Files
pyre/apps/api
RogueWave 2101e18b3e feat(phase1): wallet scanner — scan API, classifier, token fetch, web UI
- @pyre/core: conservative classifier (classifyTokenAccount) + types + risk
  constants. EMPTY only when truly empty + classic-SPL + not frozen/delegated;
  Token-2022/unknown → UNSUPPORTED; frozen/delegated/NFT/valuable/over-threshold
  → PROTECTED_SKIP; TRANSMUTABLE only via explicit route hook (none in MVP).
  43 unit tests incl. a "never says safe" assertion.
- @pyre/solana: parseTokenAccounts (SPL + Token-2022 detection, NFT heuristic,
  rent, defensive owner cross-check) + tests. Tx builders remain Phase-2 stubs.
- @pyre/config: loadConfig() from env.
- @pyre/api: POST /api/scan — validates pubkey, recomputes classification
  server-side, CORS + rate-limit; DB persistence deferred. Live-RPC smoke OK.
- @pyre/web: wallet-connect (Wallet Standard) + grouped scan UI, ember theme,
  trust wording (no "safe"); next.config transpiles @pyre/core; prod build OK.

Built by 4 agents on a locked core contract; 2 audit agents (security: SOUND;
build: 1 blocker → fixed). Stripped .js import extensions in @pyre/core so
Turbopack resolves the source package. All typecheck + tests + build green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-31 03:10:52 +00:00
..

@pyre/api

PYRE backend HTTP API. Skeleton only — endpoints exist as TODO stubs/route placeholders, NOT real implementations. No Solana transaction or scan/build logic is implemented yet (see CLAUDE.md, §14).

Stack: Node.js + Fastify + TypeScript, with PostgreSQL (@pyre/db), Redis + BullMQ for queueing jobs handled by @pyre/worker.

Responsibilities (§13)

Token scan coordination, classification helpers, route evaluation, AI generation orchestration, metadata preparation, receipt storage, Spawn record storage, public API, admin API.

Endpoints to implement (§14) — TODO

  • POST /api/scan — scan a wallet's token accounts; return summary + accounts.
  • POST /api/build/close-empty — build unsigned close-account tx for empty ATAs.
  • POST /api/build/burn — build unsigned burn tx for selected junk tokens.
  • POST /api/receipt — record/return a cleanup receipt for a confirmed tx.
  • POST /api/prometheus/generate — enqueue a Prometheus Spawn generation job.
  • Admin endpoints — review/approve/reject generated Spawn packages.

Currently only GET /health is wired up.

Backend security rules (§16)

Rate-limit scan endpoints, validate wallet pubkeys, validate token-account ownership, never trust client-submitted classifications (recompute server-side), log all transaction-build requests, protect admin endpoints, use env secrets only.

Scripts

  • devtsx watch src/index.ts
  • buildtsc -p tsconfig.json
  • typechecktsc --noEmit
  • lint / test — placeholders for now