Repository navigation
feat: address batch issues #348, #350, #354, #352 across api and wall… - #388
Merged
Emmyt24 merged 2 commits intoSep 28, 2026
Merged
Conversation
…, Octo-Protocol-org#354, Octo-Protocol-org#352 across api and wallet-core This commit simultaneously addresses 4 issues across octo-api and octo-wallet-core: 1. Issue Octo-Protocol-org#348: Request-Body Size Limits Uniformity on Mutating Routes - Audited router wiring in crates/api/src/lib.rs and confirmed that DefaultBodyLimit::max(REQUEST_BODY_LIMIT) (64 KiB) is applied uniformly to the router containing all mutating routes. - Exposed pub const REQUEST_BODY_LIMIT: usize = 64 * 1024 from crates/api/src/lib.rs. - Added a parametrized integration test every_mutating_route_rejects_an_oversized_body_with_a_clean_413 in crates/api/tests/body_size_limit_tests.rs covering every mutating route with oversized payloads asserting clean 413 Payload Too Large responses. - Closes Octo-Protocol-org#348 2. Issue Octo-Protocol-org#350: Sourced BIP-39 Checksum-Invalid Test Vectors - Added a permanent, cited corpus of checksum-invalid BIP-39 mnemonics in crates/wallet-core/src/derive.rs. - Sourced authoritative vectors from Trezor reference implementation (tests/test_mnemonic.py) as well as official BIP-39 specification test vectors (bitcoin/bips/bip-0039.mediawiki and trezor/python-mnemonic/vectors.json) by mutating the final checksum word to alternative valid wordlist entries (almost-valid vectors across 12, 15, 18, and 24-word phrases) alongside grossly invalid vectors. - Added regression test from_phrase_rejects_every_sourced_checksum_invalid_vector parametrized across the corpus to ensure wordlist-and-checksum validation is permanently upheld. - Closes Octo-Protocol-org#350 3. Issue Octo-Protocol-org#354: Public validate_seed_phrase Helper - Extracted mnemonic syntax, wordlist, and checksum validation logic into a public helper function pub fn validate_seed_phrase(phrase: &str) -> Result<(), WalletError> in crates/wallet-core/src/derive.rs. - Re-exported validate_seed_phrase from crates/wallet-core/src/lib.rs. - Refactored WalletSeed::from_phrase to call validate_seed_phrase internally so pre-flight validation and seed construction never diverge. - Documented that validate_seed_phrase is safe for untrusted input and produces no secret material. - Added regression tests verifying agreement between validate_seed_phrase and from_phrase on both valid and invalid vectors, as well as a type-level test proving no secret material is returned. - Closes Octo-Protocol-org#354 4. Issue Octo-Protocol-org#352: Document SEP-0005 Derivation Path and Hardened-Index Invariant - Expanded doc comment on derive_ed25519_secret in crates/wallet-core/src/derive.rs adhering to the project documentation register in CONTRIBUTING.md. - Explicitly documented the exact derivation path (m/44'/148'/index'), the security justification for full hardening on Ed25519 (SLIP-0010) in contrast to EVM BIP-44 unhardened derivation, and the 2^31 hardened-index ceiling. - Cross-referenced docs/deposit-model.md detailing how index 0 underpins the muxed-address architecture. - Added a runnable doc-test example demonstrating correct derivation. - Closes Octo-Protocol-org#352
|
@emperorsixpacks Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
# Conflicts: # crates/wallet-core/src/derive.rs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
…et-core
This commit simultaneously addresses 4 issues across octo-api and octo-wallet-core:
Summary
Related step / issue
Checklist
cargo fmt --all -- --checkpassescargo clippy --workspace --all-targets -- -D warningspassescargo test --workspacepassesHow to test