Skip to content

fix: consolidated fixes for issues #285, #286, #283, and #284 - #378

Merged
Emmyt24 merged 5 commits into
Octo-Protocol-org:dev-branchfrom
Grace-CODE-D:task-fixes
Sep 28, 2026
Merged

Emmyt24 merged 5 commits into
Octo-Protocol-org:dev-branchfrom
Grace-CODE-D:task-fixes

Conversation

@Grace-CODE-D

Copy link
Copy Markdown

Overview

This PR addresses and resolves the following 4 tasks:

  • Reject an audit-log category filter value that doesn't match any known category #285: Reject an audit-log category filter value that doesn't match any known category

    • Validates category against crate::audit::category::ALL in list_audit_logs.
    • Returns ApiError::BadRequest listing all valid categories on mismatch.
    • Updates docs/api.md to document all valid category values.
  • Ensure list_transactions distinguishes deposit and withdrawal rows consistently for dashboard filtering #286: Ensure list_transactions distinguishes deposit and withdrawal rows consistently for dashboard filtering

    • Adds optional direction query parameter (deposit | withdrawal) to list_transactions.
    • Validates direction parameter and returns ApiError::BadRequest on invalid values.
    • Pushes the filter down into the SQL query via Store::list_transactions_page using $2::text IS NULL OR direction = $2.
    • Preserves pagination math and cursor bounds.
    • Updates docs/api.md and docs/openapi.yaml.
  • Ensure wallet ownership is verified before a client-custody wallet is marked usable #283: Ensure wallet ownership is verified before a client-custody wallet is marked usable

    • Audited challenge issuance, signature verification, and wallet creation sequencing.
    • Confirmed create_wallet performs inline cryptographic verification of ownership via verify_ownership (using octo_wallet_core::verify_account_signature) before persisting the wallet to the database.
    • Added an explicit ownership-verification invariant doc comment to create_wallet.
  • Add a covering index for the ingest supervisor's wallets_due_for_poll query #284: Add a covering index for the ingest supervisor's wallets_due_for_poll query

    • Added migration 0021_index_wallets_due_for_poll.sql introducing indexes on wallets(network) and ingest_cursor(wallet_id, last_polled_at, updated_at).
    • Added wallets_due_for_poll query to scripts/bench_store_indexes.sh.
    • Updated migration count assertion in crates/store/tests/store_tests.rs.

Closes #285
Closes #286
Closes #283
Closes #284

…tegory set

An unrecognized category filter value silently returned zero rows, indistinguishable from a genuinely empty result. Validates the filter against the known category constants and returns a clear 400 listing valid values on a mismatch.

Closes Octo-Protocol-org#285
list_transactions returned deposits and withdrawals interleaved with no server-side direction filter, forcing dashboard clients to fetch everything and filter client-side, which breaks pagination math. Adds a validated direction query parameter pushed into SQL.

Closes Octo-Protocol-org#286
…ated without verified ownership

Audits and hardens the challenge-sign-verify-create sequence for client-custody wallet creation, ensuring create_wallet cannot succeed without an ownership signature it independently verifies.

Closes Octo-Protocol-org#283
wallets_due_for_poll runs on every supervisor tick for every network with no confirmed covering index, risking a sequential scan that worsens as wallet count grows. Adds the minimal index(es) needed, created concurrently.

Closes Octo-Protocol-org#284
@drips-wave

drips-wave Bot commented Sep 25, 2026

Copy link
Copy Markdown

@Grace-CODE-D Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

# Conflicts:
#	crates/store/src/lib.rs
#	docs/api.md
@Emmyt24
Emmyt24 merged commit c058746 into Octo-Protocol-org:dev-branch Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment