(ext_id, config)
return _load_json(ext_dir / "config.json")
def load_wasm_extension(ext_id: str) -> WasmExtension:
ext_dir = Path(settings.lnbits_extensions_path, "extensions", ext_id)
raw_config = _load_json(ext_dir / "config.json")
if not raw_config:
config = load_wasm_extension_config(ext_id)
if not config:
raise FileNotFoundError(f"Missing WASM extension config for '{ext_id}'.")
if raw_config.get("extension_type") != "wasm":
if config.get("extension_type") != "wasm":
raise ValueError(f"Extension '{ext_id}' is not a WASM extension.")
config = parse_wasm_extension_config(ext_id, raw_config)
module_path = _extension_path(ext_dir, config.wasm.module)
wit_path = _optional_extension_path(ext_dir, config.wasm.wit)
wasm_config = config.get("wasm") or {}
module_path = _extension_path(ext_dir, wasm_config.get("module"))
wit_path = _optional_extension_path(ext_dir, wasm_config.get("wit"))
_check_wasm_module(module_path)
if wit_path and not wit_path.is_file():
raise FileNotFoundError(f"WIT file not found: {wit_path}")
return WasmExtension(
id=config.id,
name=config.name,
version=config.version,
id=config.get("id") or ext_id,
name=config.get("name") or ext_id,
version=config.get("version") or "0.0",
root_path=ext_dir,
module_path=module_path,
wit_path=wit_path,
world=config.wasm.world,
exports=config.wasm.exports,
world=wasm_config.get("world") or "",
host_api=wasm_config.get("host_api") or "lnbits.core.wasm_ext.ExtensionHostAPI",
exports=wasm_config.get("exports") or [],
config=config,
)
-29
View File
@@ -60,7 +60,6 @@ class ExtensionsSettings(LNbitsSettings):
lnbits_user_default_extensions: list[str] = Field(default=[])
lnbits_extensions_deactivate_all: bool = Field(default=False)
lnbits_extensions_builder_activate_non_admins: bool = Field(default=False)
lnbits_wasm_invocation_retention_days: int = Field(default=7, ge=0)
lnbits_extensions_reviews_url: str = Field(
default="https://demo.lnbits.com/paidreviews/api/v1/AdFzLjzuKFLsdk4Bcnff6r",
description="""
@@ -82,33 +81,6 @@ class ExtensionsSettings(LNbitsSettings):
return Path(settings.lnbits_data_folder, "extensions_builder")
class WasmRuntimeLimits(LNbitsSettings):
# 0 disables the limit. Installed WASM extensions may override these defaults.
wasm_runtime_max_memory_bytes: int = Field(default=64 * 1024 * 1024, ge=0)
wasm_runtime_max_execution_ms: int = Field(default=5_000, ge=0)
wasm_runtime_max_fuel: int = Field(default=100_000_000, ge=0)
wasm_runtime_max_response_bytes: int = Field(default=1024 * 1024, ge=0)
wasm_runtime_max_request_bytes: int = Field(default=1024 * 1024, ge=0)
wasm_runtime_max_wasm_stack_bytes: int = Field(default=1024 * 1024, ge=0)
wasm_runtime_max_table_elements: int = Field(default=10_000, ge=0)
wasm_runtime_max_instances: int = Field(default=8, ge=0)
wasm_runtime_max_tables: int = Field(default=10, ge=0)
wasm_runtime_max_memories: int = Field(default=1, ge=0)
wasm_runtime_max_concurrent_invocations: int = Field(default=16, ge=0)
wasm_runtime_max_concurrent_invocations_per_extension: int = Field(default=4, ge=0)
wasm_runtime_max_concurrent_invocations_per_user: int = Field(default=4, ge=0)
wasm_runtime_max_host_calls: int = Field(default=1_000, ge=0)
wasm_runtime_max_http_calls: int = Field(default=20, ge=0)
wasm_runtime_max_storage_calls: int = Field(default=100, ge=0)
wasm_runtime_max_wallet_calls: int = Field(default=20, ge=0)
wasm_runtime_http_timeout_ms: int = Field(default=5_000, ge=0)
wasm_runtime_max_http_response_bytes: int = Field(default=1024 * 1024, ge=0)
class ExtensionsInstallSettings(LNbitsSettings):
lnbits_extensions_default_install: list[str] = Field(default=[])
# required due to GitHUb rate-limit
@@ -1034,7 +1006,6 @@ class AuditSettings(LNbitsSettings):
class EditableSettings(
UsersSettings,
ExtensionsSettings,
WasmRuntimeLimits,
ThemesSettings,
OpsSettings,
AssetSettings,
File diff suppressed because one or more lines are too long
+1 -1
View File
File diff suppressed because one or more lines are too long
@@ -1,380 +0,0 @@
window.app.component('lnbits-admin-wasm-limit-config', {
props: ['form-data'],
template: '#lnbits-admin-wasm-limit-config',
data() {
return {
selectedWasmExtensionId: null,
wasmExtensionLimitDraft: {},
wasmExtensionLimitsSaving: false,
wasmRuntimeLimitExtensions: [],
wasmRuntimeLimitExtensionsLoading: false,
wasmLimitInfoDialog: {
show: false,
title: '',
details: ''
},
wasmRuntimeLimitGroups: [
{
title: 'Execution',
fields: [
{
name: 'wasm_runtime_max_execution_ms',
label: 'Max execution time (ms)',
description:
'Maximum wall-clock time allowed for one WASM invocation.',
details:
'This is the elapsed time from starting the invocation until the export returns. When the limit is reached LNbits requests an interrupt and records the invocation as timed out if it cannot finish quickly. Use this to stop long sleeps, slow host calls, and CPU loops that run for too long.'
},
{
name: 'wasm_runtime_max_fuel',
label: 'Max fuel',
description:
'Maximum Wasmtime instruction budget for one invocation.',
details:
'Fuel is Wasmtime instruction budgeting. It is more deterministic than wall-clock time for CPU-heavy loops because each executed instruction consumes budget. Set this low enough to stop busy loops, but high enough for legitimate extension startup and JSON processing.'
},
{
name: 'wasm_runtime_max_wasm_stack_bytes',
label: 'Max WASM stack (bytes)',
description: 'Maximum stack space for WASM calls and recursion.',
details:
'This limits stack used by WebAssembly function calls. It protects the server from deep recursion or very large call chains in extension code. If legitimate extensions fail with stack overflow traps, raise this carefully.'
}
]
},
{
title: 'Memory and Data Size',
fields: [
{
name: 'wasm_runtime_max_memory_bytes',
label: 'Max memory (bytes)',
description: 'Maximum WASM linear memory per invocation.',
details:
'This caps the linear memory visible to the WASM module. It limits memory.grow and can make instantiation fail if the module asks for too much memory up front. This does not include every byte used by the Python process or Wasmtime engine internals.'
},
{
name: 'wasm_runtime_max_request_bytes',
label: 'Max request size (bytes)',
description:
'Maximum serialized input payload accepted before execution.',
details:
'This caps the serialized payload passed into a WASM export before execution starts. It protects against huge HTTP bodies, oversized event data, and expensive JSON parsing. Requests above this limit should be rejected before invoking the extension.'
},
{
name: 'wasm_runtime_max_response_bytes',
label: 'Max response size (bytes)',
description:
'Maximum serialized response returned by a WASM export.',
details:
'This caps the JSON or string response returned by the WASM export. It prevents extensions from returning huge responses that consume memory, slow down API calls, or overload the browser. Responses above this limit are treated as invalid.'
}
]
},
{
title: 'Wasmtime Objects',
fields: [
{
name: 'wasm_runtime_max_table_elements',
label: 'Max table elements',
description: 'Maximum total elements allowed in WASM tables.',
details:
'Tables store references used by WebAssembly, commonly function references. Limiting table elements prevents a module from allocating very large reference tables. Each table element also has host memory overhead.'
},
{
name: 'wasm_runtime_max_instances',
label: 'Max instances',
description:
'Maximum WebAssembly instances allowed inside one store.',
details:
'This limits how many WebAssembly instances can be created inside one Wasmtime store. LNbits normally needs one instance per invocation, so a low value is expected. Raising it should only be needed if the runtime starts supporting modules that instantiate other modules.'
},
{
name: 'wasm_runtime_max_tables',
label: 'Max tables',
description:
'Maximum WebAssembly tables allowed inside one store.',
details:
'This limits the number of WebAssembly tables in the store. It is separate from table elements: one setting limits the number of tables, the other limits their total size. Keep this small unless a component model module legitimately needs more tables.'
},
{
name: 'wasm_runtime_max_memories',
label: 'Max memories',
description:
'Maximum WebAssembly linear memories allowed inside one store.',
details:
'This limits how many separate linear memories a module can create. Most extensions should need only one memory. Keep this small to reduce memory accounting complexity and prevent multi-memory abuse.'
}
]
},
{
title: 'Concurrency',
fields: [
{
name: 'wasm_runtime_max_concurrent_invocations',
label: 'Max concurrent invocations',
description:
'Maximum running WASM invocations across the server.',
details:
'This is the global cap for running WASM invocations across all extensions and users. It protects the LNbits process from thread exhaustion, CPU pressure, and too many simultaneous stores. New invocations should be rejected or queued once this is reached.'
},
{
name: 'wasm_runtime_max_concurrent_invocations_per_extension',
label: 'Max concurrent per extension',
description:
'Maximum running WASM invocations for one extension.',
details:
'This caps how many invocations a single extension can run at once. It prevents one malicious or buggy extension from consuming the whole global concurrency budget. Set it lower than the global limit.'
},
{
name: 'wasm_runtime_max_concurrent_invocations_per_user',
label: 'Max concurrent per user',
description: 'Maximum running WASM invocations for one user.',
details:
'This caps concurrent invocations attributed to one user. It helps protect against a user repeatedly clicking, refreshing, or scripting extension calls. Invocations without a user can still be governed by the global and per-extension limits.'
}
]
},
{
title: 'Host Calls',
fields: [
{
name: 'wasm_runtime_max_host_calls',
label: 'Max host calls',
description:
'Maximum total calls from WASM into LNbits host APIs.',
details:
'This is the total budget for calls from the WASM module into LNbits host APIs during one invocation. It should count all categories together. It limits chatty extensions and prevents tight loops that repeatedly call back into Python.'
},
{
name: 'wasm_runtime_max_http_calls',
label: 'Max HTTP calls',
description: 'Maximum outbound HTTP host calls per invocation.',
details:
'This caps outbound HTTP requests made through the host API during one invocation. It reduces SSRF blast radius, protects network resources, and limits slow external dependencies. It should be enforced together with HTTP timeout and response-size limits.'
},
{
name: 'wasm_runtime_max_storage_calls',
label: 'Max storage calls',
description: 'Maximum storage host calls per invocation.',
details:
'This caps extension storage operations during one invocation. It protects the database from excessive reads and writes triggered by malicious loops. Use it with storage payload-size limits if those are added later.'
},
{
name: 'wasm_runtime_max_wallet_calls',
label: 'Max wallet calls',
description: 'Maximum wallet/payment host calls per invocation.',
details:
'This caps wallet and payment-related host calls during one invocation. These calls are security-sensitive and may touch balances, invoices, or payments. Keep this conservative and rely on explicit permissions for what the extension is allowed to do.'
}
]
},
{
title: 'HTTP',
fields: [
{
name: 'wasm_runtime_http_timeout_ms',
label: 'HTTP timeout (ms)',
description: 'Maximum time allowed for one WASM HTTP request.',
details:
'This is the per-request timeout for HTTP calls made through the WASM host API. It prevents a slow remote server from holding an invocation open indefinitely. The total invocation timeout still applies across all work.'
},
{
name: 'wasm_runtime_max_http_response_bytes',
label: 'Max HTTP response size (bytes)',
description:
'Maximum response body size accepted from one WASM HTTP request.',
details:
'This caps the response body accepted from each HTTP call made by an extension. It protects memory and parsing time when a remote server returns a very large body. Responses above the limit should fail the host call.'
}
]
}
]
}
},
computed: {
adminKey() {
return this.g.user.wallets[0].adminkey
},
isExtensionLimitRoute() {
return this.$route.path.startsWith('/admin/extensions/wasm/limits/')
},
routeWasmExtensionId() {
return this.isExtensionLimitRoute ? this.$route.params.extId : null
},
backRoute() {
return this.isExtensionLimitRoute
? '/admin/extensions/wasm/limits'
: '/admin#extensions'
},
backTooltip() {
return this.isExtensionLimitRoute
? 'Wasm Limit Config'
: 'Extensions Settings'
},
pageDescription() {
if (this.isExtensionLimitRoute) {
return 'Customize limits for one installed WASM extension.'
}
return 'These values are global defaults. Use 0 to disable a global limit.'
},
wasmRuntimeLimitExtensionOptions() {
return this.wasmRuntimeLimitExtensions.map(extension => ({
label: `${extension.name || extension.id} (${extension.id})`,
value: extension.id
}))
},
selectedWasmRuntimeLimitExtension() {
return (
this.wasmRuntimeLimitExtensions.find(
extension => extension.id === this.selectedWasmExtensionId
) || null
)
},
customWasmLimitCount() {
const extension = this.selectedWasmRuntimeLimitExtension
if (!extension || !extension.wasm_runtime_limits) {
return 0
}
return Object.keys(extension.wasm_runtime_limits).length
}
},
watch: {
selectedWasmExtensionId() {
this.loadSelectedWasmRuntimeLimitExtension()
},
routeWasmExtensionId() {
this.syncWasmExtensionLimitRoute()
}
},
created() {
this.fetchWasmRuntimeLimitExtensions()
},
methods: {
async fetchWasmRuntimeLimitExtensions() {
this.wasmRuntimeLimitExtensionsLoading = true
try {
const {data} = await LNbits.api.request(
'GET',
'/api/v1/extension/wasm/runtime-limits/extensions',
this.adminKey
)
this.wasmRuntimeLimitExtensions = data || []
if (
this.selectedWasmExtensionId &&
!this.wasmRuntimeLimitExtensions.some(
extension => extension.id === this.selectedWasmExtensionId
)
) {
this.selectedWasmExtensionId = null
}
this.syncWasmExtensionLimitRoute()
} catch (error) {
LNbits.utils.notifyApiError(error)
} finally {
this.wasmRuntimeLimitExtensionsLoading = false
}
},
syncWasmExtensionLimitRoute() {
this.selectedWasmExtensionId = this.routeWasmExtensionId
this.loadSelectedWasmRuntimeLimitExtension()
},
openWasmExtensionLimit(extensionId) {
this.$router.push(
`/admin/extensions/wasm/limits/${encodeURIComponent(extensionId)}`
)
},
loadSelectedWasmRuntimeLimitExtension() {
const extension = this.selectedWasmRuntimeLimitExtension
this.wasmExtensionLimitDraft = extension
? {...(extension.wasm_runtime_limits || {})}
: {}
},
wasmExtensionLimitHint(field) {
const globalValue = this.formData[field.name]
return `Inherited global value: ${globalValue}. ${field.description}`
},
wasmExtensionLimitPlaceholder(field) {
const globalValue = this.formData[field.name]
return globalValue === undefined || globalValue === null
? ''
: String(globalValue)
},
normalizedWasmExtensionLimitDraft() {
const limits = {}
this.wasmRuntimeLimitGroups.forEach(group => {
group.fields.forEach(field => {
const value = this.wasmExtensionLimitDraft[field.name]
const cleanValue = typeof value === 'string' ? value.trim() : value
if (
cleanValue === '' ||
cleanValue === null ||
cleanValue === undefined
) {
return
}
const numericValue = Number(cleanValue)
if (
!Number.isFinite(numericValue) ||
!Number.isInteger(numericValue) ||
numericValue < 0
) {
throw new Error(`${field.label} must be a non-negative integer.`)
}
limits[field.name] = numericValue
})
})
return limits
},
async clearWasmExtensionLimits() {
this.wasmExtensionLimitDraft = {}
await this.saveWasmExtensionLimits()
},
async saveWasmExtensionLimits() {
if (!this.selectedWasmExtensionId) {
return
}
this.wasmExtensionLimitsSaving = true
try {
const {data} = await LNbits.api.request(
'PUT',
`/api/v1/extension/wasm/runtime-limits/${encodeURIComponent(
this.selectedWasmExtensionId
)}`,
this.adminKey,
{
limits: this.normalizedWasmExtensionLimitDraft()
}
)
const index = this.wasmRuntimeLimitExtensions.findIndex(
extension => extension.id === data.id
)
if (index >= 0) {
this.wasmRuntimeLimitExtensions.splice(index, 1, data)
}
this.loadSelectedWasmRuntimeLimitExtension()
Quasar.Notify.create({
type: 'positive',
message: 'WASM extension limits saved.'
})
} catch (error) {
if (error instanceof Error && !error.response) {
Quasar.Notify.create({
type: 'negative',
message: error.message
})
} else {
LNbits.utils.notifyApiError(error)
}
} finally {
this.wasmExtensionLimitsSaving = false
}
},
showWasmLimitInfo(field) {
this.wasmLimitInfoDialog = {
show: true,
title: field.label,
details: field.details
}
}
}
})
@@ -1,380 +0,0 @@
window.app.component('lnbits-admin-wasm-runtime', {
props: ['form-data'],
template: '#lnbits-admin-wasm-runtime',
data() {
return {
wasmRuntimeLoading: false,
wasmHistoryLoading: false,
wasmRuntimeTimer: null,
wasmStats: {},
wasmCurrentInvocations: [],
wasmInvocationHistory: [],
wasmStatItems: [
{key: 'total', label: 'Total', icon: 'data_usage', color: 'primary'},
{key: 'running', label: 'Running', icon: 'play_circle', color: 'green'},
{key: 'completed', label: 'Completed', icon: 'task_alt', color: 'teal'},
{key: 'failed', label: 'Failed', icon: 'error', color: 'red'},
{
key: 'stopped',
label: 'Stopped',
icon: 'stop_circle',
color: 'orange'
},
{key: 'timeout', label: 'Timeouts', icon: 'timer_off', color: 'purple'}
],
wasmCurrentColumns: [
{
name: 'extension_id',
label: 'Extension',
field: 'extension_id',
align: 'left',
sortable: true
},
{
name: 'export_name',
label: 'Export',
field: 'export_name',
align: 'left',
sortable: true
},
{
name: 'trigger_type',
label: 'Trigger',
field: 'trigger_type',
align: 'left',
sortable: true
},
{
name: 'status',
label: 'Status',
field: 'status',
align: 'left',
sortable: true
},
{
name: 'user_id',
label: 'User',
field: 'user_id',
align: 'left',
sortable: true
},
{
name: 'started_at',
label: 'Started',
field: 'started_at',
align: 'left',
sortable: true
},
{
name: 'duration_ms',
label: 'Duration',
field: row => row.duration_ms || 0,
align: 'right',
sortable: true
},
{
name: 'context',
label: 'Context',
field: row => this.wasmContextValue(row),
align: 'left',
sortable: true
},
{name: 'actions', label: '', field: 'actions', align: 'right'}
],
wasmHistoryColumns: [
{
name: 'extension_id',
label: 'Extension',
field: 'extension_id',
align: 'left',
sortable: true
},
{
name: 'export_name',
label: 'Export',
field: 'export_name',
align: 'left',
sortable: true
},
{
name: 'trigger_type',
label: 'Trigger',
field: 'trigger_type',
align: 'left',
sortable: true
},
{
name: 'status',
label: 'Status',
field: 'status',
align: 'left',
sortable: true
},
{
name: 'user_id',
label: 'User',
field: 'user_id',
align: 'left',
sortable: true
},
{
name: 'started_at',
label: 'Started',
field: 'started_at',
align: 'left',
sortable: true
},
{
name: 'duration_ms',
label: 'Duration',
field: row => row.duration_ms || 0,
align: 'right',
sortable: true
},
{
name: 'calls',
label: 'Calls',
field: row => this.wasmCallCount(row),
align: 'left',
sortable: true
},
{
name: 'context',
label: 'Context',
field: row => this.wasmContextValue(row),
align: 'left',
sortable: true
},
{
name: 'error_message',
label: 'Error/Stop Reason',
field: row => row.error_message || row.stop_reason || '',
align: 'left',
sortable: true
}
]
}
},
computed: {
adminKey() {
return this.g.user.wallets[0].adminkey
},
wasmExtensionId() {
return this.$route.params.extId || null
},
wasmExtensionQuery() {
if (!this.wasmExtensionId) {
return ''
}
return `extension_id=${encodeURIComponent(this.wasmExtensionId)}`
}
},
watch: {
wasmExtensionId() {
this.fetchWasmRuntime()
}
},
methods: {
async fetchWasmRuntime() {
await Promise.all([
this.fetchWasmCurrentInvocations(),
this.fetchWasmInvocationHistory(),
this.fetchWasmInvocationStats()
])
},
async fetchWasmCurrentInvocations() {
this.wasmRuntimeLoading = true
try {
const query = this.wasmExtensionQuery
? `?${this.wasmExtensionQuery}`
: ''
const {data} = await LNbits.api.request(
'GET',
`/api/v1/extension/wasm/invocations/current${query}`,
this.adminKey
)
this.wasmCurrentInvocations = data || []
} catch (error) {
LNbits.utils.notifyApiError(error)
} finally {
this.wasmRuntimeLoading = false
}
},
async fetchWasmInvocationHistory() {
this.wasmHistoryLoading = true
try {
const params = ['limit=50']
if (this.wasmExtensionQuery) {
params.push(this.wasmExtensionQuery)
}
const {data} = await LNbits.api.request(
'GET',
`/api/v1/extension/wasm/invocations?${params.join('&')}`,
this.adminKey
)
this.wasmInvocationHistory = data || []
} catch (error) {
LNbits.utils.notifyApiError(error)
} finally {
this.wasmHistoryLoading = false
}
},
async fetchWasmInvocationStats() {
try {
const params = ['hours=24']
if (this.wasmExtensionQuery) {
params.push(this.wasmExtensionQuery)
}
const {data} = await LNbits.api.request(
'GET',
`/api/v1/extension/wasm/invocations/stats?${params.join('&')}`,
this.adminKey
)
this.wasmStats = data || {}
} catch (error) {
LNbits.utils.notifyApiError(error)
}
},
async stopWasmInvocation(invocationId) {
try {
await LNbits.api.request(
'POST',
`/api/v1/extension/wasm/invocations/${encodeURIComponent(invocationId)}/stop`,
this.adminKey
)
Quasar.Notify.create({
type: 'positive',
message: 'WASM invocation stop requested.'
})
await this.fetchWasmRuntime()
} catch (error) {
LNbits.utils.notifyApiError(error)
}
},
deactivateWasmExtension(extensionId) {
LNbits.utils
.confirmDialog(
`Deactivate extension '${extensionId}'?`,
'Deactivate Extension'
)
.onOk(async () => {
try {
await LNbits.api.request(
'PUT',
`/api/v1/extension/${encodeURIComponent(extensionId)}/deactivate`,
this.adminKey
)
Quasar.Notify.create({
type: 'positive',
message: `Extension '${extensionId}' deactivated.`
})
await this.fetchWasmRuntime()
} catch (error) {
LNbits.utils.notifyApiError(error)
}
})
},
formatWasmStat(key) {
const value = this.wasmStats[key]
return value === undefined || value === null ? '0' : String(value)
},
formatWasmDate(value) {
return value ? this.utils.formatDate(value) : ''
},
wasmStatusColor(status) {
return (
{
running: 'green',
stopping: 'orange',
completed: 'teal',
failed: 'red',
stopped: 'orange',
timeout: 'purple',
abandoned: 'grey'
}[status] || 'grey'
)
},
wasmTriggerColor(triggerType) {
return (
{
http: 'primary',
event: 'purple'
}[triggerType] || 'grey'
)
},
formatWasmDuration(row) {
let duration = row.duration_ms
if (
(row.status === 'running' || row.status === 'stopping') &&
row.started_at
) {
duration = Date.now() - new Date(row.started_at).getTime()
}
if (duration === undefined || duration === null) {
return ''
}
if (duration >= 1000) {
return `${(duration / 1000).toFixed(1)}s`
}
return `${duration}ms`
},
formatWasmCalls(row) {
return [
`host ${row.host_call_count || 0}`,
`http ${row.http_call_count || 0}`,
`storage ${row.storage_call_count || 0}`,
`wallet ${row.wallet_call_count || 0}`
].join(' / ')
},
wasmCallCount(row) {
return (
(row.host_call_count || 0) +
(row.http_call_count || 0) +
(row.storage_call_count || 0) +
(row.wallet_call_count || 0)
)
},
wasmContextValue(row) {
return [
row.method,
row.path,
row.event_type,
row.wallet_id,
row.payment_hash
]
.filter(Boolean)
.join(' ')
},
formatWasmContext(row) {
const items = [
row.method,
row.path,
row.event_type,
row.wallet_id ? `wallet ${row.wallet_id}` : '',
row.payment_hash ? `payment ${row.payment_hash.slice(0, 12)}...` : ''
].filter(Boolean)
return items.join(' | ')
},
formatWasmUserId(userId) {
if (!userId) {
return '-'
}
const value = String(userId)
if (value.length <= 12) {
return value
}
return `${value.slice(0, 3)}...${value.slice(-3)}`
}
},
created() {
this.fetchWasmRuntime()
this.wasmRuntimeTimer = setInterval(() => {
this.fetchWasmCurrentInvocations()
}, 5000)
},
unmounted() {
if (this.wasmRuntimeTimer) {
clearInterval(this.wasmRuntimeTimer)
}
}
})
-20
View File
@@ -99,26 +99,6 @@ const routes = [
name: 'Users',
component: PageUsers
},
{
path: '/admin/extensions/wasm',
name: 'AdminWasmRuntime',
component: PageAdmin
},
{
path: '/admin/extensions/wasm/limits',
name: 'AdminWasmLimitConfig',
component: PageAdmin
},
{
path: '/admin/extensions/wasm/limits/:extId',
name: 'AdminWasmLimitConfigDetail',
component: PageAdmin
},
{
path: '/admin/extensions/wasm/:extId',
name: 'AdminWasmRuntimeDetail',
component: PageAdmin
},
{
path: '/admin',
name: 'Admin',
+6 -35
View File
@@ -16,26 +16,18 @@ window.PageAdmin = {
},
watch: {
tab(tab) {
if (
['wasm-runtime', 'wasm-limit-config'].includes(tab) &&
this.$route.path.startsWith('/admin/extensions/wasm')
) {
return
}
const target = this.adminRouteForTab(tab)
if (this.$route.fullPath !== target) {
this.$router.push(target)
}
this.$router.push(`/admin#${tab}`)
},
$route(to) {
const tab = this.adminTabFromRoute(to)
if (this.tab !== tab) {
this.tab = tab
if (to.hash.length > 1) {
this.tab = to.hash.replace('#', '')
}
}
},
async created() {
this.tab = this.adminTabFromRoute(this.$route)
if (this.$route.hash.length > 1) {
this.tab = this.$route.hash.replace('#', '')
}
await this.getSettings()
},
computed: {
@@ -44,27 +36,6 @@ window.PageAdmin = {
}
},
methods: {
adminTabFromRoute(route) {
if (route.path.startsWith('/admin/extensions/wasm/limits')) {
return 'wasm-limit-config'
}
if (route.path.startsWith('/admin/extensions/wasm')) {
return 'wasm-runtime'
}
if (route.hash.length > 1) {
return route.hash.replace('#', '')
}
return 'funding'
},
adminRouteForTab(tab) {
if (tab === 'wasm-runtime') {
return '/admin/extensions/wasm'
}
if (tab === 'wasm-limit-config') {
return '/admin/extensions/wasm/limits'
}
return `/admin#${tab}`
},
getDefaultSetting(fieldName) {
LNbits.api.getDefaultSetting(fieldName).then(response => {
this.formData[fieldName] = response.data.default_value
-5
View File
@@ -164,11 +164,6 @@ window.PageExtensions = {
)
extension.isAvailable = true
extension.isInstalled = true
extension.isWasm =
response.data.is_wasm === true ||
response.data.isWasm === true ||
release.extension_type === 'wasm' ||
extension.isWasm === true
extension.icon = response.data.icon || extension.icon
extension.installedRelease = release
this.toggleExtension(extension)
-2
View File
@@ -67,8 +67,6 @@
"js/components/admin/lnbits-admin-users.js",
"js/components/admin/lnbits-admin-server.js",
"js/components/admin/lnbits-admin-extensions.js",
"js/components/admin/lnbits-admin-wasm-runtime.js",
"js/components/admin/lnbits-admin-wasm-limit-config.js",
"js/components/admin/lnbits-admin-notifications.js",
"js/components/admin/lnbits-admin-site-customisation.js",
"js/components/admin/lnbits-admin-assets-config.js",
-2
View File
@@ -8,8 +8,6 @@ include('components/admin/users.vue') %} {%
include('components/admin/site_customisation.vue') %} {%
include('components/admin/audit.vue') %} {%
include('components/admin/extensions.vue') %} {%
include('components/admin/wasm-runtime.vue') %} {%
include('components/admin/wasm-limit-config.vue') %} {%
include('components/admin/assets-config.vue') %} {%
include('components/admin/notifications.vue') %} {%
include('components/admin/server.vue') %} {%
@@ -1,11 +1,9 @@
<template id="lnbits-admin-extensions">
<q-card-section class="q-pa-none">
<div>
<div class="row items-center justify-between q-mb-md">
<h6 class="q-my-none">
<span v-text="$t('extensions')"></span>
</h6>
</div>
<h6 class="q-my-none">
<span v-text="$t('extensions')"></span>
</h6>
<div class="row q-col-gutter-md">
<div class="col-12 q-mb-md">
<p>
@@ -35,27 +33,6 @@
</div>
</div>
</div>
<div class="row q-col-gutter-md">
<div class="col-12 q-mb-md">
<p>Wasm Extension</p>
<div class="row q-gutter-sm">
<q-btn
unelevated
color="primary"
icon="memory"
label="WASM Runtime"
to="/admin/extensions/wasm"
></q-btn>
<q-btn
unelevated
color="primary"
icon="tune"
label="Wasm Limit Config"
to="/admin/extensions/wasm/limits"
></q-btn>
</div>
</div>
</div>
<div class="row q-col-gutter-md">
<div class="col-12 col-md-6">
<p>
@@ -147,15 +124,6 @@
/>
</q-item-section>
</q-item>
<q-input
class="q-mt-md"
filled
v-model.number="formData.lnbits_wasm_invocation_retention_days"
type="number"
min="0"
label="WASM invocation retention days"
hint="Set to 0 to disable automatic cleanup."
></q-input>
<br />
</div>
<div class="col-12 col-md-6">
@@ -1,242 +0,0 @@
<template id="lnbits-admin-wasm-limit-config">
<q-card-section class="q-pa-none">
<div>
<div class="row items-center justify-between q-mb-md q-col-gutter-sm">
<div class="row items-center q-gutter-sm">
<q-btn flat dense round icon="arrow_back" :to="backRoute">
<q-tooltip v-text="backTooltip"></q-tooltip>
</q-btn>
<div>
<h6 class="q-my-none">Wasm Limit Config</h6>
<div
class="text-caption text-grey-7"
v-text="pageDescription"
></div>
</div>
</div>
<q-btn-dropdown
unelevated
color="primary"
icon="tune"
label="Custom Extension Limit"
:loading="wasmRuntimeLimitExtensionsLoading"
>
<q-list style="min-width: 280px; max-width: min(420px, 90vw)">
<q-item-label header>
Select an extension from the list to customize
</q-item-label>
<q-item
v-if="
!wasmRuntimeLimitExtensionsLoading &&
wasmRuntimeLimitExtensionOptions.length === 0
"
>
<q-item-section>
<q-item-label>No installed WASM extensions found.</q-item-label>
</q-item-section>
</q-item>
<q-item
v-for="extension in wasmRuntimeLimitExtensionOptions"
:key="extension.value"
clickable
v-close-popup
@click="openWasmExtensionLimit(extension.value)"
>
<q-item-section>
<q-item-label v-text="extension.label"></q-item-label>
</q-item-section>
</q-item>
</q-list>
</q-btn-dropdown>
</div>
<template v-if="!isExtensionLimitRoute">
<div
v-for="(group, index) in wasmRuntimeLimitGroups"
:key="group.title"
class="q-mb-md"
>
<q-expansion-item
expand-separator
:default-opened="group.title === 'Execution'"
:label="group.title"
header-class="text-subtitle2 text-weight-medium"
>
<div class="row q-col-gutter-md q-pt-md">
<div
v-for="field in group.fields"
:key="field.name"
class="col-12 col-md-6"
>
<q-input
filled
dense
type="number"
min="0"
v-model.number="formData[field.name]"
:label="field.label"
:hint="field.description"
>
<template v-slot:append>
<q-btn
dense
flat
round
icon="info"
color="primary"
@click.stop.prevent="showWasmLimitInfo(field)"
>
<q-tooltip max-width="360px">
<span v-text="field.details"></span>
</q-tooltip>
</q-btn>
</template>
</q-input>
</div>
</div>
</q-expansion-item>
<q-separator
v-if="index < wasmRuntimeLimitGroups.length - 1"
class="q-mt-md"
></q-separator>
</div>
</template>
<div
v-if="isExtensionLimitRoute"
class="row items-center justify-between q-mb-md"
>
<div>
<div class="text-subtitle1 text-weight-medium">
Extension overrides
</div>
<div class="text-caption text-grey-7">
Empty values inherit the global defaults. A saved 0 disables that
limit for the selected extension.
</div>
</div>
<div v-if="selectedWasmRuntimeLimitExtension" class="col-12 col-md-7">
<div class="row items-center q-gutter-sm full-height">
<q-chip
dense
:color="
selectedWasmRuntimeLimitExtension.active ? 'positive' : 'grey-7'
"
text-color="white"
:label="
selectedWasmRuntimeLimitExtension.active ? 'Active' : 'Inactive'
"
></q-chip>
<q-chip
dense
outline
color="primary"
:label="customWasmLimitCount + ' custom overrides'"
></q-chip>
</div>
</div>
</div>
<q-banner
v-if="
isExtensionLimitRoute &&
!wasmRuntimeLimitExtensionsLoading &&
!selectedWasmRuntimeLimitExtension
"
rounded
class="bg-grey-2 text-grey-8 q-mb-lg"
>
WASM extension not found.
</q-banner>
<div v-if="isExtensionLimitRoute && selectedWasmRuntimeLimitExtension">
<div
v-for="(group, index) in wasmRuntimeLimitGroups"
:key="'extension-' + group.title"
class="q-mb-md"
>
<q-expansion-item
expand-separator
:default-opened="group.title === 'Execution'"
:label="group.title"
header-class="text-subtitle2 text-weight-medium"
>
<div class="row q-col-gutter-md q-pt-md">
<div
v-for="field in group.fields"
:key="'extension-' + field.name"
class="col-12 col-md-6"
>
<q-input
filled
dense
type="number"
min="0"
v-model="wasmExtensionLimitDraft[field.name]"
:label="field.label"
:hint="wasmExtensionLimitHint(field)"
:placeholder="wasmExtensionLimitPlaceholder(field)"
>
<template v-slot:append>
<q-btn
dense
flat
round
icon="info"
color="primary"
@click.stop.prevent="showWasmLimitInfo(field)"
>
<q-tooltip max-width="360px">
<span v-text="field.details"></span>
</q-tooltip>
</q-btn>
</template>
</q-input>
</div>
</div>
</q-expansion-item>
<q-separator
v-if="index < wasmRuntimeLimitGroups.length - 1"
class="q-mt-md"
></q-separator>
</div>
<div class="row justify-end q-gutter-sm q-mt-md">
<q-btn
flat
color="primary"
icon="restart_alt"
label="Clear Overrides"
:disable="wasmExtensionLimitsSaving"
@click="clearWasmExtensionLimits"
></q-btn>
<q-btn
unelevated
color="primary"
icon="save"
label="Save Extension Limits"
:loading="wasmExtensionLimitsSaving"
@click="saveWasmExtensionLimits"
></q-btn>
</div>
</div>
<q-dialog v-model="wasmLimitInfoDialog.show">
<q-card style="width: min(560px, calc(100vw - 32px)); max-width: 560px">
<q-card-section class="row items-center q-pb-none">
<div class="text-h6" v-text="wasmLimitInfoDialog.title"></div>
<q-space></q-space>
<q-btn v-close-popup flat round dense icon="close"></q-btn>
</q-card-section>
<q-card-section>
<div
class="text-body1"
style="line-height: 1.6"
v-text="wasmLimitInfoDialog.details"
></div>
</q-card-section>
</q-card>
</q-dialog>
</div>
</q-card-section>
</template>
@@ -1,245 +0,0 @@
<template id="lnbits-admin-wasm-runtime">
<q-card-section class="q-pa-none">
<div>
<div class="row items-center justify-between q-mb-md">
<div class="row items-center q-gutter-sm">
<q-btn
flat
dense
round
icon="arrow_back"
:to="
wasmExtensionId ? '/admin/extensions/wasm' : '/admin#extensions'
"
>
<q-tooltip
v-text="
wasmExtensionId ? 'Global WASM Runtime' : 'Extensions Settings'
"
></q-tooltip>
</q-btn>
<div>
<h6 class="q-my-none">WASM Runtime</h6>
<div
v-if="wasmExtensionId"
class="text-caption text-grey-7"
v-text="`Extension: ${wasmExtensionId}`"
></div>
</div>
</div>
<div>
<q-btn
flat
dense
icon="refresh"
:loading="wasmRuntimeLoading"
@click="fetchWasmRuntime"
>
<q-tooltip>Refresh runtime data</q-tooltip>
</q-btn>
</div>
</div>
<div class="row q-col-gutter-md q-mb-md">
<div
v-for="item in wasmStatItems"
:key="item.key"
class="col-6 col-sm-4 col-md-2"
>
<q-card flat bordered class="full-height">
<q-card-section class="q-pa-sm">
<div class="row items-center no-wrap q-gutter-sm">
<q-avatar
rounded
size="34px"
:color="item.color"
text-color="white"
:icon="item.icon"
></q-avatar>
<div class="col">
<div
class="text-caption text-grey-7"
v-text="item.label"
></div>
<div
class="text-h6 text-weight-bold"
v-text="formatWasmStat(item.key)"
></div>
</div>
</div>
</q-card-section>
</q-card>
</div>
</div>
<q-table
class="q-mb-lg"
dense
flat
wrap-cells
:rows="wasmCurrentInvocations"
:columns="wasmCurrentColumns"
row-key="id"
:loading="wasmRuntimeLoading"
:pagination="{rowsPerPage: 5}"
table-style="table-layout: fixed; width: 100%"
title="Current Invocations"
>
<template v-slot:body-cell-extension_id="props">
<q-td :props="props">
<q-btn
dense
flat
no-caps
color="primary"
:label="props.row.extension_id"
:to="`/admin/extensions/wasm/${encodeURIComponent(props.row.extension_id)}`"
></q-btn>
</q-td>
</template>
<template v-slot:body-cell-trigger_type="props">
<q-td :props="props">
<q-badge
outline
:color="wasmTriggerColor(props.row.trigger_type)"
v-text="props.row.trigger_type"
></q-badge>
</q-td>
</template>
<template v-slot:body-cell-status="props">
<q-td :props="props">
<q-badge
:color="wasmStatusColor(props.row.status)"
v-text="props.row.status"
></q-badge>
</q-td>
</template>
<template v-slot:body-cell-user_id="props">
<q-td :props="props">
<span v-if="props.row.user_id">
<span v-text="formatWasmUserId(props.row.user_id)"></span>
<q-tooltip v-text="props.row.user_id"></q-tooltip>
</span>
<span v-else>-</span>
</q-td>
</template>
<template v-slot:body-cell-started_at="props">
<q-td
:props="props"
v-text="formatWasmDate(props.row.started_at)"
></q-td>
</template>
<template v-slot:body-cell-duration_ms="props">
<q-td :props="props" v-text="formatWasmDuration(props.row)"></q-td>
</template>
<template v-slot:body-cell-context="props">
<q-td :props="props">
<div
style="white-space: normal; word-break: break-word"
v-text="formatWasmContext(props.row)"
></div>
</q-td>
</template>
<template v-slot:body-cell-actions="props">
<q-td :props="props">
<div class="row justify-end q-gutter-xs">
<q-btn
dense
flat
color="negative"
icon="stop_circle"
@click="stopWasmInvocation(props.row.id)"
>
<q-tooltip>Stop Invocation</q-tooltip>
</q-btn>
<q-btn
dense
unelevated
color="negative"
label="Deactivate Extension"
@click="deactivateWasmExtension(props.row.extension_id)"
></q-btn>
</div>
</q-td>
</template>
</q-table>
<q-table
dense
flat
wrap-cells
:rows="wasmInvocationHistory"
:columns="wasmHistoryColumns"
row-key="id"
:loading="wasmHistoryLoading"
:pagination="{rowsPerPage: 10}"
table-style="table-layout: fixed; width: 100%"
title="Recent Invocations"
>
<template v-slot:body-cell-extension_id="props">
<q-td :props="props">
<q-btn
dense
flat
no-caps
color="primary"
:label="props.row.extension_id"
:to="`/admin/extensions/wasm/${encodeURIComponent(props.row.extension_id)}`"
></q-btn>
</q-td>
</template>
<template v-slot:body-cell-trigger_type="props">
<q-td :props="props">
<q-badge
outline
:color="wasmTriggerColor(props.row.trigger_type)"
v-text="props.row.trigger_type"
></q-badge>
</q-td>
</template>
<template v-slot:body-cell-status="props">
<q-td :props="props">
<q-badge
:color="wasmStatusColor(props.row.status)"
v-text="props.row.status"
></q-badge>
</q-td>
</template>
<template v-slot:body-cell-user_id="props">
<q-td :props="props">
<span v-if="props.row.user_id">
<span v-text="formatWasmUserId(props.row.user_id)"></span>
<q-tooltip v-text="props.row.user_id"></q-tooltip>
</span>
<span v-else>-</span>
</q-td>
</template>
<template v-slot:body-cell-started_at="props">
<q-td
:props="props"
v-text="formatWasmDate(props.row.started_at)"
></q-td>
</template>
<template v-slot:body-cell-duration_ms="props">
<q-td :props="props" v-text="formatWasmDuration(props.row)"></q-td>
</template>
<template v-slot:body-cell-calls="props">
<q-td :props="props" v-text="formatWasmCalls(props.row)"></q-td>
</template>
<template v-slot:body-cell-context="props">
<q-td :props="props">
<div
style="white-space: normal; word-break: break-word"
v-text="formatWasmContext(props.row)"
></div>
</q-td>
</template>
<template v-slot:body-cell-error_message="props">
<q-td :props="props">
<span
style="white-space: normal; word-break: break-word"
v-text="props.row.error_message || props.row.stop_reason || ''"
></span>
</q-td>
</template>
</q-table>
</div>
</q-card-section>
</template>
+1 -13
View File
@@ -74,13 +74,7 @@
<div class="col q-gutter-y-md">
<q-card>
<!-- Mobile: Dropdown menu at top -->
<div
v-if="
$q.screen.lt.md &&
!['wasm-runtime', 'wasm-limit-config'].includes(tab)
"
class="q-px-md q-pt-md"
>
<div v-if="$q.screen.lt.md" class="q-px-md q-pt-md">
<q-select
v-model="tab"
:options="[
@@ -226,12 +220,6 @@
<q-tab-panel name="extensions">
<lnbits-admin-extensions :form-data="formData" />
</q-tab-panel>
<q-tab-panel name="wasm-runtime">
<lnbits-admin-wasm-runtime :form-data="formData" />
</q-tab-panel>
<q-tab-panel name="wasm-limit-config">
<lnbits-admin-wasm-limit-config :form-data="formData" />
</q-tab-panel>
<q-tab-panel name="notifications">
<lnbits-admin-notifications :form-data="formData" />
</q-tab-panel>
-2
View File
@@ -120,8 +120,6 @@
"js/components/admin/lnbits-admin-users.js",
"js/components/admin/lnbits-admin-server.js",
"js/components/admin/lnbits-admin-extensions.js",
"js/components/admin/lnbits-admin-wasm-runtime.js",
"js/components/admin/lnbits-admin-wasm-limit-config.js",
"js/components/admin/lnbits-admin-notifications.js",
"js/components/admin/lnbits-admin-site-customisation.js",
"js/components/admin/lnbits-admin-assets-config.js",
+1 -1
View File
@@ -89,7 +89,7 @@ def run_before_and_after_tests(settings: Settings):
@pytest.fixture(scope="session")
async def app(settings: Settings):
app = create_app()
async with LifespanManager(app, startup_timeout=30) as manager:
async with LifespanManager(app) as manager:
settings.first_install = True
await first_install(
UpdateSuperuserPassword(
+3 -10
View File
@@ -1433,7 +1433,7 @@ def test_check_revolut_signature_multiple_v1_headers():
check_revolut_signature(payload, sig_header, timestamp, secret)
def test_check_revolut_signature_docs_vector(mocker: MockerFixture):
def test_check_revolut_signature_docs_vector():
payload = (
b'{"data":{"id":"645a7696-22f3-aa47-9c74-cbae0449cc46",'
b'"new_state":"completed","old_state":"pending",'
@@ -1445,16 +1445,9 @@ def test_check_revolut_signature_docs_vector(mocker: MockerFixture):
secret = "wsk_r59a4HfWVAKycbCaNO1RvgCJec02gRd8"
sig = "v1=bca326fb378d0da7f7c490ad584a8106bab9723d8d9cdd0d50b4c5b3be3837c0"
# This is a fixed vector straight from Revolut's docs, so its timestamp is
# necessarily in the past. Freeze time to it instead of growing
# tolerance_seconds indefinitely as real time marches on.
mocker.patch(
"lnbits.core.services.fiat_providers.time.time",
return_value=int(timestamp) / 1000,
check_revolut_signature(
payload, sig, timestamp, secret, tolerance_seconds=100000000
)
check_revolut_signature(payload, sig, timestamp, secret)
check_revolut_signature(payload, sig, timestamp, secret)
@pytest.mark.anyio
-270
View File
@@ -14,21 +14,14 @@ from lnbits.core.models.extensions import (
InstallableExtension,
ReleasePaymentInfo,
)
from lnbits.core.services import extensions as extension_services
from lnbits.core.services.extensions import (
activate_extension,
attach_wasm_invocation_runtime,
deactivate_extension,
finish_wasm_invocation,
get_current_wasm_invocations,
get_valid_extension,
get_valid_extensions,
install_extension,
record_wasm_invocation_host_call,
start_extension_background_work,
start_wasm_invocation,
stop_extension_background_work,
stop_wasm_invocation,
uninstall_extension,
)
from lnbits.settings import Settings
@@ -226,269 +219,6 @@ async def test_stop_extension_background_work_handles_missing_and_async_stops(
assert called["stop"] is True
@pytest.mark.anyio
async def test_wasm_invocation_tracking_counts_and_stops(mocker: MockerFixture):
_reset_wasm_invocation_state()
mocker.patch(
"lnbits.core.services.extensions.create_wasm_invocation",
mocker.AsyncMock(),
)
update_mock = mocker.patch(
"lnbits.core.services.extensions.update_wasm_invocation",
mocker.AsyncMock(),
)
mocker.patch(
"lnbits.core.services.extensions.get_wasm_invocation",
mocker.AsyncMock(return_value=None),
)
mocker.patch(
"lnbits.core.services.extensions.mark_stale_wasm_invocations",
mocker.AsyncMock(),
)
mocker.patch(
"lnbits.core.services.extensions.delete_old_wasm_invocations",
mocker.AsyncMock(),
)
invocation = await start_wasm_invocation(
extension_id="demoext",
export_name="render",
trigger_type="http",
method="POST",
path="/api/v1/ext/demoext/run",
context={"origin": "https://example.com"},
)
store = SimpleNamespace(deadline=None)
store.set_epoch_deadline = lambda deadline: setattr(store, "deadline", deadline)
engine = SimpleNamespace(increments=0)
def increment_epoch():
engine.increments += 1
engine.increment_epoch = increment_epoch
attach_wasm_invocation_runtime(invocation.id, engine=engine, store=store)
record_wasm_invocation_host_call(invocation.id, "http.request")
record_wasm_invocation_host_call(invocation.id, "storage.get")
assert await stop_wasm_invocation(invocation.id, reason="test stop") is True
current = get_current_wasm_invocations()
assert current[0].status == "stopping"
assert store.deadline == 1
assert engine.increments == 1
await finish_wasm_invocation(invocation.id, status="failed")
assert update_mock.await_args is not None
saved = update_mock.await_args.args[0]
assert saved.status == "stopped"
assert saved.stop_reason == "test stop"
assert saved.host_call_count == 2
assert saved.http_call_count == 1
assert saved.storage_call_count == 1
def _reset_wasm_invocation_state():
with extension_services._wasm_invocation_lock:
extension_services._wasm_invocation_handles.clear()
extension_services._wasm_invocations_marked_stale = False
extension_services._wasm_invocations_last_cleanup_at = None
def test_wasm_runtime_limits_merge_sparse_extension_overrides(settings: Settings):
original_execution_ms = settings.wasm_runtime_max_execution_ms
original_memory_bytes = settings.wasm_runtime_max_memory_bytes
try:
settings.wasm_runtime_max_execution_ms = 5_000
settings.wasm_runtime_max_memory_bytes = 64 * 1024 * 1024
extension = InstallableExtension(
id="wasm_demo",
name="WASM Demo",
version="1.0.0",
wasm_runtime_limits={
"wasm_runtime_max_execution_ms": 20_000,
"wasm_runtime_max_fuel": 0,
},
)
limits = extension_services.resolve_wasm_runtime_limits(extension)
assert limits["wasm_runtime_max_execution_ms"] == 20_000
assert limits["wasm_runtime_max_fuel"] == 0
assert limits["wasm_runtime_max_memory_bytes"] == 64 * 1024 * 1024
finally:
settings.wasm_runtime_max_execution_ms = original_execution_ms
settings.wasm_runtime_max_memory_bytes = original_memory_bytes
def test_wasm_runtime_limit_override_validation():
assert extension_services.validate_wasm_runtime_limit_overrides(
{
"wasm_runtime_max_execution_ms": "7000",
"wasm_runtime_max_fuel": 0,
"wasm_runtime_max_memory_bytes": "",
}
) == {
"wasm_runtime_max_execution_ms": 7000,
"wasm_runtime_max_fuel": 0,
}
with pytest.raises(ValueError, match="Unknown WASM runtime limit field"):
extension_services.validate_wasm_runtime_limit_overrides({"unknown": 1})
with pytest.raises(ValueError, match="cannot be negative"):
extension_services.validate_wasm_runtime_limit_overrides(
{"wasm_runtime_max_execution_ms": -1}
)
with pytest.raises(ValueError, match="must be an integer"):
extension_services.validate_wasm_runtime_limit_overrides(
{"wasm_runtime_max_execution_ms": True}
)
with pytest.raises(ValueError, match="must be an integer"):
extension_services.validate_wasm_runtime_limit_overrides(
{"wasm_runtime_max_execution_ms": 1.5}
)
@pytest.mark.anyio
async def test_update_wasm_extension_runtime_limits_saves_sparse_overrides(
tmp_path,
settings: Settings,
mocker: MockerFixture,
):
ext_id = "wasm_demo"
original_extensions_path = settings.lnbits_extensions_path
try:
settings.lnbits_extensions_path = str(tmp_path)
config_dir = tmp_path / "extensions" / ext_id
config_dir.mkdir(parents=True)
(config_dir / "config.json").write_text(
'{"extension_type": "wasm"}',
encoding="utf-8",
)
installed_extension = InstallableExtension(
id=ext_id,
name="WASM Demo",
version="1.0.0",
)
mocker.patch(
"lnbits.core.services.extensions.get_installed_extension",
mocker.AsyncMock(return_value=installed_extension),
)
update_mock = mocker.patch(
"lnbits.core.services.extensions."
