Skip to content

Fix incorrect nftIssuer set to user address instead of platform address #540

Description

@DeFiVC

Bug Description

The CredentialService.mint method in src/modules/credentials/credential.service.ts (lines 66-221) sets nftIssuer to the user's stellarAddress (line 191), but this should be the platform's address since the platform is issuing the NFT.

Location

src/modules/credentials/credential.service.ts line 191

const [credential] = await db
    .insert(credentials)
    .values({
        userId,
        courseId,
        score: mintData.score,
        nftAssetCode: mintData.nftAssetCode,
        nftIssuer: mintData.stellarAddress,  // BUG: should be platform address
        mintTxHash: txHash,
    })
    .returning();

The Problem

  1. nftIssuer is set to the user's Stellar address
  2. But the platform keypair signs the mint transaction (line 101 in signatures.ts)
  3. The actual issuer of the NFT is the platform, not the user
  4. This makes the stored nftIssuer incorrect for on-chain verification

Recommended Fix

import { getPlatformKeypair } from "../../config/stellar.js";

// In the mint method:
const platformKeypair = getPlatformKeypair();

const [credential] = await db
    .insert(credentials)
    .values({
        userId,
        courseId,
        score: mintData.score,
        nftAssetCode: mintData.nftAssetCode,
        nftIssuer: platformKeypair.publicKey(),  // Correct: platform is the issuer
        mintTxHash: txHash,
    })
    .returning();

Acceptance Criteria

  • Set nftIssuer to the platform's Stellar public key
  • Verify that credential verification works with the corrected issuer
  • Update any existing incorrect records if possible

Severity

high - Incorrect NFT issuer breaks on-chain credential verification.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions