Skip to content

fix(maintenance-pool): guard assignReward by issueId and enforce unique payout index (#458) - #472

Open
Proxima84-code wants to merge 3 commits into
MergeFi:mainfrom
Proxima84-code:fix/prevent-double-reward-payout-458
Open

Proxima84-code wants to merge 3 commits into
MergeFi:mainfrom
Proxima84-code:fix/prevent-double-reward-payout-458

Conversation

@Proxima84-code

Copy link
Copy Markdown

Resolves #458 (Regression on #273).

Root Cause

In MaintenancePoolService.assignReward(), the idempotency guard existingPoolPayment filtered on payment.recipientId = :recipientId instead of payment.maintenanceIssueId = :issueId. This caused:

  1. The same maintenance issue to be rewarded multiple times when assigned to different recipients.
  2. Legitimate payouts for multiple distinct issues to the same recipient to be rejected with ConflictException.
  3. Anonymous payouts (recipientId = null) to bypass the guard entirely.
  4. An unused dead query (existingPayment) executing on every call.

Fix

  • Entity: Added nullable maintenanceIssueId and maintenanceIssue relation to Payment, along with composite unique index UQ_payment_escrow_maintenance_issue on [escrowId, maintenanceIssueId] to close concurrent race conditions at the database level.
  • EscrowService: Added optional maintenanceIssueId parameter to poolWithdraw() and persisted it on the Payment row. Fixed Soroban u64 deadline expectation in test fixtures.
  • MaintenancePoolService:
  • Test Suite:

@vercel

vercel Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Proxima84-code is attempting to deploy a commit to the chonilius' projects Team on Vercel.

A member of the Team first needs to authorize it.

@Proxima84-code

Copy link
Copy Markdown
Author

Hi @maintainers,

Since the deadline for issue #458 passed on September 30 without a solution from the original assignee, I have submitted a complete and fully tested fix here (all 78 unit tests passing locally, production build verified).

Could you please approve the CI workflow run and review the PR? Thank you!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant