feat: solve issues #349, #351, #353, and #338 across store, crypto, a… - #393
Merged
Merged
Conversation
…-Protocol-org#353, and Octo-Protocol-org#338 across store, crypto, and wallet-core Comprehensive multi-issue resolution implementing migration decision documentation, muxed address property-based round-trip testing, cryptographic nonce-uniqueness guarantees, and soft-delete semantics for webhook endpoints. 1. Issue Octo-Protocol-org#349: Migration Decision Index & Foreign Key Audit - Created `docs/migrations.md` providing a one-line-per-migration decision index spanning all 21 append-only migrations in `crates/store/migrations/`. - Documented schema changes, constraint rationale, and foreign key ON DELETE behaviors across tables. - Added explicit cross-reference to the webhook delivery cascade audit (Issue Octo-Protocol-org#338). - Updated `docs/architecture.md` with links to `docs/migrations.md`. - Added convention note to `CONTRIBUTING.md` requiring every future migration PR to update the index in `docs/migrations.md`. Closes Octo-Protocol-org#349 2. Issue Octo-Protocol-org#351: Proptest Round-Trip Corpus for Muxed Address Encoding - Added property-based tests in `crates/wallet-core/src/address.rs` using proptest with 1,000 cases across the full u64 id range. - `encode_then_decode_muxed_round_trips_for_arbitrary_u64_ids`: asserts arbitrary u64 IDs round-trip accurately through encode_muxed and decode_muxed. - `decoded_base_account_always_matches_the_original_input_account`: verifies that the recovered base account matches the initial input account across all ids. Closes Octo-Protocol-org#351 3. Issue Octo-Protocol-org#353: Nonce-Uniqueness & Input-Independence Regression Suite - Added `seals_of_same_plaintext_never_repeat_nonce` in `crates/crypto/src/lib.rs` asserting 10,000 AES-256-GCM seals of the same plaintext under the same key never produce colliding nonces. - Added `nonces_show_no_correlation_with_varying_plaintext_and_key_across_a_large_sample` generating 10,000 seals with randomized master keys and plaintexts. - Computed Pearson correlation coefficients between nonce bytes and key/plaintext inputs, verifying no gross statistical correlation (|r| < 0.05) exists. Closes Octo-Protocol-org#353 4. Issue Octo-Protocol-org#338: Webhook Endpoint Soft-Deletion to Preserve Delivery Audit Logs - Audited foreign key behavior: previously, `webhook_deliveries.endpoint_id` referenced `webhook_endpoints(id) ON DELETE CASCADE`, causing hard deletes to destroy historical delivery logs. - Added migration `0021_soft_delete_webhook_endpoints.sql` introducing `deleted_at TIMESTAMPTZ` and partial index `idx_webhook_endpoints_active_not_deleted`. - Updated `WebhookEndpoint` struct in `crates/store/src/models.rs` with `deleted_at`. - Updated `active_webhook_endpoints` in `crates/store/src/lib.rs` to filter out soft-deleted endpoints (`deleted_at IS NULL AND active = true`), ensuring `dispatch` skips retired endpoints. - Added `delete_webhook` and `list_webhooks(wallet_id, include_deleted)` in `crates/store/src/lib.rs`. - Updated API routes in `crates/api/src/routes/webhooks.rs` for soft-deletion and optional `include_deleted` query filtering. - Updated `crates/store/tests/store_tests.rs` migration version check to 21 and added test suite: `delete_webhook_soft_deletes_rather_than_hard_deleting`, `dispatch_skips_a_soft_deleted_endpoint`, `list_webhooks_excludes_soft_deleted_endpoints_by_default`, and `historical_deliveries_for_a_soft_deleted_endpoint_remain_queryable`. Closes Octo-Protocol-org#338
|
@mamzamercy0-ui Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
# Conflicts: # crates/api/src/routes/webhooks.rs # crates/crypto/src/lib.rs # crates/store/src/lib.rs # crates/store/tests/store_tests.rs # docs/architecture.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
…nd wallet-core
Comprehensive multi-issue resolution implementing migration decision documentation, muxed address property-based round-trip testing, cryptographic nonce-uniqueness guarantees, and soft-delete semantics for webhook endpoints.
docs/migrations.mdproviding a one-line-per-migration decision index spanning all 21 append-only migrations incrates/store/migrations/.docs/architecture.mdwith links todocs/migrations.md.CONTRIBUTING.mdrequiring every future migration PR to update the index indocs/migrations.md. Closes Document the full audit trail of every append-only migration's ON DELETE / constraint decisions in one changelog-style index #349crates/wallet-core/src/address.rsusing proptest with 1,000 cases across the full u64 id range.encode_then_decode_muxed_round_trips_for_arbitrary_u64_ids: asserts arbitrary u64 IDs round-trip accurately through encode_muxed and decode_muxed.decoded_base_account_always_matches_the_original_input_account: verifies that the recovered base account matches the initial input account across all ids. Closes Add a proptest round-trip corpus for encode_muxed/decode_muxed across the full u64 id range #351seals_of_same_plaintext_never_repeat_nonceincrates/crypto/src/lib.rsasserting 10,000 AES-256-GCM seals of the same plaintext under the same key never produce colliding nonces.nonces_show_no_correlation_with_varying_plaintext_and_key_across_a_large_samplegenerating 10,000 seals with randomized master keys and plaintexts.webhook_deliveries.endpoint_idreferencedwebhook_endpoints(id) ON DELETE CASCADE, causing hard deletes to destroy historical delivery logs.0021_soft_delete_webhook_endpoints.sqlintroducingdeleted_at TIMESTAMPTZand partial indexidx_webhook_endpoints_active_not_deleted.WebhookEndpointstruct incrates/store/src/models.rswithdeleted_at.active_webhook_endpointsincrates/store/src/lib.rsto filter out soft-deleted endpoints (deleted_at IS NULL AND active = true), ensuringdispatchskips retired endpoints.delete_webhookandlist_webhooks(wallet_id, include_deleted)incrates/store/src/lib.rs.crates/api/src/routes/webhooks.rsfor soft-deletion and optionalinclude_deletedquery filtering.crates/store/tests/store_tests.rsmigration version check to 21 and added test suite:delete_webhook_soft_deletes_rather_than_hard_deleting,dispatch_skips_a_soft_deleted_endpoint,list_webhooks_excludes_soft_deleted_endpoints_by_default, andhistorical_deliveries_for_a_soft_deleted_endpoint_remain_queryable. Closes Add a soft-delete path for webhook endpoints so historical deliveries stay attributable #338Summary
Related step / issue
Checklist
cargo fmt --all -- --checkpassescargo clippy --workspace --all-targets -- -D warningspassescargo test --workspacepassesHow to test