Repository navigation
Decimal-edge tests for validate_token #235
Description
Activity
- addedkind:securitySecurity hardeningSecurity hardeningarea:onchainOn-chain (Soroban) areaOn-chain (Soroban) area
on Jul 15, 2026 - addedGrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Campaign: Official Campaign | FWC26
on Jul 15, 2026 Hey!
validate_tokeninlib.rsaccepts 0..=38 decimals but the boundary cases aren't tested. I'll add cases for decimals 0, 7, 38, and 39 intests/aid_escrow_tests.rs, plus amin_decimalspolicy field (default 0) sofundwith 39 returnsError::InvalidTokenDecimals. I can have this in a couple hours. Mind if I take this on?Hi, I am a fullStack developer with years of experience, I have worked on so many project and I can submit a PR in less than 24hrs. Can I work on this please
grantfox-oss commented
on Jul 21, 2026 grantfox-ossboton Jul 21, 2026 – with GrantFox OSSMore actionsgrantfox-oss commented
on Jul 28, 2026 grantfox-ossboton Jul 28, 2026 – with GrantFox OSSMore actions🎉 This issue has been marked as completed on GrantFox as part of the Official Campaign | FWC26 campaign!
@mercy60's PR #412 was approved and merged by @kilodesodiq-arch.
🏆 @mercy60: You earned 35 FoxPoints for this contribution! Your current tier: Explorer (121 total points). Track your full progress on GrantFox.
👏 Great work, @mercy60! Keep contributing to ChainForgee.
- added a commit that references this issue
on Jul 31, 2026
Problem Statement.
validate_token(&env, &token)calls the token'sdecimals()andaccepts
0..=38as valid. The boundary cases (0, 38, 39, div by 0 due to decimals=0division) are not exercised.
Why it matters. Precision loans on tokens with 0 decimals would silently succeed
even if the integration team's policy requires minimum 6 or 7.
Technical Context.
lib.rs::validate_token.Expected Outcome. Tests for decimals = 0, 7, 38, 39. New policy field
min_decimals(default 0) configurable via admin.
Acceptance Criteria.
fundwith decimals=39 returns newError::InvalidTokenDecimals.fundwith decimals=0 still works unless policy is configured otherwise.Files or modules likely to be affected.
src/lib.rs,tests/aid_escrow_tests.rs.Difficulty. Medium
Estimated effort. S
Backlog item #27 from `docs/maintainer-issue-backlog.md.