v1.24.28
·
13 commits
to main
since this release
Security
- Block CAP-71 auth entries bound to a non-wallet address — #987 (#987) (Jake Urban, Aug 26)
Fixes a HackerOne-reported issue (tracked as wallet-eng-monorepo#59). validateAuthEntryAddress previously only enforced the bound-address check when the address was an account; a contract-bound ADDRESS_V2
preimage skipped it entirely and got signed — exactly the shape of a delegated-auth request, so a dApp could obtain a delegate signature over a smart wallet the user was never shown. Now every ScAddress arm
is rendered via addressToString and compared to the wallet key; unrenderable arms fail closed. Matches the extension's behavior. The test that previously asserted the vulnerable outcome was flipped.
Dependencies / Protocol 28
- Migrate to @stellar/stellar-sdk 17.0.1 — #988 (#988) (you, Aug 26; +1390/−483, 43 files)
Mobile port of stellar/freighter#2977. Brings Protocol 28 XDR (@stellar/js-xdr 5): class-based xdr namespace, int64 → bigint, Buffer → Uint8Array returns. Every site that relied on .toString("hex"|"base64")
on SDK bytes now uses explicit xdr.encodeBytes (SEP-53 sign-message, SEP-43 sign-auth-entry, auth JWT, analytics account hash, wasm hash/salt rendering). CAP-85 support: CONTRACT_EXECUTABLE_EXTERNAL_REF and
SCV_EXECUTABLE_TAG decode in invocation args/details, with an "unrecognized invocation" warning instead of a render-time throw. 17.0.1 chosen over 17.0.0 for the deprecated-alias safety net. Verified: tsc
clean, 223 suites / 2984 tests, Metro prod bundle builds, dev build boots on Hermes. Not yet tested on Android.
WalletKit UX
- Let the dApp request payload scroll on Android — #985 (#985) (Cássio Goulart, Aug 21)
Android-only fix: long sign-message / sign-auth-entry payloads couldn't be scrolled because gorhom's content-pan gesture cancelled the nested ScrollView. Sets enableContentPanningGesture={false} for those
two request types. Trade-off: swipe-to-dismiss on the sheet body is gone for those sheets (handle drag, backdrop tap, Cancel still work). Transaction requests are untouched.
CI / PR previews
- iOS PR preview points at the author's freighter-config sandbox — #947 (#947) (Piyal Basu, Aug 25)
prPreviewIos.yml clones the private freighter-config repo with a read-only deploy key (torn down before PR code runs), maps the PR author → their sandbox backend v1/v2 URLs, and bakes them into .env. Falls
back to staging when there's no entry, and to staging + a preview-degraded label when the config is unreachable. Sticky comment and release notes now state the target backend. Part of Fullstack PR Preview
Phase 2 (#859). - Android Emulator PR preview workflow — #971 (#971) (Piyal Basu, Aug 25)
New prPreviewAndroid.yml, the missing Android leg. Builds an installable assembleDevRelease APK signed with the checked-in debug keystore, reuses the same freighter-config sandbox resolution as iOS,
publishes to a pr-preview-android- draft release with its own sticky comment. Verified green in CI with the APK resolving to the author's sandbox.
Housekeeping
Themes: this is a security-and-infrastructure cycle rather than a feature one — the Protocol 28 SDK migration and the CAP-71 fix together get the wallet ready to correctly decode and refuse the new auth-entry
shapes, while the two CI PRs complete the full-stack PR preview flow on both platforms. Note that main is also 1 commit behind the v1.23.27 tag (the tag was cut off the release PR branch), which is normal for
this repo's release process.