fix(maintenance-pool): rekey assignReward double-payout guard on issueId (#458) - #479
Open
PINYOPATTANAWASANPORN wants to merge 1 commit into
Conversation
…eId (MergeFi#458) The MergeFi#273 fix checked (escrow.maintenancePoolId, recipientId) which fails in two cases: 1. Same issue paid to two different recipients both pass the guard. 2. Anonymous payouts (recipientId=null) are never guarded. Fix: add a nullable `issueId` column to Payment and filter the guard query on (escrow.maintenancePoolId, payment.issueId) instead. Each issue can now only receive one reward per pool regardless of recipient identity. Tests added: 6 unit tests covering allowed first reward, ConflictException on same-issue second reward with different recipient, ConflictException for anonymous double-payout, query filter shape assertion (issueId not recipientId), insufficient balance, and missing issue.
|
@PINYOPATTANAWASANPORN is attempting to deploy a commit to the chonilius' projects Team on Vercel. A member of the Team first needs to authorize it. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary of Changes
Fixes the double-payout guard in
assignReward()so it is keyed on(escrow.maintenancePoolId, issueId)instead of(escrow.maintenancePoolId, recipientId).Adds a nullable
issueIdcolumn to thePaymententity to make the guard expressible as a single indexed query.Root Cause (#458)
The
#273fix introduced this check:This has two bypass paths:
assignReward(pool, issue#1, recipientA)succeeds, thenassignReward(pool, issue#1, recipientB)also succeeds — the guard only checks the recipient, not the issue.recipientIdis undefined, the guard filters onrecipientId = null, which matches any anonymous payment in the pool — not the specific issue.Fix
issueIdis passed through toescrowService.poolWithdraw()and saved on thePaymentrow.Verification & Testing
6 unit tests added to
maintenance-pool.service.spec.ts:allows first reward for an issue— happy path passesrejects a second reward for the SAME issue regardless of recipient— ConflictException when recipientB tries to claim same issuerejects double-payout for anonymous (null recipientId) assignments— ConflictException for null recipientguards on issueId in the query (not recipientId)— assertsandWherefilter usesissueId, notrecipientIdthrows BadRequestException when balance is insufficientthrows NotFoundException when issue does not existImpact & Compatibility
issueId varcharcolumn topaymentstable. Zero-impact on existing rows (null by default).issueIdparameter.Closes #458