From a37f2c4cbcbe5daec11dfdcf1863d3ae09551bc0 Mon Sep 17 00:00:00 2001 From: eljamm Date: Sun, 2 Jun 2024 22:10:27 +0100 Subject: [PATCH 1/2] taler-mailbox: init at 0-unstable-2022-07-20 --- pkgs/by-name/taler-mailbox/example.conf | 17 ++++++++++ pkgs/by-name/taler-mailbox/package.nix | 41 +++++++++++++++++++++++++ 2 files changed, 58 insertions(+) create mode 100644 pkgs/by-name/taler-mailbox/example.conf create mode 100644 pkgs/by-name/taler-mailbox/package.nix diff --git a/pkgs/by-name/taler-mailbox/example.conf b/pkgs/by-name/taler-mailbox/example.conf new file mode 100644 index 00000000..e93b2556 --- /dev/null +++ b/pkgs/by-name/taler-mailbox/example.conf @@ -0,0 +1,17 @@ +[mailbox] +production = false +host = "https://taler-mailbox.gnunet.org" +bind_to = "localhost:11000" +message_fee = KUDOS:1 +default_doc_filetype = text/html +default_doc_lang = en +default_tos_path = terms/ +default_pp_path = privacy/ +supported_doc_filetypes = text/html application/pdf application/epub application/xml text/plain + +[mailbox-pq] +host = "localhost" +port = 5432 +user = "taler-mailbox" +password = "secret" +db_name = "taler-mailbox" diff --git a/pkgs/by-name/taler-mailbox/package.nix b/pkgs/by-name/taler-mailbox/package.nix new file mode 100644 index 00000000..7977c768 --- /dev/null +++ b/pkgs/by-name/taler-mailbox/package.nix @@ -0,0 +1,41 @@ +{ + lib, + buildGoModule, + fetchgit, +}: +buildGoModule { + pname = "taler-mailbox"; + version = "0-unstable-2022-07-20"; + + src = fetchgit { + url = "https://git.taler.net/taler-mailbox.git"; + rev = "ee5c19e9edf7e4e0959becc99e97606d9e6de041"; + hash = "sha256-t5IE8CuAKT5qlCNIqG9m8Gw0zJHa7505wHNK2ENuRQU="; + }; + + vendorHash = "sha256-frrmhfCcbY5DpCxR2g6HeSfN7xuLxpAWRahQl140voI="; + + postPatch = '' + # The mailbox has been previously declared globally so re-declaring it + # makes the program panic + substituteInPlace cmd/mailbox-server/main.go \ + --replace-fail 'm := mailbox.Mailbox{}' 'm = mailbox.Mailbox{}' + ''; + + ldflags = [ + "-s" + "-w" + ]; + + postInstall = '' + install -D ./configs/mailbox-example.conf -t $out/share/examples/taler-mailbox + ''; + + meta = { + description = "Service for asynchronous wallet-to-wallet payment messages"; + homepage = "https://git.taler.net/taler-mailbox.git"; + license = lib.licenses.agpl3Only; + maintainers = with lib.maintainers; []; + mainProgram = "mailbox-server"; + }; +} From a68ce769529d8db3618bd81cc30c30706d236827 Mon Sep 17 00:00:00 2001 From: eljamm Date: Mon, 7 Oct 2024 11:45:55 +0100 Subject: [PATCH 2/2] projects/GNUTaler: init --- projects/GNUTaler/conf/bank-ebics-keys.json | 1 + projects/GNUTaler/conf/client-ebics-keys.json | 1 + projects/GNUTaler/conf/exchange-account.json | 