0xMiden / 0xMiden/protocol

Note allowlist for public accounts

未關閉
#3,067 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
standards
主要語言
Rust
星號
132
分支
167
平均合併
1 天 23 小時
30 天內合併 PR
110

描述

Public accounts can currently be targeted by third-party executors with arbitrary input notes. We already enforce a note allowlist for network accounts, so extending the same mechanism to ordinary public accounts would let an owner restrict which notes can ever be applied to their account.

Proposal:
- Provide a note-allowlist auth component (conceptually close to `AuthSingleSigAcl`, but keyed on note scripts rather than account procedures) that public accounts can install.
- The allowlist must also cover the transaction script, so that a caller cannot bypass it by invoking account procedures directly from it (same requirement we already have for network accounts).
- It should still allow the owner to run tx-script transactions (e.g. to change account config).

_Originally posted by @bobbinth in [#2964](https://github.com/0xMiden/protocol/issues/2964#issuecomment-4513731052)_

Sub-issue of #2964

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。