feat(validation): add Stellar public key format validation in agent r…#189
Open
Stanley-Owoh wants to merge 1 commit into
Open
Conversation
…egistration and tasks
|
@Stanley-Owoh is attempting to deploy a commit to the Jaja's projects Team on Vercel. A member of the Team first needs to authorize it. |
Contributor
|
Solid Implementation @Stanley-Owoh |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add Missing Input Validation for Stellar Public Key Format in Agent Registration
Problem
Malformed Stellar Ed25519 public keys were accepted by both the agent registration endpoint and the task creation endpoint. The
stellarPublicKeyfield in the registration schema only checked that the value was a string, and thewalletpublickeyrequest header in task creation was used without any validation.Solution
Added robust validation for Stellar public keys using the regex
/^G[A-Z2-7]{55}$/, which enforces that keys start withG, are exactly 56 characters, and contain only valid Base32 characters (A-Z,2-7).Changes
backend/src/api/routes/agents.tsSTELLAR_PUBLIC_KEY_REGEXconstantstellarPublicKeyinRegisterAgentSchemato use.regex()validation with error messagepricingXLMto use.positive()validationbackend/src/api/routes/tasks.tsSTELLAR_PUBLIC_KEY_REGEXconstantwalletpublickeyheader in the POST/api/tasksroute — returns HTTP 400 with"Invalid Stellar public key format"if the header is missing or invalidbackend/tests/agents.test.ts"Stellar public key validation"test suite covering:Gprefix → 400pricingXLM→ 400pricingXLM→ 400walletpublickeyheader on task creation → 400walletpublickeyheader on task creation → 400Acceptance Criteria
stellarPublicKeyuses.regex()validation in the registration schemapricingXLMmust be positivewalletpublickeyis validated before task creationCloses #151