Skip to content

[MEDIUM] — CSV donation export hardcodes "USD Equivalent" = 0.00; downstream consumers may trust the column for tax / accounting workflows #15

Description

@ibrahimmosouf-png

Severity: Medium
Type: Bug
Scope: Donations, Users
Labels: bug, security, help wanted

Description

Both the synchronous and asynchronous export paths emit a hardcoded 0.00 USD equivalent:

  • UsersService.exportUserDonationsAsCSV (src/users/users.service.ts, line ~415).
  • ExportProcessor.handleDonationExport (src/users/export.processor.ts, line ~58).
    The comment in each location acknowledges this is a placeholder ("USD equivalent: fetched from price cache in production").

Two failure modes persist today:

  1. Users downloading the CSV for tax/accounting will see a 0.00 value and may trust it.
  2. If a future consumer (analytics dashboard, partner integration) ingests the CSV preemptively, the integration will be biased.

Recommendation

  • Drop the column entirely until a real price-oracle integration is added, or rename it to Quote: pending.
  • When ready, integrate a price oracle (Stellar Horizon /order_book snapshots, CoinGecko, or a self-hosted oracle service) and cache quotes with TTL by asset.
  • Document the absence in README.md so external integrators are not surprised.

Activity

  1. added
    bugSomething isn't working
    help wantedExtra attention is needed
    securitySecurity vulnerability or hardening
    on Jun 18, 2026
  2. added
    GrantFox OSSIssue tracked in GrantFox OSS
    Maybe RewardedIssue may be eligible for a GrantFox reward
    Official CampaignAudit finding under the Official Campaign
    on Jun 18, 2026
  3. iyanumajekodunmi756 commented on Jun 18, 2026

    @iyanumajekodunmi756
    Contributor

    Hi maintainer, I would love to work on this issue. I have studied the details of the issue description and I understood the requirements. I shall deliver with qualitative feedback and promptly.

  4. grantfox-oss commented on Jun 18, 2026

    @grantfox-oss

    🦊 GrantFox — @iyanumajekodunmi756 has been assigned to this issue as part of the Official Campaign campaign!

    Next steps:

    1. Open a Pull Request referencing this issue (e.g., Closes #15)
    2. Your PR will be reviewed by the OrbitChainLabs maintainers

    Good luck! Track your progress on GrantFox.

  5. added 2 commits that reference this issue on Jun 18, 2026
    7eee2cb
    a3e26cf
  6. grantfox-oss commented on Jun 20, 2026

    @grantfox-oss

    🎉 This issue has been marked as completed on GrantFox as part of the Official Campaign campaign!

    @iyanumajekodunmi756's PR #29 was approved and merged by @Alqku.

    🏆 @iyanumajekodunmi756: You earned 35 FoxPoints for this contribution! Your current tier: Explorer (83 total points). Track your full progress on GrantFox.

    👏 Great work, @iyanumajekodunmi756! Keep contributing to OrbitChainLabs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignbugSomething isn't workinghelp wantedExtra attention is neededsecuritySecurity vulnerability or hardening

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions