Skip to content

Bug: NIP-07 Sign in with extension shows Login failed 500 on HTTP/3 #3

Description

@cryptoquick

What the operator showed

https://services.surmount.systems/login?next=/mail after Sign in with NIP-07 extension showed Login failed: 500. Screenshot attached.

Auth on that page is NIP-98 plus session cookie (rust-nostr). Empty allowlist is fail-closed. nsec never on the server.

Cause

Public HTTPS advertises HTTP/3. Chrome posts POST /api/v1/auth/session over QUIC. The TCP path injects Axum ConnectInfo. The HTTP/3 path does not. Session create required that extractor, so Axum returned a plain-text 500. The login page prints body.error or the status.

Live probe with no live keys: HTTP/2 empty session POST was JSON 401. HTTP/3 empty session POST was that 500. HTTP/3 challenge and /login were 200.

NWC (NIP-47 URI on /mail after login) is a different surface. It looked broken because session POST 500s on HTTP/3 before /mail.

Fix in tree

Session create treats a missing peer as optional and does not ban unspecified addresses. After the operator switch (2026-09-03), HTTP/3 empty session POST is JSON 401 malformed auth material, not 500.

Git-flow branch name if more login work lands: bugfix/http3-session-connectinfo. Agents never sign and never push.

No secrets, IPs, tokens, or npubs in this issue.

Login failed 500 after NIP-07 on services.surmount.systems/login

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions