Commit Graph

3 Commits

Author SHA1 Message Date
drjones
e18bdb1b41 Audit fixes for SMS tool (5 issues)
- XSS: render from_number/code via textContent, drop innerHTML string concat
- Poll throttle: last_check column + 3s min between SMSPool /sms/check calls
- provider_cost: store REAL + CAST in admin SUM (was silently summing text as 0)
- Atomic debit: _debit() with balance_sats >= ? guard, debit-before-provision,
  refund ledger entry on provision failure (no double-spend window)
- _extract_sms: defensive field parsing (text/body/message/content, number/sender/from)
- admin: add PROVIDER COST card (USD)
2026-09-20 20:24:07 -07:00
drjones
d7ce96fba4 Clarify 20-min rental ceiling (verified: SMSPool ignores expiry param)
- sms.py: drop misleading expiry param from /purchase/sms (SMSPool hard-caps
  rentals at 1200s/20min regardless); document MAX_RENTAL_MIN as verified
- surface the ceiling in customer UI + admin panel + feasibility doc
2026-09-20 20:11:08 -07:00
drjones
48305b4ad1 Add temp-SMS tool (SMSPool-backed temp-number marketplace) to Pleiades
- sms.py: NumberProvider abstraction + SMSPoolProvider + routes (/sms, rent, poll, release) + admin (/admin/sms)
- Reuses existing sats wallet + BTCPay deposit flow; charges per-rental against balance_sats
- Code detection, lazy expiry/release, per-user session limit, per-IP rate limit
- Verified end-to-end: rented Discord US +1 534 251 1825, wallet 5000->3500 sats, release refunded SMSPool to $7.45
2026-09-20 19:34:25 -07:00