Skip to content

Security: OracleDesk/OracleDesk-Backend

Security

SECURITY.md

Security Policy

Status: testnet only, unaudited

This backend talks to OracleDesk contracts deployed on Stellar testnet only. Nothing has been professionally audited. Don't run it with mainnet funds or keys. See docs/STATUS.md for what is and isn't verified.

Reporting a vulnerability

Report privately, not in a public issue:

In scope, for example:

  • Logging in as an address you don't control (/auth/challenge, /auth/verify).
  • Getting a subscription without a matching on-chain USDC transfer, or reusing someone else's payment (payment-verification.service.ts).
  • Reaching an admin endpoint without being in ADMIN_ADDRESSES.
  • Making the backend sign or submit a transaction in dry-run mode, or on a network other than testnet in live mode.
  • A trace marked verified whose bytes don't match the on-chain hash.
  • Secrets in logs or API responses.

Out of scope: the contracts (report to OracleDesk-SmartContract), the frontend (report to OracleDesk-Frontend), and third-party dependencies unless this repo's use of them is what's exploitable.

There aren't any published security advisories