Conversation
add_trustline was a 410 stub. It now validates the asset code, issuer and limit with wallet-core's shared validate_change_trust (also used by the ChangeTrust test signer) and returns what a client needs to build and sign the ChangeTrust locally: sequence, network passphrase, base fee and limit. This follows the same non-custodial build-then-sign-locally pattern as payments and fee-bumps, and the server never signs. Closes Octo-Protocol-org#321
|
@Favourice01 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
…ement-add-trustline # Conflicts: # crates/wallet-core/src/lib.rs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #321
What
POST /v1/wallets/:id/trustlineswas a410 Gonestub. It now follows the non-custodial build-then-sign-locally pattern already used byGET /signing-infoandPOST /submit-signed. No server-side signing is added.Request:
{ "asset_code": "USDC", "asset_issuer": "G...", "limit_stroops": <optional i64> }Response (mirrors
SigningInfo):{ "account": "G...", "sequence": "159...", "network_passphrase": "...", "base_fee_stroops": 100, "asset_code": "USDC", "asset_issuer": "G...", "limit_stroops": "9223372036854775807", "submit_url": "/v1/wallets/<id>/submit-signed" }The client builds the ChangeTrust, signs it locally, and relays it through
submit-signed, whose op allowlist already admits change-trust.Details
octo_wallet_core::validate_change_trustchecks the asset code (is_valid_asset_code), requires aG...issuer (is_valid_account), and requires a non-negative limit.sign_change_trustnow calls it too, so the test signer and the route accept exactly the same inputs. As a side effect, the fixture signer now checks the asset code as well.authorize_wallet(owner JWT or the wallet's API key). Non-owners get 404, the same as every other wallet route.limit_stroopsdefaults toi64::MAX(unlimited), because Stellar reads a missing limit as 0, which removes the trustline. Likesequence, it is sent as a string because it is past JS's safe-integer range.docs/api.md,docs/architecture.mdanddocs/non-custodial-flow.mdare updated.Tests
add_trustline_returns_signing_info_for_a_valid_assetuses a local mock Horizon, so it runs without a funded testnet account.add_trustline_rejects_an_invalid_asset_codecovers an empty code, a 13-byte code, a bad issuer, a negative limit and a missing code.add_trustline_requires_wallet_authorization: no credentials gives 401, another user gives 404.custodial_trustline_is_gone.These three tests and the wallet-core
change_trusttests pass locally against Postgres.