feat(cli): 'pay' and 'serve' commands for x402 (#44) - #62
Conversation
…sh & deduplication
… 0600 serve.ts: the facilitatorApiKey resolution fell back to the literal string 'demo-key' when no real key was configured. The server would start and look fully ready, but every request would 503 because the facilitator rejects the fake credential. Now it fails fast at startup with actionable instructions, same pattern as doctor.ts. configStore.ts: ~/.niriumrc.json can hold secretKey (a real Stellar SECRET key) and facilitatorApiKey. writeFileSync with default mode leaves the file world-readable (0644 after umask) on Linux/Mac. Now writes with mode 0o600 and chmodSync afterward to also fix pre-existing files. Best-effort on Windows where POSIX modes don't apply. Wires up the test script in package.json (was a placeholder echo). Adds a file-permission test (skipped on Windows). Co-authored-by: Claude AI (Anthropic) <noreply@anthropic.com>
|
Fix: silent \demo-key\ fallback + world-readable config file Two issues fixed: 1. serve.ts — silent fake facilitator key 2. configStore.ts — secretKey written world-readable Also:
|
pay.ts imports Keypair from @stellar/stellar-sdk but the package was never listed in dependencies — a clean npm install would fail to resolve it. Pins ^14.5.0 to match packages/sdk. Verified: rm -rf node_modules && npm install && npm test passes. Co-authored-by: Claude AI (Anthropic) <noreply@anthropic.com>
- Kept both CLI commands (verify + doctor, from nirium-protocol#59 already merged) in index.ts, bin/nirium.js, and README — this branch and nirium-protocol#59 each added one, neither replaces the other. - Combined test scripts to run both test/verify.test.js and test/doctor.test.js under one `npm test`. - Aligned @stellar/stellar-sdk to ^14.5.0 (matching packages/sdk's own pin) instead of this branch's ^17.0.0, to avoid two different major versions of the same dependency living side by side once nirium-protocol#62 also merges its own ^14.5.0 addition.
- Kept all six CLI commands side by side (create/pay/serve/config from this branch, verify/doctor from nirium-protocol#59+nirium-protocol#60 already merged) in both src/index.ts and bin/nirium.js — removed a stale duplicate doctor and a broken verify (calling a nonexistent runAuditVerifier) that this branch's own index.ts still had from before verify.ts existed. - Added pay/serve/config to bin/nirium.js too — the real published entrypoint (package.json's "bin") only had create/doctor/verify; this branch's new commands were only reachable from the unpublished src/index.ts. - Added express + @types/express as real dependencies — serve.ts imports express directly but it was never declared. - Combined test scripts to run all three suites (verify/doctor/ pay-serve) under one npm test. Aligned @stellar/stellar-sdk to ^14.5.0 across the merge. - Rebuilt package-lock.json for both packages/cli and packages/sdk. Known issue NOT fixed here, left for a follow-up (see PR comment): `npm run build` still fails for pay.ts/serve.ts/config.ts — they import sibling files with an explicit .ts extension, which the test runner's native TS stripping needs but tsc's NodeNext resolution rejects. Fixing it by switching to .js extensions breaks the test runner instead (no dist/ exists when running from source). Needs an actual resolution strategy, not a one-line swap.
|
Pushed a merge-conflict resolution against current main. Along the way I found and fixed two real gaps this PR had beyond the conflict itself:
One real issue I found but did NOT fix, left for you:
Also noting, not blocking: Once |
- Fixed TS5097 build error by changing ./configStore.ts imports in src/config.ts, src/pay.ts, and src/serve.ts to .js extension (required under NodeNext module resolution for tsc build). - Updated test runner to execute sc && node --test ... against compiled dist/*.js artifacts instead of raw .ts source files. - Added startup validation unit tests for executeServeCommand in est/pay-serve.test.js covering missing acilitatorApiKey and missing payTo address. Co-authored-by: Gemini AI (Google DeepMind) <noreply@google.com>
|
Fix: TS5097 NodeNext import extensions, dist testing strategy & \executeServeCommand\ unit tests
|
|
Verified from a completely clean install (removed Merged Merging. Thanks for chasing the build error all the way through — the dist-testing restructure is the right call. |
CLI: 'pay' and 'serve' commands for x402 (#44)
Overview
This PR extends
packages/cli(nirium) with two core x402 developer commands:nirium pay <url>: Terminal payment client for x402 endpoints, automatically signing Stellar authorization entries and completing pay-to-retry cycles.nirium serve: Zero-code local x402-protected HTTP server wrapping the SDK'sx402Serve()middleware.nirium config: Secure local configuration store (~/.niriumrc.json) with automatic secret key masking (S***...XXXX).Deliverables & Features
nirium pay <url> [--amount] [--network] [--secret] [--config] [--json](packages/cli/src/pay.ts):402 Payment Required), signs auth entries using Stellar Ed25519 keypairs, and sendsPAYMENT-SIGNATUREheaders.--jsonoutput.nirium serve [--price] [--pay-to] [--port] [--route] [--network](packages/cli/src/serve.ts):x402Serve()middleware over Express to spin up a mock x402-protected endpoint for testingnirium pay.nirium config [set|get|list|delete](packages/cli/src/configStore.ts&packages/cli/src/config.ts):secretKey,payTo,network) with automatic secret masking.Tests & Verification (
packages/cli/test/pay-serve.test.js):Verified Live Testnet Payment & Tx Reference
Executed
nirium pay https://nirium-agent.fly.dev/api/v1/premium/signalsagainst Nirium's live testnet endpoint using a real testnet account (GAKBHMZEWVVW6ST7D6GNR3LTDNYTMQT3K64X2D7BN35QWJ2T7IA5AXCI).eb9c7889d9146757bc3038c085c7902db82718813f5ea5a1ce87fc68ac61b267200 OKreturning 20 live signals fromnirium-agent.fly.dev.