1 min read

BTCPay Server 2.4.5 Blocks Private-Network Requests by Default

The release also tightens refund permissions and speeds invoice creation by skipping unnecessary Lightning and fee lookups.

A firewall appliance sits beside a compact payment terminal / TokenPost.ai
A firewall appliance sits beside a compact payment terminal / TokenPost.ai

BTCPay Server 2.4.5 blocks outbound requests to private network destinations by default, adding a security control that affects merchants and developers who connect the payment processor to private services.

The change is intended to reduce server-side request forgery risks, in which a server is induced to contact systems that should not be reachable from outside. Operators who need private destinations for Lightning connections, LNURL requests, invoice notifications or webhooks may need to add exceptions.

The update also changes refund permissions. Employees who cannot create approved pull payments can no longer automatically approve refunds for invoice overpayments. Public invoice checkout, status and receipt information becomes hidden after monitoring ends, though users with invoice-view permission retain access.

Invoice creation is faster because the software skips unnecessary Lightning node and on-chain fee lookups. The release does not quantify the speed improvement.

Developers should review the breaking changes before upgrading. The release marks invoice notification URLs for deprecation, points developers to webhooks, and removes the URL field from manual invoice creation.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…