"update_installed_extension_wasm_runtime_limits",
mocker.AsyncMock(),
)
saved_limits = await extension_services.update_wasm_extension_runtime_limits(
ext_id,
{
"wasm_runtime_max_execution_ms": "15000",
"wasm_runtime_max_fuel": 0,
"wasm_runtime_max_memory_bytes": "",
},
)
finally:
settings.lnbits_extensions_path = original_extensions_path
assert saved_limits == {
"wasm_runtime_max_execution_ms": 15000,
"wasm_runtime_max_fuel": 0,
}
update_mock.assert_awaited_once_with(ext_id=ext_id, limits=saved_limits)
@pytest.mark.anyio
async def test_wasm_invocation_concurrency_limits(mocker: MockerFixture):
_reset_wasm_invocation_state()
mocker.patch(
"lnbits.core.services.extensions.create_wasm_invocation",
mocker.AsyncMock(),
)
mocker.patch(
"lnbits.core.services.extensions.update_wasm_invocation",
mocker.AsyncMock(),
)
mocker.patch(
"lnbits.core.services.extensions.get_wasm_invocation",
mocker.AsyncMock(return_value=None),
)
mocker.patch(
"lnbits.core.services.extensions.mark_stale_wasm_invocations",
mocker.AsyncMock(),
)
mocker.patch(
"lnbits.core.services.extensions.delete_old_wasm_invocations",
mocker.AsyncMock(),
)
limits = extension_services.wasm_runtime_limit_defaults()
limits.update(
{
"wasm_runtime_max_concurrent_invocations": 1,
"wasm_runtime_max_concurrent_invocations_per_extension": 1,
"wasm_runtime_max_concurrent_invocations_per_user": 1,
}
)
invocation = await start_wasm_invocation(
extension_id="demoext",
export_name="render",
user_id="user-id",
runtime_limits=limits,
)
with pytest.raises(ValueError, match="too many active invocations"):
await start_wasm_invocation(
extension_id="demoext",
export_name="render",
user_id="user-id",
runtime_limits=limits,
)
await finish_wasm_invocation(invocation.id, status="completed")
@pytest.mark.anyio
async def test_wasm_invocation_host_call_limits(mocker: MockerFixture):
_reset_wasm_invocation_state()
mocker.patch(
"lnbits.core.services.extensions.create_wasm_invocation",
mocker.AsyncMock(),
)
mocker.patch(
"lnbits.core.services.extensions.update_wasm_invocation",
mocker.AsyncMock(),
)
mocker.patch(
"lnbits.core.services.extensions.get_wasm_invocation",
mocker.AsyncMock(return_value=None),
)
mocker.patch(
"lnbits.core.services.extensions.mark_stale_wasm_invocations",
mocker.AsyncMock(),
)
mocker.patch(
"lnbits.core.services.extensions.delete_old_wasm_invocations",
mocker.AsyncMock(),
)
limits = extension_services.wasm_runtime_limit_defaults()
limits["wasm_runtime_max_host_calls"] = 1
invocation = await start_wasm_invocation(
extension_id="demoext",
export_name="render",
runtime_limits=limits,
)
record_wasm_invocation_host_call(invocation.id, "http.request")
with pytest.raises(ValueError, match="host call limit"):
record_wasm_invocation_host_call(invocation.id, "storage.get")
await finish_wasm_invocation(invocation.id, status="failed")
@pytest.mark.anyio
async def test_start_extension_background_work_handles_missing_and_sync_starts(
mocker: MockerFixture,
@@ -1,100 +0,0 @@
from types import SimpleNamespace
import pytest
from lnbits.core.wasm_ext.api.host import ExtensionHostAPI
from lnbits.core.wasm_ext.api.models import PayInvoiceRequest
@pytest.mark.anyio
async def test_wasm_wallet_pay_invoice_resolves_ln_address(mocker):
calls = {}
async def get_wallet(wallet_id: str):
calls["get_wallet"] = wallet_id
return SimpleNamespace(user="user1")
async def get_pr_from_lnurl(lnurl: str, amount_msat: int, comment: str | None):
calls["lnurl"] = (lnurl, amount_msat, comment)
return "lnbc1resolved"
async def pay_invoice(**kwargs):
calls["pay_invoice"] = kwargs
return SimpleNamespace(
checking_id="checking",
payment_hash="hash",
status="success",
amount=-21_000,
fee=-10,
pending=False,
success=True,
)
mocker.patch("lnbits.core.crud.wallets.get_wallet", get_wallet)
mocker.patch("lnbits.core.services.lnurl.get_pr_from_lnurl", get_pr_from_lnurl)
mocker.patch("lnbits.core.services.payments.pay_invoice", pay_invoice)
api = ExtensionHostAPI("demoext", ["wallet.pay_invoice"], user_id="user1")
response = await api.wallet_pay_invoice(
PayInvoiceRequest(
wallet_id="wallet1",
payment_request="alice@example.com",
max_sat=21,
description="winner",
)
)
assert response.ok is True
assert response.checking_id == "checking"
assert calls["get_wallet"] == "wallet1"
assert calls["lnurl"] == ("alice@example.com", 21_000, "winner")
assert calls["pay_invoice"]["payment_request"] == "lnbc1resolved"
assert calls["pay_invoice"]["max_sat"] == 21
@pytest.mark.anyio
async def test_wasm_wallet_pay_invoice_allows_event_wallet_only(mocker):
async def get_wallet(wallet_id: str):
return SimpleNamespace(user="other-user")
async def pay_invoice(**kwargs):
return SimpleNamespace(
checking_id="checking",
payment_hash="hash",
status="success",
amount=-1_000,
fee=0,
pending=False,
success=True,
)
mocker.patch("lnbits.core.crud.wallets.get_wallet", get_wallet)
mocker.patch("lnbits.core.services.payments.pay_invoice", pay_invoice)
api = ExtensionHostAPI(
"demoext",
["wallet.pay_invoice"],
context="event",
owner_id="owner",
wallet_id="wallet1",
)
allowed = await api.wallet_pay_invoice(
PayInvoiceRequest(
wallet_id="wallet1",
payment_request="lnbc1invoice",
max_sat=None,
description="",
)
)
assert allowed.ok is True
with pytest.raises(PermissionError, match="authenticated user context"):
await api.wallet_pay_invoice(
PayInvoiceRequest(
wallet_id="wallet2",
payment_request="lnbc1invoice",
max_sat=None,
description="",
)
)
-223
View File
@@ -1,223 +0,0 @@
import json
from pathlib import Path
from typing import Any
import pytest
from lnbits.core.models.extensions import ExtensionPermission
from lnbits.core.models.misc import WasmExtensionRegistry
from lnbits.core.wasm_ext.api.permissions import validate_wasm_extension_permissions
from lnbits.core.wasm_ext.wasm.config import parse_wasm_extension_config
from lnbits.core.wasm_ext.wasm.loader import WasmExtension, load_wasm_extension
from lnbits.settings import Settings
from tests.helpers import make_installable_extension
def test_load_wasm_extension_rejects_missing_config_id(
tmp_path: Path, settings: Settings
):
ext_id = "demoext"
_write_wasm_extension(settings, tmp_path, ext_id, config_id=None)
with pytest.raises(ValueError, match="config must define id"):
load_wasm_extension(ext_id)
def test_load_wasm_extension_rejects_mismatched_config_id(
tmp_path: Path, settings: Settings
):
ext_id = "demoext"
_write_wasm_extension(settings, tmp_path, ext_id, config_id="otherext")
with pytest.raises(ValueError, match="id mismatch"):
load_wasm_extension(ext_id)
def test_load_wasm_extension_uses_canonical_extension_id(
tmp_path: Path, settings: Settings
):
ext_id = "demoext"
_write_wasm_extension(settings, tmp_path, ext_id, config_id=ext_id)
extension = load_wasm_extension(ext_id)
assert extension.id == ext_id
def test_wasm_extension_config_ignores_unknown_fields():
config = _wasm_config("demoext")
config["unexpected"] = True
parsed = parse_wasm_extension_config("demoext", config)
assert not hasattr(parsed, "unexpected")
def test_wasm_extension_config_rejects_coerced_scalar_types():
config = _wasm_config("demoext")
config["wasm"] = {"module": 123}
with pytest.raises(ValueError, match="str type expected"):
parse_wasm_extension_config("demoext", config)
@pytest.mark.parametrize(
"config_update",
[
{"wasm": {"module": "extension.wasm", "host_api": "custom.HostAPI"}},
{
"wasm": {
"module": "extension.wasm",
"resource_limits": {"max_response_bytes": 1024},
}
},
{"build": {"source": "dev", "command": "npm run build"}},
],
)
def test_wasm_extension_config_ignores_removed_extension_control_fields(
config_update: dict[str, Any],
):
config = _wasm_config("demoext")
config.update(config_update)
parsed = parse_wasm_extension_config("demoext", config)
assert parsed.wasm.module == "extension.wasm"
assert not hasattr(parsed.wasm, "host_api")
assert not hasattr(parsed.wasm, "resource_limits")
assert not hasattr(parsed, "build")
def test_wasm_extension_config_accepts_supported_optional_sections():
config = _wasm_config("demoext")
config.update(
{
"tile": "static/icon.png",
"min_lnbits_version": "1.0.0",
"max_lnbits_version": "2.0.0",
"wasm": {
"module": "wasm/module.wasm",
"wit": "wasm/lnbits-extension.wit",
"world": "lnbits-extension",
"exports": [
{"name": "render", "visibility": "public"},
{"name": "on_invoice_paid", "visibility": "event"},
],
},
"events": {"onInvoicePaid": "on_invoice_paid"},
"ui": {"entrypoint": "static/index.html", "sandbox": True},
"sdk": {"frontend_js": "static/lnbits-extension-sdk.js"},
"ui_routes": [
{
"path": "/demo/{item_id}",
"entrypoint": "static/index.html",
"auth": "user",
"path_params": {"item_id": "str"},
}
],
"api_routes": [
{
"method": "GET",
"path": "/api/demo/{item_id}",
"export": "render",
"auth": "public",
"path_params": {"item_id": "str"},
}
],
"permissions": [{"id": "utils.basic", "description": "Basic utils"}],
}
)
parsed = parse_wasm_extension_config("demoext", config)
assert parsed.events.on_invoice_paid == "on_invoice_paid"
assert parsed.wasm.world == "lnbits-extension"
def test_wasm_extension_config_ignores_unknown_permission_fields():
config = _wasm_config("demoext")
config["permissions"] = [
{"id": "utils.basic", "label": "Basic utilities", "unknown": True}
]
parsed = parse_wasm_extension_config("demoext", config)
assert parsed.permissions == [ExtensionPermission(id="utils.basic")]
def test_install_time_permission_validation_rejects_config_id_mismatch():
ext_info = make_installable_extension("demoext")
extension_config = {
"id": "otherext",
"extension_type": "wasm",
"permissions": [{"id": "utils.basic"}],
}
with pytest.raises(ValueError, match="id mismatch"):
validate_wasm_extension_permissions(
ext_info,
[ExtensionPermission(id="utils.basic")],
extension_config,
)
def test_wasm_extension_registry_rejects_same_id_from_different_root(tmp_path: Path):
registry = WasmExtensionRegistry()
first = _wasm_extension("demoext", tmp_path / "one")
second_same_root = _wasm_extension("demoext", tmp_path / "one")
second_different_root = _wasm_extension("demoext", tmp_path / "two")
registry.register(first)
registry.register(second_same_root)
with pytest.raises(ValueError, match="already registered"):
registry.register(second_different_root)
def _write_wasm_extension(
settings: Settings,
tmp_path: Path,
ext_id: str,
*,
config_id: str | None,
) -> None:
settings.lnbits_extensions_path = str(tmp_path)
ext_dir = tmp_path / "extensions" / ext_id
ext_dir.mkdir(parents=True)
(ext_dir / "extension.wasm").write_bytes(b"\0asm")
config = {
"name": "Demo",
"short_description": "Demo extension",
"version": "1.0.0",
"extension_type": "wasm",
"wasm": {"module": "extension.wasm"},
}
if config_id is not None:
config["id"] = config_id
(ext_dir / "config.json").write_text(json.dumps(config), encoding="utf-8")
def _wasm_extension(ext_id: str, root_path: Path) -> WasmExtension:
config = parse_wasm_extension_config(ext_id, _wasm_config(ext_id))
return WasmExtension(
id=ext_id,
name=ext_id,
version="1.0.0",
root_path=root_path,
module_path=root_path / "extension.wasm",
wit_path=None,
world="",
exports=[],
config=config,
)
def _wasm_config(ext_id: str) -> dict[str, Any]:
return {
"id": ext_id,
"name": ext_id,
"short_description": "Demo extension",
"version": "1.0.0",
"extension_type": "wasm",
"wasm": {"module": "extension.wasm"},
}
@@ -1,210 +0,0 @@
from types import SimpleNamespace
from typing import Any, cast
import pytest
from pytest_mock.plugin import MockerFixture
from lnbits.core.models.extensions import ExtensionPermission
from lnbits.core.wasm_ext.api.permissions import validate_wasm_extension_permissions
from lnbits.core.wasm_ext.wasm.events import _wasm_invoice_paid_owner_id
from lnbits.core.wasm_ext.wasm.invoke import _active_installed_extension
from tests.helpers import make_installable_extension
def test_validate_wasm_permissions_rejects_broader_policy_grant():
ext_info = make_installable_extension("demoext")
extension_config = _wasm_config(
"demoext",
[
{
"id": "http.request",
"policies": [{"host": "https://api.example.com"}],
}
],
)
with pytest.raises(ValueError, match="broader policies"):
validate_wasm_extension_permissions(
ext_info,
[
ExtensionPermission(
id="http.request",
policies=[
{"host": "https://api.example.com"},
{"host": "https://evil.example.com"},
],
)
],
extension_config,
)
def test_validate_wasm_permissions_stores_narrower_policy_grant():
ext_info = make_installable_extension("demoext")
extension_config = _wasm_config(
"demoext",
[
{
"id": "ext.storage.read_public",
"description": "Read public storage.",
"policies": [
{
"table_name": "tip_jars",
"public_fields": ["id", "title", "description"],
}
],
}
],
)
permissions = validate_wasm_extension_permissions(
ext_info,
[
ExtensionPermission(
id="ext.storage.read_public",
policies=[
{
"table_name": "tip_jars",
"public_fields": ["id", "title"],
}
],
)
],
extension_config,
)
assert permissions == [
ExtensionPermission(
id="ext.storage.read_public",
description="Read public storage.",
policies=[
{
"table_name": "tip_jars",
"public_fields": ["id", "title"],
}
],
)
]
def test_validate_wasm_permissions_rejects_broader_extension_api_access():
ext_info = make_installable_extension("demoext")
extension_config = _wasm_config(
"demoext",
[
{
"id": "extension.api.request",
"policies": [{"id": "targetext", "access": ["read"]}],
}
],
)
with pytest.raises(ValueError, match="broader policies"):
validate_wasm_extension_permissions(
ext_info,
[
ExtensionPermission(
id="extension.api.request",
policies=[{"id": "targetext", "access": ["read", "write"]}],
)
],
extension_config,
)
def test_validate_wasm_permissions_allows_empty_grant():
ext_info = make_installable_extension("demoext")
extension_config = _wasm_config(
"demoext",
[
{
"id": "wallet.create_invoice_public",
"policies": [{"table": "tip_jars", "wallet_field": "wallet_id"}],
}
],
)
assert validate_wasm_extension_permissions(ext_info, [], extension_config) == []
def test_validate_wasm_permissions_rejects_unrequested_permission_grant():
ext_info = make_installable_extension("demoext")
extension_config = _wasm_config("demoext", [{"id": "utils.basic"}])
with pytest.raises(ValueError, match="unrequested permissions"):
validate_wasm_extension_permissions(
ext_info,
[
ExtensionPermission(id="utils.basic"),
ExtensionPermission(id="wallet.list"),
],
extension_config,
)
@pytest.mark.anyio
async def test_invoice_paid_owner_lookup_uses_stored_granted_policies(
mocker: MockerFixture,
):
extension = SimpleNamespace(
id="demoext",
config=_wasm_config(
"demoext",
[
{
"id": "wallet.create_invoice_public",
"policies": [
{"table": "requested_table", "wallet_field": "wallet_id"}
],
}
],
),
)
payment = SimpleNamespace(extra={"source_id": "source-1"})
installed_extension = SimpleNamespace(
permissions=[
ExtensionPermission(
id="wallet.create_invoice_public",
policies=[{"table": "granted_table", "wallet_field": "wallet_id"}],
)
]
)
mocker.patch(
"lnbits.core.wasm_ext.wasm.events.get_installed_extension",
mocker.AsyncMock(return_value=installed_extension),
)
storage_mock = mocker.patch(
"lnbits.core.wasm_ext.wasm.events.storage_get_row_owner_id",
mocker.AsyncMock(return_value="owner-1"),
)
owner_id = await _wasm_invoice_paid_owner_id(extension, payment)
assert owner_id == "owner-1"
storage_mock.assert_awaited_once_with("demoext", "granted_table", "source-1")
@pytest.mark.anyio
async def test_wasm_invocation_requires_installed_active_extension(
mocker: MockerFixture,
):
extension = SimpleNamespace(id="demoext")
mocker.patch(
"lnbits.core.wasm_ext.wasm.invoke.get_installed_extension",
mocker.AsyncMock(return_value=None),
)
with pytest.raises(PermissionError, match="deactivated"):
await _active_installed_extension(cast(Any, extension))
def _wasm_config(ext_id: str, permissions: list[dict]) -> dict:
return {
"id": ext_id,
"name": ext_id,
"short_description": "Demo extension",
"version": "1.0.0",
"extension_type": "wasm",
"wasm": {"module": "extension.wasm"},
"permissions": permissions,
}
-81
View File
@@ -1,81 +0,0 @@
from __future__ import annotations
from collections.abc import AsyncIterator
from typing import cast
import pytest
from fastapi import Request
from lnbits.core.wasm_ext.routes.api import (
WasmRequestBodyTooLargeError,
_read_api_payload,
_read_json_object_with_size,
)
@pytest.mark.anyio
async def test_wasm_json_reader_rejects_large_content_length_without_reading():
request = _FakeRequest([b"{}"], content_length="11")
with pytest.raises(WasmRequestBodyTooLargeError, match="11 bytes"):
await _read_json_object_with_size(cast(Request, request), max_body_bytes=10)
assert request.stream_started is False
@pytest.mark.anyio
async def test_wasm_json_reader_rejects_large_stream_without_content_length():
request = _FakeRequest([b'{"value":"', b"x" * 20, b'"}'])
with pytest.raises(WasmRequestBodyTooLargeError):
await _read_json_object_with_size(cast(Request, request), max_body_bytes=16)
assert request.stream_started is True
@pytest.mark.anyio
async def test_wasm_api_payload_records_actual_body_bytes():
body = b'{"amount":21}'
request = _FakeRequest(
[body],
path_params={"invoice_id": "abc"},
query_params={"include_paid": "true"},
)
payload = await _read_api_payload(
cast(Request, request),
{"invoice_id": "invoiceId"},
max_body_bytes=100,
)
assert payload.data == {
"invoiceId": "abc",
"includePaid": "true",
"amount": 21,
}
assert payload.request_bytes == len(body)
class _FakeRequest:
method = "POST"
def __init__(
self,
chunks: list[bytes],
*,
content_length: str | None = None,
path_params: dict[str, str] | None = None,
query_params: dict[str, str] | None = None,
) -> None:
self._chunks = chunks
self.headers: dict[str, str] = {}
if content_length is not None:
self.headers["content-length"] = content_length
self.path_params = path_params or {}
self.query_params = query_params or {}
self.stream_started = False
async def stream(self) -> AsyncIterator[bytes]:
self.stream_started = True
for chunk in self._chunks:
yield chunk