Reject counter documents that omit recovery state
This commit is contained in:
@@ -387,7 +387,6 @@ async fn write_seed(data_dir: &Path, mnemonic: &bip39::Mnemonic, source: SeedSou
|
||||
#[derive(Debug, Default, Serialize, Deserialize)]
|
||||
struct StoredCounters {
|
||||
/// keyset id → next unused counter.
|
||||
#[serde(default)]
|
||||
counters: BTreeMap<String, u32>,
|
||||
}
|
||||
|
||||
@@ -849,7 +848,7 @@ mod tests {
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
fs::create_dir_all(dir.path().join("wallet")).await.unwrap();
|
||||
let path = dir.path().join(COUNTER_FILE);
|
||||
for damaged in ["", " ", "{ truncated"] {
|
||||
for damaged in ["", " ", "{ truncated", "{}", "{\"counters\":null}"] {
|
||||
fs::write(&path, damaged).await.unwrap();
|
||||
assert!(reserve_counters(dir.path(), V1_KEYSET, 1).await.is_err());
|
||||
assert_eq!(fs::read_to_string(&path).await.unwrap(), damaged);
|
||||
|
||||
@@ -104,3 +104,10 @@ Read-only checks found well-shaped seed/counter JSON on dev and Yaya; no secret
|
||||
values were printed and no wallet files were changed by those checks. Production
|
||||
build/deployment of this prerequisite remains pending. Durable initial purchase
|
||||
intent, mint-operation recovery, seller receipt and refund recovery remain open.
|
||||
|
||||
Strict-schema follow-up: an existing counter document must actually contain its
|
||||
counter map. Empty JSON objects and null maps are rejected without modification,
|
||||
not deserialized as a fresh zero state. The full isolated suite again passes
|
||||
1,755tests,0failures,5existing ignored in
|
||||
`/tmp/archy-wallet-recovery-strict-schema-full-tests.log`. No live deployment or
|
||||
claim of complete initial-payment recovery is implied.
|
||||
|
||||
Reference in New Issue
Block a user