diff --git a/app.py b/app.py
index f478686..a178bde 100644
--- a/app.py
+++ b/app.py
@@ -1443,6 +1443,14 @@ def track():
API: POST /api/track/create (filename) → invoice · POST /api/track/upload?token= (file) → link · GET /api/track/events?token=
""" + how(["Pay $1 in BTC — the invoice settles and unlocks the upload instantly.","Upload your file or picture: you get a secret tracked link plus an email-ready HTML copy.","Email the HTML copy or share the link — every open fires back.","Each open reports: exact time, real IP, city/country, ISP, timezone, VPN flag, device, language, referrer.","Alerts land in your INBOX the second it happens."])
return page("track", body)
+
+BTCPAY_PUBLIC = "https://btcpay.thetempleofdoom.com"
+def public_checkout(link):
+ """LAN invoices must be payable from the open internet — swap host on checkout links."""
+ if not link:
+ return link
+ return link.replace("https://10.30.20.140", BTCPAY_PUBLIC)
+
def btc_invoice(amount="1.00"):
st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices",
headers={"Authorization": "token " + BTCPAY_KEY, "Content-Type": "application/json"},
@@ -1472,7 +1480,7 @@ def api_track_create():
con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,0,?)",
(uid or 0, token, esc(fn[:100]), "file", inv["id"], int(time.time())))
con.commit()
- return _checkout_or_json({"ok": True, "invoice_id": inv["id"], "checkoutLink": inv.get("checkoutLink"), "token": token,
+ return _checkout_or_json({"ok": True, "invoice_id": inv["id"], "checkoutLink": public_checkout(inv.get("checkoutLink")), "token": token,
"after_payment_upload_url": f"{SITE}/track/pay?token={token}"})
@app.route("/track/pay", methods=["GET"])
@@ -1649,7 +1657,7 @@ def api_mail_create():
con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)",
(uid or 0, addr, inv["id"], 0, 0, int(time.time()), pack[3]))
con.commit()
- return _checkout_or_json({"ok": True, "address": addr, "checkoutLink": inv.get("checkoutLink"), "invoice_id": inv["id"]})
+ return _checkout_or_json({"ok": True, "address": addr, "checkoutLink": public_checkout(inv.get("checkoutLink")), "invoice_id": inv["id"]})
@app.route("/api/mail/inbound", methods=["POST"])
def api_mail_inbound():
@@ -1735,7 +1743,7 @@ def api_pass_create():
con = db()
con.execute("INSERT INTO passes(user_id,invoice_id,paid,expires,plan_days) VALUES(?,?,0,0,?)", (uid, inv["id"], pack[3]))
con.commit()
- return _checkout_or_json({"ok": True, "checkoutLink": inv.get("checkoutLink"), "invoice_id": inv["id"]})
+ return _checkout_or_json({"ok": True, "checkoutLink": public_checkout(inv.get("checkoutLink")), "invoice_id": inv["id"]})
@app.route("/api/btcpay/webhook", methods=["POST"])
def btcpay_webhook():
@@ -1827,7 +1835,7 @@ def api_balance_topup():
con = db()
con.execute("INSERT INTO ledger(user_id,delta_cents,reason,ts) VALUES(?,?,?,?)", (uid, 0, f"topup invoice {inv['id']} pending", int(time.time())))
con.commit()
- return _checkout_or_json({"ok": True, "checkoutLink": inv.get("checkoutLink")})
+ return _checkout_or_json({"ok": True, "checkoutLink": public_checkout(inv.get("checkoutLink"))})
@app.route("/api/balance")
def api_balance():