What the operator showed
https://services.surmount.systems/login?next=/mail after Sign in with NIP-07 extension showed Login failed: 500. Screenshot attached.
Auth on that page is NIP-98 plus session cookie (rust-nostr). Empty allowlist is fail-closed. nsec never on the server.
Cause
Public HTTPS advertises HTTP/3. Chrome posts POST /api/v1/auth/session over QUIC. The TCP path injects Axum ConnectInfo. The HTTP/3 path does not. Session create required that extractor, so Axum returned a plain-text 500. The login page prints body.error or the status.
Live probe with no live keys: HTTP/2 empty session POST was JSON 401. HTTP/3 empty session POST was that 500. HTTP/3 challenge and /login were 200.
NWC (NIP-47 URI on /mail after login) is a different surface. It looked broken because session POST 500s on HTTP/3 before /mail.
Fix in tree
Session create treats a missing peer as optional and does not ban unspecified addresses. After the operator switch (2026-09-03), HTTP/3 empty session POST is JSON 401 malformed auth material, not 500.
Git-flow branch name if more login work lands: bugfix/http3-session-connectinfo. Agents never sign and never push.
No secrets, IPs, tokens, or npubs in this issue.

What the operator showed
https://services.surmount.systems/login?next=/mailafter Sign in with NIP-07 extension showed Login failed: 500. Screenshot attached.Auth on that page is NIP-98 plus session cookie (rust-nostr). Empty allowlist is fail-closed. nsec never on the server.
Cause
Public HTTPS advertises HTTP/3. Chrome posts
POST /api/v1/auth/sessionover QUIC. The TCP path injects AxumConnectInfo. The HTTP/3 path does not. Session create required that extractor, so Axum returned a plain-text 500. The login page printsbody.erroror the status.Live probe with no live keys: HTTP/2 empty session POST was JSON 401. HTTP/3 empty session POST was that 500. HTTP/3 challenge and
/loginwere 200.NWC (NIP-47 URI on
/mailafter login) is a different surface. It looked broken because session POST 500s on HTTP/3 before/mail.Fix in tree
Session create treats a missing peer as optional and does not ban unspecified addresses. After the operator switch (2026-09-03), HTTP/3 empty session POST is JSON 401
malformed auth material, not 500.Git-flow branch name if more login work lands:
bugfix/http3-session-connectinfo. Agents never sign and never push.No secrets, IPs, tokens, or npubs in this issue.