Skip to content

fix: validate market IDs consistently across entry points - #1434

Open
iBotayo wants to merge 1 commit into
Predictify-org:masterfrom
iBotayo:fix/1389-consistent-market-id-validation
Open

fix: validate market IDs consistently across entry points#1434
iBotayo wants to merge 1 commit into
Predictify-org:masterfrom
iBotayo:fix/1389-consistent-market-id-validation

Conversation

@iBotayo

@iBotayo iBotayo commented Aug 31, 2026

Copy link
Copy Markdown

Consistently validate market IDs across entry points

Closes #1389

Summary

This PR ensures market IDs are validated consistently across all relevant contract entry points.

The implementation establishes a canonical validation flow using the existing market state model while preserving authorization checks, public interfaces, lifecycle rules, and existing error semantics.

Root Cause

Market-ID validation was inconsistent across relevant entry points. Different paths could handle market lookup, nonexistent IDs, invalid inputs, and repeated operations differently, creating potential for inconsistent behavior and unsafe state transitions.

Implementation

This change:

  • Applies consistent market-ID validation across affected entry points.
  • Uses the existing market storage and error model where possible.
  • Ensures validation occurs before state mutation.
  • Preserves existing authorization requirements.
  • Prevents invalid/nonexistent IDs from causing unintended state changes.
  • Preserves existing public interfaces.
  • Documents important validation and state-transition invariants where appropriate.

The implementation is intentionally scoped to #1389 with no unrelated refactors or dependency changes.

Security & State Safety

The affected flows were reviewed for:

  • Invalid and nonexistent market IDs.
  • Unauthorized access.
  • Cross-market state contamination.
  • Duplicate/replayed operations.
  • Partial state mutation on failure.
  • Boundary-value behavior.
  • Deterministic error handling.
  • Storage access behavior for invalid IDs.

Invalid IDs are rejected without modifying unintended market state, while existing authorization and lifecycle protections remain enforced.

Retry & Replay Handling

Relevant state-changing operations are tested for repeated execution to ensure deterministic behavior. Retries or duplicate submissions cannot silently apply the same state transition multiple times or leave the contract in an inconsistent state.

Compatibility

No public interfaces were changed. Existing callers using valid market IDs remain compatible with the affected entry points.

Tests

Focused regression coverage includes:

  • Valid market IDs.
  • Invalid/nonexistent market IDs.
  • Relevant boundary cases.
  • Duplicate/replayed operations.
  • Cross-market isolation.
  • Authorization failures.
  • Relevant failure/retry scenarios.
  • Existing market lifecycle regressions.

Validation

The following checks were run against the final implementation:

  • cargo fmt --check
  • cargo clippy --all-targets --all-features -- -D warnings
  • cargo test
  • Focused tests for affected market-ID functionality

Acceptance Criteria

The implementation provides deterministic validation behavior, preserves authorization and state-transition invariants, handles retries and replay safely, maintains caller compatibility, and provides focused regression coverage for normal and adverse cases.

@drips-wave

drips-wave Bot commented Aug 31, 2026

Copy link
Copy Markdown

@iBotayo Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Quality-2][High] Validate market IDs consistently across entry points

1 participant