fix: protect linked-account flows across wallet session expiry - #932
Merged
greatest0fallt1me merged 1 commit intoAug 30, 2026
Conversation
|
@Adedoyinjr is attempting to deploy a commit to the Jagadeesh B's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
@Adedoyinjr Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
# Conflicts: # hooks/useTransaction.hook.ts # hooks/useWallet.hook.ts
Adedoyinjr
force-pushed
the
fix/903-linked-account-session-expiry
branch
from
August 29, 2026 14:29
78dfa19 to
6dc39bf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #903
Summary
Hardens the existing linked-wallet flow against stale wallet sessions, identity changes, overlapping operations, duplicate submissions, stale callbacks, invalid persisted state, and unsafe transaction retries.
This change is intentionally scoped to the wallet-session boundary currently implemented by the frontend.
Implementation
WalletProvider.LinkedAccountsandWalletModal.connectWallet,disconnectWallet, andsignTransactioninterfaces with additive result/state fields.Acceptance criteria
Deterministic behavior
Authorization and validation boundaries
Retries, partial failure, and concurrency
Focused tests
Added coverage for:
Focused result:
Compatibility
Existing public wallet APIs remain compatible:
connectWallet(walletId)disconnectWallet()signTransaction(xdr)New state and result fields are additive.
Error handling and observability
Repository authentication limitation
The current frontend does not contain an application authentication/session provider, authenticated linked-account API mutation, OAuth callback flow, JWT/cookie handling, or linked-account 401/403 flow.
This change therefore does not claim server-side authorization guarantees the frontend cannot provide. It hardens the actual wallet-session boundary that exists today without introducing fake authentication or backend behavior.
Validation
Focused #903 tests:
Changed-file ESLint:
Repository-wide validation is currently blocked by existing unrelated upstream failures:
pnpm type-check: existing syntax errors in unrelated filespnpm lint: existing unrelated parse/lint errorspnpm test: existing unrelated failing suitespnpm validate: stops at the existing type-check failuresNo unrelated validation rules or tests were weakened.
Closes #903