Repository navigation
Harden proposal discussion thread: signed authorship, cursor pagination, rate limiting, safe Markdown - #561
Merged
james2177 merged 5 commits intoSep 30, 2026
Conversation
…n thread: pagination, rate Closes stellar-vortex-protocol#476
…and voter history pages wi Closes stellar-vortex-protocol#477
…-Security-Policy via middl Closes stellar-vortex-protocol#478
…odel and build an XSS/inje Closes stellar-vortex-protocol#481
|
@martinzhames Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
# Conflicts: # middleware.ts # src/app/governance/[id]/ProposalDetailClient.tsx # src/lib/textSafety.ts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Harden proposal discussion thread: signed authorship, cursor pagination, rate limiting, safe Markdown
What was solved
#476 — [High] Harden the proposal discussion thread: pagination, rate limits, signed authorship and moderation-safe rendering
Harden the proposal discussion thread by rebuilding comment storage on the API layer with cursor pagination, client-side rate limiting, wallet-signed authorship verification (SEP-53 style with a signMessage shim fallback), and moderation-safe Markdown rendering. The UI must show a 'verified author' badge only after client-side signature verification, enforce 1–2,000 char limits with counters, support optimistic posting with rollback, handle 429 via Retry-After, and provide report/hide-local controls with locally persisted hidden IDs.
Addressed:
#477 — [High] Build the governance archive and voter history pages with search, filters and participation stats
Add a searchable governance archive page at /governance/archive with URL-synced filters (status, category, date range, text search), sorting, pagination, outcome/tally/execution display, and CSV export, plus a per-address voter history page at /governance/voter/[address] with strkey validation, vote list (choice, weight, timestamp, proposal link), participation rate over selectable windows, graceful 404, CSV export, and SEO metadata/sitemap entries.
Addressed:
#478 — [High] Move to a nonce-based Content-Security-Policy via middleware and remove
'unsafe-inline'for scriptsImplement a per-request nonce-based Content-Security-Policy for the Next.js app: add middleware that generates a cryptographic nonce, sets a CSP with script-src 'self' 'nonce-…' 'strict-dynamic' (dropping 'unsafe-inline' for scripts), and forwards the nonce via a request header for Next's inline scripts; extract a shared pure policy builder used by both middleware and next.config.mjs; add a CSP report endpoint that validates, rate-limits, and logs violations via secureLogger; start in Report-Only mode; keep dev HMR working; and update the security audit doc with verification steps.
Addressed:
#481 — [High] Write a signing-flow threat model and build an XSS/injection payload regression suite across every rendered field
Add a STRIDE-style threat model for the swap/registration/vote signing flows and a data-driven XSS/injection regression suite that renders a shared hostile-string corpus through every component displaying externally supplied data, enforcing sanitisation and safe URL handling (notably toast hrefs).
Addressed:
Changes
src/lib/textSafety.ts(modify)src/app/governance/voter/[address]/page.tsx(create)docs/threat-model.md(create)src/lib/governanceStore.ts(modify)src/app/governance/archive/page.tsx(create)src/lib/csp.ts(create)src/app/governance/[id]/ProposalDetailClient.tsx(modify)src/lib/wallet/signMessage.ts(create)middleware.ts(create)src/test/hostileStrings.ts(create)Approach
'unsafe-inline'for scripts #478 — [High] Move to a nonce-based Content-Security-Policy via middleware and remove'unsafe-inline'for scripts (Changed: middleware.ts, src/lib/csp.ts, src/lib/csp.ts, middleware.ts)Issues
Closes #476
Closes #477
Closes #478
Closes #481