You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(mock): guard the invoice amount against overflow, and complete the 0.3.2 changelog #66
Two small follow-ups from the post-merge review of 0.3.2 (#64, #65).
Overflow.MockLnServer.bolt11Amount computes amountSat * 10 on a value parsed from the request body without bounds. Above Long.MAX_VALUE / 10 it wraps silently, producing a negative or nonsense prefix. Refuse amountSat > 2_100_000_000_000_000 (21M BTC in sats) with a 400, or use Math.multiplyExact and refuse on overflow. The encoding itself is correct (1 sat = 10n, amountless for <= 0), and the bech32 checksum covers the new HRP.
Changelog. The 0.3.2 entry does not mention the lombok 1.18.42 / jackson-databind 2.20.0 bumps (chore(deps): lombok 1.18.42, jackson-databind 2.20.0 #65), or that phoenixd-mock now inherits the managed jackson version instead of pinning 2.17.0. The existing 0.3.1 heading also uses an em dash (## 0.3.1 — 2026-09-23), which the house style avoids.
Summary
Two small follow-ups from the post-merge review of 0.3.2 (#64, #65).
MockLnServer.bolt11AmountcomputesamountSat * 10on a value parsed from the request body without bounds. AboveLong.MAX_VALUE / 10it wraps silently, producing a negative or nonsense prefix. RefuseamountSat > 2_100_000_000_000_000(21M BTC in sats) with a 400, or useMath.multiplyExactand refuse on overflow. The encoding itself is correct (1 sat =10n, amountless for<= 0), and the bech32 checksum covers the new HRP.## 0.3.1 — 2026-09-23), which the house style avoids.