Skip to content

feat: enforce identity and add broadcast consts - #85

Merged
GabrielePicco merged 2 commits into
mainfrom
feat/enforce-identity-add-broadcast
Sep 5, 2025
Merged

GabrielePicco merged 2 commits into
mainfrom
feat/enforce-identity-add-broadcast

Conversation

@GabrielePicco

@GabrielePicco GabrielePicco commented Sep 5, 2025 •

Copy link
Copy Markdown
Contributor

feat: enforce identity and add broadcast consts

Status Type ⚠️ Core Change Issue
Ready Feature No -

Description

  • Enforce committing identity
  • Add broadcast consts (custom case in the SDK)

Greptile Summary

Updated On: 2025-09-05 13:36:34 UTC

This PR introduces two key changes to the delegation program: identity enforcement and a new broadcast constant. The main security enhancement is in src/processor/commit_state.rs, where the code now validates that only authorized validators can commit state changes for delegated accounts. The validation checks that the validator making the commit either matches the delegation record's authority field or that no specific authority was set (using Pubkey::default()). If an unauthorized validator attempts to commit, the operation fails with DlpError::InvalidAuthority.

Additionally, the PR adds a new constant BROADCAST_IDENTITY in src/consts.rs with the pubkey "Broadcast1111111111111111111111111111111111". This constant appears to be a special placeholder identity used for broadcast operations in the SDK, following the same pattern as the existing DEFAULT_VALIDATOR_IDENTITY constant.

These changes fit into the broader delegation system by strengthening access control - previously any validator could commit state for any delegated account, which was a potential security vulnerability. The new authority check ensures proper ownership validation while maintaining backward compatibility for delegations without explicit authorities set. The broadcast identity provides the SDK with a standardized way to handle special broadcast cases where a specific validator identity may not be applicable.

Confidence score: 4/5

  • This PR introduces important security improvements with minimal risk of breaking existing functionality
  • Score reflects solid implementation of authority validation with proper error handling and logging
  • Pay close attention to the commit_state.rs logic to ensure the authority validation covers all edge cases

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 files reviewed, 1 comment

Edit Code Review Bot Settings | Greptile

Comment thread src/consts.rs
@GabrielePicco
GabrielePicco merged commit 1f74c71 into main Sep 5, 2025
3 checks passed
@GabrielePicco
GabrielePicco deleted the feat/enforce-identity-add-broadcast branch September 5, 2025 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant