Note allowlist for public accounts
- Vorherrschende Sprache
- Rust
- Sterne
- 132
- Forks
- 167
- Ø Merge
- 1 T. 23 Std.
- Gemergte PRs (30 T.)
- 110
Beschreibung
Public accounts can currently be targeted by third-party executors with arbitrary input notes. We already enforce a note allowlist for network accounts, so extending the same mechanism to ordinary public accounts would let an owner restrict which notes can ever be applied to their account.
Proposal:
- Provide a note-allowlist auth component (conceptually close to `AuthSingleSigAcl`, but keyed on note scripts rather than account procedures) that public accounts can install.
- The allowlist must also cover the transaction script, so that a caller cannot bypass it by invoking account procedures directly from it (same requirement we already have for network accounts).
- It should still allow the owner to run tx-script transactions (e.g. to change account config).
_Originally posted by @bobbinth in [#2964](https://github.com/0xMiden/protocol/issues/2964#issuecomment-4513731052)_
Sub-issue of #2964
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.