Repository navigation
fix(api): stop leaking wallet address in /policies query string (#525) - #628
Merged
nonsobethel0-dev merged 2 commits intoSep 23, 2026
Conversation
fetchUserPolicies sent the wallet as ?wallet=..., leaking the address into server/proxy access logs and browser history. The backend already resolves the wallet from the JWT and ignores this param (backend Parashield-Protocol#345), so drop it and the now-unused argument; usePolicies still gates the fetch on a connected wallet. Closes Parashield-Protocol#525
Add a regression test that fetchUserPolicies is called with no wallet argument, and key the stale-wallet test's pending requests by the wallet active at call time instead of the removed argument. Refs Parashield-Protocol#525
|
@springswell Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
❌ Deploy Preview for boisterous-sunshine-dd4c4c failed.
|
nonsobethel0-dev
merged commit Sep 23, 2026
3e5d502
into
Parashield-Protocol:main
0 of 5 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
fetchUserPoliciesinsrc/lib/api.tssent the connected wallet as a query parameter:GET /policies?wallet=G.... Query strings get written to server and proxy access logs and to browser history, so the user's Stellar address leaked in plaintext.Why the param can simply be removed
The backend already ignores it. In
parashield-backend/src/policy/policy.controller.ts,getMyPoliciesonly readspageandlimitfrom the query string and resolves the wallet from the authenticated request (req.user?.walletAddress || req.wallet):The axios client already attaches
Authorization: Bearer <token>to every request, so removing the param changes nothing on the backend. It also doesn't need moving to a body or a header.Changes
Commit 1: fix
src/lib/api.ts:fetchUserPolicies()takes no argument and callsGET /policieswith no query string. Added a doc comment explaining why.src/hooks/usePolicies.ts: callsfetchUserPolicies(). It still skips fetching while no wallet is connected, and still refetches or aborts when the wallet changes.Commit 2: tests (
src/__tests__/usePolicies.test.tsx)fetchUserPoliciesis called with no arguments.Testing
usePolicy > refetch allows manual refresh independent of id changes. It also fails onmainwithout this change, and it testsusePolicy, not the code changed here.src/lib/__tests__/api.test.tsalso fails onmainbefore any of these changes (Cannot read properties of undefined (reading 'interceptors')). That is unrelated.tsc --noEmitreports no errors in the changed files.Out of scope / follow-up
fetchUserClaimsalso sends?wallet=. The backend'sGET /claimsstill requires that param (@Query('wallet'), with a 403 if it doesn't match the JWT), so removing it on the frontend alone would break claims. That needs a coordinated backend change first, like [Perf] Home page re-renders all product cards on every search keystroke despite debounce #345 for policies.fetchChallenge(/auth/challenge?wallet=) runs before authentication, so there is no JWT to take the wallet from.Closes [security] Wallet address passed as query parameter in fetchUserPolicies #525
Closes [ux] Export dropdown doesn't close on outside click when button is inside a scrollable container #524
Closes [perf] useClaims hook creates new AbortController on every refetch call #527
Closes [bug] ErrorBoundary fallback doesn't receive error details #526