Skip to content

Add strict mutation request policies - #121

Draft
csmithington wants to merge 2 commits into
joshstevens19:masterfrom
usherlabs:upstream/request-policy
Draft

csmithington wants to merge 2 commits into
joshstevens19:masterfrom
usherlabs:upstream/request-policy

Conversation

@csmithington

Copy link
Copy Markdown

Summary

This contributes the generic request-policy layer developed downstream without FIET source values, secrets, fork governance, or locked-build metadata. The final commit is policy-only and is stacked on the transaction-integrity draft #120 (which in turn includes the accepted response contract from #119). It should be rebased as those dependencies are decided.

  • add tagged jwt_hs256 request verification and IPv4/IPv6/CIDR allowlists to network permissions
  • validate schemes, parameters, IP grammar, header names, and referenced non-empty secrets before serving
  • default to socket-peer IP resolution; make trusted X-Forwarded-For explicit and fail closed on malformed values
  • run existing basic/API-key authorization first, then compose matching policies with IP-before-JWT AND semantics
  • protect transaction mutation and signing routes, including deprecated signing aliases, without changing health/read/history/management routes
  • deterministically order random candidates, select only eligible candidates, and preserve the first ordered policy error when none pass
  • fail closed with a sanitized operator error if a previously validated secret disappears at runtime
  • provide an authoritative IP-rule fixture corpus and focused edge-case tests

Validation

  • cargo fmt --all -- --check
  • cargo clippy -- -D warnings -A clippy::uninlined_format_args
  • cargo test --exclude rust-sdk-playground --workspace (73 core tests plus workspace/doc tests)
  • npm run build in documentation/rrelayer

Review notes

The default signature header remains configurable and currently defaults to x-appsmith-signature for compatibility with the deployed downstream integration. All examples use documentation-only addresses and a generic secret environment-variable name.

Persist signed attempt evidence before RPC broadcast, recover ambiguous sends from durable history, and keep nonce and wallet-index state coherent across failures.
Add validated source-IP and HS256 JWT controls to mutation and signing routes while preserving existing authentication and read/management behavior.
@vercel

vercel Bot commented Aug 5, 2026

Copy link
Copy Markdown

@csmithington is attempting to deploy a commit to the joshaavecom's projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant