fix: validate market IDs consistently across entry points - #1434
Open
iBotayo wants to merge 1 commit into
Open
Conversation
|
@iBotayo Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Consistently validate market IDs across entry points
Closes #1389
Summary
This PR ensures market IDs are validated consistently across all relevant contract entry points.
The implementation establishes a canonical validation flow using the existing market state model while preserving authorization checks, public interfaces, lifecycle rules, and existing error semantics.
Root Cause
Market-ID validation was inconsistent across relevant entry points. Different paths could handle market lookup, nonexistent IDs, invalid inputs, and repeated operations differently, creating potential for inconsistent behavior and unsafe state transitions.
Implementation
This change:
The implementation is intentionally scoped to #1389 with no unrelated refactors or dependency changes.
Security & State Safety
The affected flows were reviewed for:
Invalid IDs are rejected without modifying unintended market state, while existing authorization and lifecycle protections remain enforced.
Retry & Replay Handling
Relevant state-changing operations are tested for repeated execution to ensure deterministic behavior. Retries or duplicate submissions cannot silently apply the same state transition multiple times or leave the contract in an inconsistent state.
Compatibility
No public interfaces were changed. Existing callers using valid market IDs remain compatible with the affected entry points.
Tests
Focused regression coverage includes:
Validation
The following checks were run against the final implementation:
cargo fmt --checkcargo clippy --all-targets --all-features -- -D warningscargo testAcceptance Criteria
The implementation provides deterministic validation behavior, preserves authorization and state-transition invariants, handles retries and replay safely, maintains caller compatibility, and provides focused regression coverage for normal and adverse cases.