Component: server/src/endpoints/deposit.rs (check_token_status, ~L212)
Severity: Low (reliability; 500 on a legitimate config)
Summary
ServerConfig::load treats token_server_url as optional (get_optional_env_or_config), but check_token_status unwraps it unconditionally:
let request = client
.get(format!(
"{}/token/token_verify/{}",
config.token_server_url.as_ref().unwrap(),
token_id
))
This runs when a deposit arrives with a token that isn't yet confirmed in the Mercury DB (i.e., every token-server deployment where the token confirmation races the deposit). With token_server_url unset, the request handler panics and Rocket returns a 500.
Suggested direction
When token_server_url is None, either treat the token check as not-configured (fail closed with a clear error, or skip the upstream check if that's the intended mode), instead of panicking.
Found during security review of feature/bip448-web-wallet-mutinynet @ 64d2423.
Component:
server/src/endpoints/deposit.rs(check_token_status, ~L212)Severity: Low (reliability; 500 on a legitimate config)
Summary
ServerConfig::loadtreatstoken_server_urlas optional (get_optional_env_or_config), butcheck_token_statusunwraps it unconditionally:This runs when a deposit arrives with a token that isn't yet confirmed in the Mercury DB (i.e., every token-server deployment where the token confirmation races the deposit). With
token_server_urlunset, the request handler panics and Rocket returns a 500.Suggested direction
When
token_server_urlisNone, either treat the token check as not-configured (fail closed with a clear error, or skip the upstream check if that's the intended mode), instead of panicking.Found during security review of
feature/bip448-web-wallet-mutinynet@ 64d2423.