You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This test-only security issue converts the authorization findings from #47 into regression coverage. Every merged auth-gated contract entry point must reject missing authorization and authorization from the wrong identity.
Blocked by #47: use its final entry-point and intended-authorizer table as the coverage checklist.
Requirements and Context
For every function classified by #47 as merchant-, subscriber-, or administrator-authorized, add:
a no-auth test; and
a wrong-authorizer test where the Soroban test framework can express the exact authorization tree.
At minimum, cover the merged versions of:
create_plan();
subscribe();
cancel();
upgrade and downgrade functions;
subscriber plan-version migration;
record_usage();
plan-version creation;
token/router/oracle allowlist or configuration;
trial/pricing configuration;
subscriber-controlled payment, slippage, cap, or migration settings;
Do not assume functions from open issues exist. Test the exact merged contract.
Test methodology
A test using only env.mock_all_auths() cannot prove that the correct address was required.
Use:
env.set_auths(&[]) or the current SDK-equivalent for missing auth;
explicit MockAuth / MockAuthInvoke authorization trees for correct and wrong signers;
authorization assertions provided by soroban_sdk::testutils;
exact function names and arguments where require_auth_for_args() is used.
For each auth-gated function, prove:
no authorization fails;
an unrelated address's authorization fails;
the intended stored/supplied address succeeds;
authorization for different arguments cannot be replayed where argument-scoped auth applies;
failure occurs before any persistent mutation or external token/router/oracle call;
all relevant state and balances remain unchanged.
Pay special attention to functions that accept an Address parameter. Verify the function requires authorization from that exact identity rather than accepting any signature.
Where ownership should be derived from storage, verify that passing or referencing another user's subscription, plan group, or configuration does not redirect the auth check.
Expected permissionless/public behavior
Use the audit to add focused counter-tests confirming intentionally permissionless/public entry points remain callable without auth, including where merged:
charge(), while still enforcing state, schedule, and allowance rules;
get_plan();
get_subscription();
get_usage();
get_usage_report();
preview functions;
public configuration reads.
These tests prevent a future contributor from accidentally adding an authorization requirement that breaks keeper or client integrations.
Account and contract authorizers
Where the final design permits contract addresses as merchants, subscribers, or administrators, include appropriate tests or document why the scenario cannot be represented safely in the current test scope.
Do not assume account-address and contract-address authorization trees are identical.
Description
This test-only security issue converts the authorization findings from #47 into regression coverage. Every merged auth-gated contract entry point must reject missing authorization and authorization from the wrong identity.
Blocked by #47: use its final entry-point and intended-authorizer table as the coverage checklist.
Requirements and Context
For every function classified by #47 as merchant-, subscriber-, or administrator-authorized, add:
At minimum, cover the merged versions of:
create_plan();subscribe();cancel();record_usage();Do not assume functions from open issues exist. Test the exact merged contract.
Test methodology
A test using only
env.mock_all_auths()cannot prove that the correct address was required.Use:
env.set_auths(&[])or the current SDK-equivalent for missing auth;MockAuth/MockAuthInvokeauthorization trees for correct and wrong signers;soroban_sdk::testutils;require_auth_for_args()is used.For each auth-gated function, prove:
Pay special attention to functions that accept an
Addressparameter. Verify the function requires authorization from that exact identity rather than accepting any signature.Where ownership should be derived from storage, verify that passing or referencing another user's subscription, plan group, or configuration does not redirect the auth check.
Expected permissionless/public behavior
Use the audit to add focused counter-tests confirming intentionally permissionless/public entry points remain callable without auth, including where merged:
charge(), while still enforcing state, schedule, and allowance rules;get_plan();get_subscription();get_usage();get_usage_report();These tests prevent a future contributor from accidentally adding an authorization requirement that breaks keeper or client integrations.
Account and contract authorizers
Where the final design permits contract addresses as merchants, subscribers, or administrators, include appropriate tests or document why the scenario cannot be represented safely in the current test scope.
Do not assume account-address and contract-address authorization trees are identical.
Naming
Use consistent names such as:
Security finding handling
If a test proves that unauthorized mutation is currently possible:
Suggested Execution
security/unauthorized-caller-testssrc/test.rs, ortest(security): cover unauthorized callers for auth-gated functionsTest and Commit Steps
mock_all_auths()as evidence.crate-type = ["rlib"]on Windows if required:crate-type = ["cdylib", "rlib"]and build:If focused test modules are added, stage them as well.
Guidelines
Closes #<issue-number>.mock_all_auths()as proof of correct authorization.charge()and public reads.27.0.3.Complexity
High (200 pts)