Skip to content

fix(factory): validate the staking asset token in create_pool - #434

Merged
ritaifeoluwa merged 1 commit into
SmartDropLabs:mainfrom
Awwal-dev34:fix/factory-validate-token-address
Sep 29, 2026
Merged

ritaifeoluwa merged 1 commit into
SmartDropLabs:mainfrom
Awwal-dev34:fix/factory-validate-token-address

Conversation

@Awwal-dev34

@Awwal-dev34 Awwal-dev34 commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Overview

Factory::create_pool did not actually reject a staking asset that is not a token contract. validate_asset probed balance but treated an unanswerable probe (Err(_)) as success, so any plain address — or an unrelated deployed contract — could be registered as a pool's staking asset. This change makes validation strict: the asset must answer the SEP-41 interface.

Related Issue

Implements the strict SEP-41 asset validation requested in #430.

Changes

  • [MODIFY] soroban/contracts/factory/src/lib.rs

    • validate_asset now probes the read-only SEP-41 entry point symbol and requires the call to succeed, returning FactoryError::InvalidAsset otherwise. The previous permissive Err(_) => Ok(()) fallback — which accepted an address that never answered — is removed.
  • [MODIFY] soroban/contracts/factory/src/test.rs

    • Added a test_asset helper that registers a real SEP-41 (Stellar asset) contract, and routed create_pool / create_pools_batch test call sites through it so they pass a deployed token.
    • Added test_create_pool_rejects_non_token_asset: a bare generated address is rejected with InvalidAsset and no pool is registered.
    • Added test_create_pool_rejects_contract_without_sep41_interface: a real deployed contract that does not expose SEP-41 is rejected.
    • Added test_create_pool_accepts_sep41_token_asset: a genuine token is accepted and recorded on the pool.
    • Added test_create_pools_batch_rejects_non_token_asset: an invalid asset in a batch reverts the whole batch (including the leading valid pool).
  • [MODIFY] soroban/contracts/factory/tests/factory_pool_integration.rs

    • Same test_asset helper so the factory integration suite creates pools with a real token asset.

Verification Results

cargo test -p factory
  87 passed; 0 failed   (unit tests, up from 83)
   9 passed; 0 failed   (factory_pool_integration)

The new rejection tests fail against the previous permissive check and pass with the strict SEP-41 probe.

Acceptance Criteria Status
create_pool rejects a non-token staking asset ✅ InvalidAsset, no pool registered
create_pool rejects an unrelated contract ✅ covered by test_create_pool_rejects_contract_without_sep41_interface
Valid SEP-41 token still accepted ✅ all existing create_pool tests use a real token
Batch creation stays atomic on an invalid asset ✅ test_create_pools_batch_rejects_non_token_asset

Closes #430

@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Awwal-dev34 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@netlify

netlify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for sdcontracts ready!

Name Link
🔨 Latest commit 5c616cc
🔍 Latest deploy log https://app.netlify.com/projects/sdcontracts/deploys/6abaa075429a9c000867a9f4
😎 Deploy Preview https://deploy-preview-434--sdcontracts.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@ritaifeoluwa
ritaifeoluwa merged commit bfcaf7e into SmartDropLabs:main Sep 29, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[security] factory: create_pool doesn't validate token address

2 participants