feat: secure upgrade mechanism, flash loan attack prevention, DTO refactor, event schema standardization#415
Merged
Smartdevs17 merged 4 commits intoMay 28, 2026
Conversation
- Add STANDARD_TIMELOCK_SECS (48h) and EMERGENCY_TIMELOCK_SECS (4h) constants - Add TimelockNotElapsed and StorageLayoutMismatch error variants - Add TimelockQueued stage to UpgradeStage enum - Add execute_after and is_emergency fields to UpgradeProposal and UpgradeStatus - Add upgrade_queue_timelock() to start the standard 48h countdown post-approval - Add upgrade_propose_emergency() for 4h emergency path (admin only) - Enforce timelock in upgrade_execute() — rejects before execute_after elapses - Add UpgradeTimelockQueuedEvent and UpgradeEmergencyProposedEvent to events - Update all tests to go through queue_and_execute() helper for correct flow
…evention - Add ManipulationConfig with pool liquidity cap (50%), price impact limit, TWAP deviation threshold, and concurrent loan detection - Add TwapAccumulator/TwapState structs with time-windowed price sampling - Add check_twap_deviation(), check_liquidity_cap(), check_price_impact() - Add per-asset AssetLoanGuard to block concurrent flash loans (sandwich prevention) - Update flash_loan() signature to accept spot_price for TWAP checks - Add flash_record_price() and set_flash_manipulation_config() entrypoints - Apply same attack guards to hello-world flash_loan module - Update all tests to use new flash_loan() signature with spot_price - Add tests for liquidity cap, price impact, and TWAP deviation blocking Closes Smartdevs17#379, Smartdevs17#401
- Add api/src/dto/ directory with TypeScript DTO classes - base.dto.ts: FieldError, ValidationResult, helper validators (isValidStellarAddress, isValidAmount, isOptionalString), MAX_I128 constant - lending.dto.ts: LendingOperationDto, PrepareRequestDto, SubmitRequestDto, RelayDelegatedDto, PrepareResponseDto, TransactionResponseDto — all with static validate() and fromBody()/fromQuery() factories + JSDoc/OpenAPI schemas - subscription.dto.ts: CreateSubscriptionDto covering all subscription fields - pagination.dto.ts: PaginationQueryDto with configurable max-limit - dto/index.ts: barrel re-export - middleware/validation.ts: add DTO-based middleware variants (validateLendingOperationDto, validatePrepareDto, validateSubmitDto, validateRelayDelegatedDto, validateCreateSubscriptionDto, validatePaginationDto) that attach typed DTOs to req for use in controllers — existing express-validator chain preserved Closes Smartdevs17#362
AMM (amm.rs): - Add explicit topics attributes: amm_swap, amm_liq_add, amm_liq_rm, amm_op, amm_cb_valid - Add timestamp: u64 field to SwapExecutedEvent, LiquidityAddedEvent, LiquidityRemovedEvent, CallbackValidatedEvent (AmmOperationEvent already had it) - Update all emit helper functions to pass env.ledger().timestamp() Bridge (bridge.rs): - Add explicit topics attributes: br_reg, br_fee, br_active, br_dep, br_wdraw, br_pause, br_val_upd, br_sec_cfg, br_slash, br_ch_emrg, br_anomaly - Add timestamp: u64 to all 11 bridge event structs (previously none had it) - Update all emit call sites to include timestamp Docs: - Add docs/event-schema.md: mandatory fields spec, topic naming conventions, per-contract event catalogue, backward-compat note, PR checklist CI: - Add scripts/check_event_schema.sh: detects contractevent structs missing the required timestamp field; warns on missing explicit topics Closes Smartdevs17#356, Smartdevs17#408
|
@akintewe is attempting to deploy a commit to the smartdevs17's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
@akintewe Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR implements four open issues across the StellarLend codebase:
Issue #382 — Secure upgrade mechanism with timelock and multisig
STANDARD_TIMELOCK_SECS(48 h) andEMERGENCY_TIMELOCK_SECS(4 h) constants tostellarlend-commonTimelockQueuedstage inUpgradeStageenum; proposals must passupgrade_queue_timelock()before executionupgrade_propose_emergency()entrypoint uses the shorter 4 h delayupgrade_execute()now checksexecute_afterand panics withTimelockNotElapsedif the window has not elapsedUpgradeTimelockQueuedEventandUpgradeEmergencyProposedEventemitted on queue/emergency-proposeIssue #379 — Flash loan attack prevention with price manipulation detection
ManipulationConfigwith configurable pool-liquidity cap (50%), price impact limit (1%), TWAP deviation threshold (2%), and concurrent-loan guardTwapAccumulator/TwapStatemaintain a time-windowed rolling average of oracle pricescheck_twap_deviation()blocks loans when spot price deviates excessively from TWAPcheck_liquidity_cap()limits each flash loan to a fraction of pool liquiditycheck_price_impact()uses constant-product approximation to bound impactAssetLoanGuardprevents concurrent loans on the same asset (sandwich mitigation)lending/src/flash_loan.rsandhello-world/src/flash_loan.rsflash_record_price()andset_flash_manipulation_config()entrypointsIssue #362 — TypeScript DTO refactor
api/src/dto/directory with typed DTO classesbase.dto.ts:ValidationResult,FieldError,isValidStellarAddress(),isValidAmount(),MAX_I128lending.dto.ts:LendingOperationDto,PrepareRequestDto,SubmitRequestDto,RelayDelegatedDto, response DTOssubscription.dto.ts:CreateSubscriptionDtopagination.dto.ts:PaginationQueryDtostatic validate()+fromBody()/fromQuery()factoriesmiddleware/validation.tsattach typed DTOs toreqIssue #356 — Standardized event schemas
topicsattributes (amm_swap,amm_liq_add,amm_liq_rm,amm_op,amm_cb_valid) andtimestamp: u64fieldtopicsattributes andtimestamp: u64field to all 11 structsdocs/event-schema.md: mandatory field spec, topic naming conventions, per-contract catalogue, PR checklistscripts/check_event_schema.sh: CI script that detects event structs missingtimestampTest plan
cargo test -p stellarlend-common— upgrade timelock tests passcargo test -p lending— flash loan, upgrade, migration tests passcargo test -p hello-world— flash loan tests passcargo test -p bridgeand-p amm— compile with new event fieldsscripts/check_event_schema.sh— reports 0 violationscd api && npx tsc --noEmit— DTO types compile cleanlyCloses #356 closes #362 closes #379 closes #382