fix: make calculate_fee_split read-only - #675
Open
Akinsuyiphilip wants to merge 4 commits into
Open
Conversation
Align the settlement timelock with the seven-day recovery window and reject scheduled execution while recovery is pending, preventing compromised-admin upgrades and transfers from racing past recovery. Generated with Codebuff 🤖 Co-Authored-By: Codebuff <noreply@codebuff.com>
Keep calculate_fee_split neutral for storage TTLs and bootstrap telemetry so untrusted callers cannot keep merchants warm or spam events. Generated with Codebuff 🤖 Co-Authored-By: Codebuff <noreply@codebuff.com>
Use the Soroban testutils traits correctly and keep the regression focused on storage TTL and event neutrality. Generated with Codebuff 🤖 Co-Authored-By: Codebuff <noreply@codebuff.com>
|
@Akinsuyiphilip Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #498
Summary
Make
calculate_fee_splita genuinely read-only fee quote operation.Problem
calculate_fee_splitpreviously reused storage helpers intended for mutatingpayment paths. Those helpers could refresh merchant and settlement-rule TTLs
and emit
bootstrap_fallbackwhenever no explicit rule was configured.Because the quote endpoint is publicly callable, an attacker could repeatedly
invoke it to:
This made a read path observable as a storage mutation and created avoidable
resource costs for the contract and downstream consumers.
Changes
calculate_fee_splitto use the read-only resolver.bootstrap_fallback.operations.
Security and behavior
calculate_fee_splitstill validates the merchant and amount and returns thesame fee split, but it no longer writes persistent storage or emits events.
Callers can safely use it for off-chain quotes without keeping otherwise
expirable entries alive or spamming fallback telemetry.
Testing
Added/updated coverage for:
calculate_fee_split_read_is_ttl_and_event_neutralValidation: