Repository navigation
End event streams when their macaroon is revoked or expires - #303
Open
benthecarman wants to merge 4 commits into
Open
benthecarman wants to merge 4 commits into
benthecarman wants to merge 4 commits into
Conversation
Move the SubscribeEvents streaming loop out of the request dispatch match into its own function so it can be reused by additional event streaming RPCs. No behavior change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SubscribeEvents delivers every event, so clients that only care about one kind of event have to receive and discard everything else. Add SubscribeChannelEvents, SubscribePaymentEvents, and SubscribeForwardingEvents RPCs, which stream only the matching subset of events. SubscribeEvents is unchanged. Channel events are ChannelStateChanged, SpliceNegotiated, and SpliceNegotiationFailed. Payment events are PaymentReceived, PaymentSuccessful, PaymentFailed, and PaymentClaimable. Forwarding events are PaymentForwarded; they get their own stream because they are the highest-volume event on a routing node and are not this node's own payments. Based on an earlier contribution that added an event kind filter to SubscribeEventsRequest; reworked into separate RPCs per review. Co-authored-by: Ekong Jemimah <ekongjemimah@gmail.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
pay --wait only looks at PaymentSuccessful and PaymentFailed events, so subscribe to payment events rather than every server event. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Event subscriptions were authorized only when they started. After a
root was revoked or a time-before caveat passed, new requests were
rejected, but an open stream kept forwarding events, including
payment preimages, until the client disconnected.
The shared event stream helper now rechecks the credential against
the store before forwarding each event and after the subscriber lags,
so every subscription kind is covered. Revocation notifies open
streams and the earliest expiry arms a timer, so idle streams also
close promptly. A failed check ends the stream with UNAUTHENTICATED
("Macaroon revoked" or "Macaroon expired").
The recheck shares its root and caveat checks with request admission
so the two cannot drift apart, and takes only the roots read lock.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
I've assigned @valentinewallace as a reviewer! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Based on #300
Event streams were only authorized when they were opened, so revoking a macaroon or hitting a
time-beforeexpiry blocked new requests but an open stream kept forwarding events (including payment preimages) until the client disconnected.Now the stream helper rechecks the credential before each event, on revocation, and at expiry, and ends the stream with
UNAUTHENTICATED.Found by Project Loupe