Configure Secure Cookie Storage parameters for Session JWTs
- Category: Backend: Web3 Auth & Stellar Signatures
- Task ID: BE-W3A-115
Description
This issue is dedicated to the technical design, implementation, and rigorous auditing of 'Configure Secure Cookie Storage parameters for Session JWTs' inside the Lance marketplace ecosystem, specifically focusing on the Backend: Web3 Auth & Stellar Signatures component. You must implement strict input sanitization, validate data structure boundaries, and prevent common exploit vectors such as replay attacks, front-running, or address poisoning. Make sure to integrate standard cryptographic safety wrappers and enforce rigid auth gating rules. Ensure that your implementation strictly adheres to the project's architectural guidelines, features self-documenting code with comprehensive inline annotations, and provides solid verification proofs. Any modifications to state variables must undergo strict validation before commits.
Requirements
- Implement signature validation and session routing inside
backend/src/routes/auth.rs for Configure Secure Cookie Storage parameters for Session JWTs.
- Decode and validate Stellar public addresses securely, checking checksum bytes using dynamic decoders.
- Integrate Redis client helpers or secure cookies parameters inside the Axum route state.
- Write comprehensive test mockups to verify signature validations and challenge timelines.
Acceptance Criteria
- Login succeeds with Freighter wallet signatures that conform to SEP-53 standard.
- Incorrect signatures or expired challenges are rejected with a strict 401 Unauthorized status.
- Redis blacklist lookups execute within 1ms and effectively block revoked sessions.
Configure Secure Cookie Storage parameters for Session JWTs
Description
This issue is dedicated to the technical design, implementation, and rigorous auditing of 'Configure Secure Cookie Storage parameters for Session JWTs' inside the Lance marketplace ecosystem, specifically focusing on the Backend: Web3 Auth & Stellar Signatures component. You must implement strict input sanitization, validate data structure boundaries, and prevent common exploit vectors such as replay attacks, front-running, or address poisoning. Make sure to integrate standard cryptographic safety wrappers and enforce rigid auth gating rules. Ensure that your implementation strictly adheres to the project's architectural guidelines, features self-documenting code with comprehensive inline annotations, and provides solid verification proofs. Any modifications to state variables must undergo strict validation before commits.
Requirements
backend/src/routes/auth.rsfor Configure Secure Cookie Storage parameters for Session JWTs.Acceptance Criteria