Skip to content

feat: solve issues #349, #351, #353, and #338 across store, crypto, a… - #393

Merged
Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
mamzamercy0-ui:dev-branch
Sep 28, 2026
Merged

Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
mamzamercy0-ui:dev-branch

Conversation

@mamzamercy0-ui

Copy link
Copy Markdown

…nd wallet-core

Comprehensive multi-issue resolution implementing migration decision documentation, muxed address property-based round-trip testing, cryptographic nonce-uniqueness guarantees, and soft-delete semantics for webhook endpoints.

  1. Issue Document the full audit trail of every append-only migration's ON DELETE / constraint decisions in one changelog-style index #349: Migration Decision Index & Foreign Key Audit
  1. Issue Add a proptest round-trip corpus for encode_muxed/decode_muxed across the full u64 id range #351: Proptest Round-Trip Corpus for Muxed Address Encoding
  • Added property-based tests in crates/wallet-core/src/address.rs using proptest with 1,000 cases across the full u64 id range.
  • encode_then_decode_muxed_round_trips_for_arbitrary_u64_ids: asserts arbitrary u64 IDs round-trip accurately through encode_muxed and decode_muxed.
  • decoded_base_account_always_matches_the_original_input_account: verifies that the recovered base account matches the initial input account across all ids. Closes Add a proptest round-trip corpus for encode_muxed/decode_muxed across the full u64 id range #351
  1. Issue Add a nonce-uniqueness regression test asserting many seals of the same plaintext never repeat a nonce #353: Nonce-Uniqueness & Input-Independence Regression Suite
  • Added seals_of_same_plaintext_never_repeat_nonce in crates/crypto/src/lib.rs asserting 10,000 AES-256-GCM seals of the same plaintext under the same key never produce colliding nonces.
  • Added nonces_show_no_correlation_with_varying_plaintext_and_key_across_a_large_sample generating 10,000 seals with randomized master keys and plaintexts.
  • Computed Pearson correlation coefficients between nonce bytes and key/plaintext inputs, verifying no gross statistical correlation (|r| < 0.05) exists. Closes Add a nonce-uniqueness regression test asserting many seals of the same plaintext never repeat a nonce #353
  1. Issue Add a soft-delete path for webhook endpoints so historical deliveries stay attributable #338: Webhook Endpoint Soft-Deletion to Preserve Delivery Audit Logs
  • Audited foreign key behavior: previously, webhook_deliveries.endpoint_id referenced webhook_endpoints(id) ON DELETE CASCADE, causing hard deletes to destroy historical delivery logs.
  • Added migration 0021_soft_delete_webhook_endpoints.sql introducing deleted_at TIMESTAMPTZ and partial index idx_webhook_endpoints_active_not_deleted.
  • Updated WebhookEndpoint struct in crates/store/src/models.rs with deleted_at.
  • Updated active_webhook_endpoints in crates/store/src/lib.rs to filter out soft-deleted endpoints (deleted_at IS NULL AND active = true), ensuring dispatch skips retired endpoints.
  • Added delete_webhook and list_webhooks(wallet_id, include_deleted) in crates/store/src/lib.rs.
  • Updated API routes in crates/api/src/routes/webhooks.rs for soft-deletion and optional include_deleted query filtering.
  • Updated crates/store/tests/store_tests.rs migration version check to 21 and added test suite: delete_webhook_soft_deletes_rather_than_hard_deleting, dispatch_skips_a_soft_deleted_endpoint, list_webhooks_excludes_soft_deleted_endpoints_by_default, and historical_deliveries_for_a_soft_deleted_endpoint_remain_queryable. Closes Add a soft-delete path for webhook endpoints so historical deliveries stay attributable #338

Summary

Related step / issue

Checklist

  • cargo fmt --all -- --check passes
  • cargo clippy --workspace --all-targets -- -D warnings passes
  • cargo test --workspace passes
  • No secrets (seeds/keys) logged or persisted in plaintext
  • Added/updated tests (test vectors for crypto/derivation changes)
  • Updated docs / CHANGELOG if behavior changed

How to test

…-Protocol-org#353, and Octo-Protocol-org#338 across store, crypto, and wallet-core

Comprehensive multi-issue resolution implementing migration decision documentation,
muxed address property-based round-trip testing, cryptographic nonce-uniqueness
guarantees, and soft-delete semantics for webhook endpoints.

1. Issue Octo-Protocol-org#349: Migration Decision Index & Foreign Key Audit
- Created `docs/migrations.md` providing a one-line-per-migration decision index
  spanning all 21 append-only migrations in `crates/store/migrations/`.
- Documented schema changes, constraint rationale, and foreign key ON DELETE
  behaviors across tables.
- Added explicit cross-reference to the webhook delivery cascade audit (Issue Octo-Protocol-org#338).
- Updated `docs/architecture.md` with links to `docs/migrations.md`.
- Added convention note to `CONTRIBUTING.md` requiring every future migration PR
  to update the index in `docs/migrations.md`.
Closes Octo-Protocol-org#349

2. Issue Octo-Protocol-org#351: Proptest Round-Trip Corpus for Muxed Address Encoding
- Added property-based tests in `crates/wallet-core/src/address.rs` using proptest
  with 1,000 cases across the full u64 id range.
- `encode_then_decode_muxed_round_trips_for_arbitrary_u64_ids`: asserts arbitrary
  u64 IDs round-trip accurately through encode_muxed and decode_muxed.
- `decoded_base_account_always_matches_the_original_input_account`: verifies that
  the recovered base account matches the initial input account across all ids.
Closes Octo-Protocol-org#351

3. Issue Octo-Protocol-org#353: Nonce-Uniqueness & Input-Independence Regression Suite
- Added `seals_of_same_plaintext_never_repeat_nonce` in `crates/crypto/src/lib.rs`
  asserting 10,000 AES-256-GCM seals of the same plaintext under the same key
  never produce colliding nonces.
- Added `nonces_show_no_correlation_with_varying_plaintext_and_key_across_a_large_sample`
  generating 10,000 seals with randomized master keys and plaintexts.
- Computed Pearson correlation coefficients between nonce bytes and key/plaintext
  inputs, verifying no gross statistical correlation (|r| < 0.05) exists.
Closes Octo-Protocol-org#353

4. Issue Octo-Protocol-org#338: Webhook Endpoint Soft-Deletion to Preserve Delivery Audit Logs
- Audited foreign key behavior: previously, `webhook_deliveries.endpoint_id`
  referenced `webhook_endpoints(id) ON DELETE CASCADE`, causing hard deletes to
  destroy historical delivery logs.
- Added migration `0021_soft_delete_webhook_endpoints.sql` introducing `deleted_at TIMESTAMPTZ`
  and partial index `idx_webhook_endpoints_active_not_deleted`.
- Updated `WebhookEndpoint` struct in `crates/store/src/models.rs` with `deleted_at`.
- Updated `active_webhook_endpoints` in `crates/store/src/lib.rs` to filter out soft-deleted
  endpoints (`deleted_at IS NULL AND active = true`), ensuring `dispatch` skips retired endpoints.
- Added `delete_webhook` and `list_webhooks(wallet_id, include_deleted)` in `crates/store/src/lib.rs`.
- Updated API routes in `crates/api/src/routes/webhooks.rs` for soft-deletion and optional
  `include_deleted` query filtering.
- Updated `crates/store/tests/store_tests.rs` migration version check to 21 and added test suite:
  `delete_webhook_soft_deletes_rather_than_hard_deleting`,
  `dispatch_skips_a_soft_deleted_endpoint`,
  `list_webhooks_excludes_soft_deleted_endpoints_by_default`, and
  `historical_deliveries_for_a_soft_deleted_endpoint_remain_queryable`.
Closes Octo-Protocol-org#338
@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@mamzamercy0-ui Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

# Conflicts:
#	crates/api/src/routes/webhooks.rs
#	crates/crypto/src/lib.rs
#	crates/store/src/lib.rs
#	crates/store/tests/store_tests.rs
#	docs/architecture.md
@Emmyt24
Emmyt24 merged commit 329b9a4 into Octo-Protocol-org:dev-branch Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment