Add flash loan manipulation guards#401
Open
TUPM96 wants to merge 1 commit into
Open
Conversation
|
@TUPM96 is attempting to deploy a commit to the smartdevs17's projects Team on Vercel. A member of the Team first needs to authorize it. |
6 tasks
Smartdevs17
pushed a commit
that referenced
this pull request
May 28, 2026
…actor, event schema standardization (#415) * feat(upgrade): add 48h standard and 4h emergency timelocks with multisig - Add STANDARD_TIMELOCK_SECS (48h) and EMERGENCY_TIMELOCK_SECS (4h) constants - Add TimelockNotElapsed and StorageLayoutMismatch error variants - Add TimelockQueued stage to UpgradeStage enum - Add execute_after and is_emergency fields to UpgradeProposal and UpgradeStatus - Add upgrade_queue_timelock() to start the standard 48h countdown post-approval - Add upgrade_propose_emergency() for 4h emergency path (admin only) - Enforce timelock in upgrade_execute() — rejects before execute_after elapses - Add UpgradeTimelockQueuedEvent and UpgradeEmergencyProposedEvent to events - Update all tests to go through queue_and_execute() helper for correct flow * feat(flash-loan): add TWAP price manipulation detection and attack prevention - Add ManipulationConfig with pool liquidity cap (50%), price impact limit, TWAP deviation threshold, and concurrent loan detection - Add TwapAccumulator/TwapState structs with time-windowed price sampling - Add check_twap_deviation(), check_liquidity_cap(), check_price_impact() - Add per-asset AssetLoanGuard to block concurrent flash loans (sandwich prevention) - Update flash_loan() signature to accept spot_price for TWAP checks - Add flash_record_price() and set_flash_manipulation_config() entrypoints - Apply same attack guards to hello-world flash_loan module - Update all tests to use new flash_loan() signature with spot_price - Add tests for liquidity cap, price impact, and TWAP deviation blocking Closes #379, #401 * feat(api): add DTO layer with structured validation for all endpoints - Add api/src/dto/ directory with TypeScript DTO classes - base.dto.ts: FieldError, ValidationResult, helper validators (isValidStellarAddress, isValidAmount, isOptionalString), MAX_I128 constant - lending.dto.ts: LendingOperationDto, PrepareRequestDto, SubmitRequestDto, RelayDelegatedDto, PrepareResponseDto, TransactionResponseDto — all with static validate() and fromBody()/fromQuery() factories + JSDoc/OpenAPI schemas - subscription.dto.ts: CreateSubscriptionDto covering all subscription fields - pagination.dto.ts: PaginationQueryDto with configurable max-limit - dto/index.ts: barrel re-export - middleware/validation.ts: add DTO-based middleware variants (validateLendingOperationDto, validatePrepareDto, validateSubmitDto, validateRelayDelegatedDto, validateCreateSubscriptionDto, validatePaginationDto) that attach typed DTOs to req for use in controllers — existing express-validator chain preserved Closes #362 * feat(events): standardize event schemas across all contracts AMM (amm.rs): - Add explicit topics attributes: amm_swap, amm_liq_add, amm_liq_rm, amm_op, amm_cb_valid - Add timestamp: u64 field to SwapExecutedEvent, LiquidityAddedEvent, LiquidityRemovedEvent, CallbackValidatedEvent (AmmOperationEvent already had it) - Update all emit helper functions to pass env.ledger().timestamp() Bridge (bridge.rs): - Add explicit topics attributes: br_reg, br_fee, br_active, br_dep, br_wdraw, br_pause, br_val_upd, br_sec_cfg, br_slash, br_ch_emrg, br_anomaly - Add timestamp: u64 to all 11 bridge event structs (previously none had it) - Update all emit call sites to include timestamp Docs: - Add docs/event-schema.md: mandatory fields spec, topic naming conventions, per-contract event catalogue, backward-compat note, PR checklist CI: - Add scripts/check_event_schema.sh: detects contractevent structs missing the required timestamp field; warns on missing explicit topics Closes #356, #408
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #379
Summary
Tests