• v1.0.0 66025ef585

    btcbob released this 2026-10-08 21:44:44 +00:00 | 1 commits to master since this release

    The first tagged release of xmr-cart: a small XMR-only shop in vanilla PHP and SQLite. It verifies payments against your own Monero node with your private view key, fails closed when it can't, and never holds a spend key.

    Install

    R=https://git.subgenius.finance/SubGeniusFinance/xmr-cart/releases/download/v1.0.0
    curl -LO $R/xmr-cart-1.0.0.tar.gz -LO $R/xmr-cart-1.0.0.tar.gz.sha256
    sha256sum -c xmr-cart-1.0.0.tar.gz.sha256
    tar xzf xmr-cart-1.0.0.tar.gz && sudo mv xmr-cart-1.0.0 /var/www/xmr-cart
    cd /var/www/xmr-cart && sudo ./install.sh
    

    Or clone the v1.0.0 tag. The installer checks PHP and its extensions, then asks for the store name, URL and currency, the admin email (all notifications to it, or split by type), the From address, buyer emails on/off, and your network + node (it test-calls the node and catches a wrong-network one). It writes config.php with fresh secrets and prints the nginx block, the cron lines and your setup key. Then open /admin/, enter the setup key, a passphrase and your wallet's address + private view key.

    Requirements: PHP 8.0+ with pdo_sqlite, curl, gd, bcmath, gmp, mbstring; nginx or Apache; cron or a systemd timer; a full, non-pruned Monero node you run.

    What's in 1.0.0

    Shop

    • Catalog in batches, product photos with a gallery, per-item share links and #anchors.
    • A cart: several items, one order, one payment. Stock is reserved atomically, so a limited run can't oversell.
    • Per-item "Needs a shipping address": digital-only carts skip the postal fields.
    • A required XMR return address at checkout (masked, with a show toggle), so refunds have somewhere to go.

    Payments

    • Detection with the view key only, Pedersen commitment check, configurable confirmations.
    • An order never expires while a payment may still be on its way: expiry waits for a full scan to the tip plus a grace period.
    • Underpaid orders hold for 24h, then expire with the received amount on record. Over- and underpayments show Refund due in the admin.
    • No usable XMR price (stale for 15 min, or an implausible jump) stops checkout instead of mispricing it.

    Notifications (all optional)

    • Owner: paid, new order, refund due, payment checks down / back, checkout paused / back, low stock / sold out. Each once per event; one address or one per type. Owner mail never carries buyer details.
    • Buyer: payment received, and shipped with carrier + tracking (links for USPS, UPS, FedEx, DHL).

    Privacy and security

    • Buyer details (name, email, address, phone, return address, tracking) are erased 30 days after shipping, 7 days after an order dies; empty dead orders are deleted.
    • Uploads are re-encoded, which strips EXIF/GPS.
    • First-run setup needs the setup_key from config.php; the store refuses to run with a weak cookie secret; changing the passphrase ends every admin session; Secure cookies on HTTPS.
    • Wallet changes are refused while orders are open.

    Upgrading

    This is the first tagged release. If you run an earlier checkout from master, pull and reload: the database migrates itself (new columns only). Add setup_key and a 32+ character cookie_secret to config.php if they're missing, and for real money list only nodes you run in nodes.

    MIT licensed. Payment verification is SlowBearDigger's xmr-pay-woocommerce engine, unmodified; see LICENSE-THIRD-PARTY.md.

    Downloads