Skip to content

[Contracts] RemittanceNFT validate_metadata_uri ignores the documented ipfs/https prefix check and leaves two dead bindings #1145

Description

@grantfox-oss

Telegram (ask questions / claim the issue here first): https://t.me/+DOylgFv1jyJlNzM0

Labels: enhancement, good first issue, contracts, nft, rust

validate_metadata_uri in contracts/remittance_nft/src/lib.rs:176-190 doesn't do what its doc comment says. It builds _ipfs_prefix/_https_prefix, then throws both away (underscore-discarded, never compared) and only enforces uri.len() < 8. The comment claims it "checks the URI starts with valid prefix," but any string of 8+ chars, like aaaaaaaa, sails through mint(), admin_remint(), and update_metadata_uri().

So the code and its stated contract disagree, plus there's dead bindings hanging around. Not a fund-loss path, just a correctness/clarity gap: either implement the prefix check the comment promises, or fix the comment and drop the dead bindings so they line up.

What the fix has to hold to

  • Code and doc comment agree. Either enforce the documented ipfs:///https:// prefix check, or correct the comment to say only a length floor is enforced.
  • No leftover unused bindings (_ipfs_prefix/_https_prefix) if you don't add the prefix check.
  • Whatever validation you keep applies consistently across every caller (mint, admin_remint, update_metadata_uri).
  • Full RFC-compliant URI parsing and on-chain content-addressing are out of scope.

Done when

  • Either an actual prefix check (ipfs:// or https://) is implemented, or the doc comment is corrected to state only a length floor
  • The unused _ipfs_prefix/_https_prefix bindings are removed if no prefix check is added
  • Test asserts a non-ipfs/https URI is rejected (or documents that it's intentionally accepted)
  • cargo test + cargo fmt + cargo clippy green, CI passing

Where to start
Edit validate_metadata_uri in contracts/remittance_nft/src/lib.rs (176-190) to either implement the prefix comparison or align the comment and drop the dead bindings. Add a test in the remittance_nft test module for whichever behavior you pick. Small and newcomer-friendly, about a day.

Activity

  1. added
    enhancementNew feature or request
    contractsIssues related to smart contracts
    nftNFT functionality
    rustPull requests that update rust code
    on Jun 27, 2026
  2. shobhamerabacha-star commented on Sep 15, 2026

    @shobhamerabacha-star

    Hi there,

    I am interested in working on this issue.
    Plan:

    1. Implement [Contracts] RemittanceNFT validate_metadata_uri ignores the documented ipfs/https prefix check and leaves two dead bindings with explicit require_auth checks, secure state storage, and gas optimization.
    2. Cover contract calls with hermetic unit tests verifying events and token balances.

    Looking forward to collaborating on this—please assign!

  3. Banx17 commented on Sep 27, 2026

    @Banx17
    Contributor

    @Banx17 has applied to work on this issue as part of the Stellar Wave Program's 9th wave.

    Good day team, i will love to work on this issue for your team, it matches my dev stack please kindly assign.

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @Banx17 to this issue.

  4. drips-wave commented on Sep 27, 2026

    @drips-wave

    Congratulations, @Banx17! 🎉 Your application was accepted by the repo's maintainers, and the issue is due on September 30, 2026.

    🧑‍💻 @Banx17: Please resolve the issue such that the repo's maintainers have enough time to review your contribution before the due date. You'll earn Points for completing the issue on-time, which will make you eligible for a share of the Stellar Wave Program's reward pool.

    Warning

    When opening a PR, please link it to this issue to ensure it gets tracked accurately. Points are awarded when this issue is marked as completed by the maintainer.

    🤠 Repo maintainers: Please keep an eye on the contributor's progress and review their work before the due date. You can manage this issue, including adjusting its complexity and points, here.

    🌊 Happy Wave 🌊

  5. added a commit that references this issue on Oct 7, 2026
  6. grantfox-oss commented on Oct 7, 2026

    @grantfox-oss
    Author

    🎉 This issue has been marked as completed on GrantFox!

    @Banx17's PR #1951 was approved and merged by @K1NGD4VID.

    🏆 @Banx17: You earned 40 FoxPoints for this contribution! Your current tier: Builder (2,240 total points). Track your full progress on GrantFox.

    👏 Great work, @Banx17! Keep contributing to LabsCrypt.

  7. drips-wave commented on Oct 7, 2026

    @drips-wave

    This issue has been marked as completed by a Drips Wave moderator for @Banx17 as part of the Stellar Wave Program's 9th Wave 🥳

    Moderator's reason: [Auto-assessed] The PR was successfully merged by maintainer @K1NGD4VID, and it comprehensively resolves issue #1145 by replacing the dead metadata prefix bindings with an active prefix check (ipfs:// or https://), updating all corresponding callers, and adding rigorous test coverage.

    😎 @Banx17: You earned 150 Points for completing this issue! After the current Wave ends, you'll be eligible for a percentage of the Wave's reward pool based on the percentage of total points you've earned. Learn more here.

    🧑‍💻 Repo maintainers: How'd the contributor do? Leave a review to share your experience working with them.

    ℹ️ Note: This issue was marked complete via moderation. Points were issued even though the GitHub issue remains open.

  8. added a commit that references this issue on Oct 7, 2026
    987df06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Stellar WaveIssues in the Stellar wave programcontractsIssues related to smart contractsenhancementNew feature or requestgood first issueGood for newcomersnftNFT functionalityrustPull requests that update rust code

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions