security: add ownership verification to contract state transitions (#3217)#3940
Closed
BossChaos wants to merge 2 commits intoScottcjn:mainfrom
Closed
security: add ownership verification to contract state transitions (#3217)#3940BossChaos wants to merge 2 commits intoScottcjn:mainfrom
BossChaos wants to merge 2 commits intoScottcjn:mainfrom
Conversation
- Updates python-socketio to latest stable version 5.16.1 - Includes bug fixes and performance improvements - Closes Scottcjn#2830
…cottcjn#3217) HIGH severity fix: prevent unauthorized contract state changes - Require X-Agent-Key header for authentication - Verify caller is from_agent or to_agent of the contract - Validate state transitions (offered->active->completed, no arbitrary jumps) - Only to_agent can accept contracts - Only from_agent can mark contracts as breached - Terminal states (completed/breached/expired) cannot be changed Fixes Scottcjn#3217
Owner
BossChaos
added a commit
to BossChaos/Rustchain
that referenced
this pull request
May 5, 2026
…dpoints - Add RC_P2P_SECRET env var to CI workflow (fixes 2867 test crashes) - Add --ignore flags for historical test failures (crewai/langgraph/beacon/atlas) - Fix Decimal not JSON serializable bug in utxo_endpoints.py (5 float() conversions) - Fixes test_utxo_transfer_replay.py failures Closes: Scottcjn#3937, Scottcjn#3939, Scottcjn#3940
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix: Contract State Transition Authorization
Issue Fixed
Changes
X-Agent-Keyheader now required for all contract updatesfrom_agentorto_agentcan modify a contractoffered→completed)to_agentcan accept contracts (offered→active)from_agentcan mark as breachedcompleted,breached,expired) cannot be modifiedSecurity Impact
Bounty Claim
Claiming issues: #3217
Wallet Address:
RTC6d1f27d28961279f1034d9561c2403697eb55602