2.4.3:2
What's Changed
Restores BTCPay Server data left behind by an update from StartOS 0.3.x, and updates BTCPay Server to the 2.4.3 pre-release build rc6.
Updating from StartOS 0.3.x moves your BTCPay Server data — stores, invoices, wallets and settings — onto the storage this package uses. On servers running BTCPay Server 2.4.2 or later under StartOS 0.3.x, that move was skipped, and BTCPay Server started against empty storage: no stores, no accounts, every password rejected, and "No server admins exist" from the Reset Server Admin Password action.
Nothing was deleted. Your data stayed where the previous package kept it. This release moves it across on the first start after updating, so that start takes longer than usual — it is moving a database — and your original login works again once it finishes.
If you already hit this and created a new account in the empty BTCPay Server, that account and anything created with it is moved aside rather than deleted, and your original data takes its place. Contact support before removing what was set aside if you might need it.
Lightning credentials. If BTCPay Server is wired to a Lightning node, this update raises a critical task asking you to replace that node's credentials, and stops BTCPay Server until you clear it. The servers affected above never received that prompt when they should have; the 2.4.2 release notes explain why it matters.
New in rc6:
- Store users — a server admin can no longer be added to a store, nor have their role in a store changed, by someone who is not a server admin themselves. The rule applies both to a store's Users page and to the API.
- Plugins — the check that keeps an outdated plugin disabled until it is updated now covers seven more: Ecwid, SamRock, Stripe, BigCommerce, Mark Paid at Checkout, Ark and Cashu. If you use any of them, update it under Server Settings → Plugins; until then it stays disabled.
If you are updating from a version earlier than 2.4.3, that release was also a security update:
- Crowdfund — an app's description is no longer rendered as raw HTML, closing a cross-site scripting vector.
- Shopify plugin — BTCPay Server now refuses to load outdated versions of the Shopify plugin and keeps them disabled until they are updated. If you use the Shopify integration, update the Shopify plugin under Server Settings → Plugins after this update; the newer plugin fixes a refund webhook vulnerability.
About this version: it ships BTCPay Server's 2.4.3 pre-release build (rc6) from BTCPay Server's internal image channel; upstream has not yet published a 2.4.3 release, git tag, or changelog. The upstream changes above were identified by comparing the published images. Upstream's full release notes will appear at https://github.com/btcpayserver/btcpayserver/releases once 2.4.3 is published.
Downloads
SHA256 Hashes
f19346e0698ac0e8af5e30d02ca82ecc433618c384197a4b42185ad547cfcdaa btcpayserver_aarch64.s9pk
b100284d602a4c0354bee505ae728405fe54da0e34caa34c280f0e9a677285b9 btcpayserver_x86_64.s9pk