Skip to content

feat: lock shortcut wiring, handle resolution validation, invoice mismatch errors, and spend limit max amount extraction - #1436

Open
bitcoindev817-hue wants to merge 1 commit into
ancore-org:mainfrom
bitcoindev817-hue:feat/issues-1398-1403-1395-1401
Open

bitcoindev817-hue wants to merge 1 commit into
ancore-org:mainfrom
bitcoindev817-hue:feat/issues-1398-1403-1395-1401

Conversation

@bitcoindev817-hue

Copy link
Copy Markdown

Summary of Changes

This PR resolves four critical security, extension, and contract issues on ancore-org/ancore:

  1. [EXTENSION] Wire "Lock shortcut" Security Setting ([EXTENSION] The "Lock shortcut" security setting has zero effect — its only implementation is entirely unmounted, parallel to the real lock/unlock system #1398)

    • Wired keyboard hotkeys (⌘+Shift+L / Ctrl+Shift+L) in ExtensionAuthProvider (apps/extension-wallet/src/router/AuthGuard.tsx).
    • Connected hotkeys to useSettingsStore (enableLockShortcut) and lockWallet().
    • Updated useLockManager hook to use active extension auth context lock when mounted inside the provider.
  2. [EXTENSION] Handle Resolution Schema Check & Recipient Address Format Validation ([EXTENSION] @username handle resolution bypasses its own schema check, and the resolved address is never format-validated before becoming the send destination #1395)

    • Removed unvalidated fallback return in apps/extension-wallet/src/services/handle-resolver.ts to ensure safeParse MUST succeed.
    • Updated resolvedHandleSchema in @ancore/types to validate both G... (public key) and C... (contract) Stellar address formats.
    • Added explicit isStellarAddress check in useSendTransaction.ts following handle resolution prior to setting recipient to address.
  3. [CONTRACT] Invoice Contract AssetMismatch & AmountMismatch Validation ([CONTRACT] Invoice contract declares AssetMismatch/AmountMismatch errors that no code path can ever return #1403)

    • Added pay_verified to InvoiceContract in contracts/invoice/src/lib.rs supporting optional expected amount and asset parameters.
    • Enforced return of InvoiceError::AmountMismatch when caller expected amount does not match invoice amount, and InvoiceError::AssetMismatch when asset does not match.
    • Added unit test coverage test_pay_verified_mismatches.
  4. [CONTRACT] Account Spend Limit Maximum Amount Extraction ([CONTRACT] extract_spend_amount picks the first positive i128 argument as "the spend amount" — trivially bypasses per-call and cumulative spend limits #1401)

    • Updated extract_spend_amount in contracts/account/src/lib.rs to compute the maximum positive i128 argument value across all call arguments.
    • Prevents decoy arguments (e.g. 1i128) preceding larger amounts (e.g. 999_999i128) from masking or bypassing per-call and cumulative spend limit checks.
    • Added unit test test_execute_session_key_multiple_args_decoy_prevention.

Closes #1398
Closes #1403
Closes #1395
Closes #1401

@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@bitcoindev817-hue Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: d0675e12-a2d9-4b3e-b814-fc30655a989b


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment