FilOzone / FilOzone/filecoin-cloud

No validation for network configuration JSON (contract addresses, duplicate active versions, schema)

Open
#48 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
4
Forks
10
Avg merge
1h 1m
Merged PRs (30d)
1

Description

## Problem
The network configuration JSON (containing calibration/mainnet networks with contract deployments) has no validation layer, which could lead to runtime errors or deployment issues.

## Missing Validations

### 1. Contract Address Format Validation
No checks that contract addresses are:
- Properly formatted (valid hex, correct length)
- Properly checksummed (EIP-55 format)
- Actually valid Ethereum/Filecoin addresses

Example from current config:
```json
"implementation": "0x88449EcAd119B6c05fa5eFB18C80d86d5781fc10"
```
There's no validation that these addresses are valid before the app tries to use them.

### 2. Multiple Active Versions
No validation to prevent multiple versions with `"status": "active"` within the same network. This could cause ambiguity about which contract version should be used.

Example risk:
```json
"versions": [
{
"version": "v0.1.0",
"status": "active", // ❌ First active version
...
},
{
"version": "v1.0.0",
"status": "active", // ❌ Second active version - which one is used?
...
}
]
```

### 3. Schema Validation
No validation for:
- Required fields (chainId, rpcUrl, contracts, etc.)
- Valid status values (should be enum: "active" | "inactive" | "testing")
- Nested contract structure completeness
- Type correctness at runtime

### 4. Business Logic Validation
No checks for:
- At least one active version per network
- Valid version format (semantic versioning)
- Valid URLs (rpcUrl, explorerUrl, linkToRelease)
- chainId matches network name expectations (314 for mainnet, 314159 for calibration)

## Current Risks

**Risk 1:** Invalid address format
```json
"proxy": "0xINVALID" // No validation, app crashes at runtime
```

**Risk 2:** Two active versions
```json
"calibration": {
"versions": [
{ "status": "active", ... },
{ "status": "active", ... } // Which contracts does the app use?
]
}
```

**Risk 3:** Missing required fields
```json
{
"version": "v1.0.0",
// Missing "status" field - no validation
"contracts": { ... }
}
```

## Suggested Solution: Zod Schema
```typescript
import { z } from 'zod'
import { isAddress } from 'viem'

const ContractSchema = z.object({
implementation: z.string().refine(isAddress, 'Invalid address'),
proxy: z.string().refine(isAddress, 'Invalid address'),
stateView: z.string().refine(isAddress, 'Invalid address').optional(),
// ...
})

const VersionSchema = z.object({
version: z.string().regex(/^v\d+\.\d+\.\d+$/),
status: z.enum(['active', 'inactive', 'testing']),
isNew: z.boolean(),
linkToRelease: z.string().url().or(z.literal('')),
contracts: z.object({
warmStorage: ContractSchema,
serviceProviderRegistry: ContractSchema,
})
})

const NetworkSchema = z.object({
name: z.string(),
rpcUrl: z.string().url(),
chainId: z.number(),
explorerUrl: z.string().url(),
versions: z.array(VersionSchema)
.refine(
(versions) => versions.filter(v => v.status === 'active').length <= 1,
'Only one version can be active'
)
})
```

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.