Repository navigation
Conversation
The synchronizer accepts a ledger time within its tolerance of the record time, so a use can commit up to the tolerance outside the window in record time. The README and the field docs state this, recommend a margin or revocation for an exact cutoff, and name the native error for a delayed submission. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The guard fetches the grant before its checks, so the grantee check runs only when a consumer signatory or controller is a grant stakeholder. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…troller Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…y role authorities Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AGENTS.md lists the example lint and test commands and the sandbox suites. The check-sandbox.sh comment names the suites that check validity bounds, and the README marks external signing as untested. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
New tests cover failures that a consumer try/catch cannot catch, the native fetch error for a non-grantee actor, microsecond window edges, epoch reuse and future epochs, a consumer signatory that supplies the grantee's authority, and cached disclosures after Revoke and Renounce. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…or revocation The treasury tests show that a revoked proposer or approver grant does not stop a pending approval or execution, that a grant with the correct authority and the wrong permission fails with a scope mismatch, and that a role grant outside its window fails at the proposal. The licensing test shows that revoking the operator keeps the issued licenses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Member
|
Thanks for creating @pepebndc. I applied the fixes manually on the main branch. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR applies the findings of an independent two-model review (Claude and Codex) of #48 at a49fd3f. It targets
feat/scoped-authorization-grant, so it can merge into #48 as one unit. Each finding is one commit.The review found no critical, high, or medium defect. No commit changes the grant template or the guard logic. Two commits change doc comments in
OpenZeppelin.ScopedAuthorizationGrantV1(99bc9b0, 352c07b). The rest change documentation, one script comment, and tests.Changes
AuthorizationScopedoc require epochs to increase and never be reused, and describe future-epoch grants.controller authorization.actoris required.OZ_LEDGER_PORTdoes not isolate parallel sandbox runs.AGENTS.mdlists the example and sandbox commands. Thecheck-sandbox.shcomment names the suites that check time. The README marks external signing as untested.try/catchcannot catch, the native error for a non-grantee actor, microsecond window edges, epoch reuse and future epochs, a consumer signatory that supplies the grantee's authority, and cached disclosures afterRevokeandRenounce.Finding 8 (strict evaluation of the failure statuses) is not applied, because it changes production code for a small cost only.
Verification
All pass locally on SDK 3.5.8. I did not run the sandbox suites.
Caveats
ScopedAuthorizationGrantV1EdgeTest.damlusestry/catchto show that a consumer cannot catch a guard failure. The build reports deprecation warnings for that module. A module pragma does not turn them off.ErrorInfo, external signing, different ledger and record times, multi-participant tests, anupgrade-checkdry run, a Canton 3.4 runtime run, authority rotation in a consumer fixture, and a caught exception after a successful guard. Each needs a setup that Daml Script on the in-memory ledger does not provide, or a larger fixture.🤖 Generated with Claude Code