This backend talks to OracleDesk contracts deployed on Stellar testnet only. Nothing has been professionally audited. Don't run it with mainnet funds or keys. See docs/STATUS.md for what is and isn't verified.
Report privately, not in a public issue:
- GitHub Security Advisories for this repository, or
- email SECURITY-CONTACT-TBD@example.invalid
In scope, for example:
- Logging in as an address you don't control (
/auth/challenge,/auth/verify). - Getting a subscription without a matching on-chain USDC transfer, or
reusing someone else's payment (
payment-verification.service.ts). - Reaching an admin endpoint without being in
ADMIN_ADDRESSES. - Making the backend sign or submit a transaction in
dry-runmode, or on a network other than testnet inlivemode. - A trace marked verified whose bytes don't match the on-chain hash.
- Secrets in logs or API responses.
Out of scope: the contracts (report to OracleDesk-SmartContract), the frontend (report to OracleDesk-Frontend), and third-party dependencies unless this repo's use of them is what's exploitable.