fix: prevent mutating a settled or cancelled split - #1380
Merged
SheyeJDev merged 2 commits intoSep 27, 2026
Merged
Conversation
…split-lifecycle.ts
…sts__/split-lifecycle.test.ts
|
@darkwalker2 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Contributor
|
LGTM |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
split-lifecycle.tsalready derives a split's state deterministically, but theonly post-completion guard wired to anything was
isCancellable():isTerminalwas exported, tested, and never called by production code, and the per-action
rules ("no deposits or metadata edits once locked", "nothing at all once
settled") existed only as comments.
This PR turns that policy into one table that every mutation path can consult,
and makes cancellation use it so the two can never disagree.
Related Issue
Closes #1325
Changes
backend/src/lib/split-lifecycle.ts— addsSPLIT_ACTIONS/SplitActionfor the actions a caller can request, plus:
isActionAllowed(state, action)— the post-completion policy in one place.Terminal states (
settled,cancelled) permit no mutation;distributingpermits only
distribute;draft/activepermit everything mutating; andreadis permitted in every state.assertActionAllowed(state, action)— throwssplit_not_mutable(409) naming both the state and the action, so a callercan tell "this project is settled" from "this project is locked".
isCancellable()now delegates toisActionAllowed(state, "cancel"). Itsbehaviour is unchanged (verified for all five states) but the cancellation
policy can no longer drift from the rest of the table.
backend/src/__tests__/split-lifecycle.test.ts— adds a truth table overevery state/action pair, the
isCancellableequivalence, the error shape, andthe "second cancellation" case.
assertActionAllowedis the entry point for the deposit/distribute/metadatapaths; this PR wires the cancellation path through the same table rather than
editing the on-chain transaction builders, which need a live project read.
Verification Results
The 25 pre-existing lifecycle tests still pass, including the
isTerminal/isCancellableblock, so the delegation preserved existingbehaviour.
deriveSplitState) unchanged and still the source of truthisActionAllowedderives permission from that state onlyassertActionAllowedrefuses every mutation onsettled/cancelledand everything butdistributewhiledistributing; cancellation now shares the same table