One asset per invoice from a registry (lib/crypto_asset.rb): BTC, LTC,
ETH, XMR, SOL, ALGO, USDT/USDC on ERC-20/TRC-20/BEP-20/Solana/Algorand.
Migration 003 generalizes the ltc_* columns to crypto_* + crypto_coin
(existing LTC invoices backfilled). QR payload adapts per asset: BIP21
amount URIs where supported, bare address for tokens with a network
hint on the PDF. Default addresses come from the CRYPTO_ADDRESSES
secret (JSON code=>address); LTC_ADDRESS still works as legacy.
Updates CLAUDE.md to reflect what the site actually is now (entity page +
invoicing, not just contact form):
- "What this is" expanded to two responsibilities.
- New "Storage stack dependency" section explaining the Postgres + MinIO
split, the storage repo, and the failure mode if storage is down.
- Stack list gains Sequel/pg, Prawn, aws-sdk-s3, AdminAuth, the two
external Docker networks, and postgres in the dev shell.
- New "Invoicing" section: routes (admin + public), storage model with
the uuid mass-assignment caveat, PDF rendering + Noto Georgian fallback,
frontend touch, and the open caveats (single-process number allocator,
UUID == access).
- Secrets table extended with ADMIN_*, ASXPIO_DB_PASSWORD,
ASXPIO_S3_ACCESS_KEY, ASXPIO_S3_SECRET_KEY and their rotation rules
(dual-repo update, push storage first).
- Records the URL-safe-password lesson from the deploy that broke prod
twice, with a generator one-liner.
- Recovery snippet uses a <prod-host> placeholder rather than the real
internal IP, since this file lives in a public repo.
Also drops the global-prefs lines from Hard Rules — those belong in the
user-level CLAUDE.md, not the project file.