Skip to content

Persist target allocations, verify Stellar submissions, and add user API keys - #205

Merged
github-actions[bot] merged 4 commits into
TRELLIS-STELLAR:mainfrom
OTD-Aregbesola:codex/persist-allocations-oracle-api-keys
Oct 6, 2026
Merged

github-actions[bot] merged 4 commits into
TRELLIS-STELLAR:mainfrom
OTD-Aregbesola:codex/persist-allocations-oracle-api-keys

Conversation

@OTD-Aregbesola

Copy link
Copy Markdown
Contributor

Target allocations, oracle verification, and consumer API keys previously relied on placeholder or in-memory behavior. This change makes them persistent and validates submissions against the Stellar ledger.

  • Persist complete allocation versions, validate asset membership and 100% totals, replace current targets atomically, and expose recoverable history.
  • Store indexed submission history, reject duplicate payloads and transactions atomically, and retain replay records indefinitely.
  • Verify successful Soroban submit_price transactions against the configured network and contract, with confirmation checks and bounded retries for transient RPC failures.
  • Add hashed user API keys, metadata-only listing, owner-scoped revocation, last-use auditing, caching, and scope enforcement. Revocation also invalidates API-key-issued JWTs. Static keys remain supported with deprecation guidance.

The Stellar payload representation follows the existing six-argument submit_price interface: SHA-256 of its canonical XDR argument vector. Related contract work: TRELLIS-STELLAR/Trellis-contracts#9. Verification requires a Stellar transaction reference; legacy payload signatures alone are not ledger evidence.

Validation: 56 tests passed on the rebased branch, including existing rebalancing behavior. Two additional API key strategy tests passed with the upstream quota dependency isolated using its last valid configuration. All three migrations passed PostgreSQL smoke checks in PGlite, including rollback, restart persistence, unique replay indexes, and revocation.

Existing malformed quota configuration on main blocks the full TypeScript build and the direct API key strategy test suite. That unrelated configuration is unchanged. Scoped ESLint and diff whitespace checks passed; existing formatting in shared app and rebalancing code remains outside scope.

Closes #12
Closes #11
Closes #10
Closes #9

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Code Review & Auto-Merge — @dorismaduegbunam 🚀

Thank you @OTD-Aregbesola for your contribution!

Verified code changes and repository requirements. Merging pull request.

@github-actions
github-actions Bot merged commit ec57f4c into TRELLIS-STELLAR:main Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant