lib.rs 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101
  1. //! Cdk mintd lib
  2. // std
  3. #[cfg(feature = "auth")]
  4. use std::collections::HashMap;
  5. use std::env::{self};
  6. use std::net::SocketAddr;
  7. use std::path::{Path, PathBuf};
  8. use std::str::FromStr;
  9. use std::sync::Arc;
  10. // external crates
  11. use anyhow::{anyhow, bail, Result};
  12. use axum::Router;
  13. use bip39::Mnemonic;
  14. // internal crate modules
  15. use cdk::cdk_database::{self, MintDatabase, MintKVStore, MintKeysDatabase};
  16. use cdk::cdk_payment;
  17. use cdk::cdk_payment::MintPayment;
  18. use cdk::mint::{Mint, MintBuilder, MintMeltLimits};
  19. #[cfg(any(
  20. feature = "cln",
  21. feature = "lnbits",
  22. feature = "lnd",
  23. feature = "ldk-node",
  24. feature = "fakewallet",
  25. feature = "grpc-processor"
  26. ))]
  27. use cdk::nuts::nut17::SupportedMethods;
  28. use cdk::nuts::nut19::{CachedEndpoint, Method as NUT19Method, Path as NUT19Path};
  29. #[cfg(any(
  30. feature = "cln",
  31. feature = "lnbits",
  32. feature = "lnd",
  33. feature = "ldk-node",
  34. feature = "fakewallet"
  35. ))]
  36. use cdk::nuts::CurrencyUnit;
  37. #[cfg(feature = "auth")]
  38. use cdk::nuts::{AuthRequired, Method, ProtectedEndpoint, RoutePath};
  39. use cdk::nuts::{ContactInfo, MintVersion, PaymentMethod};
  40. use cdk::types::QuoteTTL;
  41. use cdk_axum::cache::HttpCache;
  42. #[cfg(feature = "postgres")]
  43. use cdk_postgres::{MintPgAuthDatabase, MintPgDatabase};
  44. #[cfg(all(feature = "auth", feature = "sqlite"))]
  45. use cdk_sqlite::mint::MintSqliteAuthDatabase;
  46. #[cfg(feature = "sqlite")]
  47. use cdk_sqlite::MintSqliteDatabase;
  48. use cli::CLIArgs;
  49. use config::{AuthType, DatabaseEngine, LnBackend};
  50. use env_vars::ENV_WORK_DIR;
  51. use setup::LnBackendSetup;
  52. use tower::ServiceBuilder;
  53. use tower_http::compression::CompressionLayer;
  54. use tower_http::decompression::RequestDecompressionLayer;
  55. use tower_http::trace::TraceLayer;
  56. use tracing_appender::{non_blocking, rolling};
  57. use tracing_subscriber::fmt::writer::MakeWriterExt;
  58. use tracing_subscriber::EnvFilter;
  59. #[cfg(feature = "swagger")]
  60. use utoipa::OpenApi;
  61. pub mod cli;
  62. pub mod config;
  63. pub mod env_vars;
  64. pub mod setup;
  65. const CARGO_PKG_VERSION: Option<&'static str> = option_env!("CARGO_PKG_VERSION");
  66. #[cfg(feature = "cln")]
  67. fn expand_path(path: &str) -> Option<PathBuf> {
  68. if path.starts_with('~') {
  69. if let Some(home_dir) = home::home_dir().as_mut() {
  70. let remainder = &path[2..];
  71. home_dir.push(remainder);
  72. let expanded_path = home_dir;
  73. Some(expanded_path.clone())
  74. } else {
  75. None
  76. }
  77. } else {
  78. Some(PathBuf::from(path))
  79. }
  80. }
  81. /// Performs the initial setup for the application, including configuring tracing,
  82. /// parsing CLI arguments, setting up the working directory, loading settings,
  83. /// and initializing the database connection.
  84. async fn initial_setup(
  85. work_dir: &Path,
  86. settings: &config::Settings,
  87. db_password: Option<String>,
  88. ) -> Result<(
  89. Arc<dyn MintDatabase<cdk_database::Error> + Send + Sync>,
  90. Arc<dyn MintKeysDatabase<Err = cdk_database::Error> + Send + Sync>,
  91. Arc<dyn MintKVStore<Err = cdk_database::Error> + Send + Sync>,
  92. )> {
  93. let (localstore, keystore, kv) = setup_database(settings, work_dir, db_password).await?;
  94. Ok((localstore, keystore, kv))
  95. }
  96. /// Sets up and initializes a tracing subscriber with custom log filtering.
  97. /// Logs can be configured to output to stdout only, file only, or both.
  98. /// Returns a guard that must be kept alive and properly dropped on shutdown.
  99. pub fn setup_tracing(
  100. work_dir: &Path,
  101. logging_config: &config::LoggingConfig,
  102. ) -> Result<Option<tracing_appender::non_blocking::WorkerGuard>> {
  103. let default_filter = "debug";
  104. let hyper_filter = "hyper=warn,rustls=warn,reqwest=warn";
  105. let h2_filter = "h2=warn";
  106. let tower_http = "tower_http=warn";
  107. let rustls = "rustls=warn";
  108. let env_filter = EnvFilter::new(format!(
  109. "{default_filter},{hyper_filter},{h2_filter},{tower_http},{rustls}"
  110. ));
  111. use config::LoggingOutput;
  112. match logging_config.output {
  113. LoggingOutput::Stderr => {
  114. // Console output only (stderr)
  115. let console_level = logging_config
  116. .console_level
  117. .as_deref()
  118. .unwrap_or("info")
  119. .parse::<tracing::Level>()
  120. .unwrap_or(tracing::Level::INFO);
  121. let stderr = std::io::stderr.with_max_level(console_level);
  122. tracing_subscriber::fmt()
  123. .with_env_filter(env_filter)
  124. .with_writer(stderr)
  125. .init();
  126. tracing::info!("Logging initialized: console only ({}+)", console_level);
  127. Ok(None)
  128. }
  129. LoggingOutput::File => {
  130. // File output only
  131. let file_level = logging_config
  132. .file_level
  133. .as_deref()
  134. .unwrap_or("debug")
  135. .parse::<tracing::Level>()
  136. .unwrap_or(tracing::Level::DEBUG);
  137. // Create logs directory in work_dir if it doesn't exist
  138. let logs_dir = work_dir.join("logs");
  139. std::fs::create_dir_all(&logs_dir)?;
  140. // Set up file appender with daily rotation
  141. let file_appender = rolling::daily(&logs_dir, "cdk-mintd.log");
  142. let (non_blocking_appender, guard) = non_blocking(file_appender);
  143. let file_writer = non_blocking_appender.with_max_level(file_level);
  144. tracing_subscriber::fmt()
  145. .with_env_filter(env_filter)
  146. .with_writer(file_writer)
  147. .init();
  148. tracing::info!(
  149. "Logging initialized: file only at {}/cdk-mintd.log ({}+)",
  150. logs_dir.display(),
  151. file_level
  152. );
  153. Ok(Some(guard))
  154. }
  155. LoggingOutput::Both => {
  156. // Both console and file output (stderr + file)
  157. let console_level = logging_config
  158. .console_level
  159. .as_deref()
  160. .unwrap_or("info")
  161. .parse::<tracing::Level>()
  162. .unwrap_or(tracing::Level::INFO);
  163. let file_level = logging_config
  164. .file_level
  165. .as_deref()
  166. .unwrap_or("debug")
  167. .parse::<tracing::Level>()
  168. .unwrap_or(tracing::Level::DEBUG);
  169. // Create logs directory in work_dir if it doesn't exist
  170. let logs_dir = work_dir.join("logs");
  171. std::fs::create_dir_all(&logs_dir)?;
  172. // Set up file appender with daily rotation
  173. let file_appender = rolling::daily(&logs_dir, "cdk-mintd.log");
  174. let (non_blocking_appender, guard) = non_blocking(file_appender);
  175. // Combine console output (stderr) and file output
  176. let stderr = std::io::stderr.with_max_level(console_level);
  177. let file_writer = non_blocking_appender.with_max_level(file_level);
  178. tracing_subscriber::fmt()
  179. .with_env_filter(env_filter)
  180. .with_writer(stderr.and(file_writer))
  181. .init();
  182. tracing::info!(
  183. "Logging initialized: console ({}+) and file at {}/cdk-mintd.log ({}+)",
  184. console_level,
  185. logs_dir.display(),
  186. file_level
  187. );
  188. Ok(Some(guard))
  189. }
  190. }
  191. }
  192. /// Retrieves the work directory based on command-line arguments, environment variables, or system defaults.
  193. pub async fn get_work_directory(args: &CLIArgs) -> Result<PathBuf> {
  194. let work_dir = if let Some(work_dir) = &args.work_dir {
  195. tracing::info!("Using work dir from cmd arg");
  196. work_dir.clone()
  197. } else if let Ok(env_work_dir) = env::var(ENV_WORK_DIR) {
  198. tracing::info!("Using work dir from env var");
  199. env_work_dir.into()
  200. } else {
  201. work_dir()?
  202. };
  203. tracing::info!("Using work dir: {}", work_dir.display());
  204. Ok(work_dir)
  205. }
  206. /// Loads the application settings based on a configuration file and environment variables.
  207. pub fn load_settings(work_dir: &Path, config_path: Option<PathBuf>) -> Result<config::Settings> {
  208. // get config file name from args
  209. let config_file_arg = match config_path {
  210. Some(c) => c,
  211. None => work_dir.join("config.toml"),
  212. };
  213. let mut settings = if config_file_arg.exists() {
  214. config::Settings::new(Some(config_file_arg))
  215. } else {
  216. tracing::info!("Config file does not exist. Attempting to read env vars");
  217. config::Settings::default()
  218. };
  219. // This check for any settings defined in ENV VARs
  220. // ENV VARS will take **priority** over those in the config
  221. settings.from_env()
  222. }
  223. async fn setup_database(
  224. settings: &config::Settings,
  225. _work_dir: &Path,
  226. _db_password: Option<String>,
  227. ) -> Result<(
  228. Arc<dyn MintDatabase<cdk_database::Error> + Send + Sync>,
  229. Arc<dyn MintKeysDatabase<Err = cdk_database::Error> + Send + Sync>,
  230. Arc<dyn MintKVStore<Err = cdk_database::Error> + Send + Sync>,
  231. )> {
  232. match settings.database.engine {
  233. #[cfg(feature = "sqlite")]
  234. DatabaseEngine::Sqlite => {
  235. let db = setup_sqlite_database(_work_dir, _db_password).await?;
  236. let localstore: Arc<dyn MintDatabase<cdk_database::Error> + Send + Sync> = db.clone();
  237. let kv: Arc<dyn MintKVStore<Err = cdk_database::Error> + Send + Sync> = db.clone();
  238. let keystore: Arc<dyn MintKeysDatabase<Err = cdk_database::Error> + Send + Sync> = db;
  239. Ok((localstore, keystore, kv))
  240. }
  241. #[cfg(feature = "postgres")]
  242. DatabaseEngine::Postgres => {
  243. // Get the PostgreSQL configuration, ensuring it exists
  244. let pg_config = settings.database.postgres.as_ref().ok_or_else(|| {
  245. anyhow!("PostgreSQL configuration is required when using PostgreSQL engine")
  246. })?;
  247. if pg_config.url.is_empty() {
  248. bail!("PostgreSQL URL is required. Set it in config file [database.postgres] section or via CDK_MINTD_POSTGRES_URL/CDK_MINTD_DATABASE_URL environment variable");
  249. }
  250. #[cfg(feature = "postgres")]
  251. let pg_db = Arc::new(MintPgDatabase::new(pg_config.url.as_str()).await?);
  252. #[cfg(feature = "postgres")]
  253. let localstore: Arc<dyn MintDatabase<cdk_database::Error> + Send + Sync> =
  254. pg_db.clone();
  255. #[cfg(feature = "postgres")]
  256. let kv: Arc<dyn MintKVStore<Err = cdk_database::Error> + Send + Sync> = pg_db.clone();
  257. #[cfg(feature = "postgres")]
  258. let keystore: Arc<
  259. dyn MintKeysDatabase<Err = cdk_database::Error> + Send + Sync,
  260. > = pg_db;
  261. #[cfg(feature = "postgres")]
  262. return Ok((localstore, keystore, kv));
  263. #[cfg(not(feature = "postgres"))]
  264. bail!("PostgreSQL support not compiled in. Enable the 'postgres' feature to use PostgreSQL database.")
  265. }
  266. #[cfg(not(feature = "sqlite"))]
  267. DatabaseEngine::Sqlite => {
  268. bail!("SQLite support not compiled in. Enable the 'sqlite' feature to use SQLite database.")
  269. }
  270. #[cfg(not(feature = "postgres"))]
  271. DatabaseEngine::Postgres => {
  272. bail!("PostgreSQL support not compiled in. Enable the 'postgres' feature to use PostgreSQL database.")
  273. }
  274. }
  275. }
  276. #[cfg(feature = "sqlite")]
  277. async fn setup_sqlite_database(
  278. work_dir: &Path,
  279. _password: Option<String>,
  280. ) -> Result<Arc<MintSqliteDatabase>> {
  281. let sql_db_path = work_dir.join("cdk-mintd.sqlite");
  282. #[cfg(not(feature = "sqlcipher"))]
  283. let db = MintSqliteDatabase::new(&sql_db_path).await?;
  284. #[cfg(feature = "sqlcipher")]
  285. let db = {
  286. // Get password from command line arguments for sqlcipher
  287. MintSqliteDatabase::new((sql_db_path, _password.unwrap())).await?
  288. };
  289. Ok(Arc::new(db))
  290. }
  291. /**
  292. * Configures a `MintBuilder` instance with provided settings and initializes
  293. * routers for Lightning Network backends.
  294. */
  295. async fn configure_mint_builder(
  296. settings: &config::Settings,
  297. mint_builder: MintBuilder,
  298. runtime: Option<std::sync::Arc<tokio::runtime::Runtime>>,
  299. work_dir: &Path,
  300. kv_store: Option<Arc<dyn MintKVStore<Err = cdk::cdk_database::Error> + Send + Sync>>,
  301. ) -> Result<(MintBuilder, Vec<Router>)> {
  302. let mut ln_routers = vec![];
  303. // Configure basic mint information
  304. let mint_builder = configure_basic_info(settings, mint_builder);
  305. // Configure lightning backend
  306. let mint_builder = configure_lightning_backend(
  307. settings,
  308. mint_builder,
  309. &mut ln_routers,
  310. runtime,
  311. work_dir,
  312. kv_store,
  313. )
  314. .await?;
  315. // Configure caching
  316. let mint_builder = configure_cache(settings, mint_builder);
  317. Ok((mint_builder, ln_routers))
  318. }
  319. /// Configures basic mint information (name, contact info, descriptions, etc.)
  320. fn configure_basic_info(settings: &config::Settings, mint_builder: MintBuilder) -> MintBuilder {
  321. // Add contact information
  322. let mut contacts = Vec::new();
  323. if let Some(nostr_key) = &settings.mint_info.contact_nostr_public_key {
  324. contacts.push(ContactInfo::new("nostr".to_string(), nostr_key.to_string()));
  325. }
  326. if let Some(email) = &settings.mint_info.contact_email {
  327. contacts.push(ContactInfo::new("email".to_string(), email.to_string()));
  328. }
  329. // Add version information
  330. let mint_version = MintVersion::new(
  331. "cdk-mintd".to_string(),
  332. CARGO_PKG_VERSION.unwrap_or("Unknown").to_string(),
  333. );
  334. // Configure mint builder with basic info
  335. let mut builder = mint_builder
  336. .with_name(settings.mint_info.name.clone())
  337. .with_version(mint_version)
  338. .with_description(settings.mint_info.description.clone());
  339. // Add optional information
  340. if let Some(long_description) = &settings.mint_info.description_long {
  341. builder = builder.with_long_description(long_description.to_string());
  342. }
  343. for contact in contacts {
  344. builder = builder.with_contact_info(contact);
  345. }
  346. if let Some(pubkey) = settings.mint_info.pubkey {
  347. builder = builder.with_pubkey(pubkey);
  348. }
  349. if let Some(icon_url) = &settings.mint_info.icon_url {
  350. builder = builder.with_icon_url(icon_url.to_string());
  351. }
  352. if let Some(motd) = &settings.mint_info.motd {
  353. builder = builder.with_motd(motd.to_string());
  354. }
  355. if let Some(tos_url) = &settings.mint_info.tos_url {
  356. builder = builder.with_tos_url(tos_url.to_string());
  357. }
  358. builder
  359. }
  360. /// Configures Lightning Network backend based on the specified backend type
  361. async fn configure_lightning_backend(
  362. settings: &config::Settings,
  363. mut mint_builder: MintBuilder,
  364. ln_routers: &mut Vec<Router>,
  365. _runtime: Option<std::sync::Arc<tokio::runtime::Runtime>>,
  366. work_dir: &Path,
  367. _kv_store: Option<Arc<dyn MintKVStore<Err = cdk::cdk_database::Error> + Send + Sync>>,
  368. ) -> Result<MintBuilder> {
  369. let mint_melt_limits = MintMeltLimits {
  370. mint_min: settings.ln.min_mint,
  371. mint_max: settings.ln.max_mint,
  372. melt_min: settings.ln.min_melt,
  373. melt_max: settings.ln.max_melt,
  374. };
  375. tracing::debug!("Ln backend: {:?}", settings.ln.ln_backend);
  376. match settings.ln.ln_backend {
  377. #[cfg(feature = "cln")]
  378. LnBackend::Cln => {
  379. let cln_settings = settings
  380. .cln
  381. .clone()
  382. .expect("Config checked at load that cln is some");
  383. let cln = cln_settings
  384. .setup(
  385. ln_routers,
  386. settings,
  387. CurrencyUnit::Msat,
  388. None,
  389. work_dir,
  390. None,
  391. )
  392. .await?;
  393. mint_builder = configure_backend_for_unit(
  394. settings,
  395. mint_builder,
  396. CurrencyUnit::Sat,
  397. mint_melt_limits,
  398. Arc::new(cln),
  399. )
  400. .await?;
  401. }
  402. #[cfg(feature = "lnbits")]
  403. LnBackend::LNbits => {
  404. let lnbits_settings = settings.clone().lnbits.expect("Checked on config load");
  405. let lnbits = lnbits_settings
  406. .setup(
  407. ln_routers,
  408. settings,
  409. CurrencyUnit::Sat,
  410. None,
  411. work_dir,
  412. None,
  413. )
  414. .await?;
  415. mint_builder = configure_backend_for_unit(
  416. settings,
  417. mint_builder,
  418. CurrencyUnit::Sat,
  419. mint_melt_limits,
  420. Arc::new(lnbits),
  421. )
  422. .await?;
  423. }
  424. #[cfg(feature = "lnd")]
  425. LnBackend::Lnd => {
  426. let lnd_settings = settings.clone().lnd.expect("Checked at config load");
  427. let lnd = lnd_settings
  428. .setup(
  429. ln_routers,
  430. settings,
  431. CurrencyUnit::Msat,
  432. None,
  433. work_dir,
  434. None,
  435. )
  436. .await?;
  437. mint_builder = configure_backend_for_unit(
  438. settings,
  439. mint_builder,
  440. CurrencyUnit::Sat,
  441. mint_melt_limits,
  442. Arc::new(lnd),
  443. )
  444. .await?;
  445. }
  446. #[cfg(feature = "fakewallet")]
  447. LnBackend::FakeWallet => {
  448. let fake_wallet = settings.clone().fake_wallet.expect("Fake wallet defined");
  449. tracing::info!("Using fake wallet: {:?}", fake_wallet);
  450. for unit in fake_wallet.clone().supported_units {
  451. let fake = fake_wallet
  452. .setup(
  453. ln_routers,
  454. settings,
  455. unit.clone(),
  456. None,
  457. work_dir,
  458. _kv_store.clone(),
  459. )
  460. .await?;
  461. mint_builder = configure_backend_for_unit(
  462. settings,
  463. mint_builder,
  464. unit.clone(),
  465. mint_melt_limits,
  466. Arc::new(fake),
  467. )
  468. .await?;
  469. }
  470. }
  471. #[cfg(feature = "grpc-processor")]
  472. LnBackend::GrpcProcessor => {
  473. let grpc_processor = settings
  474. .clone()
  475. .grpc_processor
  476. .expect("grpc processor config defined");
  477. tracing::info!(
  478. "Attempting to start with gRPC payment processor at {}:{}.",
  479. grpc_processor.addr,
  480. grpc_processor.port
  481. );
  482. for unit in grpc_processor.clone().supported_units {
  483. tracing::debug!("Adding unit: {:?}", unit);
  484. let processor = grpc_processor
  485. .setup(ln_routers, settings, unit.clone(), None, work_dir, None)
  486. .await?;
  487. mint_builder = configure_backend_for_unit(
  488. settings,
  489. mint_builder,
  490. unit.clone(),
  491. mint_melt_limits,
  492. Arc::new(processor),
  493. )
  494. .await?;
  495. }
  496. }
  497. #[cfg(feature = "ldk-node")]
  498. LnBackend::LdkNode => {
  499. let ldk_node_settings = settings.clone().ldk_node.expect("Checked at config load");
  500. tracing::info!("Using LDK Node backend: {:?}", ldk_node_settings);
  501. let ldk_node = ldk_node_settings
  502. .setup(
  503. ln_routers,
  504. settings,
  505. CurrencyUnit::Sat,
  506. _runtime,
  507. work_dir,
  508. None,
  509. )
  510. .await?;
  511. mint_builder = configure_backend_for_unit(
  512. settings,
  513. mint_builder,
  514. CurrencyUnit::Sat,
  515. mint_melt_limits,
  516. Arc::new(ldk_node),
  517. )
  518. .await?;
  519. }
  520. LnBackend::None => {
  521. tracing::error!(
  522. "Payment backend was not set or feature disabled. {:?}",
  523. settings.ln.ln_backend
  524. );
  525. bail!("Lightning backend must be configured");
  526. }
  527. };
  528. Ok(mint_builder)
  529. }
  530. /// Helper function to configure a mint builder with a lightning backend for a specific currency unit
  531. async fn configure_backend_for_unit(
  532. settings: &config::Settings,
  533. mut mint_builder: MintBuilder,
  534. unit: cdk::nuts::CurrencyUnit,
  535. mint_melt_limits: MintMeltLimits,
  536. backend: Arc<dyn MintPayment<Err = cdk_payment::Error> + Send + Sync>,
  537. ) -> Result<MintBuilder> {
  538. let payment_settings = backend.get_settings().await?;
  539. if let Some(bolt12) = payment_settings.get("bolt12") {
  540. if bolt12.as_bool().unwrap_or_default() {
  541. mint_builder
  542. .add_payment_processor(
  543. unit.clone(),
  544. PaymentMethod::Bolt12,
  545. mint_melt_limits,
  546. Arc::clone(&backend),
  547. )
  548. .await?;
  549. }
  550. }
  551. mint_builder
  552. .add_payment_processor(
  553. unit.clone(),
  554. PaymentMethod::Bolt11,
  555. mint_melt_limits,
  556. backend,
  557. )
  558. .await?;
  559. if let Some(input_fee) = settings.info.input_fee_ppk {
  560. mint_builder.set_unit_fee(&unit, input_fee)?;
  561. }
  562. #[cfg(any(
  563. feature = "cln",
  564. feature = "lnbits",
  565. feature = "lnd",
  566. feature = "fakewallet",
  567. feature = "grpc-processor"
  568. ))]
  569. {
  570. let nut17_supported = SupportedMethods::default_bolt11(unit);
  571. mint_builder = mint_builder.with_supported_websockets(nut17_supported);
  572. }
  573. Ok(mint_builder)
  574. }
  575. /// Configures cache settings
  576. fn configure_cache(settings: &config::Settings, mint_builder: MintBuilder) -> MintBuilder {
  577. let cached_endpoints = vec![
  578. CachedEndpoint::new(NUT19Method::Post, NUT19Path::MintBolt11),
  579. CachedEndpoint::new(NUT19Method::Post, NUT19Path::MeltBolt11),
  580. CachedEndpoint::new(NUT19Method::Post, NUT19Path::Swap),
  581. ];
  582. let cache: HttpCache = settings.info.http_cache.clone().into();
  583. mint_builder.with_cache(Some(cache.ttl.as_secs()), cached_endpoints)
  584. }
  585. #[cfg(feature = "auth")]
  586. async fn setup_authentication(
  587. settings: &config::Settings,
  588. _work_dir: &Path,
  589. mut mint_builder: MintBuilder,
  590. _password: Option<String>,
  591. ) -> Result<MintBuilder> {
  592. if let Some(auth_settings) = settings.auth.clone() {
  593. tracing::info!("Auth settings are defined. {:?}", auth_settings);
  594. let auth_localstore: Arc<
  595. dyn cdk_database::MintAuthDatabase<Err = cdk_database::Error> + Send + Sync,
  596. > = match settings.database.engine {
  597. #[cfg(feature = "sqlite")]
  598. DatabaseEngine::Sqlite => {
  599. #[cfg(feature = "sqlite")]
  600. {
  601. let sql_db_path = _work_dir.join("cdk-mintd-auth.sqlite");
  602. #[cfg(not(feature = "sqlcipher"))]
  603. let sqlite_db = MintSqliteAuthDatabase::new(&sql_db_path).await?;
  604. #[cfg(feature = "sqlcipher")]
  605. let sqlite_db = {
  606. // Get password from command line arguments for sqlcipher
  607. MintSqliteAuthDatabase::new((sql_db_path, _password.unwrap())).await?
  608. };
  609. Arc::new(sqlite_db)
  610. }
  611. #[cfg(not(feature = "sqlite"))]
  612. {
  613. bail!("SQLite support not compiled in. Enable the 'sqlite' feature to use SQLite database.")
  614. }
  615. }
  616. #[cfg(feature = "postgres")]
  617. DatabaseEngine::Postgres => {
  618. #[cfg(feature = "postgres")]
  619. {
  620. // Get the PostgreSQL configuration, ensuring it exists
  621. let pg_config = settings.database.postgres.as_ref().ok_or_else(|| {
  622. anyhow!("PostgreSQL configuration is required when using PostgreSQL engine")
  623. })?;
  624. if pg_config.url.is_empty() {
  625. bail!("PostgreSQL URL is required for auth database. Set it in config file [database.postgres] section or via CDK_MINTD_POSTGRES_URL/CDK_MINTD_DATABASE_URL environment variable");
  626. }
  627. Arc::new(MintPgAuthDatabase::new(pg_config.url.as_str()).await?)
  628. }
  629. #[cfg(not(feature = "postgres"))]
  630. {
  631. bail!("PostgreSQL support not compiled in. Enable the 'postgres' feature to use PostgreSQL database.")
  632. }
  633. }
  634. #[cfg(not(feature = "sqlite"))]
  635. DatabaseEngine::Sqlite => {
  636. bail!("SQLite support not compiled in. Enable the 'sqlite' feature to use SQLite database.")
  637. }
  638. #[cfg(not(feature = "postgres"))]
  639. DatabaseEngine::Postgres => {
  640. bail!("PostgreSQL support not compiled in. Enable the 'postgres' feature to use PostgreSQL database.")
  641. }
  642. };
  643. let mut protected_endpoints = HashMap::new();
  644. let mut blind_auth_endpoints = vec![];
  645. let mut clear_auth_endpoints = vec![];
  646. let mut unprotected_endpoints = vec![];
  647. let mint_blind_auth_endpoint =
  648. ProtectedEndpoint::new(Method::Post, RoutePath::MintBlindAuth);
  649. protected_endpoints.insert(mint_blind_auth_endpoint, AuthRequired::Clear);
  650. clear_auth_endpoints.push(mint_blind_auth_endpoint);
  651. // Helper function to add endpoint based on auth type
  652. let mut add_endpoint = |endpoint: ProtectedEndpoint, auth_type: &AuthType| {
  653. match auth_type {
  654. AuthType::Blind => {
  655. protected_endpoints.insert(endpoint, AuthRequired::Blind);
  656. blind_auth_endpoints.push(endpoint);
  657. }
  658. AuthType::Clear => {
  659. protected_endpoints.insert(endpoint, AuthRequired::Clear);
  660. clear_auth_endpoints.push(endpoint);
  661. }
  662. AuthType::None => {
  663. unprotected_endpoints.push(endpoint);
  664. }
  665. };
  666. };
  667. // Get mint quote endpoint
  668. {
  669. let mint_quote_protected_endpoint =
  670. ProtectedEndpoint::new(cdk::nuts::Method::Post, RoutePath::MintQuoteBolt11);
  671. add_endpoint(mint_quote_protected_endpoint, &auth_settings.get_mint_quote);
  672. }
  673. // Check mint quote endpoint
  674. {
  675. let check_mint_protected_endpoint =
  676. ProtectedEndpoint::new(Method::Get, RoutePath::MintQuoteBolt11);
  677. add_endpoint(
  678. check_mint_protected_endpoint,
  679. &auth_settings.check_mint_quote,
  680. );
  681. }
  682. // Mint endpoint
  683. {
  684. let mint_protected_endpoint =
  685. ProtectedEndpoint::new(cdk::nuts::Method::Post, RoutePath::MintBolt11);
  686. add_endpoint(mint_protected_endpoint, &auth_settings.mint);
  687. }
  688. // Get melt quote endpoint
  689. {
  690. let melt_quote_protected_endpoint = ProtectedEndpoint::new(
  691. cdk::nuts::Method::Post,
  692. cdk::nuts::RoutePath::MeltQuoteBolt11,
  693. );
  694. add_endpoint(melt_quote_protected_endpoint, &auth_settings.get_melt_quote);
  695. }
  696. // Check melt quote endpoint
  697. {
  698. let check_melt_protected_endpoint =
  699. ProtectedEndpoint::new(Method::Get, RoutePath::MeltQuoteBolt11);
  700. add_endpoint(
  701. check_melt_protected_endpoint,
  702. &auth_settings.check_melt_quote,
  703. );
  704. }
  705. // Melt endpoint
  706. {
  707. let melt_protected_endpoint =
  708. ProtectedEndpoint::new(Method::Post, RoutePath::MeltBolt11);
  709. add_endpoint(melt_protected_endpoint, &auth_settings.melt);
  710. }
  711. // Swap endpoint
  712. {
  713. let swap_protected_endpoint = ProtectedEndpoint::new(Method::Post, RoutePath::Swap);
  714. add_endpoint(swap_protected_endpoint, &auth_settings.swap);
  715. }
  716. // Restore endpoint
  717. {
  718. let restore_protected_endpoint =
  719. ProtectedEndpoint::new(Method::Post, RoutePath::Restore);
  720. add_endpoint(restore_protected_endpoint, &auth_settings.restore);
  721. }
  722. // Check proof state endpoint
  723. {
  724. let state_protected_endpoint =
  725. ProtectedEndpoint::new(Method::Post, RoutePath::Checkstate);
  726. add_endpoint(state_protected_endpoint, &auth_settings.check_proof_state);
  727. }
  728. mint_builder = mint_builder.with_auth(
  729. auth_localstore.clone(),
  730. auth_settings.openid_discovery,
  731. auth_settings.openid_client_id,
  732. clear_auth_endpoints,
  733. );
  734. mint_builder =
  735. mint_builder.with_blind_auth(auth_settings.mint_max_bat, blind_auth_endpoints);
  736. let mut tx = auth_localstore.begin_transaction().await?;
  737. tx.remove_protected_endpoints(unprotected_endpoints).await?;
  738. tx.add_protected_endpoints(protected_endpoints).await?;
  739. tx.commit().await?;
  740. }
  741. Ok(mint_builder)
  742. }
  743. /// Build mints with the configured the signing method (remote signatory or local seed)
  744. async fn build_mint(
  745. settings: &config::Settings,
  746. keystore: Arc<dyn MintKeysDatabase<Err = cdk_database::Error> + Send + Sync>,
  747. mint_builder: MintBuilder,
  748. ) -> Result<Mint> {
  749. if let Some(signatory_url) = settings.info.signatory_url.clone() {
  750. tracing::info!(
  751. "Connecting to remote signatory to {} with certs {:?}",
  752. signatory_url,
  753. settings.info.signatory_certs.clone()
  754. );
  755. Ok(mint_builder
  756. .build_with_signatory(Arc::new(
  757. cdk_signatory::SignatoryRpcClient::new(
  758. signatory_url,
  759. settings.info.signatory_certs.clone(),
  760. )
  761. .await?,
  762. ))
  763. .await?)
  764. } else if let Some(seed) = settings.info.seed.clone() {
  765. let seed_bytes: Vec<u8> = seed.into();
  766. Ok(mint_builder.build_with_seed(keystore, &seed_bytes).await?)
  767. } else if let Some(mnemonic) = settings
  768. .info
  769. .mnemonic
  770. .clone()
  771. .map(|s| Mnemonic::from_str(&s))
  772. .transpose()?
  773. {
  774. Ok(mint_builder
  775. .build_with_seed(keystore, &mnemonic.to_seed_normalized(""))
  776. .await?)
  777. } else {
  778. bail!("No seed nor remote signatory set");
  779. }
  780. }
  781. async fn start_services_with_shutdown(
  782. mint: Arc<cdk::mint::Mint>,
  783. settings: &config::Settings,
  784. ln_routers: Vec<Router>,
  785. work_dir: &Path,
  786. mint_builder_info: cdk::nuts::MintInfo,
  787. shutdown_signal: impl std::future::Future<Output = ()> + Send + 'static,
  788. ) -> Result<()> {
  789. let listen_addr = settings.info.listen_host.clone();
  790. let listen_port = settings.info.listen_port;
  791. let cache: HttpCache = settings.info.http_cache.clone().into();
  792. #[cfg(feature = "management-rpc")]
  793. let mut rpc_enabled = false;
  794. #[cfg(not(feature = "management-rpc"))]
  795. let rpc_enabled = false;
  796. #[cfg(feature = "management-rpc")]
  797. let mut rpc_server: Option<cdk_mint_rpc::MintRPCServer> = None;
  798. #[cfg(feature = "management-rpc")]
  799. {
  800. if let Some(rpc_settings) = settings.mint_management_rpc.clone() {
  801. if rpc_settings.enabled {
  802. let addr = rpc_settings.address.unwrap_or("127.0.0.1".to_string());
  803. let port = rpc_settings.port.unwrap_or(8086);
  804. let mut mint_rpc = cdk_mint_rpc::MintRPCServer::new(&addr, port, mint.clone())?;
  805. let tls_dir = rpc_settings.tls_dir_path.unwrap_or(work_dir.join("tls"));
  806. if !tls_dir.exists() {
  807. tracing::error!("TLS directory does not exist: {}", tls_dir.display());
  808. bail!("Cannot start RPC server: TLS directory does not exist");
  809. }
  810. mint_rpc.start(Some(tls_dir)).await?;
  811. rpc_server = Some(mint_rpc);
  812. rpc_enabled = true;
  813. }
  814. }
  815. }
  816. if rpc_enabled {
  817. if mint.mint_info().await.is_err() {
  818. tracing::info!("Mint info not set on mint, setting.");
  819. mint.set_mint_info(mint_builder_info).await?;
  820. mint.set_quote_ttl(QuoteTTL::new(10_000, 10_000)).await?;
  821. } else {
  822. if mint.localstore().get_quote_ttl().await.is_err() {
  823. mint.set_quote_ttl(QuoteTTL::new(10_000, 10_000)).await?;
  824. }
  825. // Add version information
  826. let mint_version = MintVersion::new(
  827. "cdk-mintd".to_string(),
  828. CARGO_PKG_VERSION.unwrap_or("Unknown").to_string(),
  829. );
  830. let mut stored_mint_info = mint.mint_info().await?;
  831. stored_mint_info.version = Some(mint_version);
  832. mint.set_mint_info(stored_mint_info).await?;
  833. tracing::info!("Mint info already set, not using config file settings.");
  834. }
  835. } else {
  836. tracing::info!("RPC not enabled, using mint info from config.");
  837. mint.set_mint_info(mint_builder_info).await?;
  838. mint.set_quote_ttl(QuoteTTL::new(10_000, 10_000)).await?;
  839. }
  840. let mint_info = mint.mint_info().await?;
  841. let nut04_methods = mint_info.nuts.nut04.supported_methods();
  842. let nut05_methods = mint_info.nuts.nut05.supported_methods();
  843. let bolt12_supported = nut04_methods.contains(&&PaymentMethod::Bolt12)
  844. || nut05_methods.contains(&&PaymentMethod::Bolt12);
  845. let v1_service =
  846. cdk_axum::create_mint_router_with_custom_cache(Arc::clone(&mint), cache, bolt12_supported)
  847. .await?;
  848. let mut mint_service = Router::new()
  849. .merge(v1_service)
  850. .layer(
  851. ServiceBuilder::new()
  852. .layer(RequestDecompressionLayer::new())
  853. .layer(CompressionLayer::new()),
  854. )
  855. .layer(TraceLayer::new_for_http());
  856. #[cfg(feature = "swagger")]
  857. {
  858. if settings.info.enable_swagger_ui.unwrap_or(false) {
  859. mint_service = mint_service.merge(
  860. utoipa_swagger_ui::SwaggerUi::new("/swagger-ui")
  861. .url("/api-docs/openapi.json", cdk_axum::ApiDoc::openapi()),
  862. );
  863. }
  864. }
  865. for router in ln_routers {
  866. mint_service = mint_service.merge(router);
  867. }
  868. mint.start().await?;
  869. let socket_addr = SocketAddr::from_str(&format!("{listen_addr}:{listen_port}"))?;
  870. let listener = tokio::net::TcpListener::bind(socket_addr).await?;
  871. tracing::info!("listening on {}", listener.local_addr().unwrap());
  872. // Wait for axum server to complete with custom shutdown signal
  873. let axum_result = axum::serve(listener, mint_service).with_graceful_shutdown(shutdown_signal);
  874. match axum_result.await {
  875. Ok(_) => {
  876. tracing::info!("Axum server stopped with okay status");
  877. }
  878. Err(err) => {
  879. tracing::warn!("Axum server stopped with error");
  880. tracing::error!("{}", err);
  881. bail!("Axum exited with error")
  882. }
  883. }
  884. mint.stop().await?;
  885. #[cfg(feature = "management-rpc")]
  886. {
  887. if let Some(rpc_server) = rpc_server {
  888. rpc_server.stop().await?;
  889. }
  890. }
  891. Ok(())
  892. }
  893. async fn shutdown_signal() {
  894. tokio::signal::ctrl_c()
  895. .await
  896. .expect("failed to install CTRL+C handler");
  897. tracing::info!("Shutdown signal received");
  898. }
  899. fn work_dir() -> Result<PathBuf> {
  900. let home_dir = home::home_dir().ok_or(anyhow!("Unknown home dir"))?;
  901. let dir = home_dir.join(".cdk-mintd");
  902. std::fs::create_dir_all(&dir)?;
  903. Ok(dir)
  904. }
  905. /// The main entry point for the application when used as a library
  906. pub async fn run_mintd(
  907. work_dir: &Path,
  908. settings: &config::Settings,
  909. db_password: Option<String>,
  910. enable_logging: bool,
  911. runtime: Option<std::sync::Arc<tokio::runtime::Runtime>>,
  912. ) -> Result<()> {
  913. let _guard = if enable_logging {
  914. setup_tracing(work_dir, &settings.info.logging)?
  915. } else {
  916. None
  917. };
  918. let result =
  919. run_mintd_with_shutdown(work_dir, settings, shutdown_signal(), db_password, runtime).await;
  920. // Explicitly drop the guard to ensure proper cleanup
  921. if let Some(guard) = _guard {
  922. tracing::info!("Shutting down logging worker thread");
  923. drop(guard);
  924. // Give the worker thread a moment to flush any remaining logs
  925. tokio::time::sleep(tokio::time::Duration::from_millis(100)).await;
  926. }
  927. tracing::info!("Mintd shutdown");
  928. result
  929. }
  930. /// Run mintd with a custom shutdown signal
  931. pub async fn run_mintd_with_shutdown(
  932. work_dir: &Path,
  933. settings: &config::Settings,
  934. shutdown_signal: impl std::future::Future<Output = ()> + Send + 'static,
  935. db_password: Option<String>,
  936. runtime: Option<std::sync::Arc<tokio::runtime::Runtime>>,
  937. ) -> Result<()> {
  938. let (localstore, keystore, kv) = initial_setup(work_dir, settings, db_password.clone()).await?;
  939. let mint_builder = MintBuilder::new(localstore);
  940. let (mint_builder, ln_routers) =
  941. configure_mint_builder(settings, mint_builder, runtime, work_dir, Some(kv)).await?;
  942. #[cfg(feature = "auth")]
  943. let mint_builder = setup_authentication(settings, work_dir, mint_builder, db_password).await?;
  944. let mint = build_mint(settings, keystore, mint_builder).await?;
  945. tracing::debug!("Mint built from builder.");
  946. let mint = Arc::new(mint);
  947. // Checks the status of all pending melt quotes
  948. // Pending melt quotes where the payment has gone through inputs are burnt
  949. // Pending melt quotes where the payment has **failed** inputs are reset to unspent
  950. mint.check_pending_melt_quotes().await?;
  951. let result = start_services_with_shutdown(
  952. mint.clone(),
  953. settings,
  954. ln_routers,
  955. work_dir,
  956. mint.mint_info().await?,
  957. shutdown_signal,
  958. )
  959. .await;
  960. // Ensure any remaining tracing data is flushed
  961. // This is particularly important for file-based logging
  962. tracing::debug!("Flushing remaining trace data");
  963. result
  964. }