RUNSTR v1.7.3 - Security Hardening, Submission Reliability & Branch Unification
What's New in v1.7.3
Security
- Secure RNG for Nostr key generation (crypto.getRandomValues replaces Math.random)
- Secure RNG for CoinOS credential generation
- SecureNsecStorage used consistently in Running Bitcoin post flow
- Centralized sign-out flow via AuthContext prevents partial state cleanup
- GlobalNDK signer cleared on sign-out to prevent stale identity
Submission Pipeline Reliability
- 5-second timeouts on club/team Supabase queries during reward tag building
- 5-second timeout on SubscriptionService tier check prevents hangs
- Timeout on image upload auth signing with Amber signer serialization
- Restored relay minimum connection check before publishing
- Hoisted async club lookups out of JSON.stringify to prevent silent failures
- Diagnostic logging for silent early returns in auto-submit pipeline
- Hardened early return status reporting and PPQ total timeout protection
Bug Fixes
- Cache crash fix: SimpleCache.delete prevents TeamCacheService crash
- Workout invalidation now passes competition team IDs correctly
- Health auto-submit retries on transient failures instead of silently dropping
- Reward summary defaults nullable totals to zero (prevents NaN display)
- Team join resolves current user npub correctly
- Manual entry range validation enforced
- Removed broken ChallengeService import
- Fixed chat double-submit on rapid taps
- Fixed German translation string
Improvements
- Subscription status card on Rewards page (10x boost, clean framing)
- Subscription economics updated — 10x boost, 15k/21k pricing, 5/week cap
- Terminology cleanup — rewards everywhere
- SafeAreaView migrated to react-native-safe-area-context (12 screens)
- ~12K lines of dead code removed
- Nostr club/team relay queries replaced with Supabase-only
Infrastructure
- Merged v1.7.0 (clubs) + v1.7.2 (security fixes) into unified branch
- 4 critical-path verification scripts (216 assertions)
- Pre-release audit fixes (performance, i18n, UX, data integrity)
Install
Download the APK below and install on Android. iOS builds available via TestFlight.