16 +++ projects/GNUTaler/conf/private.key | 1 + projects/GNUTaler/conf/taler-accounts.conf | 10 ++ .../GNUTaler/conf/taler-denominations.conf | 95 +++++++++++++ projects/GNUTaler/default.nix | 27 ++++ projects/GNUTaler/example.nix | 133 ++++++++++++++++++ 8 files changed, 284 insertions(+) create mode 100644 projects/GNUTaler/conf/bank-ebics-keys.json create mode 100644 projects/GNUTaler/conf/client-ebics-keys.json create mode 100644 projects/GNUTaler/conf/exchange-account.json create mode 100644 projects/GNUTaler/conf/private.key create mode 100644 projects/GNUTaler/conf/taler-accounts.conf create mode 100644 projects/GNUTaler/conf/taler-denominations.conf create mode 100644 projects/GNUTaler/default.nix create mode 100644 projects/GNUTaler/example.nix diff --git a/projects/GNUTaler/conf/bank-ebics-keys.json b/projects/GNUTaler/conf/bank-ebics-keys.json new file mode 100644 index 00000000..e3ebadb6 --- /dev/null +++ b/projects/GNUTaler/conf/bank-ebics-keys.json @@ -0,0 +1 @@ +{"bank_encryption_public_key":"621028HG1M30JAM6923FE381040GA003G80GY01GG80GM0M2040G1EACATA11EF5SVKNBNBYF1S3WSKQ2A2R9VZ7RW2HRX00293JPZ7VQ780RFRVYTQKKDDNJAQGBH4659GT9QYBMJCG1RKZEH1WDJ0GAAY7B7NBMW6FWXCKFYRMZQME0WBGZ1AAMY2VBQ5XAFV8216EFNF2EPG6M5ZGHG9RG6EGED56TK9JESQ02Q7AAVBRAAARVBN9NHCN64KQ3SRRHYXB8RWRK4TSSC93XG8RWMQH4ZDJSBYDCEXFY6G3AWTZ0EZNCJJAYB98T4GNFWZMN81AVYCQHXT1APX81AXCAYNK7J9XETF5CN1J1WV0BVA2BYG4VAMAW123REPN67JF1TNWPTADBMHS17N2V1GFYT8JRWX4TGM2996NXTEPMA8C2CDDE0CRY2A6HT8C5H2D6C62YGRSCF820C0G008","bank_authentication_public_key":"621028HG1M30JAM6923FE381040GA003G80GY01GG80GM0M2040G1EACATA11EF5SVKNBNBYF1S3WSKQ2A2R9VZ7RW2HRX00293JPZ7VQ780RFRVYTQKKDDNJAQGBH4659GT9QYBMJCG1RKZEH1WDJ0GAAY7B7NBMW6FWXCKFYRMZQME0WBGZ1AAMY2VBQ5XAFV8216EFNF2EPG6M5ZGHG9RG6EGED56TK9JESQ02Q7AAVBRAAARVBN9NHCN64KQ3SRRHYXB8RWRK4TSSC93XG8RWMQH4ZDJSBYDCEXFY6G3AWTZ0EZNCJJAYB98T4GNFWZMN81AVYCQHXT1APX81AXCAYNK7J9XETF5CN1J1WV0BVA2BYG4VAMAW123REPN67JF1TNWPTADBMHS17N2V1GFYT8JRWX4TGM2996NXTEPMA8C2CDDE0CRY2A6HT8C5H2D6C62YGRSCF820C0G008","accepted":true} diff --git a/projects/GNUTaler/conf/client-ebics-keys.json b/projects/GNUTaler/conf/client-ebics-keys.json new file mode 100644 index 00000000..d599e868 --- /dev/null +++ b/projects/GNUTaler/conf/client-ebics-keys.json @@ -0,0 +1 @@ +{"signature_private_keyencryption_private_keyauthentication_private_keysubmitted_ini":true,"submitted_hia":true} diff --git a/projects/GNUTaler/conf/exchange-account.json b/projects/GNUTaler/conf/exchange-account.json new file mode 100644 index 00000000..4bc476ff --- /dev/null +++ b/projects/GNUTaler/conf/exchange-account.json @@ -0,0 +1,16 @@ +[ + { + "operation": "exchange-enable-wire-0", + "arguments": { + "payto_uri": "payto://x-taler-bank/bank:8082/exchange?receiver-name=Exchange", + "debit_restrictions": [], + "credit_restrictions": [], + "priority": 0, + "validity_start": { + "t_s": 1725886541 + }, + "master_sig_add": "68WDT3JX1S5GQ9D3RZWXQVZK9AHFZ46YY5DA993720YA3SCBR4SW3X09NH5DECTXGWBKSN0MGKE1ANA9QZ95SKSNYPS9T9G46PCJC20", + "master_sig_wire": "39CEN9007DEXXMSDFZX1R2YYNANZYAFHX4EZC4ZX3C8DQEYT83JNVCVYMWYDGWEX6S891ZPXD6QHJE9J41YV9EN703Q0NM0MVE4FP18" + } + } +] diff --git a/projects/GNUTaler/conf/private.key b/projects/GNUTaler/conf/private.key new file mode 100644 index 00000000..3025c977 --- /dev/null +++ b/projects/GNUTaler/conf/private.key @@ -0,0 +1 @@ +ƒØ'IÕ‚–v&©ˆû¾¢¶ßH{VWýrƒ¶CjÜ>¦ \ No newline at end of file diff --git a/projects/GNUTaler/conf/taler-accounts.conf b/projects/GNUTaler/conf/taler-accounts.conf new file mode 100644 index 00000000..9246c25a --- /dev/null +++ b/projects/GNUTaler/conf/taler-accounts.conf @@ -0,0 +1,10 @@ +[exchange-account-test] +PAYTO_URI = payto://x-taler-bank/bank:8082/exchange?receiver-name=Exchange +ENABLE_DEBIT = YES +ENABLE_CREDIT = YES + +[exchange-accountcredentials-test] +WIRE_GATEWAY_URL = http://bank:8082/accounts/exchange/taler-wire-gateway/ +WIRE_GATEWAY_AUTH_METHOD = BASIC +USERNAME = exchange +PASSWORD = exchange diff --git a/projects/GNUTaler/conf/taler-denominations.conf b/projects/GNUTaler/conf/taler-denominations.conf new file mode 100644 index 00000000..e0c46ba9 --- /dev/null +++ b/projects/GNUTaler/conf/taler-denominations.conf @@ -0,0 +1,95 @@ +[COIN-KUDOS-n1-t1726827661] +VALUE = KUDOS:0.1 +DURATION_WITHDRAW = 7 days +DURATION_SPEND = 2 years +DURATION_LEGAL = 6 years +FEE_WITHDRAW = KUDOS:0 +FEE_DEPOSIT = KUDOS:0 +FEE_REFRESH = KUDOS:0 +FEE_REFUND = KUDOS:0 +RSA_KEYSIZE = 2048 +CIPHER = RSA + +[COIN-KUDOS-n2-t1726827661] +VALUE = KUDOS:0.2 +DURATION_WITHDRAW = 7 days +DURATION_SPEND = 2 years +DURATION_LEGAL = 6 years +FEE_WITHDRAW = KUDOS:0 +FEE_DEPOSIT = KUDOS:0 +FEE_REFRESH = KUDOS:0 +FEE_REFUND = KUDOS:0 +RSA_KEYSIZE = 2048 +CIPHER = RSA + +[COIN-KUDOS-n3-t1726827661] +VALUE = KUDOS:0.4 +DURATION_WITHDRAW = 7 days +DURATION_SPEND = 2 years +DURATION_LEGAL = 6 years +FEE_WITHDRAW = KUDOS:0 +FEE_DEPOSIT = KUDOS:0 +FEE_REFRESH = KUDOS:0 +FEE_REFUND = KUDOS:0 +RSA_KEYSIZE = 2048 +CIPHER = RSA + +[COIN-KUDOS-n4-t1726827661] +VALUE = KUDOS:0.8 +DURATION_WITHDRAW = 7 days +DURATION_SPEND = 2 years +DURATION_LEGAL = 6 years +FEE_WITHDRAW = KUDOS:0 +FEE_DEPOSIT = KUDOS:0 +FEE_REFRESH = KUDOS:0 +FEE_REFUND = KUDOS:0 +RSA_KEYSIZE = 2048 +CIPHER = RSA + +[COIN-KUDOS-n5-t1726827661] +VALUE = KUDOS:1.6 +DURATION_WITHDRAW = 7 days +DURATION_SPEND = 2 years +DURATION_LEGAL = 6 years +FEE_WITHDRAW = KUDOS:0 +FEE_DEPOSIT = KUDOS:0 +FEE_REFRESH = KUDOS:0 +FEE_REFUND = KUDOS:0 +RSA_KEYSIZE = 2048 +CIPHER = RSA + +[COIN-KUDOS-n6-t1726827661] +VALUE = KUDOS:3.2 +DURATION_WITHDRAW = 7 days +DURATION_SPEND = 2 years +DURATION_LEGAL = 6 years +FEE_WITHDRAW = KUDOS:0 +FEE_DEPOSIT = KUDOS:0 +FEE_REFRESH = KUDOS:0 +FEE_REFUND = KUDOS:0 +RSA_KEYSIZE = 2048 +CIPHER = RSA + +[COIN-KUDOS-n7-t1726827661] +VALUE = KUDOS:6.4 +DURATION_WITHDRAW = 7 days +DURATION_SPEND = 2 years +DURATION_LEGAL = 6 years +FEE_WITHDRAW = KUDOS:0 +FEE_DEPOSIT = KUDOS:0 +FEE_REFRESH = KUDOS:0 +FEE_REFUND = KUDOS:0 +RSA_KEYSIZE = 2048 +CIPHER = RSA + +[COIN-KUDOS-n8-t1726827661] +VALUE = KUDOS:12.8 +DURATION_WITHDRAW = 7 days +DURATION_SPEND = 2 years +DURATION_LEGAL = 6 years +FEE_WITHDRAW = KUDOS:0 +FEE_DEPOSIT = KUDOS:0 +FEE_REFRESH = KUDOS:0 +FEE_REFUND = KUDOS:0 +RSA_KEYSIZE = 2048 +CIPHER = RSA diff --git a/projects/GNUTaler/default.nix b/projects/GNUTaler/default.nix new file mode 100644 index 00000000..031849fb --- /dev/null +++ b/projects/GNUTaler/default.nix @@ -0,0 +1,27 @@ +{ + pkgs, + sources, + ... +} @ args: { + packages = { + inherit + (pkgs) + libeufin + taler-exchange + taler-merchant + taler-wallet-core + ; + }; + nixos = { + examples = { + base = { + path = ./example.nix; + description = "Basic configuration, mainly used for testing purposes."; + }; + }; + # TODO: enable when https://github.com/NixOS/nixpkgs/pull/332699 is merged + # tests = import "${sources.inputs.nixpkgs}/nixos/tests/taler" args; + # modules.services.taler = "${sources.inputs.nixpkgs}/nixos/modules/services/taler/module.nix"; + # modules.services.libeufin = "${sources.inputs.nixpkgs}/nixos/modules/services/libeufin/module.nix"; + }; +} diff --git a/projects/GNUTaler/example.nix b/projects/GNUTaler/example.nix new file mode 100644 index 00000000..a34917fc --- /dev/null +++ b/projects/GNUTaler/example.nix @@ -0,0 +1,133 @@ +{ + lib, + pkgs, + ... +}: let + CURRENCY = "KUDOS"; + FIAT_CURRENCY = "CHF"; + + testExchange = { + MASTER_PUBLIC_KEY = "2TQSTPFZBC2MC4E52NHPA050YXYG02VC3AB50QESM6JX1QJEYVQ0"; + BASE_URL = "http://localhost:8081/"; + }; +in { + services.taler = { + # Import exchange account into Taler's main config + # https://docs.taler.net/taler-exchange-manual.html#exchange-bank-account-configuration + includes = [./conf/taler-accounts.conf]; + + settings = { + taler.CURRENCY = CURRENCY; + }; + + exchange = { + enable = true; + debug = true; + openFirewall = true; # default 8081 + # Generated with `taler-harness deployment gen-coin-config` + # See https://docs.taler.net/taler-exchange-manual.html#coins-denomination-keys + denominationConfig = lib.readFile ./conf/taler-denominations.conf; + settings = { + exchange = testExchange; + exchange-offline = { + # WARN: This file will be world-readable. You should either point to + # a location outside the Nix store or set up secret management. + # See https://wiki.nixos.org/wiki/Comparison_of_secret_managing_schemes + MASTER_PRIV_FILE = "${./conf/private.key}"; + }; + }; + }; + + merchant = { + enable = true; + debug = true; + openFirewall = true; # default 8083 + settings = { + # Add exchange to the list of trusted payment service providers + # See https://docs.taler.net/taler-merchant-manual.html#exchange + merchant-exchange-test = { + EXCHANGE_BASE_URL = testExchange.BASE_URL; + MASTER_KEY = testExchange.MASTER_PUBLIC_KEY; + inherit CURRENCY; + }; + }; + }; + }; + + services.libeufin = { + bank = { + enable = true; + debug = true; + openFirewall = true; # default 8082 + # Needed for currency conversion to work + initialAccounts = [ + { + username = "exchange"; + password = "exchange"; + name = "Exchange"; + } + ]; + + settings = { + libeufin-bank = { + WIRE_TYPE = "x-taler-bank"; + # WIRE_TYPE = "iban"; + X_TALER_BANK_PAYTO_HOSTNAME = "localhost:8082"; + # IBAN_PAYTO_BIC = "SANDBOXX"; + BASE_URL = "localhost:8082"; + + SUGGESTED_WITHDRAWAL_EXCHANGE = testExchange.BASE_URL; + + ALLOW_REGISTRATION = "yes"; + + REGISTRATION_BONUS_ENABLED = "yes"; + REGISTRATION_BONUS = "${CURRENCY}:100"; + DEFAULT_DEBT_LIMIT = "${CURRENCY}:500"; + + # NOTE: For conversion to work, the exchange's bank account must be + # registered before the bank is started. + # The `services.libeufin.bank.initialAccounts` option can be used to do this. + ALLOW_CONVERSION = "yes"; + ALLOW_EDIT_CASHOUT_PAYTO_URI = "yes"; + + inherit CURRENCY FIAT_CURRENCY; + }; + }; + }; + + nexus = { + enable = true; + debug = true; + openFirewall = true; # default 8084 + settings = { + # https://docs.taler.net/libeufin/nexus-manual.html#setting-up-the-ebics-subscriber + # https://docs.taler.net/libeufin/setup-ebics-at-postfinance.html + nexus-ebics = { + # == Mandatory == + CURRENCY = FIAT_CURRENCY; + # Bank + HOST_BASE_URL = "https://isotest.postfinance.ch/ebicsweb/ebicsweb"; + BANK_DIALECT = "postfinance"; + # EBICS IDs + HOST_ID = "PFEBICS"; + USER_ID = "PFC00639"; + PARTNER_ID = "PFC00639"; + # Account information + IBAN = "CH4740123RW4167362694"; + BIC = "BIC"; + NAME = "nixosTest nixosTest"; + + # == Optional == + # WARN: This file will be world-readable. You should either point to + # a location outside the Nix store or set up secret management. + # See https://wiki.nixos.org/wiki/Comparison_of_secret_managing_schemes + CLIENT_PRIVATE_KEYS_FILE = "${./conf/client-ebics-keys.json}"; + BANK_PUBLIC_KEYS_FILE = "${./conf/bank-ebics-keys.json}"; + }; + }; + }; + }; + + # Install CLI wallet + environment.systemPackages = [pkgs.taler-wallet-core]; +}