Skip to content

feat(vault): add remove_address to revoke a single allowlisted depositor - #1336

Open
Manta-Byte wants to merge 1 commit into
CalloraOrg:mainfrom
Manta-Byte:feat/vault-allowlist-remove-address
Open

Manta-Byte wants to merge 1 commit into
CalloraOrg:mainfrom
Manta-Byte:feat/vault-allowlist-remove-address

Conversation

@Manta-Byte

Copy link
Copy Markdown
Contributor

Closes #1109

Summary

Adds remove_address(caller, depositor) to the vault so a single compromised depositor can be revoked without clearing the whole allowlist and re-adding everyone else.

Criteria → code and tests

Criterion Code Test
Owner can remove one address and others remain allowed remove_address in lib.rs removes only the matching entry remove_address_keeps_other_entries_and_they_can_deposit
Removed address gets CallerNotInAllowlist on next deposit Same path; the deposit check reads the updated list removed_address_cannot_deposit
Non-owner call returns Unauthorized require_auth + owner check, same pattern as add_address / clear_all non_owner_remove_address_returns_unauthorized
allowlist_remove event with caller and depositor topics event_allowlist_remove in events.rs, published as (allowlist_remove, callora_v1, caller, depositor) remove_address_emits_allowlist_remove_event_with_correct_topics, test_event_allowlist_remove_bytes

Design and failure modes

  • Idempotent removal: removing an address that is not in the list returns Ok(()), changes no state and emits no event. Retries are safe, and events only reflect real state changes. Documented in the function's doc comment. Test: remove_address_not_in_list_is_idempotent_and_emits_no_event.
  • Security: owner-only with the same auth pattern as the other allowlist mutators. A non-owner call changes nothing.
  • Re-add: a removed address can be added again (remove_then_re_add_works).
  • Compatibility: no new storage keys, no changed signatures or error values. Existing deployments and indexers are unaffected; the new topic is additive.
  • Observability: docs/EVENT_TOPICS.md now lists allowlist_remove (topic 47), with totals and the vault filter list updated. scripts/check-event-shape.sh passes locally.

Files changed

  • contracts/vault/src/lib.rs: remove_address and test module declaration
  • contracts/vault/src/events.rs: event_allowlist_remove and snapshot test
  • contracts/vault/src/test_allowlist_remove.rs: new tests
  • docs/EVENT_TOPICS.md: topic documentation

Validation

cargo test -p callora-vault allowlist

…tor (CalloraOrg#1109)

Owner-only remove_address removes one entry, leaves the rest intact, is idempotent when absent, and emits allowlist_remove with version, caller and depositor topics.
@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@Manta-Byte Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remove single depositors from vault allowlist

2 participants