Repository navigation
Conversation
TradePanel hardcoded 1% slippage: too tight on fresh launches (avoidable reverts) with no override. Add 0.5/1/3% presets plus custom 0.1-20% input, persisted per chain, wired into minOut and Minimum received. Default stays 1% so existing behavior is unchanged unless the user picks otherwise. New pure module trade-slippage.ts (presets, parse/clamp/format, external- store with server snapshot so hydration never mismatches) with 7 unit tests.
…deRabbit, PR Twigpine#30) parseSlippageInput("0.01") passed validation then clamped to 10bps, silently changing the selection to 0.1%. Reject anything below SLIPPAGE_MIN_BPS so the field keeps the previous value and shows the 0.1-20% hint.
…n errors (PR Twigpine#30) - parseSlippageField rejects minus/letters, normalizes decimal comma to dot - input handler no longer strips chars before parsing (0,5 no longer becomes 5%) - trade captures slippageBps per transaction and passes it to friendlyError
… fallback on preflight fail (PR Twigpine#30 CI) - declare tradeSlippageBps outside try, assign after preflight awaits - catch uses it when set, else default (preflight errors are never slippage reverts)
- sync had no limit despite being the most expensive route (tx-less calls fan out over every chain); 10/min per IP - meta is unsigned by design, so the IP bucket is the only spam defense; 20/min per IP before validation - presence hashes caller-controlled UA into a DB row per variant; 30/min per IP after the bot short-circuit - write-limits.test.ts pins the wiring (429 shape, limit-before-work order)
|
Warning Review limit reachedNext included review available in 59 minutes. View limit detailsLimit details: You’ve used the included review currently available. This review ran on the open-source allowance, not this organization's plan, because the pull request author doesn't have an assigned seat. Waiting won't change this — ask an organization admin to assign them a seat, or add seats in Billing if every seat is already assigned, then retry. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (7)
Comment |
|
@Ayush7614 closing this as already implemented through merged PRs #30 and #37. I checked all seven file patches and resulting file hashes: they match those two PRs exactly, with no additional change to review here. The slippage and rate-limit work was useful and has already landed. This combined copy is now redundant. Please close superseded PRs once their changes are merged, and check current main before opening a replacement. As noted on #41, keep one active PR per fix and put follow-up changes on the existing branch. If something is still missing after #30 and #37, please identify the remaining issue and submit only that difference against current main. |
TradePanel hardcoded 1% slippage (too tight on fresh launches, too loose for large size) and three unauthenticated write routes had no per-IP limits.
This PR:
trade-slippage.ts,TradePanel.tsx): presets 0.5%/1%/3% plus custom 0.1–20% input, per-chain persistence via localStorage, clamping, decimal-comma normalization, validation of raw input (PR feat(trade): user slippage control with per-chain persistence #30: minus/letters not stripped to valid, comma → dot), external store with server snapshot so hydration matches. Quote andMinimum receiveduse the selected bps; errors surface the actual slippage viafriendlyError({slippagePct}). 8 unit tests intrade-slippage.test.ts(presets, clamp, parseSlippageInput/Field, format, storage key, bounds, external store).api/launch/sync|meta|presence): per-IP token-bucket via sharedrateLimitedineditServer.ts— sync 10/min (most expensive, fans out over chains), meta 20/min (unsigned, only spam defense), presence 30/min (UA-controlled hash would mint rows per rotated UA). Limits run before any DB/RPC work and return 429slow downlike sibling routes; presence keeps bot short-circuit before the bucket, sync keeps 400 shape validation. 5 structural tests inwrite-limits.test.tspin the wiring and order.Verified on upstream/main base: