Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,6 @@ jobs:
uses: crytic/slither-action@v0.3.0
with:
target: .
node-version: 24
fail-on: low
slither-args: --exclude-dependencies
4 changes: 1 addition & 3 deletions .github/workflows/treeage-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,6 @@ on:
permissions:
contents: read

timeout-minutes: 15

concurrency:
group: treeage-ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
Expand All @@ -26,6 +24,7 @@ jobs:
test:
name: TreeAge / Node 22 / compile + test
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: treeage-hardhat
Expand All @@ -36,7 +35,6 @@ jobs:
uses: actions/setup-node@v4
with:
node-version: '22.x'
cache: false
- name: Verify Node and npm versions
run: |
node --version
Expand Down
114 changes: 106 additions & 8 deletions .wordlist
Original file line number Diff line number Diff line change
@@ -1,19 +1,117 @@
ABI
ACDT
API
APIs
AgentExecutor
AgentKit
BLS
BN
Barz
BarzAdapter
BarzDeploymentAdapter
BarzFactory
BaseSepolia
BaseMainnet
BaseAgentVault
TreeAge
TreeAgeCalculator
AgentExecutor
PAYMASTER_ADDRESS
ABI
BaseMainnet
BaseSepolia
Besu
BlobAndProofV
BlobCellsAndProofsV
BlobsBundleV
CDP
CLI
ChatGPT
ClientVersionV
EIP
EIPs
EL
EOA
EOA's
ERC
ETH
EVM
EthCapabilities
EthCapabilitiesDeleteStrategy
EthCapabilitiesEffectiveResource
EthCapabilitiesHead
EthSimulateBlockResultSingleSuccess
EthSimulatePayload
EthSimulateResult
ExecutionPayloadBodyV
FP
ForkchoiceStateV
ForkchoiceUpdatedResponseV
Getter
GraphQL
Gwei
IPC
JSON
JWT
KZG
MSM
MUL
Merkle
Multisig
PAYMASTER_ADDRESS
PREDEPLOY
PRs
PayloadAttributesV
PayloadStatusV
RLP
RPC
RestrictedPayloadStatusV
SDK
SHA
SLOAD
SSZ
Sepolia
TreeAge
TreeAgeCalculator
UI
UUPS
WS
WithdrawalV
ZK
ZkExecutionErrors
arg
besu
buildBlockV
env
barz
erigon
eth
ethereumJS
forkchoiceUpdatedV
forkchoiceupdatedv
getBlobsV
getClientVersionV
getInclusionListV
getPayloadBodiesByHashV
getPayloadBodiesByRangeV
getinclusionlistv
getpayloadbodiesbyhashv
getpayloadbodiesbyrangev
https
ipc
js
mainnet
mempool
merkle
multisig
npm
onchain
paymaster
pre
prevRandao
pyspelling
randao
secp
sha
simulateV
smart
src
teku
txs
txt
uint
vm
wallet
yParity
21 changes: 13 additions & 8 deletions contracts/Paymaster.sol
Original file line number Diff line number Diff line change
Expand Up @@ -121,14 +121,15 @@ contract Paymaster {
// ========== ERC20 receiving ==========

/// Receive tokens from caller. Caller must approve this contract first.
function receiveToken(address token, uint256 amount) external {
function receiveToken(address token, uint256 amount) external nonReentrant {
require(token != address(0), "Invalid token address");
require(amount > 0, "Amount must be greater than 0");

_safeTransferFrom(token, msg.sender, address(this), amount);

// Effects first. If the token call fails, the whole transaction (including this state/event) reverts.
tokenBalances[token][msg.sender] += amount;
emit ReceivedToken(msg.sender, token, amount);

_safeTransferFrom(token, msg.sender, address(this), amount);
}

/// Allow a user to claim their recorded token balance; tokens are sent to the fixed PAYMASTER_ADDRESS.
Expand All @@ -152,22 +153,26 @@ contract Paymaster {
// Approvals and paymaster funding are owner-managed.

/// Approve a spender for a specific token with max allowance (owner only)
function approveSpender(address token, address spender) external onlyOwner {
function approveSpender(address token, address spender) external onlyOwner nonReentrant {
require(token != address(0), "Invalid token address");
require(spender != address(0), "Invalid spender address");

_safeApprove(token, spender, MAX_ALLOWANCE);

// Record effects before the external token call; a failed approval reverts these changes.
spenderAllowances[token][spender] = MAX_ALLOWANCE;
emit SpenderApproved(token, spender, MAX_ALLOWANCE);

_safeApprove(token, spender, MAX_ALLOWANCE);
}

/// Approve the fixed PAYMASTER_ADDRESS to spend contract-held tokens (owner only)
function approvePaymasterForToken(address token) external onlyOwner {
function approvePaymasterForToken(address token) external onlyOwner nonReentrant {
require(token != address(0), "Invalid token address");
_safeApprove(token, PAYMASTER_ADDRESS, MAX_ALLOWANCE);

// Record effects before the external token call; a failed approval reverts these changes.
spenderAllowances[token][PAYMASTER_ADDRESS] = MAX_ALLOWANCE;
emit SpenderApproved(token, PAYMASTER_ADDRESS, MAX_ALLOWANCE);

_safeApprove(token, PAYMASTER_ADDRESS, MAX_ALLOWANCE);
}

/// Owner withdraw tokens from contract and send them to the fixed PAYMASTER_ADDRESS
Expand Down
20 changes: 6 additions & 14 deletions foundry.toml
Original file line number Diff line number Diff line change
@@ -1,27 +1,19 @@
recipe = "foundry"
authors = ["moonrager13"]

[profile.default]
solc-version = "0.8.19"
src = "contracts"
out = "out"
libs = ["node_modules"]
solc_version = "0.8.24"
optimizer = true
optimizer_runs = 200
remappings = [
"ds-test/=lib/ds-test/src/",
"forge-std/=lib/forge-std/src/",
]

[profile.default.rpc_endpoints]
[rpc_endpoints]
mainnet = "https://eth-mainnet.g.alchemy.com/v2/${ALCHEMY_KEY}"
sepolia = "https://eth-sepolia.g.alchemy.com/v2/${ALCHEMY_KEY}"
polygon = "https://polygon-mainnet.g.alchemy.com/v2/${ALCHEMY_KEY}"
arbitrum = "https://arb-mainnet.g.alchemy.com/v2/${ALCHEMY_KEY}"

[profile.default.etherscan]
[etherscan]
mainnet = { key = "${ETHERSCAN_API_KEY}", url = "https://api.etherscan.io" }
sepolia = { key = "${ETHERSCAN_API_KEY}", url = "https://api-sepolia.etherscan.io" }
polygon = { key = "${POLYGONSCAN_API_KEY}", url = "https://api.polygonscan.com" }
arbitrum = { key = "${ARBISCAN_API_KEY}", url = "https://api.arbiscan.io" }

[dependencies]
ds-test = { git = "https://github.com/dapphub/ds-test", rev = "cd98eff" }
forge-std = { git = "https://github.com/foundry-rs/forge-std", rev = "2a2ce3c" }
Loading
Loading