Update docs/build-notes.md

Document completed authentication milestone
This commit is contained in:
2026-08-29 07:22:28 +00:00
parent 9b56404e13
commit 00ec5ca002
+21 -9
View File
@@ -42,6 +42,21 @@
- Display Fulcrum server version and blockchain height through the status API
- Verify live blockchain height from the physical StartOS server
### Milestone 4 — Authentication and access control
- Add password authentication for the Munin web interface
- Require authentication before accessing the status API
- Store the configured admin password through the StartOS package configuration
- Pass the configured admin password to the service through `MUNIN_ADMIN_PASSWORD`
- Create cryptographically random session tokens
- Store active sessions in memory with a 24-hour expiration
- Protect sessions with an `HttpOnly`, `Secure`, `SameSite=Strict` cookie
- Compare passwords using a timing-safe comparison
- Return HTTP 401 when the status API is accessed without a valid session
- Provide a web login form for authentication
- Verify successful login and authenticated status API access on the physical StartOS server
- Verify the authentication-protected S9PK package contains the authentication backend and updated web interface
## Current architecture
- StartOS package
@@ -49,9 +64,11 @@
- nginx serving the web interface
- Node.js status API
- Static dashboard in `web/index.html`
- Password authentication and session handling in `server/auth.js`
- Fulcrum provided as a StartOS dependency
- Electrum protocol connectivity check from Munin to Fulcrum
- Blockchain height queried through Fulcrum
- Admin password provided to the service through the StartOS package environment
## Current status
@@ -59,21 +76,16 @@ Munin Bitcoin is running as a StartOS service and can verify connectivity to the
Munin can query the current Bitcoin blockchain height through Fulcrum.
The Munin web interface now requires password authentication before the protected status API can be accessed.
Authenticated sessions use a temporary in-memory session token with a 24-hour lifetime.
Bitcoin Core RPC is not currently used by Munin.
Wallet configuration, label storage, transaction scanning, and notification functionality are not yet implemented.
## Next steps
### Milestone 4 — Authentication and access control
- Add user authentication for the Munin web interface
- Require authentication before accessing wallet and monitoring data
- Add password management
- Protect wallet addresses, xpubs, BSMS data, labels, and transaction information
- Keep authentication credentials separate from wallet data
- Integrate with StartOS authentication/security conventions where appropriate
### Milestone 5 — Address watchlist
- Add watch-only Bitcoin addresses