Skip to content

fix: validate order identifiers and test public position flows - #110

Merged
kartojal merged 1 commit into
mainfrom
fix/validate-order-identifiers
Sep 25, 2026
Merged

kartojal merged 1 commit into
mainfrom
fix/validate-order-identifiers

Conversation

@kartojal

@kartojal kartojal commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Reject ambiguous or malformed order identifiers at runtime before metadata requests or signing. Inputs such as { tokenID: "123", positionID: null }, both IDs, neither ID, and null/blank/non-string IDs now fail with a clear error. An omitted or undefined unused identifier remains valid.

Add public limit and market order tests with real signing and mocked HTTP. They cover automatic V3 signing, V1/V2 overrides still routing positions to V3, position-based tick/fee/book lookups, balance adjustment, and the complete posting payload with the position in tokenId. Token order version selection remains unchanged.

Validation: 355 tests pass; Biome, ESM/CJS build with declarations, TypeScript --noEmit, and diff checks pass. The new validation regressions failed before the fix. HTTP is mocked; no live orders were submitted.


Note

Medium Risk
Stricter runtime validation can break callers that previously passed ambiguous or malformed IDs; order creation paths are affected but behavior for valid inputs is preserved.

Overview
Order identifier validation is tightened in resolveOrderAssetID: callers must supply exactly one of tokenID or positionID as a non-empty string. Ambiguous or bad inputs (both set, neither set, null, blank/whitespace-only, or non-string values) now throw a clear error before metadata fetches, signing, or HTTP posts. An omitted/undefined unused field still works as before.

Tests add unit coverage for the new validation on both resolveOrderAssetID and resolveOrderRouting, plus integration-style client tests for public limit/market position orders (real signing, mocked HTTP): Exchange V3 signing regardless of version override, position-based tick/fee/book lookups, balance-adjusted amounts, full /order payload with the position in tokenId, early rejection without side effects, and unchanged token-order version routing.

Reviewed by Cursor Bugbot for commit a57923e. Bugbot is set up for automated code reviews on this repo. Configure here.

@kartojal
kartojal requested a review from a team as a code owner September 25, 2026 15:00
@kartojal
kartojal merged commit 8046a89 into main Sep 25, 2026
5 checks passed
@kartojal
kartojal deleted the fix/validate-order-identifiers branch September 25, 2026 15:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants