Files
RogueWave 2101e18b3e feat(phase1): wallet scanner — scan API, classifier, token fetch, web UI
- @pyre/core: conservative classifier (classifyTokenAccount) + types + risk
  constants. EMPTY only when truly empty + classic-SPL + not frozen/delegated;
  Token-2022/unknown → UNSUPPORTED; frozen/delegated/NFT/valuable/over-threshold
  → PROTECTED_SKIP; TRANSMUTABLE only via explicit route hook (none in MVP).
  43 unit tests incl. a "never says safe" assertion.
- @pyre/solana: parseTokenAccounts (SPL + Token-2022 detection, NFT heuristic,
  rent, defensive owner cross-check) + tests. Tx builders remain Phase-2 stubs.
- @pyre/config: loadConfig() from env.
- @pyre/api: POST /api/scan — validates pubkey, recomputes classification
  server-side, CORS + rate-limit; DB persistence deferred. Live-RPC smoke OK.
- @pyre/web: wallet-connect (Wallet Standard) + grouped scan UI, ember theme,
  trust wording (no "safe"); next.config transpiles @pyre/core; prod build OK.

Built by 4 agents on a locked core contract; 2 audit agents (security: SOUND;
build: 1 blocker → fixed). Stripped .js import extensions in @pyre/core so
Turbopack resolves the source package. All typecheck + tests + build green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-31 03:10:52 +00:00
..

@pyre/config

Shared configuration and environment loading for PYRE.

Purpose

Per §13: shared config and environment loading. Provides a typed Env interface and a loadConfig() loader that maps the variables in the repo-root .env.example into typed config.

Trust rule

There is intentionally no wallet private-key / mnemonic variable here, and there never will be (§3). All signing happens client-side in the user's wallet.

Variables (mirrors .env.example)

  • SolanaSOLANA_RPC_URL, SOLANA_RPC_WS_URL, SOLANA_CLUSTER
  • DatabaseDATABASE_URL
  • RedisREDIS_URL
  • AIANTHROPIC_API_KEY, OPENAI_API_KEY, IMAGE_GEN_PROVIDER, IMAGE_GEN_API_KEY
  • App URLs / portsWEB_PORT, API_PORT, WEB_PUBLIC_URL, API_PUBLIC_URL
  • Admin / securityADMIN_API_TOKEN, RATE_LIMIT_SCAN_PER_MIN
  • Classification thresholdsPROTECTED_USD_THRESHOLD, MAX_PRICE_IMPACT_BPS, QUOTE_MAX_AGE_MS
  • Optional / later phasesIPFS_OR_ARWEAVE_ENDPOINT, IPFS_OR_ARWEAVE_TOKEN, PUMPFUN_CREATOR_WALLET_PUBKEY (public key only)

Status

Skeleton. Defines Env; loadConfig() is a stub.

TODO

  • Implement loadConfig() — read process.env, validate/coerce, apply defaults, fail fast on missing required values. Never hardcode secrets.