Skip to content

feat(signature-hint-auditor): map envelope signature hints to public candidates - #490

Merged
egekoca merged 2 commits into
RevenantLabs:mainfrom
chainsmt:feat/signature-hint-auditor
Sep 30, 2026
Merged

egekoca merged 2 commits into
RevenantLabs:mainfrom
chainsmt:feat/signature-hint-auditor

Conversation

@chainsmt

@chainsmt chainsmt commented Sep 29, 2026 •

Copy link
Copy Markdown

Closes #467

Summary

Adds an offline Transaction Signature Hint Auditor under features/signature-hint-auditor/. Paste a transaction envelope XDR, optionally provide public G… signer candidates, and see every decorated signature’s four-byte hint mapped to zero/one/many candidates — without treating a hint match as cryptographic verification.

Motivation

Envelope XDR already carries decorated signature hints, but operators often confuse “hint matches this pubkey” with “signature verified.” Four bytes collide. Fee-bump envelopes also mix outer fee-source signatures with inner transaction signatures. This tool separates groups and labels matches honestly.

What this PR does

  • Decodes supported classic (v0/v1) and fee-bump envelopes locally with @stellar/stellar-sdk — no Horizon / no network (msw/handlers.ts is empty).
  • Lists every decorated signature hint in original order (lib/decorated-signatures.ts).
  • Accepts optional public signer keys and derives their hints the network way (last four bytes of the raw public key) via lib/signer-hints.ts.
  • Maps hints to zero, one, or many candidates and surfaces collisions (lib/hint-candidates.ts + CollisionNotice).
  • Keeps fee-bump outer and inner signature groups separate in the UI (SignatureRows).
  • Labels every match as a hint match, never a verified signature.
  • Refuses secret seeds (S…) on prefix alone in both envelope and signer fields and remounts the form so seeds do not linger in the textarea. Input stays memory-only.
  • Error codes with dedicated copy: empty_xdr, invalid_xdr, invalid_public_signer, unsupported_envelope, too_many_signers.
  • Full feature contract plus deterministic fixtures for signatures and forced hint collisions; e2e covers the ambiguous-hint path.

Architecture notes

  • Slice-only: features/signature-hint-auditor/.
  • Collision fixture forces two genuine public keys to share a recorded hint so the ambiguous UI is deterministic.
  • Related reading: patterns similar to fee-bump-inspector hint listing, but this slice is independent.

Acceptance criteria coverage

  • Decode supported envelopes; list every decorated hint in original order
  • Optional public signers; derive hints; never accept secret seeds
  • Zero/one/many candidates per hint; identify collisions
  • Separate fee-bump outer vs inner groups
  • Label matches as hint matches only; keep input in memory

Out of scope

  • Cryptographic signature verification
  • Threshold / weight checks
  • Transaction submission
  • Network lookups

Test plan

  • npm run verify:features -- signature-hint-auditor (35 files)
  • npm test -- features/signature-hint-auditor (73 tests)
  • Manual: signed classic envelope + matching pubkey → single hint match
  • Manual: fee-bump envelope → outer and inner groups
  • Manual: paste S… seed → refused and cleared
  • Manual: collision fixture → multiple candidates called out

@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@chainsmt Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@egekoca
egekoca merged commit 177f43b into RevenantLabs:main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Transactions] Transaction Signature Hint Auditor

2 participants