Skip to content

[High] SEP-10-Style Challenge Authentication for Solvers with Short-Lived JWTs #442

Description

@james2177

Description:
Implement a challenge–response login where solvers sign a server-issued Stellar transaction challenge (SEP-10 compatible) and receive a short-lived JWT used for REST and WS authentication.

Problem Statement & Context:
Solver actions are authenticated per-request with message signatures, and WS connections are anonymous. There is no session concept, which prevents per-solver WS channels, capability filtering, and scoped rate limits.

Scope & Acceptance Criteria:

  • GET /api/v1/auth/challenge?account= and POST /api/v1/auth/token per SEP-10 (home domain, web_auth_domain, nonce, 5-min time bounds).
  • JWT (EdDSA) with sub, role: solver|user|admin, 15-min expiry; refresh via re-challenge.
  • WS accepts the token during handshake (subprotocol or first message) and binds identity to the connection.
  • Existing signed-message endpoints keep working (backward compatible).
  • Out of scope: user wallets login UX.

Implementation Guidelines:

  1. Key Files/Modules: new src/auth/ module, src/intents/intents.gateway.ts, src/common/stellar-signature.ts.
  2. Design/Architecture: Use WebAuth helpers from @stellar/stellar-sdk; JWT signing key separate from Soroban signer.
  3. Edge Cases/Constraints: Multisig accounts (threshold checks); challenge replay prevention with nonce store.
  4. Testing: Full SEP-10 conformance tests incl. multisig and expired challenges.

Definition of "Done": Common DoD; docs/solver-onboarding.md updated.

Resources:


Common Definition of "Done" (applies in addition to the criteria above):

  • Code written, tested, and documented (TSDoc on public APIs, README/runbook/ADR updates where behaviour changes).
  • All acceptance criteria met; npm run lint, npm run typecheck, npm test, npm run test:e2e pass in CI.
  • PR follows .github/PULL_REQUEST_TEMPLATE, uses a Conventional Commit title (enforced by commitlint), includes test output / metrics screenshots, and references the issue.
  • New env vars are added to .env.example variants and src/config/env.validation.ts (the check:env-drift script must pass).
  • Reviewed and approved by at least one CODEOWNER.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Stellar WaveIssues in the Stellar wave program

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions