This site serves the repository over git's dumb-HTTP protocol as plain static files (plain files — there is no git server here, or any server at all):
git clone https://git.ardegazu.ro/banca.git
cd banca
What it is
Any identity can found a bank: charter a currency, take customers, mint, settle
payments. A bank is one end-to-end-encrypted replicated log and its
link — #<secret>.<bankerPub> — is the whole capability: who
the banker is falls out of the URL before a single entry is read, and the ledger
lives only on its members' devices. No server holds it, or could.
Payments settle provisionally the moment they replicate — two
customers standing in a market converge with the banker asleep — and become
final when the banker acknowledges them. Acknowledged money carries a
portable wallet-kit receipt that
verifies on its own, in any wallet, with the bank offline. The interface never blurs
the two states; that distinction is the product. And the neutral unit of account, the
gaz (GAZ), is reserved: a charter claiming it is refused for every
banker — nobody can issue it.
Installable PWA, safe-area aware, works from any static file host.
What's in the repo
client/src/banca/lib/ — the bank
protocol.cljs — the BANK/1 op union; fold.cljs — the settlement fold, a pure replay of the whole history (no window, no eviction: a fold that forgot would be a fold that lied); wallet.cljs + view.cljs — receipts and the view model that names every payment state honestly.
the rooms core — not in this repo
The encrypted replicated log, presence and the offline mailbox are ardegazu.rooms.*, compiled off the classpath out of ardegazu-rooms-kit (sha-pinned). Fix it there; every rooms app inherits.
docs/PROTOCOL.md — the contract
BANK/1, the normative text: ops, authorization, the fold, receipts, injection surfaces. §11 is the honest list of limits; §12 is what any interface built on it has to say.
deploy/ — the publish pipeline
publish-repo.sh builds this very site: landing page + bare mirror exploded to loose objects, behind an anonymity gate that refuses to publish identity-bearing bytes.
How it works (the short version)
The link IS the bank. The secret and the banker's public key live in the URL fragment (#…) and never leave the browser. Policy is a pure function of the link, so the banker is known before an op is read — an op claiming banker powers without the banker's signature simply does not fold.
No server. Browsers are libp2p peers: they meet through a circuit-relay node, upgrade to direct WebRTC, and replicate an encrypted OrbitDB log. Every entry is sealed at rest; a decrypt failure is the access check. Members who are never online together converge through the sealed offline mailbox.
Provisional, then final. Any member's replica may append a payment; the deterministic fold settles it everywhere it lands. The banker's ack pins it — and a mint's ack signs an issuance receipt no back-dated entry can displace.
Receipts stand alone. A receipt is Ed25519 over canonical JSON — it verifies in any wallet, against nothing but the banker's key, with the bank offline or dead.
Money is arithmetic, not floats. The fold is BigInt end to end; amounts up to 250 settle exactly, in any order, on every device.
Hosting without an origin server. The client is a static build served as plain files — IPFS, named by IPNS, fronted by DNSLink. This page works the same way.
Run it yourself
cd client && npm install && npm run dev # http://localhost:5173
# open two tabs on the same #room URL — you are your own first customer
(needs JVM ≥ 17 + the clojure CLI for shadow-cljs; npm test drives the
black-box suite against the BUILT output — the settlement fold against hand-computed
golden scenarios with order independence asserted for every one, the wire vectors, and
the whole view model, because the part of a money app that can lie to you is the part
that renders it.)
Deploy: npm run build, then publish client/dist/ as static
files anywhere. It needs nothing but a libp2p circuit relay + mailbox it's allowed to
talk to.
Guarantees & limits, honestly
You trust each banker with that bank's money. A banker can mint without limit, refuse to ack forever, and close your account — none of it cryptographically prevented. What you get is a signed, replicated record of every act, which you can show to anyone. That is attribution, not security, and the two are never confused here.
Provisional is not final. A settled payment can still be displaced by an entry that has not reached you yet. Only final — acked — is irreversible, and the interface says so beside every payment it renders.
The bank dies with the banker key. No recovery, no succession. A lost banker seed leaves a bank that still settles provisionally and can never mint or finalize again.
The ledger is public to link holders, permanently. Removal is not retraction; guard the link like you'd guard the vault.
A rate is an assertion, not an oracle — a number the banker published, no more binding than a sign in a window. And nothing here is insured, redeemable or legal tender: a balance is a record of what a log says, agreed to by the people reading it.
The relay/mailbox operator sees ciphertext, sizes, timing and IPs. Not content, not balances, not who banks with whom.
🪙 banca
o bancă p2p între prieteni, fără servere — fondezi una, îi emiți banii, faci plățile finale. Fără server, fără conturi; pagina asta e și repo-ul git.
Situl servește repository-ul prin protocolul dumb-HTTP al lui git, ca simple fișiere statice (chiar simple fișiere — nu există aici niciun server git, de fapt niciun server):
git clone https://git.ardegazu.ro/banca.git
cd banca
Ce este
Orice identitate poate fonda o bancă: își întemeiază o monedă, primește clienți,
emite, decontează plăți. O bancă e un singur log replicat, criptat
cap-la-cap, iar linkul ei — #<secret>.<bankerPub> —
e toată capabilitatea: cine e bancherul reiese din URL înainte să fie citită vreo
intrare, iar registrul trăiește doar pe dispozitivele membrilor. Niciun server nu-l
ține — și nici n-ar avea cum.
Plățile se decontează provizoriu în clipa în care se replică —
doi clienți față în față într-o piață ajung la aceleași solduri cu bancherul dormind —
și devin finale când bancherul le confirmă. Banii confirmați poartă o
chitanță portabilă wallet-kit care se
verifică singură, în orice portofel, cu banca offline. Interfața nu amestecă niciodată
cele două stări; distincția asta e produsul. Iar unitatea de cont neutră,
gazul (GAZ), e rezervată: o cartă care o revendică e refuzată
oricărui bancher — gazul nu-l poate emite nimeni.
PWA instalabil, atent la safe-area, merge de pe orice host de fișiere statice.
Ce e în repo
client/src/banca/lib/ — banca
protocol.cljs — uniunea de operații BANK/1; fold.cljs — decontarea, o rejucare pură a întregii istorii (fără fereastră, fără evacuare: un fold care ar uita ar fi un fold care minte); wallet.cljs + view.cljs — chitanțele și modelul de vedere care numește cinstit fiecare stare a unei plăți.
nucleul de camere — nu e în repo-ul ăsta
Logul replicat criptat, prezența și mailboxul offline sunt ardegazu.rooms.*, compilate de pe classpath din ardegazu-rooms-kit (pin pe sha). Repari acolo; moștenesc toate aplicațiile cu camere.
docs/PROTOCOL.md — contractul
BANK/1, textul normativ: operații, autorizare, foldul, chitanțele, suprafețele de injecție. §11 e lista cinstită de limite; §12 e ce trebuie să spună orice interfață construită pe el.
deploy/ — conducta de publicare
publish-repo.sh construiește chiar situl ăsta: pagină de prezentare + oglindă bare desfăcută în obiecte loose, în spatele unei porți de anonimat care refuză să publice octeți purtători de identitate.
Cum funcționează (versiunea scurtă)
Linkul ESTE banca. Secretul și cheia publică a bancherului stau în fragmentul URL-ului (#…) și nu pleacă niciodată din browser. Politica e o funcție pură a linkului, așa că bancherul e cunoscut înainte de citirea vreunei operații — o operație care pretinde puteri de bancher fără semnătura bancherului pur și simplu nu se foldează.
Fără server. Browserele sunt peers libp2p: se întâlnesc printr-un nod circuit-relay, trec pe WebRTC direct și replică un log OrbitDB criptat. Fiecare intrare e sigilată; eșecul decriptării e chiar controlul de acces. Membrii care nu sunt niciodată online în același timp converg prin mailboxul offline sigilat.
Provizoriu, apoi final. Replica oricărui membru poate adăuga o plată; foldul determinist o decontează identic oriunde ajunge. Confirmarea bancherului o pironește — iar confirmarea unui mint semnează o chitanță de emisiune pe care nicio intrare antedatată n-o mai poate disloca.
Chitanțele stau singure. O chitanță e Ed25519 peste JSON canonic — se verifică în orice portofel, doar cu cheia bancherului, cu banca offline sau moartă.
Banii sunt aritmetică, nu floats. Foldul e BigInt de la un capăt la altul; sume până la 250 se decontează exact, în orice ordine, pe fiecare dispozitiv.
Găzduire fără server de origine. Clientul e un build static servit ca simple fișiere — IPFS, numit prin IPNS, cu DNSLink în față. Pagina asta funcționează la fel.
Rulează-l singur
cd client && npm install && npm run dev # http://localhost:5173
# deschide două taburi pe același URL cu #cameră — ești primul tău client
(cere JVM ≥ 17 + CLI-ul clojure pentru shadow-cljs; npm test mână
suita black-box peste buildul COMPILAT — foldul de decontare pe scenarii de aur
calculate de mână, cu independența de ordine afirmată pentru fiecare, vectorii de
sârmă și tot modelul de vedere, pentru că partea dintr-o aplicație de bani care te
poate minți e cea care îi afișează.)
Deploy: npm run build, apoi publică client/dist/ ca
fișiere statice oriunde. N-are nevoie decât de un circuit relay libp2p + mailbox cu
care are voie să vorbească.
Garanții și limite, pe bune
Te încrezi în fiecare bancher pentru banii băncii lui. Un bancher poate emite fără limită, poate refuza confirmarea la nesfârșit și îți poate închide contul — nimic din toate astea nu e împiedicat criptografic. Ce primești e o evidență semnată și replicată a fiecărui act, pe care o poți arăta oricui. Asta e atribuire, nu securitate, și cele două nu se confundă niciodată aici.
Provizoriu nu înseamnă final. O plată decontată mai poate fi dislocată de o intrare care încă n-a ajuns la tine. Doar finalul — confirmatul — e ireversibil, iar interfața o spune lângă fiecare plată pe care o afișează.
Banca moare odată cu cheia bancherului. Fără recuperare, fără succesiune. Un seed de bancher pierdut lasă o bancă ce mai decontează provizoriu și nu mai poate emite sau finaliza niciodată.
Registrul e public pentru purtătorii linkului, permanent. Scoaterea nu e retractare; păzește linkul cum ai păzi seiful.
Un curs e o afirmație, nu un oracol — un număr publicat de bancher, cu nimic mai obligatoriu decât un afiș în vitrină. Și nimic de aici nu e asigurat, răscumpărabil sau mijloc legal de plată: un sold e evidența a ceea ce spune un log, acceptată de cei care îl citesc.
Operatorul releului/mailboxului vede ciphertext, dimensiuni, timpi și IP-uri. Nu conținut, nu solduri, nu cine ține banii la cine.
🪙 banca
szerver nélküli p2p bank a barátok között — alapíts egyet, bocsásd ki a pénzét, tedd véglegessé a fizetéseket. Se szerver, se fiókok; ez az oldal egyben a git repó is.
Az oldal a repót a git dumb-HTTP protokollján át szolgálja ki, sima statikus fájlokként (tényleg sima fájlok — nincs itt git szerver, sőt semmilyen szerver):
git clone https://git.ardegazu.ro/banca.git
cd banca
Mi ez
Bármely identitás alapíthat bankot: valutát jegyez, ügyfeleket fogad, kibocsát,
fizetéseket számol el. Egy bank egyetlen, végponttól végpontig titkosított
replikált log, és a linkje — #<secret>.<bankerPub> —
a teljes capability: hogy ki a bankár, az az URL-ből következik, mielőtt egyetlen
bejegyzés is beolvasásra kerülne, a főkönyv pedig csak a tagok eszközein él. Szerver
nem tárolja — nem is tudná.
A fizetések a replikáció pillanatában ideiglenesen számolódnak el —
két ügyfél a piacon ugyanoda jut, miközben a bankár alszik —, és akkor válnak
véglegessé, amikor a bankár nyugtázza őket. A nyugtázott pénzhez
hordozható wallet-kit elismervény jár,
amely önmagát igazolja, bármely tárcában, offline bank mellett is. A felület soha nem
mossa össze a két állapotot; ez a különbség maga a termék. A semleges elszámolási
egység, a gaz (GAZ) pedig fenntartott: az azt igénylő alapítólevelet
minden bankártól megtagadja — a gazt senki sem bocsáthatja ki.
Telepíthető PWA, safe-area-tudatos, bármilyen statikus fájlkiszolgálóról megy.
Mi van a repóban
client/src/banca/lib/ — a bank
protocol.cljs — a BANK/1 műveletunió; fold.cljs — az elszámolás, a teljes történet tiszta visszajátszása (nincs ablak, nincs kilakoltatás: a felejtő fold hazudó fold volna); wallet.cljs + view.cljs — az elismervények és a nézetmodell, amely minden fizetési állapotot őszintén nevez meg.
a szoba-mag — nincs ebben a repóban
A titkosított replikált log, a jelenlét és az offline mailbox az ardegazu.rooms.*, a classpathról fordítva az ardegazu-rooms-kit-ből (sha-ra tűzve). Ott javítod; minden szobás app örökli.
docs/PROTOCOL.md — a szerződés
BANK/1, a normatív szöveg: műveletek, jogosultság, a fold, elismervények, injektálási felületek. A §11 a korlátok őszinte listája; a §12 az, amit minden ráépülő felületnek ki kell mondania.
deploy/ — a publikálási csővezeték
A publish-repo.sh építi ezt az oldalt: nyitóoldal + loose objektumokra bontott bare tükör, egy anonimitási kapu mögött, amely identitáshordozó bájtokat nem enged ki.
Hogyan működik (a rövid változat)
A link MAGA a bank. A titok és a bankár nyilvános kulcsa az URL fragmentben él (#…), és soha nem hagyja el a böngészőt. A szabályzat a link tiszta függvénye, így a bankár már azelőtt ismert, hogy egyetlen művelet beolvasásra kerülne — a bankári jogokat a bankár aláírása nélkül igénylő művelet egyszerűen nem foldolódik.
Se szerver. A böngészők libp2p peerek: egy circuit-relay csomóponton át találkoznak, közvetlen WebRTC-re váltanak, és egy titkosított OrbitDB logot replikálnak. Minden bejegyzés lepecsételve pihen; a sikertelen visszafejtés maga a hozzáférés-ellenőrzés. Az egyszerre sosem elérhető tagok a lepecsételt offline mailboxon át konvergálnak.
Ideiglenes, majd végleges. Bármely tag replikája hozzáfűzhet egy fizetést; a determinisztikus fold mindenhol ugyanúgy számolja el. A bankár nyugtája rögzíti — egy mint nyugtája pedig kibocsátási elismervényt ír alá, amelyet visszadátumozott bejegyzés többé nem mozdíthat ki.
Az elismervény önmagában megáll. Ed25519 kanonikus JSON felett — bármely tárcában ellenőrizhető, semmi máshoz nem kell, mint a bankár kulcsa, offline vagy halott bank mellett is.
A pénz aritmetika, nem float. A fold végig BigInt; a 250-ig terjedő összegek pontosan, tetszőleges sorrendben, minden eszközön ugyanúgy számolódnak el.
Hosztolás origin-szerver nélkül. A kliens statikus build, sima fájlokként — IPFS-en, IPNS által nevezve, DNSLinkkel elöl. Ez az oldal is pontosan így működik.
Futtasd magad
cd client && npm install && npm run dev # http://localhost:5173
# nyiss két fület ugyanarra a #szoba URL-re — te vagy a saját első ügyfeled
(JVM ≥ 17 + clojure CLI kell a shadow-cljs-hez; az npm test a black-box
csomagot a LEFORDÍTOTT build ellen hajtja — az elszámolási foldot kézzel számolt arany
forgatókönyveken, mindegyikre kimondott sorrendfüggetlenséggel, a wire-vektorokat és a
teljes nézetmodellt, mert egy pénzes appból az a rész tud hazudni neked, amelyik
megjeleníti.)
Deploy: npm run build, majd tedd ki a client/dist/-et
statikus fájlokként bárhová. Semmi más nem kell hozzá, mint egy libp2p circuit relay +
mailbox, amellyel beszélhet.
Garanciák és korlátok, őszintén
Minden bankárban az ő bankja pénzéig bízol. Egy bankár korlát nélkül kibocsáthat, örökre megtagadhatja a nyugtázást, és lezárhatja a számládat — ezt semmi sem akadályozza kriptográfiailag. Amit kapsz: minden aktus aláírt, replikált nyoma, amelyet bárkinek megmutathatsz. Ez attribúció, nem biztonság, és a kettő itt sosem keveredik.
Az ideiglenes nem végleges. Egy elszámolt fizetést még kimozdíthat egy bejegyzés, amely nem ért el hozzád. Csak a végleges — a nyugtázott — visszafordíthatatlan, és a felület ezt minden megjelenített fizetés mellé odaírja.
A bank a bankárkulccsal együtt hal meg. Nincs helyreállítás, nincs utódlás. Az elveszett bankár-seed olyan bankot hagy, amely ideiglenesen még elszámol, de kibocsátani vagy véglegesíteni soha többé nem tud.
A főkönyv a link birtokosainak nyilvános, örökre. Az eltávolítás nem visszavonás; őrizd a linket, ahogy a széfet őriznéd.
Az árfolyam állítás, nem orákulum — egy szám, amelyet a bankár közzétett, semmivel sem kötelezőbb, mint egy tábla a kirakatban. És itt semmi sincs biztosítva, semmi sem beváltható vagy törvényes fizetőeszköz: az egyenleg annak nyoma, amit egy log mond, és amit az olvasói elfogadnak.
A relé/mailbox üzemeltetője ciphertextet, méreteket, időzítést és IP-ket lát. Tartalmat nem, egyenlegeket nem, azt sem, ki kinél bankol.