Skip to content

feat(api): implement the trustline signing-info endpoint - #382

Merged
Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
Favourice01:feat/api/implement-add-trustline
Sep 28, 2026
Merged

Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
Favourice01:feat/api/implement-add-trustline

Conversation

@Favourice01

Copy link
Copy Markdown

Closes #321

What

POST /v1/wallets/:id/trustlines was a 410 Gone stub. It now follows the non-custodial build-then-sign-locally pattern already used by GET /signing-info and POST /submit-signed. No server-side signing is added.

Request: { "asset_code": "USDC", "asset_issuer": "G...", "limit_stroops": <optional i64> }

Response (mirrors SigningInfo):

{ "account": "G...", "sequence": "159...", "network_passphrase": "...", "base_fee_stroops": 100,
  "asset_code": "USDC", "asset_issuer": "G...", "limit_stroops": "9223372036854775807",
  "submit_url": "/v1/wallets/<id>/submit-signed" }

The client builds the ChangeTrust, signs it locally, and relays it through submit-signed, whose op allowlist already admits change-trust.

Details

  • Shared validation: octo_wallet_core::validate_change_trust checks the asset code (is_valid_asset_code), requires a G... issuer (is_valid_account), and requires a non-negative limit. sign_change_trust now calls it too, so the test signer and the route accept exactly the same inputs. As a side effect, the fixture signer now checks the asset code as well.
  • Authorization: authorize_wallet (owner JWT or the wallet's API key). Non-owners get 404, the same as every other wallet route.
  • Self-issued assets: a request where the issuer is the wallet's own account is rejected up front, because a ChangeTrust to your own asset is malformed on-chain and would only burn a fee.
  • Limits: limit_stroops defaults to i64::MAX (unlimited), because Stellar reads a missing limit as 0, which removes the trustline. Like sequence, it is sent as a string because it is past JS's safe-integer range.
  • Docs: docs/api.md, docs/architecture.md and docs/non-custodial-flow.md are updated.

Tests

  • add_trustline_returns_signing_info_for_a_valid_asset uses a local mock Horizon, so it runs without a funded testnet account.
  • add_trustline_rejects_an_invalid_asset_code covers an empty code, a 13-byte code, a bad issuer, a negative limit and a missing code.
  • add_trustline_requires_wallet_authorization: no credentials gives 401, another user gives 404.
  • It replaces custodial_trustline_is_gone.

These three tests and the wallet-core change_trust tests pass locally against Postgres.

add_trustline was a 410 stub. It now validates the asset code, issuer and limit
with wallet-core's shared validate_change_trust (also used by the ChangeTrust
test signer) and returns what a client needs to build and sign the ChangeTrust
locally: sequence, network passphrase, base fee and limit. This follows the same
non-custodial build-then-sign-locally pattern as payments and fee-bumps, and the
server never signs.

Closes Octo-Protocol-org#321
@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@Favourice01 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

…ement-add-trustline

# Conflicts:
#	crates/wallet-core/src/lib.rs
@Emmyt24
Emmyt24 merged commit 645acb3 into Octo-Protocol-org:dev-branch Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Implement POST /v1/wallets/:id/trustlines end to end instead of the current unimplemented stub

2 participants