<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
         xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>

    <groupId>xyz.tcheeric</groupId>
    <artifactId>imani-wallet-lib</artifactId>
    <version>0.3.9</version>
    <packaging>pom</packaging>
    <name>Imani Wallet</name>
    <description>Cashu wallet library (base, observability, cashu, nostr, app, NIPs) — standalone project extracted from imani-bridge</description>

    <modules>
        <!-- Core modules (layered architecture) -->
        <module>wallet-core</module>
        <!-- NIP implementations -->
        <module>wallet-nips</module>
        <!-- Application modules -->
        <module>wallet-bench</module>
        <!-- Integration Test module -->
        <module>wallet-it</module>
    </modules>

    <properties>
        <java.version>21</java.version>
        <maven.compiler.source>${java.version}</maven.compiler.source>
        <maven.compiler.target>${java.version}</maven.compiler.target>
        <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>

        <imani-bom.version>0.1.98</imani-bom.version>

        <!-- Cashu versions (from BOM, but needed for wallet-core-base direct reference).
             These MUST match what imani-bom declares. 0.1.25 shipped compiled against
             cashu-voucher 0.8.0 while imani-bom 0.1.41 handed downstream gateways 0.10.0,
             so gateway-core ran 0.8.0-compiled classes against a 0.10.0 jar. Restated here
             only because wallet-core-base references them outside dependencyManagement. -->

        <!-- Definite-length V4 CBOR (cashu-ts interop). Matches imani-bom 0.1.41.
             The historical 0.16.0 NUT-04 DTO pin was lifted here. -->

        <!-- Integration Test Defaults -->
        <skipITs>true</skipITs>
        <skipITs.wallet>true</skipITs.wallet>

        <!-- OpenTelemetry semantic conventions (not in BOM) -->
        <opentelemetry-semconv.version>1.30.1-alpha</opentelemetry-semconv.version>

        <!-- Build Plugin Versions -->
        <maven.surefire.plugin.version>3.5.2</maven.surefire.plugin.version>
        <maven.failsafe.plugin.version>3.2.5</maven.failsafe.plugin.version>
        <maven.shade.plugin.version>3.6.0</maven.shade.plugin.version>
        <maven.jar.plugin.version>3.3.0</maven.jar.plugin.version>
        <maven.compiler.plugin.version>3.13.0</maven.compiler.plugin.version>
        <maven.enforcer.plugin.version>3.4.1</maven.enforcer.plugin.version>
        <jacoco.plugin.version>0.8.10</jacoco.plugin.version>
        <expressly.version>5.0.0</expressly.version>

        <!-- Test-only dependency versions -->
        <phoenixd-rest.version>0.1.4</phoenixd-rest.version>
        <cashu-gateway-phoenixd.version>0.4.1</cashu-gateway-phoenixd.version>
    </properties>

    <dependencyManagement>
        <dependencies>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>imani-bom</artifactId>
                <version>${imani-bom.version}</version>
                <type>pom</type>
                <scope>import</scope>
            </dependency>

            <!-- cashu-lib 0.20.0 (see property above); kept explicit to
                 wallet-lib's backward-compat PostMintQuoteResponse shim
                 compiling. Lifts in a dedicated cashu-lib bump PR; out of
                 scope for spec-048 (whose only bom-consumption purpose is
                 nostr-java 2.0.7 alignment). See pom property comment above. -->

            <!-- Override BOM-managed wallet module versions for this project -->
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>wallet-core-base</artifactId>
                <version>${project.version}</version>
            </dependency>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>wallet-core-observability</artifactId>
                <version>${project.version}</version>
            </dependency>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>wallet-core-cashu</artifactId>
                <version>${project.version}</version>
            </dependency>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>wallet-core-nostr</artifactId>
                <version>${project.version}</version>
            </dependency>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>wallet-core-app</artifactId>
                <version>${project.version}</version>
            </dependency>

            <!-- Identity modules used by wallet-core and wallet-nips -->
        </dependencies>
    </dependencyManagement>

    <build>
        <pluginManagement>
            <plugins>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-compiler-plugin</artifactId>
                    <version>${maven.compiler.plugin.version}</version>
                    <configuration>
                        <parameters>true</parameters>
                        <annotationProcessorPaths>
                            <path>
                                <groupId>org.projectlombok</groupId>
                                <artifactId>lombok</artifactId>
                            </path>
                        </annotationProcessorPaths>
                    </configuration>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-surefire-plugin</artifactId>
                    <version>${maven.surefire.plugin.version}</version>
                    <configuration>
                        <useModulePath>false</useModulePath>
                        <systemPropertyVariables>
                            <!--
                              WALLET-02. The mint-URL allowlist is deny-by-default: an
                              unconfigured allowlist refuses every host, because fail-open there
                              would reintroduce the SSRF for any consumer that forgot to set it.
                              The unit tests dial fictitious mints, so they need those names
                              declared. This is test scope only; deployments set
                              WALLET_MINT_ALLOWLIST to the mints they actually trust.

                              allowInternalAddresses is on here because the test mints resolve
                              to nothing or to localhost, and the point of these tests is the
                              wallet logic rather than the network boundary. The boundary itself
                              is asserted directly by MintUrlValidatorTest, which controls these
                              properties per-test.
                            -->
                            <wallet.mint.allowlist>mint.example.com,mint.example,mint.test,mint.example.imani.casa,testmint.example,mint.test.com,mint,localhost</wallet.mint.allowlist>
                            <wallet.mint.allowPlaintextHttp>true</wallet.mint.allowPlaintextHttp>
                            <wallet.mint.allowInternalAddresses>true</wallet.mint.allowInternalAddresses>
                        </systemPropertyVariables>
                    </configuration>
                </plugin>
                <plugin>
                    <groupId>org.jacoco</groupId>
                    <artifactId>jacoco-maven-plugin</artifactId>
                    <version>${jacoco.plugin.version}</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-failsafe-plugin</artifactId>
                    <version>${maven.failsafe.plugin.version}</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-shade-plugin</artifactId>
                    <version>${maven.shade.plugin.version}</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-enforcer-plugin</artifactId>
                    <version>${maven.enforcer.plugin.version}</version>
                </plugin>
            </plugins>
        </pluginManagement>
    </build>

    <profiles>
        <profile>
            <id>it-wallet</id>
            <properties>
                <skipITs.wallet>false</skipITs.wallet>
            </properties>
        </profile>
    </profiles>

    <distributionManagement>
        <repository>
            <id>reposilite-releases</id>
            <url>https://maven.398ja.xyz/releases</url>
        </repository>
        <snapshotRepository>
            <id>reposilite-snapshots</id>
            <url>https://maven.398ja.xyz/snapshots</url>
        </snapshotRepository>
    </distributionManagement>

    <repositories>
        <repository>
            <id>central</id>
            <url>https://repo.maven.apache.org/maven2</url>
            <releases><enabled>true</enabled></releases>
            <snapshots><enabled>false</enabled></snapshots>
        </repository>
        <repository>
            <id>reposilite-releases</id>
            <url>https://maven.398ja.xyz/releases</url>
        </repository>
        <repository>
            <id>reposilite-snapshots</id>
            <url>https://maven.398ja.xyz/snapshots</url>
        </repository>
    </repositories>

</project>
