- .gitignore: Add protection for .env, *.pem, *.key, private_key.pem, privkey.pem, ec.key, chiave_privata.key, and shell scripts bal-*.sh - make_release.sh: Remove hardcoded token 5cfa8c33e337ebaadb355c0ffa2d053d521ee43b Add loading from .env file with GITEA_API_TOKEN variable Add error handling if token is not set (prevents script from running without proper authentication) - .env.example: Add template file for Gitea API token setup (not committed to git, .gitignored) - generate_keys.sh: Add chmod 600 to protect private_key.pem permissions - contrib/download_and_install_bal.sh: Remove hardcoded xpub and fixed_fee. Make all settings required as arguments or environment variables (xpub, fixed_fee, willexecutor_url, email, info) Add proper error handling and usage instructions if required arguments are not provided - tests/secret_leakage_tests.rs: Add regression tests that: * Verify .gitignore protects .env, .pem, .key files * Verify no private key files are tracked in git (only public_key.pem is allowed) * Scan shell scripts for potential hardcoded tokens - All tests pass: cargo test (8 tests: 3 SQL injection + 2 panic regression + 3 secret leakage) - Build verified: cargo check (0 errors)
bal-server
Installation
$ git clone ....
$ cd bal-server
$ openssl genpkey -algorithm ED25519 -out private_key.pem
$ openssl pkey -in private_key.pem -pubout -out public_key.pem
$ cargo build --release
$ sudo cp target/release/bal-server /usr/local/bin
$ bal-server
Configuration
The bal-server application can be configured using environment variables. The following variables are available:
| Variable | Description | Default |
|---|---|---|
BAL_SERVER_CONFIG_FILE |
Path to the configuration file. If the file does not exist, a new one will be created. | $HOME/.config/bal-server/default-config.toml |
BAL_SERVER_DB_FILE |
Path to the SQLite3 database file. If the file does not exist, a new one will be created. | bal.db |
BAL_SERVER_BIND_ADDRESS |
Public address for listening to requests. | 127.0.0.1 |
BAL_SERVER_BIND_PORT |
Default port for listening to requests. | 9137 |
BAL_SERVER_PUB_KEY_PATH |
WillExecutor Ed25519 public key | public_key.pem |
BAL_SERVER_REGTEST_ADDRESS |
Bitcoin address for the regtest environment. | - |
BAL_SERVER_REGTEST_FIXED_FEE |
Fixed fee for the regtest environment. | 50000 |
BAL_SERVER_SIGNET_ADDRESS |
Bitcoin address for the signet environment. | - |
BAL_SERVER_SIGNET_FIXED_FEE |
Fixed fee for the signet environment. | 50000 |
BAL_SERVER_TESTNET_ADDRESS |
Bitcoin address for the testnet environment. | - |
BAL_SERVER_TESTNET_FIXED_FEE |
Fixed fee for the testnet environment. | 50000 |
BAL_SERVER_BITCOIN_ADDRESS |
Bitcoin address for the mainnet environment. | - |
BAL_SERVER_BITCOIN_FIXED_FEE |
Fixed fee for the mainnet environment. | 50000 |
bal-pusher
bal-pusher is a tool that retrieves Bitcoin transactions from a database and pushes them to the Bitcoin network when their locktime exceeds the median time past (MTP). It listens for Bitcoin block updates via ZMQ.
Installation
To use bal-pusher, you need to compile and install Bitcoin with ZMQ (ZeroMQ) support enabled. Then, configure your Bitcoin node and bal-pusher to push the transactions.
Prerequisites
-
Bitcoin with ZMQ Support: Ensure that Bitcoin is compiled with ZMQ support. Add the following line to your
bitcoin.conffile:zmqpubhashblock=tcp://127.0.0.1:28332 -
Install Rust and Cargo: If you haven't already installed Rust and Cargo, you can follow the official instructions to do so: Rust Installation.
Configuration
bal-pusher can be configured using environment variables. If no configuration file is provided, a default configuration file will be created.
Available Configuration Variables
| Variable | Description | Default |
|---|---|---|
BAL_PUSHER_CONFIG_FILE |
Path to the configuration file. If the file does not exist, it will be created. | $HOME/.config/bal-pusher/default-config.toml |
BAL_PUSHER_DB_FILE |
Path to the SQLite3 database file. If the file does not exist, it will be created. | bal.db |
BAL_PUSHER_ZMQ_LISTENER |
ZMQ listener for Bitcoin updates. | tcp://127.0.0.1:28332 |
BAL_PUSHER_BITCOIN_HOST |
Bitcoin server host for RPC connections. | http://127.0.0.1 |
BAL_PUSHER_BITCOIN_PORT |
Bitcoin RPC server port. | 8332 |
BAL_PUSHER_BITCOIN_COOKIE_FILE |
Path to Bitcoin RPC cookie file. | $HOME/.bitcoin/.cookie |
BAL_PUSHER_BITCOIN_RPC_USER |
Bitcoin RPC username. | - |
BAL_PUSHER_BITCOIN_RPC_PASSWORD |
Bitcoin RPC password. | - |
BAL_PUSHER_SEND_STATS |
Contact welist to provide times | false |
WELIST_SERVER_URL |
welist server url to provide times | https://welist.bitcoin-afer.life |
BAL_SERVER_URL |
WillExecutor server url | - |
SSL_KEY_PATH |
Ed25519 private key pem file | private_key.pem |
Running bal-pusher
Once the application is installed and configured, you can start bal-pusher by running the following command:
$ bal-pusher [bitcoin|testnet|regtest|]
This will start the service, which will listen for Bitcoin blocks via ZMQ and push transactions from the database when their locktime exceeds the median time past.