Skip to content

docs: document fund() griefing fix and sponsor whitelist in README - #430

Open
Wilfred007 wants to merge 1 commit into
MergeFi:mainfrom
Grandida-Projects:docs/fund-griefing-analysis
Open

Wilfred007 wants to merge 1 commit into
MergeFi:mainfrom
Grandida-Projects:docs/fund-griefing-analysis

Conversation

@Wilfred007

Copy link
Copy Markdown
Contributor
  • Add 'Sponsor whitelist' subsection to contracts/escrow explaining the griefing vector (predictable issue_id + open fund() = squatting), the register_sponsor → fund two-step flow, and why admin-pre-registration was chosen over commit-reveal or permissionless recovery alternatives.
  • Include a Soroban transaction-ordering note: no public mempool, but proactive squatting (not front-running) is the real threat model, and the whitelist closes it unconditionally.
  • Update the function-list block with register_sponsor, force_reopen, get_registered_sponsor; add descriptions for all three new entrypoints.
  • Update the Security model section with a dedicated 'fund() sponsor whitelist' bullet explaining NotWhitelisted and force_reopen.
  • Update the Data models section to document DataKey::SponsorWhitelist.
  • Update the Backend integration section: step 1 now describes the register_sponsor → verify → fund prompt sequence mergefi-backend must follow for escrow fund flows.

Summary

Closes #1
Closes #21
Closes #2
Closes #23

Related issues

Changes

Test plan

  • Existing tests pass (make test)
  • New tests added for changed behaviour
  • Manually verified against a local node / testnet where applicable

Checklist

  • Branch is up to date with main
  • No debug / dead code left in
  • cargo fmt and cargo clippy are clean

- Add 'Sponsor whitelist' subsection to contracts/escrow explaining
  the griefing vector (predictable issue_id + open fund() = squatting),
  the register_sponsor → fund two-step flow, and why admin-pre-registration
  was chosen over commit-reveal or permissionless recovery alternatives.
- Include a Soroban transaction-ordering note: no public mempool, but
  proactive squatting (not front-running) is the real threat model, and
  the whitelist closes it unconditionally.
- Update the function-list block with register_sponsor, force_reopen,
  get_registered_sponsor; add descriptions for all three new entrypoints.
- Update the Security model section with a dedicated 'fund() sponsor
  whitelist' bullet explaining NotWhitelisted and force_reopen.
- Update the Data models section to document DataKey::SponsorWhitelist.
- Update the Backend integration section: step 1 now describes the
  register_sponsor → verify → fund prompt sequence mergefi-backend
  must follow for escrow fund flows.
@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@Wilfred007 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@vercel

vercel Bot commented Sep 30, 2026

Copy link
Copy Markdown

@Wilfred007 is attempting to deploy a commit to the chonilius' projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant