Bug Description
The CredentialService.mint method in src/modules/credentials/credential.service.ts (lines 66-221) sets nftIssuer to the user's stellarAddress (line 191), but this should be the platform's address since the platform is issuing the NFT.
Location
src/modules/credentials/credential.service.ts line 191
const [credential] = await db
.insert(credentials)
.values({
userId,
courseId,
score: mintData.score,
nftAssetCode: mintData.nftAssetCode,
nftIssuer: mintData.stellarAddress, // BUG: should be platform address
mintTxHash: txHash,
})
.returning();
The Problem
nftIssuer is set to the user's Stellar address
- But the platform keypair signs the mint transaction (line 101 in signatures.ts)
- The actual issuer of the NFT is the platform, not the user
- This makes the stored
nftIssuer incorrect for on-chain verification
Recommended Fix
import { getPlatformKeypair } from "../../config/stellar.js";
// In the mint method:
const platformKeypair = getPlatformKeypair();
const [credential] = await db
.insert(credentials)
.values({
userId,
courseId,
score: mintData.score,
nftAssetCode: mintData.nftAssetCode,
nftIssuer: platformKeypair.publicKey(), // Correct: platform is the issuer
mintTxHash: txHash,
})
.returning();
Acceptance Criteria
- Set
nftIssuer to the platform's Stellar public key
- Verify that credential verification works with the corrected issuer
- Update any existing incorrect records if possible
Severity
high - Incorrect NFT issuer breaks on-chain credential verification.
Bug Description
The
CredentialService.mintmethod insrc/modules/credentials/credential.service.ts(lines 66-221) setsnftIssuerto the user'sstellarAddress(line 191), but this should be the platform's address since the platform is issuing the NFT.Location
src/modules/credentials/credential.service.tsline 191The Problem
nftIssueris set to the user's Stellar addressnftIssuerincorrect for on-chain verificationRecommended Fix
Acceptance Criteria
nftIssuerto the platform's Stellar public keySeverity
high - Incorrect NFT issuer breaks on-chain credential verification.