Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
411 commits
Select commit Hold shift + click to select a range
b7907df
Merge pull request #1208 from IfyJustin91/docs/disputes-41-rustdoc
mikewheeleer Jul 26, 2026
2e029e3
Merge pull request #1207 from CHKM001/docs/reputation-auth
mikewheeleer Jul 26, 2026
0cefd41
Merge pull request #1206 from chiboy84/feature/reputation-22-index-event
mikewheeleer Jul 26, 2026
28abdeb
Merge pull request #1202 from Yerimahjr/feature/disputes-42-pauseguard
mikewheeleer Jul 26, 2026
71b2540
Merge pull request #1199 from Yerimahjr/docs/reputation-31-threatmodel
mikewheeleer Jul 26, 2026
b7c84b9
Merge pull request #1195 from paul-motron/test/milestones-41-budget
mikewheeleer Jul 26, 2026
96fcfcc
Merge pull request #1193 from paul-motron/docs/milestones-41-rustdoc
mikewheeleer Jul 26, 2026
9baf06d
Merge pull request #1192 from keljoshX/docs/contracts-21-storage
mikewheeleer Jul 26, 2026
67a3f5b
Merge pull request #1189 from Carlys17/feature/reputation-11-bounds
mikewheeleer Jul 26, 2026
4e2823b
Merge pull request #1187 from Tonyfash/test/settlement-41-budget
mikewheeleer Jul 26, 2026
89cf949
Merge pull request #1186 from Stanley-Owoh/add-randomized-property-te…
mikewheeleer Jul 26, 2026
c134043
Merge pull request #1184 from quickweb-stack/docs/disputes-31-threatm…
mikewheeleer Jul 26, 2026
7473c80
Merge pull request #1182 from onajidavid87-web/Replace-magic-numbers-…
mikewheeleer Jul 26, 2026
bfc19d8
Merge pull request #1179 from Simongodw/docs/escrow-31-threatmodel
mikewheeleer Jul 26, 2026
99654ab
Merge pull request #1178 from onajidavid87-web/main
mikewheeleer Jul 26, 2026
a53880e
Merge pull request #1168 from Kingsley4867/feature/authorization-22-i…
mikewheeleer Jul 26, 2026
60b7209
Merge pull request #1149 from shaarknado/fix/pause-guard-issue-1064
mikewheeleer Jul 26, 2026
c98feb8
Merge pull request #1143 from bajehjude-del/docs/milestones-11-auth
mikewheeleer Jul 26, 2026
496174b
Merge pull request #1141 from dragespips/docs/milestones-21-storage
mikewheeleer Jul 26, 2026
ae49075
Merge pull request #1100 from abdoolbasit374-web/docs/milestones-31-t…
mikewheeleer Jul 26, 2026
ec3b533
Merge pull request #1096 from Osifowora/Document-the-settlement-autho…
mikewheeleer Jul 26, 2026
beae2b1
Merge pull request #1092 from nuhumusamagaji/fix/804-issue-804
mikewheeleer Jul 26, 2026
f08e63a
Merge pull request #1089 from nuhumusamagaji/docs/813-storage-model
mikewheeleer Jul 26, 2026
6b188ae
Merge pull request #1088 from Ikechukwu-Patrick/feature/reputation-31…
mikewheeleer Jul 26, 2026
dbe6aa0
Merge pull request #1083 from tobiadewola41-eng/main
mikewheeleer Jul 26, 2026
0a9db0d
Merge pull request #1078 from Clinton6801/refactor/contracts-mileston…
mikewheeleer Jul 26, 2026
cd56c86
Merge pull request #1076 from abdullahilateefat03-boop/refactor/807-d…
mikewheeleer Jul 26, 2026
86172fa
Merge pull request #1038 from ruthoreaji-123/docs/arbiter-21-storage
mikewheeleer Jul 26, 2026
57db515
Merge pull request #1029 from blessme247/feature/contracts-revoke-app…
mikewheeleer Jul 26, 2026
e4a957f
Merge pull request #1028 from amankoli09/docs/arbiter-11-auth
mikewheeleer Jul 26, 2026
5b4a3d9
Merge pull request #1026 from bamiebot-maker/feature/events-12-config…
mikewheeleer Jul 26, 2026
88aca10
Merge branch 'pr-1025'
mikewheeleer Jul 26, 2026
cdf773e
Merge branch 'pr-1027'
mikewheeleer Jul 26, 2026
128daf9
Merge branch 'pr-1030'
mikewheeleer Jul 26, 2026
6ba55c4
Merge branch 'pr-1031'
mikewheeleer Jul 26, 2026
086c5c8
Merge branch 'pr-1032'
mikewheeleer Jul 26, 2026
0dc3113
Merge branch 'pr-1033'
mikewheeleer Jul 26, 2026
f963bff
Merge branch 'pr-1034'
mikewheeleer Jul 26, 2026
5725cc6
Merge branch 'pr-1035'
mikewheeleer Jul 26, 2026
a17644f
Merge branch 'pr-1036'
mikewheeleer Jul 26, 2026
d8d1d31
Merge branch 'pr-1037'
mikewheeleer Jul 26, 2026
dfbff3e
Merge branch 'pr-1039'
mikewheeleer Jul 26, 2026
ee1311f
Merge branch 'pr-1040'
mikewheeleer Jul 26, 2026
d5137e5
Merge branch 'pr-1071'
mikewheeleer Jul 26, 2026
676ac00
Merge branch 'pr-1073'
mikewheeleer Jul 26, 2026
c728a48
Merge branch 'pr-1074'
mikewheeleer Jul 26, 2026
d01b6cc
Merge branch 'pr-1075'
mikewheeleer Jul 26, 2026
9bc6a57
Merge branch 'pr-1077'
mikewheeleer Jul 26, 2026
1dee67e
Merge branch 'pr-1079'
mikewheeleer Jul 26, 2026
c9a7ab4
Merge branch 'pr-1081'
mikewheeleer Jul 26, 2026
b6c4f9e
Merge branch 'pr-1082'
mikewheeleer Jul 26, 2026
2f9380c
Merge branch 'pr-1084'
mikewheeleer Jul 26, 2026
9e23b35
Merge branch 'pr-1085'
mikewheeleer Jul 26, 2026
6ac51e8
Merge branch 'pr-1086'
mikewheeleer Jul 26, 2026
9523aad
Merge branch 'pr-1087'
mikewheeleer Jul 26, 2026
790df93
Merge branch 'pr-1090'
mikewheeleer Jul 26, 2026
a7b2cf3
Merge branch 'pr-1091'
mikewheeleer Jul 26, 2026
89714f5
Merge branch 'pr-1094'
mikewheeleer Jul 26, 2026
6764607
Merge branch 'pr-1095'
mikewheeleer Jul 26, 2026
dfabb2c
Merge branch 'pr-1097'
mikewheeleer Jul 26, 2026
fd560ea
Merge branch 'pr-1098'
mikewheeleer Jul 26, 2026
571ed54
Merge branch 'pr-1099'
mikewheeleer Jul 26, 2026
12b3611
Merge branch 'pr-1101'
mikewheeleer Jul 26, 2026
7c12a29
Merge branch 'pr-1102'
mikewheeleer Jul 26, 2026
bde86bc
Merge branch 'pr-1103'
mikewheeleer Jul 26, 2026
3c4ddf0
Merge branch 'pr-1104'
mikewheeleer Jul 26, 2026
779aefb
Merge branch 'pr-1105'
mikewheeleer Jul 26, 2026
f8690d5
Merge branch 'pr-1142'
mikewheeleer Jul 26, 2026
f717f52
Merge branch 'pr-1144'
mikewheeleer Jul 26, 2026
cf7c7ee
Merge branch 'pr-1145'
mikewheeleer Jul 26, 2026
08bebfe
Merge branch 'pr-1167'
mikewheeleer Jul 26, 2026
4f93789
Merge branch 'pr-1169'
mikewheeleer Jul 26, 2026
b8f1d9d
Merge branch 'pr-1170'
mikewheeleer Jul 26, 2026
d1cd0d9
Merge branch 'pr-1171'
mikewheeleer Jul 26, 2026
59e5627
Merge branch 'pr-1172'
mikewheeleer Jul 26, 2026
eb7ebcd
Merge branch 'pr-1173'
mikewheeleer Jul 26, 2026
8fb59c2
Merge branch 'pr-1174'
mikewheeleer Jul 26, 2026
99812ae
Merge branch 'pr-1175'
mikewheeleer Jul 26, 2026
3c4acd5
Merge branch 'pr-1176'
mikewheeleer Jul 26, 2026
cdf9317
Merge branch 'pr-1177'
mikewheeleer Jul 26, 2026
b2c742c
Merge branch 'pr-1180'
mikewheeleer Jul 26, 2026
1468124
Merge branch 'pr-1181'
mikewheeleer Jul 26, 2026
8eaa4ac
Merge branch 'pr-1183'
mikewheeleer Jul 26, 2026
7fae062
Merge branch 'pr-1185'
mikewheeleer Jul 26, 2026
1692573
Merge branch 'pr-1188'
mikewheeleer Jul 26, 2026
c1e4a0e
Merge branch 'pr-1190'
mikewheeleer Jul 26, 2026
5cec028
Merge branch 'pr-1191'
mikewheeleer Jul 26, 2026
6a67c01
Merge branch 'pr-1196'
mikewheeleer Jul 26, 2026
ee863b8
Merge branch 'pr-1197'
mikewheeleer Jul 26, 2026
6d55772
Merge branch 'pr-1198'
mikewheeleer Jul 26, 2026
9616b32
Merge branch 'pr-1200'
mikewheeleer Jul 26, 2026
4baf515
Merge branch 'pr-1201'
mikewheeleer Jul 26, 2026
34d5a0d
Merge branch 'pr-1203'
mikewheeleer Jul 26, 2026
71a39ca
Merge branch 'pr-1204'
mikewheeleer Jul 26, 2026
25b2b52
Merge branch 'pr-1205'
mikewheeleer Jul 26, 2026
26c8693
Merge branch 'pr-1210'
mikewheeleer Jul 26, 2026
b4ef942
Merge branch 'pr-1211'
mikewheeleer Jul 26, 2026
14c08cc
feat(settlement): add bounded batch settlement entrypoint
mikewheeleer Jul 26, 2026
5a7e005
feat(milestones): implement rollback with protocol fee reversal
Jul 26, 2026
ad0eba6
Merge pull request #1215 from Nehza001/feature/settlement-21-batch
mikewheeleer Jul 26, 2026
d2272d8
Merge branch 'pr-1216'
mikewheeleer Jul 26, 2026
a338e69
feat(disputes): add guarded rollback
Habeeb-100 Jul 26, 2026
7c85e79
docs(storage): document storage layout and TTL
OluRemiFour Jul 26, 2026
2ce35b0
quick fix [ci skip]
OluRemiFour Jul 26, 2026
8d9ac41
docs(events): document storage layout and TTL
OluRemiFour Jul 26, 2026
0d1c867
fix
OluRemiFour Jul 26, 2026
77d965c
quick fix [ci skip]
OluRemiFour Jul 26, 2026
2f14f4f
Return typed DisputePayouts struct instead of tuple in resolution_pay…
Alimzy Jul 26, 2026
1d8f91b
docs(authorization): document storage layout and TTL
uche102 Jul 26, 2026
9851fb1
test(disputes): cover event topics/payloads
Emelie-Dev Jul 26, 2026
0dc8be5
feat(arbiter): add config read view
Emmanuellsensai Jul 26, 2026
73f4d78
feat(events): add input bounds validation
Osifowora Jul 26, 2026
8736058
refactor(milestones): return a typed struct
Emelie-Dev Jul 26, 2026
25d6b98
feat(arbiter): add admin parameter setter
Emmanuellsensai Jul 26, 2026
a7233fd
feat(events): add paginated enumeration view
Osifowora Jul 27, 2026
4cbd8f3
fix(escrow): restore clean lib.rs and reapply arbiter config setter s…
Emmanuellsensai Jul 27, 2026
b1277ec
docs(events): document authorization rules for events
Osifowora Jul 27, 2026
8fc38cc
fix(escrow): trim lib.rs to arbiter config change only
Emmanuellsensai Jul 27, 2026
a1a538c
docs(storage): document authorization rules
Osifowora Jul 27, 2026
f06bd29
fix(escrow): restore clean lib.rs and reapply arbiter config setter s…
Emmanuellsensai Jul 27, 2026
1c1fdca
fix(escrow): restore clean lib.rs and reapply arbiter config setter s…
Emmanuellsensai Jul 27, 2026
f285b4c
Merge pull request #1229 from aseyitan/docs/storage-11-auth
mikewheeleer Jul 27, 2026
f125a43
Merge pull request #1228 from aseyitan/docs/events-11-auth
mikewheeleer Jul 27, 2026
eac3b6d
Merge pull request #1227 from aseyitan/paginated-enumeration-view
mikewheeleer Jul 27, 2026
77c83d1
Merge pull request #1225 from Emmanuellsensai/feature/arbiter-52-setter
mikewheeleer Jul 27, 2026
5611378
Merge pull request #1222 from Emelie-Dev/test/disputes-51-events
mikewheeleer Jul 27, 2026
e0f48f6
Merge pull request #1221 from uche102/docs/authorization-storage-ttl
mikewheeleer Jul 27, 2026
de9b6a0
Merge pull request #1219 from heymide/docs/events-21-storage
mikewheeleer Jul 27, 2026
bb808f4
Merge branch 'pr-1226'
mikewheeleer Jul 27, 2026
05b4746
Merge branch 'pr-1224'
mikewheeleer Jul 27, 2026
5047d00
Merge branch 'pr-1223'
mikewheeleer Jul 27, 2026
7fc0f7a
Merge branch 'pr-1220'
mikewheeleer Jul 27, 2026
35d98d9
Merge branch 'pr-1217'
mikewheeleer Jul 27, 2026
4fb6582
refactor(milestones): name magic numbers
abrahambaba1 Jul 27, 2026
f5b1efb
Merge branch 'main' into refactor/milestones-41-consts
abrahambaba1 Jul 27, 2026
c49c9d9
docs(arbiter): document error codes
Psalmuel01 Jul 27, 2026
5def350
Merge pull request #1231 from PsalmuelOS/docs/arbiter-51-errdocs
mikewheeleer Jul 27, 2026
b841de7
Merge pull request #1230 from abrahambaba1/refactor/milestones-41-consts
mikewheeleer Jul 27, 2026
2ee98b9
test(milestones): cover event topics/payloads
Paulo-byt Jul 27, 2026
e50a50d
test(milestones): cover event topics/payloads
Paulo-byt Jul 27, 2026
8f42f4c
fix(escrow): restore DisputeConfig lost in bad merge, dedupe get_arbi…
Paulo-byt Jul 27, 2026
c3a5266
feat(reputation): add admin parameter setter
Paulo-byt Jul 27, 2026
6a4314c
Merge pull request #1234 from Paulo-byt/feature/reputation-52-setter
mikewheeleer Jul 27, 2026
cd96b2d
Merge pull request #1232 from Paulo-byt/test/milestones-51-events
mikewheeleer Jul 27, 2026
6a91ad1
test(contracts): add resource-budget assertion tests
Joyyyb Jul 27, 2026
518874e
Add overflow/saturation tests and fix merge corruption (#875)
odusanya03 Jul 27, 2026
3d4e3c0
Add paginated contract enumeration view
odusanya03 Jul 27, 2026
15ae213
Merge branch 'main' into Add-a-paginated-enumeration-view-for-storage…
odusanya03 Jul 27, 2026
18d09d7
Merge pull request #1 from odusanya03/Add-a-paginated-enumeration-vie…
odusanya03 Jul 27, 2026
b8868f7
feat(arbiter): make arbiter limit an admin-configurable parameter
odusanya03 Jul 27, 2026
7dcffd2
refactor(milestones): centralize storage keys
Jul 27, 2026
95f42ef
fix(escrow): resolve macro panic and broken imports after merge
Jul 27, 2026
b5365e3
fix(escrow): resolve merge conflicts in mod.rs and types.rs
Jul 27, 2026
b0dea3d
fix: resolve test modules and types merge conflicts
Jul 27, 2026
6ff905e
fix(escrow): remove redundant errors to respect Soroban 50-variant ma…
Jul 27, 2026
efd930d
fix(tests): resolve test utils imports, event types, and symbol deref…
Jul 27, 2026
6ef75bd
fix(escrow): resolve merge conflicts across tests and enforce soroban…
Jul 27, 2026
518600c
fix: resolve merge conflicts and align test suites with soroban v22
Jul 27, 2026
b6b43e1
feat(disputes): add paginated enumeration view
odusanya03 Jul 27, 2026
49de105
Merge branch 'main' into Add-overflow-and-saturation-tests
odusanya03 Jul 27, 2026
2cc4b8b
Merge remote-tracking branch 'upstream/main' into resolve-pr1243
Jul 27, 2026
815fe74
feat(settlement): add admin-configurable batch settlement limit and r…
BigJohn-dev Jul 27, 2026
fb4ce34
sonesdof (#1247)
samad13 Jul 27, 2026
c9f3a3a
docs(contracts): document authorization rules (#1241)
code3ks Jul 27, 2026
3d71ce1
refactor(tests): merge duplicate participant index pagination modules…
midexol Jul 27, 2026
4f0132d
refactor(disputes): split into a module (#1239)
doctorlight0 Jul 27, 2026
accd714
docs(milestones): document invariants (#1237)
bonaventure001 Jul 27, 2026
19b6d98
Work flow11 (#1236)
lekanay2005-coder Jul 27, 2026
570936f
fix(escrow): restore list_contracts_by_participant entrypoint in lib.rs
Jul 27, 2026
20711e9
fix(escrow): restrict submit_work_evidence caller and milestone state
sir-emmy1 Jul 27, 2026
6e57207
Merge branch 'main' into security/contracts-work-evidence-gating
sir-emmy1 Jul 27, 2026
649ef8a
feat(escrow): add simulate/dry-run
yugomania Jul 28, 2026
b43741e
fix(escrow): remove unimplemented participant index tests
yugomania Jul 28, 2026
396628c
fix(escrow): fix event cloning in milestones_events test
yugomania Jul 28, 2026
2cffe66
fix(escrow): fix Val::VOID / as_deref compile errors
yugomania Jul 28, 2026
c882859
feat(reputation): add reset_reputation_config function (#881) (#1279)
Pafekzy Jul 28, 2026
4fe81c2
feat(milestones): add pause-aware guard (#1278)
Anichris-koded Jul 28, 2026
dd09e88
refactor(reputation): type the reputation failures (#1276)
sir-emmy1 Jul 28, 2026
f1375e6
feat(contracts): add input bounds validation (#1274)
azahjessica49-commits Jul 28, 2026
5041112
docs(authorization): document the model and invariants (#1253)
JClark011 Jul 28, 2026
8d8b6b2
feat(escrow): add admin setter for contracts parameters (#1252)
neyij Jul 28, 2026
db211f2
feat(events): add bounded batch entrypoint (#1251)
frank0277 Jul 28, 2026
ef609e8
Feature/disputes 22 index event (#1250)
BigJohn-dev Jul 28, 2026
cfc3043
refactor(disputes): return a typed struct (#1249)
matieuu1 Jul 28, 2026
e4af823
refactor(contracts): introduce typed storage key for contract entries…
MJ-RWA Jul 28, 2026
978c706
feat(authorization): add paginated enumeration view (#1285)
Truphile Jul 28, 2026
e72f89f
docs(escrow): document authorization rules (#1284)
Truphile Jul 28, 2026
805e4b0
feat(milestones): add input bounds validation requirements spec (#1283)
olatundefay-prog Jul 28, 2026
a2cd7e9
Test/disputes 21 authmatrix (#1282)
Truphile Jul 28, 2026
367bdec
feat(storage): add input bounds validation (#1244)
Ova-Klik Jul 28, 2026
7450d31
feat(milestones): add paginated enumeration view
soterika Jul 28, 2026
b09e6b5
Merge branch 'main' into feature/milestones-13-paginate
ola196 Jul 28, 2026
4e50c27
fix(escrow): resolve unreachable panics and missing EscrowError enum …
Jul 28, 2026
2b6c326
fix(escrow): export DisputeConfig and MAX_FEE_BPS to ensure 100% rele…
Jul 28, 2026
f4ca9c0
Feature/reputation 13 paginate (#1291)
ola196 Jul 28, 2026
57898e9
Closes #742 — Add pause and emergency interaction tests for governanc…
GBOYEE Jul 28, 2026
a7fc3d8
refactor(escrow): extract require_active_contract preamble (#749) (#1…
GBOYEE Jul 28, 2026
991c9ff
fix: decode PendingAdminProposal in get_pending_governance_admin with…
Jokay1997 Jul 28, 2026
0514204
Feature/milestones 12 config limit (#1287)
ola196 Jul 28, 2026
191737f
feat(reputation): add pause-aware guard (#1277)
ugoocreates-pixel Jul 28, 2026
7a369f4
test(escrow): add exhaustive milestone authorization matrix test suit…
Unclebaffa Jul 28, 2026
e59b430
fix(escrow): add missing InvalidContractId and LimitOutOfRange error …
Unclebaffa Jul 28, 2026
f6fdfda
fix(escrow): export missing types and constants (ReputationConfig, Ev…
Unclebaffa Jul 28, 2026
71df727
Merge branch 'main' into test/milestones-21-authmatrix
Unclebaffa Jul 28, 2026
0e8f7d2
feat(disputes): add simulate/dry-run
abrahambaba1 Jul 29, 2026
f9afe9d
fix(test): bind settlement token in dispute test helpers
abrahambaba1 Jul 29, 2026
c94eac4
test: enhance milestones authorization matrix tests and documentation
Unclebaffa Jul 29, 2026
5ec17c1
fix: remove duplicate InvalidDepositAmount error variant
Unclebaffa Jul 29, 2026
b1ba319
feat: add config read view (#1301)
Frontman-Code Jul 29, 2026
884e915
docs(contracts): document invariants (#1299)
LuisD-Dev Jul 29, 2026
f67fada
fix(escrow): reject role-overlapping client in migration proposal (#1…
olufunsoolutayo Jul 29, 2026
765df34
docs(contracts): document error codes (#1297)
BABAT-CODE Jul 29, 2026
29624c7
test(contracts): cover event topics/payloads (#1296)
BABAT-CODE Jul 29, 2026
79658c6
feat: Add input bounds validation to the settlement entrypoints (#894…
favouronyinye Jul 29, 2026
c40bafa
fix: resolve duplicate contract definitions and exposure errors (#1293)
NoobFaris Jul 29, 2026
3fa78b0
Merge PR #1300
mikewheeleer Jul 29, 2026
7c910e6
Merge PR #1294
mikewheeleer Jul 29, 2026
a5165c9
Merge PR #1286
mikewheeleer Jul 29, 2026
ade6f5a
Merge PR #1280 (took PR side)
mikewheeleer Jul 29, 2026
4249f3e
Merge PR #1275
mikewheeleer Jul 29, 2026
a6f3e4b
Merge PR #1246
mikewheeleer Jul 29, 2026
c3c0b48
Merge PR #1245
mikewheeleer Jul 29, 2026
bc91776
Merge PR #1243
mikewheeleer Jul 29, 2026
9966f4c
Merge PR #1238
mikewheeleer Jul 29, 2026
00ec509
Merge PR #1235
mikewheeleer Jul 29, 2026
e16e654
test(settlement): cover overflow and saturation (#1302)
Yinklekay Jul 29, 2026
8099b77
refactor(disputes): name magic numbers (#1305)
Jenks00 Jul 29, 2026
36dc1b7
refactor(escrow): replace magic numbers with named constants (#1304)
Michealshodipo56 Jul 29, 2026
d5eac25
docs(settlement): add rustdoc examples (#1303)
Gabugo-tech Jul 29, 2026
05c7b29
test: add escrow sanity check unit test
Alimzy Jul 29, 2026
df95074
docs/reputation-51-errdocs (#1309)
Gogo-Eng Jul 29, 2026
3a08f77
feat(contracts): add pause-aware guard to mutating entrypoints (#1308)
David-282 Jul 29, 2026
ba93732
refactor: enforce amount_validation bounds in create_contract and dep…
tobiadewola41-eng Jul 29, 2026
54cf117
Merge PR #1306
mikewheeleer Jul 29, 2026
f97383e
refactor: reformat access control tests and implement reputation modu…
TobyKing007 Jul 29, 2026
5405baa
feat(escrow): return MilestoneProgress struct from get_milestone_prog…
itzabdoull Jul 29, 2026
cbab918
Merge PR #1310
mikewheeleer Jul 29, 2026
4a9dbf3
Fix escrow Soroban 22 compatibility and budget tests (#1313)
merciiiqode Jul 29, 2026
7455f24
test(contracts): add boundary tests (#1312)
GideonBature Jul 29, 2026
98d2142
fix: resolve escrow contract entrypoint wiring
adewaleomolara522-coder Jul 29, 2026
e952074
Merge branch 'main' into fix/escrow-contract-entrypoints
adewaleomolara522-coder Jul 29, 2026
25038ce
test(events): add authorization-matrix tests
chidii Jul 30, 2026
38aa5a3
Merge branch 'main' into test/events-21-authmatrix
chidii Jul 30, 2026
a0ae7ac
Merge pull request #1315 from chidii/test/events-21-authmatrix
mikewheeleer Jul 30, 2026
8da3926
Merge pull request #1314 from adewaleomolara522-coder/fix/escrow-cont…
mikewheeleer Jul 30, 2026
62ae761
feat(escrow): rate limit protocol fee withdrawals
Meet-hybrid Jul 30, 2026
0e2ed17
fix: remove invalid filename with colon breaking Windows CI checkout
Meet-hybrid Jul 30, 2026
76f09d1
Merge pull request #1316 from Meet-hybrid/security/contracts-fee-with…
mikewheeleer Jul 30, 2026
4fbf37b
refactor(disputes): name magic numbers in DisputeConfig defaults
Vin1974va Jul 30, 2026
74f156a
Merge remote-tracking branch 'refs/remotes/pr/1317'
mikewheeleer Jul 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 25 additions & 21 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,21 +1,25 @@
/target/
target_local/
**/*.rs.bk
# Soroban CLI / local test output (do not commit)
contracts/**/test_snapshots/
contracts/**/.soroban/
**/.soroban/
**/snapshots/
.cargo/

# Coverage output
coverage_summary.txt
lcov.info

# Soroban CLI wasm / identity artifacts
*.wasm
*.xdr

# Transient PR drafting artifacts
PR_DESCRIPTION.md
PULL_REQUEST.md
/target/
target_local/
**/*.rs.bk
# Soroban CLI / local test output (do not commit)
contracts/**/test_snapshots/
contracts/**/.soroban/
**/.soroban/
**/snapshots/
.cargo/

# Coverage output
coverage_summary.txt
lcov.info

# Soroban CLI wasm / identity artifacts
*.wasm
*.xdr

# Transient PR drafting artifacts
PR_DESCRIPTION.md
PULL_REQUEST.md
.aider*



3 changes: 3 additions & 0 deletions .kilo/kilo.jsonc
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"snapshot": false
}
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"specId": "a677d5ab-e552-4be2-9da3-319567875f16", "workflowType": "requirements-first", "specType": "feature"}
228 changes: 228 additions & 0 deletions .kiro/specs/milestones-input-bounds-validation/requirements.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,228 @@
# Requirements Document

## Introduction

The milestones entrypoints in the TalentTrust escrow smart contract
(`contracts/escrow/src/milestones.rs`) currently accept arguments without explicit
numeric or length bounds, risking bad on-chain state when callers supply
out-of-range values. This feature adds structured bounds validation — backed by
typed `EscrowError` codes — to every milestones entrypoint that accepts a
user-supplied numeric or string argument.

Scope is limited to the milestones module (`milestones.rs`,
`milestones_consts.rs`) and the constants/types it depends on. All existing
accepted inputs must continue to be accepted; only out-of-range values are newly
rejected.

---

## Glossary

- **Milestones Entrypoints**: The public contract functions that operate on milestone
data: `release_milestone`, `refund_unreleased_milestones`, `submit_work_evidence`,
`get_milestone`, `get_milestones`, `get_milestone_approvals`,
`get_approval_deadline`, `get_work_evidence`, and `is_milestone_overdue`.
- **Milestone_Index**: A zero-based `u32` index into the milestone vector for a
given escrow contract. Valid range: `[0, milestones.len() − 1]`.
- **Work_Evidence**: A Soroban `String` submitted by the freelancer to document
completed work. Length is measured in UTF-8 bytes via `String::len()`.
- **Milestone_Indices_Vec**: A `Vec<u32>` of milestone indices supplied to
`refund_unreleased_milestones`. Must be non-empty, free of duplicates, and every
element must be a valid `Milestone_Index`.
- **EscrowError**: The `#[contracterror]` enum defined in `lib.rs`; all typed
error codes for the escrow contract live here.
- **Validator**: The bounds-validation logic inside the milestones entrypoints
(not a separate contract or module — validation runs in-line before state reads
or writes).
- **MAX_WORK_EVIDENCE_BYTES**: The maximum byte length allowed for a work-evidence
string. Currently **1 000** bytes (matching the existing guard in
`submit_work_evidence_impl`), centralised as a named constant in
`milestones_consts.rs`.
- **MIN_WORK_EVIDENCE_BYTES**: The minimum byte length for a work-evidence string.
**1** byte — empty evidence is meaningless.
- **WORK_EVIDENCE_TOO_LONG**: `EscrowError::EvidenceTooLong` — returned when
`evidence.len() > MAX_WORK_EVIDENCE_BYTES`.
- **WORK_EVIDENCE_EMPTY**: `Error::EvidenceTooLong` used for the too-long case;
the existing `Error::EvidenceTooLong` variant covers the over-limit path. For
empty evidence a distinct error (`Error::EmptyEvidence`) is introduced.

---

## Requirements

### Requirement 1: Milestone Index Bounds for `release_milestone`

**User Story:** As a contract client or arbiter, I want `release_milestone` to
reject an out-of-range milestone index with a typed error, so that callers
receive actionable feedback and the contract never panics on an invalid index.

#### Acceptance Criteria

1. WHEN `milestone_index` is greater than or equal to `milestones.len()` for the
specified contract, THE Validator SHALL reject the call with
`Error::IndexOutOfBounds` before performing any auth or state mutation.
2. WHEN `milestone_index` is `u32::MAX` and the contract has fewer than
`u32::MAX + 1` milestones, THE Validator SHALL reject the call with
`Error::IndexOutOfBounds`.
3. WHEN `milestone_index` is exactly `milestones.len() − 1` (the last valid
index) and all other preconditions are met, THE Validator SHALL accept the
call and proceed with the release flow.
4. IF the contract identified by `contract_id` does not exist, THEN THE Validator
SHALL reject the call with `EscrowError::ContractNotFound` before performing
any index check.

---

### Requirement 2: Milestone Index Bounds for `refund_unreleased_milestones`

**User Story:** As a contract client, I want `refund_unreleased_milestones` to
validate every supplied milestone index against the actual milestone count, so
that partial-index vectors cannot corrupt accounting state.

#### Acceptance Criteria

1. WHEN `milestone_indices` is empty, THE Validator SHALL reject the call with
`EscrowError::EmptyRefundRequest` before loading any contract state.
2. WHEN `milestone_indices` contains duplicate values, THE Validator SHALL
unconditionally reject the call with `EscrowError::DuplicateMilestoneInRefund`,
regardless of whether the indices are otherwise valid.
3. WHEN any element of `milestone_indices` is greater than or equal to
`milestones.len()`, THE Validator SHALL reject the call with
`Error::IndexOutOfBounds`.
4. WHEN `milestone_indices` contains `u32::MAX` and the milestone vector has
fewer entries than `u32::MAX + 1`, THE Validator SHALL reject the call with
`Error::IndexOutOfBounds`.
5. WHEN every element of `milestone_indices` is a valid, non-duplicate index into
an unreleased, non-refunded milestone, THE Validator SHALL accept the call and
proceed with the refund flow.

---

### Requirement 3: Milestone Index Bounds for `submit_work_evidence`

**User Story:** As a freelancer, I want `submit_work_evidence` to reject an
out-of-range index with a typed error, so that the entrypoint fails safely
without state corruption.

#### Acceptance Criteria

1. WHEN `milestone_index` is greater than or equal to `milestones.len()` for the
specified contract, THE Validator SHALL reject the call with
`Error::IndexOutOfBounds`.
2. WHEN `milestone_index` is exactly `milestones.len() − 1` and all other
preconditions are met, THE Validator SHALL accept the call.

---

### Requirement 4: Work Evidence Length Bounds for `submit_work_evidence`

**User Story:** As a freelancer, I want `submit_work_evidence` to reject evidence
strings that are empty or exceed the protocol maximum, so that on-chain storage
is bounded and callers receive explicit typed feedback.

#### Acceptance Criteria

1. WHEN `evidence.len()` is `0` (empty string), THE Validator SHALL reject the
call with `Error::EmptyEvidence`.
2. WHEN `evidence.len()` is greater than `MAX_WORK_EVIDENCE_BYTES` (1 000),
THE Validator SHALL reject the call with `Error::EvidenceTooLong`.
3. WHEN `evidence.len()` is exactly `MAX_WORK_EVIDENCE_BYTES`, THE Validator
SHALL accept the call and store the evidence.
4. WHEN `evidence.len()` is exactly `1` (minimum), THE Validator SHALL accept
the call.
5. THE Milestones_Module SHALL expose `MAX_WORK_EVIDENCE_BYTES` and
`MIN_WORK_EVIDENCE_BYTES` as named `pub const` values in
`milestones_consts.rs`, so that test and governance code can reference limits
symbolically rather than by literal.

---

### Requirement 5: Named Constants in `milestones_consts.rs`

**User Story:** As a developer reviewing or testing the milestones module, I want
all protocol-level bounds to be defined as named constants in `milestones_consts.rs`,
so that limits are documented in one place and test assertions never depend on
literals.

#### Acceptance Criteria

1. THE Milestones_Module SHALL define `MAX_WORK_EVIDENCE_BYTES: u32 = 1_000` in
`milestones_consts.rs`.
2. THE Milestones_Module SHALL define `MIN_WORK_EVIDENCE_BYTES: u32 = 1` in
`milestones_consts.rs`.
3. FOR ALL uses of the evidence length bound in `milestones.rs`, the source SHALL
reference `MAX_WORK_EVIDENCE_BYTES` and `MIN_WORK_EVIDENCE_BYTES` rather than
inline literals.
4. WHEN the constants in `milestones_consts.rs` are changed, THE Milestones_Module
SHALL enforce the updated bounds in all entrypoints without requiring changes
to call sites beyond the constant definition.

---

### Requirement 6: New `Error` Variant for Empty Evidence

**User Story:** As an API consumer, I want a distinct typed error when I submit
an empty work-evidence string, so that I can distinguish "too long" from "empty"
without inspecting string content.

#### Acceptance Criteria

1. THE EscrowContract SHALL expose a new `Error::EmptyEvidence` variant in the
`Error` contracterror enum.
2. WHEN `submit_work_evidence` is called with an empty string, THE Validator SHALL
return `Error::EmptyEvidence`.
3. WHEN `submit_work_evidence` is called with a non-empty string that exceeds
`MAX_WORK_EVIDENCE_BYTES`, THE Validator SHALL return `Error::EvidenceTooLong`
(not `EmptyEvidence`).

---

### Requirement 7: Preservation of All Existing Accepted Inputs

**User Story:** As an integrator with contracts already on-chain, I want all
currently-accepted milestone entrypoint inputs to remain accepted after this
change, so that the deployment is backward-compatible.

#### Acceptance Criteria

1. THE Validator SHALL accept any `milestone_index` value in the range
`[0, milestones.len() − 1]` that was previously accepted before this feature.
2. THE Validator SHALL accept any `evidence` string with byte length in the range
`[1, MAX_WORK_EVIDENCE_BYTES]` that was previously accepted.
3. THE Validator SHALL accept any `milestone_indices` vector that was previously
accepted by `refund_unreleased_milestones`.
4. FOR ALL valid inputs, the Validator SHALL produce identical on-chain state
changes as the pre-validation code path (validation is purely additive — no
business logic changes).

---

### Requirement 8: Test Coverage for Boundary Values

**User Story:** As a code reviewer, I want comprehensive tests covering min, max,
zero, and over-limit values for every new validation guard, so that regressions
are caught before deployment.

#### Acceptance Criteria

1. THE Test_Suite SHALL include at least one test for each of the following
boundary classes for every numeric/length bound added:
- Exact minimum (accepted)
- Exact maximum (accepted)
- Zero / below minimum (rejected with correct error)
- One above maximum (rejected with correct error)
2. WHERE the system contains one or more milestones entrypoints, THE Test_Suite
SHALL include at least one regression test per entrypoint confirming that a
previously-valid input still succeeds after this change.
3. WHEN tests for `release_milestone` index bounds run, THE Test_Suite SHALL
cover `milestone_index = 0`, `milestone_index = milestones.len() − 1`, and
`milestone_index = milestones.len()` (out of bounds by 1).
4. WHEN tests for `submit_work_evidence` length bounds run, THE Test_Suite SHALL
cover evidence of length `0`, `1`, `MAX_WORK_EVIDENCE_BYTES`, and
`MAX_WORK_EVIDENCE_BYTES + 1`.
5. WHEN tests for `refund_unreleased_milestones` index bounds run, THE Test_Suite
SHALL cover an empty indices vector, a duplicate-index vector, an
out-of-bounds single index, and a valid single index.
6. THE Test_Suite SHALL be placed in a new test file
`contracts/escrow/src/test/milestones_bounds_validation.rs` and registered in
`contracts/escrow/src/test/mod.rs`.
5 changes: 4 additions & 1 deletion .vscode/settings.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
{
"kiroAgent.configureMCP": "Disabled"
"kiroAgent.configureMCP": "Disabled",
"githubPullRequests.ignoredPullRequestBranches": [
"main"
]
}
Loading