Restore authoritative receipt consensus time for scoped keys - #92
Merged
Conversation
When /api/time/block rejects a logging-only key, read the same immutable block keylessly, validate its metadata, and preserve strict failure semantics for malformed upstream data. Constraint: Logging-scoped keys receive HTTP 401 from /api/time/block while /searchAssetFromChain is public. Rejected: Falling back to mutable ledger timestamps | they are not authoritative block time Confidence: high Scope-risk: narrow Directive: Keep this fallback keyless and limited to scoped-route authentication failures. Tested: npm run build; npm test; targeted getBlock and completeReceipt tests; live block 1742929 read through the fallback Not-tested: Cloud Run deployment; npm audit still reports 1 low, 3 moderate, and 2 high pre-existing advisories
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Logging-scoped credentials can anchor receipts but receive HTTP 401 from
/api/time/block. The immutable public/searchAssetFromChainresponse already carries the authoritative block time, so receipts could remain confirmed whileconsensusTimestayed null forever.What
The immutable on-chain verification path is unchanged, and the fallback never sends
x-api-key.Verification
AuthError; permissive timestamp validation failed to reject"1"getBlock/completeReceipttests passnpm run buildnpm test1742929through an intentionally invalid scoped key returned the expected public immutable block timenpm audit --audit-level=lowstill reports the repository baseline of 1 low, 3 moderate, and 2 high advisories; this PR changes no dependency or lockfileNo deploy is included in this PR.