Skip to content

Feature: Implement Idempotent Stellar Wallet Provisioning #90

Description

@3m1n3nc3

Description

Generate one Stellar keypair after consent, protect it with KMS, and recover from partial failures.

File Location

Wallet provisioning service/job, KMS/Stellar adapters, outbox handlers, and tests

Design Reference

API Roadmap Phase 1: Implement Idempotent Stellar Wallet Provisioning.

Dependencies

  • Status: Blocked
  • Blocked by: Feature: Add Custodial Wallet Persistence and KMS References; Feature: Add Onboarding and Consent Persistence; Feature: Add Transaction Outbox and Job Delivery Foundation
  • Blocks: Feature: Implement Sponsored Stellar Account Funding; integration suite

Tasks

  • Require verification and custodial consent
  • Reserve wallet/idempotency record before external key work
  • Generate keypair in trusted boundary and store secret immediately via KMS
  • Persist only public key and opaque reference
  • Recover from DB, KMS, and process failures without duplicate active wallets
  • Audit lifecycle without secret material

Acceptance Criteria

  • Concurrent retries produce at most one active wallet
  • Plaintext secret is absent from DB/logs/errors
  • Partial failures are repairable
  • Failure-injection tests pass

Verification Evidence

  • Attach concurrency/failure tests and automated secret scan

Difficulty

Advanced

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions