Skip to content

feat: implement multisig proposal queue API (#961) - #977

Merged
Chucks1093 merged 3 commits into
accesslayerorg:mainfrom
zainabwahab-eth:feat/961-multisig-proposal-queue
Sep 28, 2026
Merged

Chucks1093 merged 3 commits into
accesslayerorg:mainfrom
zainabwahab-eth:feat/961-multisig-proposal-queue

Conversation

@zainabwahab-eth

Copy link
Copy Markdown
Contributor

Closes #961

Summary

Implements the multi-sig proposal queue API for managing admin proposals requiring multi-sig approval.

Endpoints Implemented

  • GET /admin/proposals - Paginated proposal queue with status filter (pending/executed/rejected)
  • GET /admin/proposals/:id - Detailed proposal view with all signatures and signer addresses
  • POST /admin/proposals/:id/sign - Submit signature/approval, triggers execution when threshold reached
  • POST /admin/proposals/:id/reject - Reject proposal with rejector address and timestamp

Key Features

  • Signer Authorization: Uses existing ADMIN_MULTISIG_WALLETS env config (2-of-3 default) for authorization
  • Threshold Execution: Automatic execution when required distinct authorized signatures are collected
  • Duplicate Prevention: DB-level unique constraint on (proposalId, signer) prevents duplicate signatures
  • Concurrency Safety: Uses Prisma transactions for atomic signature counting and state transitions
  • Proposal Lifecycle: Enforces valid state transitions (pending → executed/rejected), rejects invalid transitions
  • Audit Trail: All actions logged via existing audit infrastructure

Database Changes

  • New multisig_proposals table with proposal metadata, status, threshold, proposer
  • New multisig_signatures table with foreign key to proposals, unique constraint on (proposalId, signer)
  • Migration: 20260927000000_add_multisig_proposal_queue

Tests

  • Comprehensive integration tests covering all endpoints and error cases
  • Unit tests for service layer covering threshold logic, authorization, state transitions
  • Concurrency test for race condition prevention around threshold execution

Documentation

  • Updated docs/api-endpoints.md with all new endpoints, request/response examples, and error codes

- Add MultisigProposal and MultisigSignature Prisma models with migration
- Implement GET /admin/proposals (paginated queue with status filter)
- Implement GET /admin/proposals/:id (detailed view with all signatures)
- Implement POST /admin/proposals/:id/sign (submit signature with threshold execution)
- Implement POST /admin/proposals/:id/reject (reject proposal with rejector/timestamp)
- Use ADMIN_MULTISIG_WALLETS for signer authorization (2-of-3 default)
- Prevent duplicate signatures with DB unique constraint
- Atomic threshold execution with DB transactions
- Comprehensive integration and unit tests
- Update API documentation
@zainabwahab-eth
zainabwahab-eth force-pushed the feat/961-multisig-proposal-queue branch from 62c0ee3 to 153850d Compare September 27, 2026 09:53
@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

@zainabwahab-eth Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Chucks1093
Chucks1093 merged commit 95dc667 into accesslayerorg:main Sep 28, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Build multi-sig proposal queue API with signature tracking

2 participants