Skip to content

Feature: Implement Idempotent Stellar Wallet Provisioning #90

Description

@3m1n3nc3

Description

Generate one Stellar keypair after consent, protect it with KMS, and recover from partial failures.

File Location

Wallet provisioning service/job, KMS/Stellar adapters, outbox handlers, and tests

Design Reference

API Roadmap Phase 1: Implement Idempotent Stellar Wallet Provisioning.

Dependencies

  • Status: Blocked
  • Blocked by: Feature: Add Custodial Wallet Persistence and KMS References; Feature: Add Onboarding and Consent Persistence; Feature: Add Transaction Outbox and Job Delivery Foundation
  • Blocks: Feature: Implement Sponsored Stellar Account Funding; integration suite

Tasks

  • Require verification and custodial consent
  • Reserve wallet/idempotency record before external key work
  • Generate keypair in trusted boundary and store secret immediately via KMS
  • Persist only public key and opaque reference
  • Recover from DB, KMS, and process failures without duplicate active wallets
  • Audit lifecycle without secret material

Acceptance Criteria

  • Concurrent retries produce at most one active wallet
  • Plaintext secret is absent from DB/logs/errors
  • Partial failures are repairable
  • Failure-injection tests pass

Verification Evidence

  • Attach concurrency/failure tests and automated secret scan

Difficulty

Advanced

Metadata

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions