Skip to content

fix(web): remove fake vouch XDR, externalize config, drop node-crypto… - #101

Merged
EmeditWeb merged 2 commits into
mainfrom
fix/web-code-lapses-vouch-config-crypto-bundle
Sep 24, 2026
Merged

EmeditWeb merged 2 commits into
mainfrom
fix/web-code-lapses-vouch-config-crypto-bundle

Conversation

@EmeditWeb

Copy link
Copy Markdown
Member

No description provided.

EmeditWeb and others added 2 commits September 21, 2026 12:15
… fallback, split bundle

Resolve four code-lapse issues surfaced in the CI/quality pass:

- Vouch signing theater: Vouch.tsx and MentorDashboard.tsx fabricated a
  random XDR string and asked Freighter to sign it, then discarded the
  signature entirely — a blind-sign trust hazard that accomplished nothing.
  Vouch approval is an authenticated, off-chain backend transition
  (POST /vouching/approve, authorized by the mentor's wallet-bound JWT), so
  the bogus signing step is removed and the handlers call the mutation
  directly. Dead txHash plumbing dropped from useOptimisticVouch and
  vouching.service. If on-chain vouching is ever wired up, it should route
  through useTransaction + a backend-built XDR the way deposits do — never a
  client-fabricated one.

- Hardcoded config: API_BASE_URL, STELLAR_NETWORK and the five CONTRACT_IDS
  now read from VITE_* env vars with testnet defaults, matching the existing
  SOROBAN_RPC_URL pattern that .env.example already advertised but the code
  ignored. .env.example documents every variable.

- Browser-incompatible crypto: soroban.service computeSha256 dropped its
  `await import('crypto')` Node fallback, which triggered Vite's "'crypto'
  externalized for browser compatibility" warning and emitted a
  __vite-browser-external chunk. Web Crypto (crypto.subtle) is the single
  portable SHA-256 path across secure browser contexts and Node 19+.

- Monolithic bundle: the router now lazy-loads every route page, so the
  Stellar SDK and other heavy per-page deps leave the initial chunk. Initial
  entry drops from ~2,008 kB (565 kB gzip) to 386 kB (124 kB gzip); stellar-sdk
  is isolated in a lazy chunk loaded only on the pages that need it.

Verified: eslint clean, 49/49 vitest pass, production build green with the
crypto externalization warning gone.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@EmeditWeb
EmeditWeb merged commit 9fa787b into main Sep 24, 2026
2 checks passed
@EmeditWeb
EmeditWeb deleted the fix/web-code-lapses-vouch-config-crypto-bundle branch September 29, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant