diff --git a/README.md b/README.md index 999476d..c61d69c 100644 --- a/README.md +++ b/README.md @@ -1,53 +1,57 @@ # Protocolix -An experimental Capacitor and Vue mobile-wallet shell for IPI protocol research. +Capacitor application scaffold for a future IPI mobile wallet, with checked-in +Android and iOS projects and a small browser shell. -> **Status: pre-alpha.** Protocolix is not a production wallet. Key storage, -> transaction review, chain identity, recovery, device integrity, supply-chain -> security, and release signing have not been documented or audited for real -> assets. +## What the source implements -## Current scope +- Capacitor 8 projects for Android and iOS; +- IPI application identifiers and native launch assets; +- a Vite-built web shell; and +- the default Capacitor camera demonstration. -The repository provides a cross-platform application shell with Capacitor -targets for Android and iOS. It is a place to prototype wallet interactions, -including research around hardware-backed P-256/R1 keys and NFC-assisted flows. -Those experiments do not establish that a device, NFC tag, or transaction path -is secure. - -Relevant background material includes: - -- [Chainway R1 product information](https://chainway.us/Products/Info/135); and -- research on asymmetric cryptography in security-enabled NFC tags - ([publication](https://www.researchgate.net/publication/260655435_Security-Enabled_Near-Field_Communication_Tag_With_Flexible_Architecture_Supporting_Asymmetric_Cryptography)). - -External links are research inputs, not endorsements or security attestations. +The current application does **not** implement accounts, key generation or +storage, chain identity, balances, transaction construction, signing, recovery, +NFC, secure-element access, or an IPI network connection. The repository name +and native targets describe its intended integration role, not completed wallet +behavior. ## Development +The current Capacitor and Vite dependency graph requires Node.js `>=22.12.0`; +the verified audit environment used Node 24. + ```sh npm install npm start -npm test npm run build +npm run sync ``` -After adding or changing native plugins, synchronize platform projects with: +`npm run build` currently produces the web bundle. `npm run sync` copies web +assets and plugin configuration into the native projects after dependencies are +installed. There is no application test suite yet; the generated native example +tests do not exercise wallet behavior. -```sh -npm run sync -``` +## Intended integration boundary -Never commit signing keys, recovery phrases, API secrets, or production wallet -material. Security-sensitive findings must use the private reporting process in -the organization [security policy](https://github.com/ipicoin/.github/blob/main/SECURITY.md). +Protocolix is expected to consume a separately reviewed wallet/key layer and to +present network identity, signer intent, messages, fees, and recovery behavior +before it can become a wallet. Research around P-256/R1, WebAuthn, NFC, or +hardware-backed keys belongs behind explicit platform interfaces and threat +models; adding a plugin is not evidence that those paths are secure. -## Release requirements +## Development status -A real wallet release requires, at minimum, a reviewed threat model, explicit -chain and transaction displays, deterministic builds where the platform allows -them, protected release signing, recovery and migration tests, dependency -review, independent security assessment, and a public support lifecycle. +**Prototype scaffold.** The web shell builds, but this is not a wallet release +and must not be used to protect assets. A supported release requires implemented +wallet behavior, deterministic tests, secure storage and recovery design, +dependency review, protected release signing, migration procedures, and an +independent security assessment. + +Never commit signing keys, recovery phrases, API secrets, or production wallet +material. Report security-sensitive findings through the organization +[security policy](https://github.com/ipicoin/.github/blob/main/SECURITY.md). ## License diff --git a/package-lock.json b/package-lock.json index e430919..839add8 100644 --- a/package-lock.json +++ b/package-lock.json @@ -28,6 +28,9 @@ "octokit": "^5.0.5", "vite": "^7.3.6", "vitest": "^4.1.8" + }, + "engines": { + "node": ">=22.12.0" } }, "node_modules/@babel/helper-string-parser": { @@ -2154,16 +2157,16 @@ } }, "node_modules/brace-expansion": { - "version": "5.0.6", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz", - "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==", + "version": "5.0.9", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz", + "integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==", "dev": true, "license": "MIT", "dependencies": { "balanced-match": "^4.0.2" }, "engines": { - "node": "18 || 20 || >=22" + "node": "20 || >=22" } }, "node_modules/buffer-crc32": { @@ -2665,9 +2668,9 @@ } }, "node_modules/ip-address": { - "version": "10.2.0", - "resolved": "https://registry.npmjs.org/ip-address/-/ip-address-10.2.0.tgz", - "integrity": "sha512-/+S6j4E9AHvW9SWMSEY9Xfy66O5PWvVEJ08O0y5JGyEKQpojb0K0GKpz/v5HJ/G0vi3D2sjGK78119oXZeE0qA==", + "version": "10.5.0", + "resolved": "https://registry.npmjs.org/ip-address/-/ip-address-10.5.0.tgz", + "integrity": "sha512-R5SnVLJmgYYvf2F2ZgwSBnelz5G4q5AxIC277GDfUaNbrZKNANcBC7RHqYYePlszf4kBolVkJauG0ZjHHFh55g==", "dev": true, "license": "MIT", "engines": { @@ -2879,9 +2882,9 @@ "license": "MIT" }, "node_modules/nanoid": { - "version": "3.3.12", - "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.12.tgz", - "integrity": "sha512-ZB9RH/39qpq5Vu6Y+NmUaFhQR6pp+M2Xt76XBnEwDaGcVAqhlvxrl3B2bKS5D3NH3QR76v3aSrKaF/Kiy7lEtQ==", + "version": "3.3.18", + "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.18.tgz", + "integrity": "sha512-DTg4MJbGMWkfi6VZFdNt2/caMbQy4Ou+Op/hJQvGEWcnVfoA1QA+xzRKAzw9jD6+GVOOeYr/mIcuDSdug6F6+w==", "funding": [ { "type": "github", @@ -3114,9 +3117,9 @@ } }, "node_modules/postcss": { - "version": "8.5.15", - "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.15.tgz", - "integrity": "sha512-FfR8sjd4em2T6fb3I2MwAJU7HWVMr9zba+enmQeeWFfCbm+UOC/0X4DS8XtpUTMwWMGbjKYP7xjfNekzyGmB3A==", + "version": "8.5.26", + "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.26.tgz", + "integrity": "sha512-u82N74LFzG8ca+dD8puPnplTXoGH4fTPpVGuIbt36G3qvNlkvfD0lEAZSxaly3KX8TS/L1A1gsCEmvKmBcVbkQ==", "funding": [ { "type": "opencollective", @@ -3133,7 +3136,7 @@ ], "license": "MIT", "dependencies": { - "nanoid": "^3.3.12", + "nanoid": "^3.3.17", "picocolors": "^1.1.1", "source-map-js": "^1.2.1" }, @@ -3530,9 +3533,9 @@ } }, "node_modules/tar": { - "version": "7.5.16", - "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.16.tgz", - "integrity": "sha512-56adEpPMouktRlBLXiaYFFzZ/3+JXa8P9n7WbR+ibIjtviN55mEaOkiysCnPnWm+7kkui1Dn8J9l+g6zV8731w==", + "version": "7.5.22", + "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.22.tgz", + "integrity": "sha512-MFO/QzvtAOmJbkhOaCTvbGcFN9L9b+JunIsDwaKljSOdcLMea3NJ1k9Usz/rjdfSXTq4dfzfeS7W4p4YOAAHeA==", "dev": true, "license": "BlueOak-1.0.0", "dependencies": { diff --git a/package.json b/package.json index 56b0787..bfc1ff4 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,10 @@ { "name": "protocolix", "version": "0.1.0", - "description": "Experimental Capacitor and Vue mobile-wallet shell for IPI protocol research.", + "description": "Capacitor Android/iOS application scaffold for future IPI wallet integration.", + "engines": { + "node": ">=22.12.0" + }, "type": "module", "keywords": [ "capacitor",