Skip to content

Optional token_server_url config is unconditionally unwrapped in deposit token check #19

Description

@Rob1Ham

Component: server/src/endpoints/deposit.rs (check_token_status, ~L212)
Severity: Low (reliability; 500 on a legitimate config)

Summary

ServerConfig::load treats token_server_url as optional (get_optional_env_or_config), but check_token_status unwraps it unconditionally:

let request = client
    .get(format!(
        "{}/token/token_verify/{}",
        config.token_server_url.as_ref().unwrap(),
        token_id
    ))

This runs when a deposit arrives with a token that isn't yet confirmed in the Mercury DB (i.e., every token-server deployment where the token confirmation races the deposit). With token_server_url unset, the request handler panics and Rocket returns a 500.

Suggested direction

When token_server_url is None, either treat the token check as not-configured (fail closed with a clear error, or skip the upstream check if that's the intended mode), instead of panicking.

Found during security review of feature/bip448-web-wallet-mutinynet @ 64d2423.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions