Repository navigation
Conversation
- Signers now commit to an AuthDigestPreimage { account, signature_payload,
context_rule_ids }: External signers sign sha256(preimage.to_xdr()) and
Delegated signers authorize __check_auth with the preimage as the single
argument. Replace the old sha256(payload || rule_ids.to_xdr()) digest
across the authorization flow, the __check_auth snippets, the auth digest
computation steps and the diagram, and note the v0.7.x -> v0.8.0 change.
- Fix the delegated signer client example: the nested entry targets the
smart account and carries the preimage map, and the re-simulated output
shows it. Document the auth_digest view, the stellar_xdr encoding of the
preimage, and point to the auth_entries reference test and smart-account-kit.
- Add the CreateContractExternalRef(owner, tag) context type (Protocol 28,
CAP-85) and its trust and matching caveats.
- Policies: document the weighted threshold operation ordering, and correct
the spending limit parameters (period_ledgers, not seconds), transfer-only
scope, zero-amount transfers and the 815-entry history cap.
- Describe batch_add_signer as a module helper the contract must wrap with
its own authorization, not a SmartAccount trait method.
- Link the multisig and factory examples from the overview.
The add_context_rule example did not compile against stellar-accounts: - Pass the context type, name, signers and policies by reference, as add_context_rule expects. - Add the missing semicolon and Signer import. - Replace the invalid 1_year / 7_days / 12_hours literals and the undefined current_ledger with e.ledger().sequence() and a DAY_IN_LEDGERS constant. - Clone the verifier addresses that are used for more than one signer.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adapts the Stellar Smart Account docs to the breaking changes on
stellar-contractsmain(checked atd3f7df8), mainly #868 (auth payload digest) and #866 (soroban-sdk v28,CreateContractExternalRef), plus #848, #759, #819 and #867 for the policy and example updates.Stacked on #245. Retarget to
mainonce #244 and #245 are merged.Two commits:
The digest change landed after
v0.8.0-rc.3and is not in a tagged release yet (latest isv0.7.2). Until v0.8.0 ships, these pages describemainrather than what a v0.7.x user runs.Breaking changes covered
Signed message (
authorization-flow.mdx,signers-and-verifiers.mdx,smart-account.mdx)AuthDigestPreimage { account, signature_payload, context_rule_ids }instead ofsha256(signature_payload || context_rule_ids.to_xdr()).Externalsigners signsha256(preimage.to_xdr()).Delegatedsigners authorizerequire_auth_for_args((preimage,)), so they sign the struct itself instead of a 32-byte digest.AuthDigestPreimagesection in Authorization Flow. Updated the sequence diagram, the delegated and external signer steps, both__check_authsnippets and the Auth Digest Computation steps.auth_digest(preimage)view and added astellar_xdrencoding of the preimage.Delegated signer client flow (
signers-and-verifiers.mdx)ScVal::Mapand passes it as the only argument of the delegated signer's__check_authentry. The re-simulated JSON shows the map.hash(HashIdPreimage), which was already wrong for v0.7.x, and it pointed__check_authat the target contract instead of the smart account. The smart account address now comes from the simulated entry.Error(Auth, InvalidAction)with a trap inside__check_auth, not aSmartAccountError). Linked the upstreamauth_entriesreference test andstellar/smart-account-kit.#transaction-simulation-behavioranchor is unchanged. The upstream README links to it.Context rules (
context-rules.mdx,authorization-flow.mdx)CreateContractExternalRef(Address, String)context type (Protocol 28, CAP-85). Added a callout: such a rule trusts the owner contract, and matching follows how the executable is referenced, so aCreateContract(hash)rule doesn't cover an external-ref deployment of the same hash.Policies (
policies.mdx)set_signer_weightbeforeset_threshold; when lowering, callset_thresholdbefore reducing weights. A wrong order reverts withInvalidThreshold(3211). The caveats and the signer-management callouts link to it.HistoryCapacityExceededbeyond that).period_ledgers(in ledgers, not seconds), and the policy only permitstransfercalls.Other pre-existing fixes
batch_add_signeris not aSmartAccounttrait method. It's a helper function that performs no authorization, so the docs now show a contract wrapping it withrequire_auth, as the multisig example does.Context Rules example (
context-rules.mdx, second commit)add_context_ruletakes the context type, name, signers and policies by reference. The example passed them by value.useand the missingSignerimport.1_year/7_days/12_hoursare not valid Rust literals, andcurrent_ledgerwas undefined. Replaced them withe.ledger().sequence()and aDAY_IN_LEDGERSconstant.bls_verifieranded25519_verifierare each used for two signers, so the first use is now cloned.Addressis notCopy, so the second use failed as a moved value.Verification
stellar-contractsmain:smart_account/{mod,storage}.rs, the policy modules, the multisig example andtest/auth_entries.rs. That test confirms that a delegated entry carrying the digest bytes instead of the preimage struct fails.cargo checkagainststellar-accountsonmain. Negative control: the previous version fails with 13 errors.__check_authexcerpts and were notcargo checked. The TypeScript example was not run.pnpm run buildwas not run.