Skip to content

Stellar: adapt smart account docs to latest stellar-contracts - #246

Draft
brozorec wants to merge 3 commits into
docs/stellar-token-breaking-changesfrom
docs/stellar-smart-account-0.8
Draft

brozorec wants to merge 3 commits into
docs/stellar-token-breaking-changesfrom
docs/stellar-smart-account-0.8

Conversation

@brozorec

@brozorec brozorec commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Adapts the Stellar Smart Account docs to the breaking changes on stellar-contracts main (checked at d3f7df8), mainly #868 (auth payload digest) and #866 (soroban-sdk v28, CreateContractExternalRef), plus #848, #759, #819 and #867 for the policy and example updates.

Stacked on #245. Retarget to main once #244 and #245 are merged.

Two commits:

  1. Smart account pages adapted to the breaking changes.
  2. A fix for the Context Rules example, which did not compile even before this change.

The digest change landed after v0.8.0-rc.3 and is not in a tagged release yet (latest is v0.7.2). Until v0.8.0 ships, these pages describe main rather than what a v0.7.x user runs.

Breaking changes covered

Signed message (authorization-flow.mdx, signers-and-verifiers.mdx, smart-account.mdx)

  • Signers now commit to AuthDigestPreimage { account, signature_payload, context_rule_ids } instead of sha256(signature_payload || context_rule_ids.to_xdr()). External signers sign sha256(preimage.to_xdr()). Delegated signers authorize require_auth_for_args((preimage,)), so they sign the struct itself instead of a 32-byte digest.
  • New AuthDigestPreimage section in Authorization Flow. Updated the sequence diagram, the delegated and external signer steps, both __check_auth snippets and the Auth Digest Computation steps.
  • Added a callout on the v0.7.x → v0.8.0 change that links to the upstream migration guide. Also documented the new auth_digest(preimage) view and added a stellar_xdr encoding of the preimage.

Delegated signer client flow (signers-and-verifiers.mdx)

  • The TypeScript example now builds the preimage as an ScVal::Map and passes it as the only argument of the delegated signer's __check_auth entry. The re-simulated JSON shows the map.
  • Pre-existing errors fixed along the way: the old example passed hash(HashIdPreimage), which was already wrong for v0.7.x, and it pointed __check_auth at the target contract instead of the smart account. The smart account address now comes from the simulated entry.
  • Added a callout for the failure mode (Error(Auth, InvalidAction) with a trap inside __check_auth, not a SmartAccountError). Linked the upstream auth_entries reference test and stellar/smart-account-kit.
  • The #transaction-simulation-behavior anchor is unchanged. The upstream README links to it.

Context rules (context-rules.mdx, authorization-flow.mdx)

  • New CreateContractExternalRef(Address, String) context type (Protocol 28, CAP-85). Added a callout: such a rule trusts the owner contract, and matching follows how the executable is referenced, so a CreateContract(hash) rule doesn't cover an external-ref deployment of the same hash.

Policies (policies.mdx)

  • Weighted threshold: new "Required Operation Ordering" section. When raising, call set_signer_weight before set_threshold; when lowering, call set_threshold before reducing weights. A wrong order reverts with InvalidThreshold (3211). The caveats and the signer-management callouts link to it.
  • Spending limit: zero-amount transfers are always allowed, and history is capped at 815 entries (HistoryCapacityExceeded beyond that).
  • Pre-existing errors fixed along the way: the window is period_ledgers (in ledgers, not seconds), and the policy only permits transfer calls.

Other pre-existing fixes

  • batch_add_signer is not a SmartAccount trait method. It's a helper function that performs no authorization, so the docs now show a contract wrapping it with require_auth, as the multisig example does.
  • The overview now links the multisig example, the new factory example and smart-account-kit.

Context Rules example (context-rules.mdx, second commit)

  • add_context_rule takes the context type, name, signers and policies by reference. The example passed them by value.
  • Added the missing semicolon on the use and the missing Signer import.
  • 1_year / 7_days / 12_hours are not valid Rust literals, and current_ledger was undefined. Replaced them with e.ledger().sequence() and a DAY_IN_LEDGERS constant.
  • bls_verifier and ed25519_verifier are each used for two signers, so the first use is now cloned. Address is not Copy, so the second use failed as a moved value.

Verification

  • Checked every API claim against stellar-contracts main: smart_account/{mod,storage}.rs, the policy modules, the multisig example and test/auth_entries.rs. That test confirms that a delegated entry carrying the digest bytes instead of the preimage struct fails.
  • All 5 pages compile with the site's MDX + GFM pipeline, and every internal anchor link resolves.
  • The Context Rules example was extracted verbatim, wrapped in a function whose parameters stand in for the placeholder variables, and passed cargo check against stellar-accounts on main. Negative control: the previous version fails with 13 errors.
  • Not done: the other Rust snippets on these pages are partial __check_auth excerpts and were not cargo checked. The TypeScript example was not run. pnpm run build was not run.

- Signers now commit to an AuthDigestPreimage { account, signature_payload,
  context_rule_ids }: External signers sign sha256(preimage.to_xdr()) and
  Delegated signers authorize __check_auth with the preimage as the single
  argument. Replace the old sha256(payload || rule_ids.to_xdr()) digest
  across the authorization flow, the __check_auth snippets, the auth digest
  computation steps and the diagram, and note the v0.7.x -> v0.8.0 change.
- Fix the delegated signer client example: the nested entry targets the
  smart account and carries the preimage map, and the re-simulated output
  shows it. Document the auth_digest view, the stellar_xdr encoding of the
  preimage, and point to the auth_entries reference test and smart-account-kit.
- Add the CreateContractExternalRef(owner, tag) context type (Protocol 28,
  CAP-85) and its trust and matching caveats.
- Policies: document the weighted threshold operation ordering, and correct
  the spending limit parameters (period_ledgers, not seconds), transfer-only
  scope, zero-amount transfers and the 815-entry history cap.
- Describe batch_add_signer as a module helper the contract must wrap with
  its own authorization, not a SmartAccount trait method.
- Link the multisig and factory examples from the overview.
The add_context_rule example did not compile against stellar-accounts:

- Pass the context type, name, signers and policies by reference, as
  add_context_rule expects.
- Add the missing semicolon and Signer import.
- Replace the invalid 1_year / 7_days / 12_hours literals and the undefined
  current_ledger with e.ledger().sequence() and a DAY_IN_LEDGERS constant.
- Clone the verifier addresses that are used for more than one signer.
@brozorec
brozorec requested a review from ozgunozerk October 6, 2026 14:05
@brozorec brozorec self-assigned this Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant