Skip to content

v0.1.10 — Fix production mode: encrypted key storage, on-chain balance, RPC routing

Choose a tag to compare

@0xAllenDev 0xAllenDev released this 04 Mar 11:43
· 78 commits to main since this release

What's Changed

Fixed

  • Production mode broken — effective_rpc_url never used: All RPC calls now use network-aware URL resolver instead of raw env var. Localnet/mainnet routing was silently ignored
  • ag402 balance / ag402 status only showed local SQLite ledger: Now queries real on-chain USDC balance via RPC in production mode
  • ag402 pay blocked by empty local ledger in production: Pre-check uses on-chain balance; payment flow reordered to pay-on-chain-first
  • ag402 setup / ag402 upgrade incomplete mainnet config: Now writes X402_NETWORK, USDC_MINT_ADDRESS, and all required fields

Security

  • Private key no longer stored in plaintext .env: Keys stored exclusively in encrypted ~/.ag402/wallet.key (PBKDF2-480K + AES). load_config() auto-decrypts at startup via AG402_UNLOCK_PASSWORD or interactive prompt
  • Private key masked in all display paths: ag402 setup summary, ag402 env set, ag402 env show
  • install_key_guard() activated: Root logger filter installed at CLI entry, redacting private keys from log output
  • ~/.ag402/.gitignore auto-created: Prevents accidental git commit of key files
  • RPC error messages truncated: Capped at 120 chars to prevent leaking RPC API keys
  • ag402 upgrade requires encryption: Fails if cryptography not installed, preventing key-less production state
  • Example docs updated: No longer shows plaintext SOLANA_PRIVATE_KEY= in .env examples

Full Changelog: https://github.com/AetherCore-Dev/ag402/blob/main/CHANGELOG.md