Skip to content

feat: Privy Authentication Enhancements (Issues #612, #614, #615, #616) - #722

Merged
Akatenvictor merged 1 commit into
AudioBitsStellar:mainfrom
coding-may:feature/privy-auth-enhancements
Sep 29, 2026
Merged

Akatenvictor merged 1 commit into
AudioBitsStellar:mainfrom
coding-may:feature/privy-auth-enhancements

Conversation

@coding-may

Copy link
Copy Markdown
Contributor

Summary

This PR implements four interconnected Privy authentication features that enhance the AudioBlock authentication system.

Closes #612, Closes #614, Closes #615, Closes #616

Issues Addressed

Key Features

🔐 Issue #612: Embedded Wallet Creation

  • Privy webhook handler for user.created events
  • Automatic embedded wallet linking during account creation
  • Default listener role assignment

🌌 Issue #614: Stellar Wallet Linking

  • Webhook handler for user.linked_account events
  • Stellar wallet detection and linking
  • Support for external wallets (MetaMask, WalletConnect, Freighter)

🛡️ Issue #615: Role-Based Access Control

  • Comprehensive RBAC middleware system
  • Role-based permissions mapping (listener, artist, moderator, admin, super_admin)
  • Fine-grained permission checking
  • Resource ownership validation

👤 Issue #616: Artist vs Listener Account Type

  • Account type service for role management
  • Listener → Artist upgrade flow
  • Downgrade protection when content exists
  • Dedicated API endpoints

Documentation

  • docs/ACCOUNT_TYPES.md - Account type guide
  • docs/PRIVY_WEBHOOKS.md - Webhook implementation guide

Testing

  • ✅ Unit tests for AccountTypeService
  • ✅ Unit tests for RBAC middleware
  • ✅ Integration tests coverage

Security

  • HMAC-SHA256 webhook signature verification
  • Timestamp-based replay protection
  • Server-side permission enforcement
  • Audit logging for role changes

Closes AudioBitsStellar#612, Closes AudioBitsStellar#614, Closes AudioBitsStellar#615, Closes AudioBitsStellar#616

- Issue AudioBitsStellar#612: Add support for embedded wallet creation on signup
  * Webhook handler for user.created events
  * Automatic embedded wallet linking during account creation
  * Default listener role assignment for new signups

- Issue AudioBitsStellar#614: Add Stellar wallet linking through Privy
  * Webhook handler for user.linked_account events
  * Stellar wallet detection (chain_type=stellar, address starts with G)
  * stellarPublicKey field population for royalty payments
  * Support for external wallet connections (MetaMask, WalletConnect)

- Issue AudioBitsStellar#615: Implement role-based access control on Privy identity
  * RolePermissions mapping for listener, artist, moderator, admin
  * requireRoles middleware factory for route protection
  * requirePermissions middleware for fine-grained access control
  * Helper functions: hasPermission, hasRole, canAccessResource
  * Convenience middlewares: requireArtist, requireAdmin, etc.
  * Full integration with both legacy JWT and Privy auth

- Issue AudioBitsStellar#616: Implement artist vs listener account type distinction
  * AccountTypeService for role management
  * Account type selection during signup
  * Listener to artist upgrade flow
  * Downgrade protection when content exists
  * Dedicated API endpoints for account type management
  * Integration with RBAC permissions system

Additional improvements:
- Privy webhook signature verification (HMAC-SHA256)
- Comprehensive test coverage for RBAC and account types
- Documentation for account types and webhook integration
- Support for social logins (Twitter, Google) via webhooks
- Audit logging for all account type changes
@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@coding-may Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Akatenvictor
Akatenvictor merged commit fd641ad into AudioBitsStellar:main Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants