Skip to content

Mobile app bypasses the on-chain globe-wallet contract's spend-limit and asset-whitelist enforcement entirely #51

Description

@ndii-dev

sendPayment() in src/services/stellar.ts submits raw Stellar Operation.payment transactions directly against Horizon, with no interaction whatsoever with the Orbit-Wal/contract repo's globe-wallet Soroban contract, which implements per-user daily spend limits and an asset whitelist (record_spend, get_assets). This means any protection the contract layer is meant to provide (e.g. a user-configured daily cap intended to limit blast radius of a compromised device) provides zero actual protection today, because the mobile client never routes payments through it — the enforcement exists on paper in a different repo and nowhere in the actual signing path.

Definition of done:

  • Documented decision: should ordinary payments route through the Soroban contract (adding complexity/fees) or should the contract's spend-limit only apply to a specific class of managed/custodial flows — this needs an explicit answer, not silent divergence
  • If routing through the contract is the right answer, a Soroban RPC client integration added to src/services/
  • If it's not, the contract repo's spend-limit feature's actual scope/purpose needs to be re-documented so it stops implying protection the mobile app doesn't provide

Before opening a PR for this issue, read CONTRIBUTING.md.

This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:

  • Root cause / design-decision rationale in your own words — not a restatement of this issue
  • Every Definition of done bullet above addressed explicitly, with a one-line note on how
  • Evidence the code actually runs: pasted test/build output, a screen recording or before/after screenshots for UI changes, or real (non-mocked) logs for network/contract-facing work
  • New or updated tests included and shown passing (paste the output)
  • Any adjacent/related behavior this issue calls out re-verified, not assumed unaffected

PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.

Metadata

Metadata

Assignees

No one assigned

    Labels

    GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions