Skip to content

feat: address batch issues #348, #350, #354, #352 across api and wall… - #388

Merged
Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
emperorsixpacks:dev-branch
Sep 28, 2026
Merged

Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
emperorsixpacks:dev-branch

Conversation

@emperorsixpacks

Copy link
Copy Markdown

…et-core

This commit simultaneously addresses 4 issues across octo-api and octo-wallet-core:

  1. Issue Add a regression test asserting request-body size limits apply uniformly across every mutating route #348: Request-Body Size Limits Uniformity on Mutating Routes
  • Audited router wiring in crates/api/src/lib.rs and confirmed that DefaultBodyLimit::max(REQUEST_BODY_LIMIT) (64 KiB) is applied uniformly to the router containing all mutating routes.
  • Exposed pub const REQUEST_BODY_LIMIT: usize = 64 * 1024 from crates/api/src/lib.rs.
  • Added a parametrized integration test every_mutating_route_rejects_an_oversized_body_with_a_clean_413 in crates/api/tests/body_size_limit_tests.rs covering every mutating route with oversized payloads asserting clean 413 Payload Too Large responses.
  • Closes Add a regression test asserting request-body size limits apply uniformly across every mutating route #348
  1. Issue Add BIP-39 checksum-invalid test vectors to WalletSeed::from_phrase's suite #350: Sourced BIP-39 Checksum-Invalid Test Vectors
  • Added a permanent, cited corpus of checksum-invalid BIP-39 mnemonics in crates/wallet-core/src/derive.rs.
  • Sourced authoritative vectors from Trezor reference implementation (tests/test_mnemonic.py) as well as official BIP-39 specification test vectors (bitcoin/bips/bip-0039.mediawiki and trezor/python-mnemonic/vectors.json) by mutating the final checksum word to alternative valid wordlist entries (almost-valid vectors across 12, 15, 18, and 24-word phrases) alongside grossly invalid vectors.
  • Added regression test from_phrase_rejects_every_sourced_checksum_invalid_vector parametrized across the corpus to ensure wordlist-and-checksum validation is permanently upheld.
  • Closes Add BIP-39 checksum-invalid test vectors to WalletSeed::from_phrase's suite #350
  1. Issue Add a validate_seed_phrase public helper for pre-flight client-side mnemonic validation #354: Public validate_seed_phrase Helper
  • Extracted mnemonic syntax, wordlist, and checksum validation logic into a public helper function pub fn validate_seed_phrase(phrase: &str) -> Result<(), WalletError> in crates/wallet-core/src/derive.rs.
  • Re-exported validate_seed_phrase from crates/wallet-core/src/lib.rs.
  • Refactored WalletSeed::from_phrase to call validate_seed_phrase internally so pre-flight validation and seed construction never diverge.
  • Documented that validate_seed_phrase is safe for untrusted input and produces no secret material.
  • Added regression tests verifying agreement between validate_seed_phrase and from_phrase on both valid and invalid vectors, as well as a type-level test proving no secret material is returned.
  • Closes Add a validate_seed_phrase public helper for pre-flight client-side mnemonic validation #354
  1. Issue Document the SEP-0005 derivation path and hardened-index invariant directly above derive_ed25519_secret #352: Document SEP-0005 Derivation Path and Hardened-Index Invariant
  • Expanded doc comment on derive_ed25519_secret in crates/wallet-core/src/derive.rs adhering to the project documentation register in CONTRIBUTING.md.
  • Explicitly documented the exact derivation path (m/44'/148'/index'), the security justification for full hardening on Ed25519 (SLIP-0010) in contrast to EVM BIP-44 unhardened derivation, and the 2^31 hardened-index ceiling.
  • Cross-referenced docs/deposit-model.md detailing how index 0 underpins the muxed-address architecture.
  • Added a runnable doc-test example demonstrating correct derivation.
  • Closes Document the SEP-0005 derivation path and hardened-index invariant directly above derive_ed25519_secret #352

Summary

Related step / issue

Checklist

  • cargo fmt --all -- --check passes
  • cargo clippy --workspace --all-targets -- -D warnings passes
  • cargo test --workspace passes
  • No secrets (seeds/keys) logged or persisted in plaintext
  • Added/updated tests (test vectors for crypto/derivation changes)
  • Updated docs / CHANGELOG if behavior changed

How to test

…, Octo-Protocol-org#354, Octo-Protocol-org#352 across api and wallet-core

This commit simultaneously addresses 4 issues across octo-api and octo-wallet-core:

1. Issue Octo-Protocol-org#348: Request-Body Size Limits Uniformity on Mutating Routes
- Audited router wiring in crates/api/src/lib.rs and confirmed that DefaultBodyLimit::max(REQUEST_BODY_LIMIT) (64 KiB) is applied uniformly to the router containing all mutating routes.
- Exposed pub const REQUEST_BODY_LIMIT: usize = 64 * 1024 from crates/api/src/lib.rs.
- Added a parametrized integration test every_mutating_route_rejects_an_oversized_body_with_a_clean_413 in crates/api/tests/body_size_limit_tests.rs covering every mutating route with oversized payloads asserting clean 413 Payload Too Large responses.
- Closes Octo-Protocol-org#348

2. Issue Octo-Protocol-org#350: Sourced BIP-39 Checksum-Invalid Test Vectors
- Added a permanent, cited corpus of checksum-invalid BIP-39 mnemonics in crates/wallet-core/src/derive.rs.
- Sourced authoritative vectors from Trezor reference implementation (tests/test_mnemonic.py) as well as official BIP-39 specification test vectors (bitcoin/bips/bip-0039.mediawiki and trezor/python-mnemonic/vectors.json) by mutating the final checksum word to alternative valid wordlist entries (almost-valid vectors across 12, 15, 18, and 24-word phrases) alongside grossly invalid vectors.
- Added regression test from_phrase_rejects_every_sourced_checksum_invalid_vector parametrized across the corpus to ensure wordlist-and-checksum validation is permanently upheld.
- Closes Octo-Protocol-org#350

3. Issue Octo-Protocol-org#354: Public validate_seed_phrase Helper
- Extracted mnemonic syntax, wordlist, and checksum validation logic into a public helper function pub fn validate_seed_phrase(phrase: &str) -> Result<(), WalletError> in crates/wallet-core/src/derive.rs.
- Re-exported validate_seed_phrase from crates/wallet-core/src/lib.rs.
- Refactored WalletSeed::from_phrase to call validate_seed_phrase internally so pre-flight validation and seed construction never diverge.
- Documented that validate_seed_phrase is safe for untrusted input and produces no secret material.
- Added regression tests verifying agreement between validate_seed_phrase and from_phrase on both valid and invalid vectors, as well as a type-level test proving no secret material is returned.
- Closes Octo-Protocol-org#354

4. Issue Octo-Protocol-org#352: Document SEP-0005 Derivation Path and Hardened-Index Invariant
- Expanded doc comment on derive_ed25519_secret in crates/wallet-core/src/derive.rs adhering to the project documentation register in CONTRIBUTING.md.
- Explicitly documented the exact derivation path (m/44'/148'/index'), the security justification for full hardening on Ed25519 (SLIP-0010) in contrast to EVM BIP-44 unhardened derivation, and the 2^31 hardened-index ceiling.
- Cross-referenced docs/deposit-model.md detailing how index 0 underpins the muxed-address architecture.
- Added a runnable doc-test example demonstrating correct derivation.
- Closes Octo-Protocol-org#352
@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@emperorsixpacks Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

# Conflicts:
#	crates/wallet-core/src/derive.rs
@Emmyt24
Emmyt24 merged commit b8bada5 into Octo-Protocol-org:dev-branch Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment