etherspot / etherspot/relayx

Operational risk: RELAYX_STUB_MODE bypasses safety checks in production if mis-set

Open
#40 0 comments 0 reactions 0 assignees View on GitHub
documentation rust
Dominant language
Rust
Stars
0
Forks
1
PR merge metrics
No merged PRs in 30d

Description

## Summary

When `RELAYX_STUB_MODE` is enabled, `stub_mode_enabled()` short-circuits RPC calls and returns synthetic data (`src/utils/misc.rs`, `src/provider/tx.rs`, `fee_data.rs`, etc.).

## Risk

A single mis-set environment variable in production causes **fake hashes**, **skipped balance checks**, and **non-authoritative fee data**, which is dangerous for funds and incident response.

## Suggested mitigations

- Log a highly visible warning at startup when stub mode is on.
- Optionally refuse to start unless `RELAYX_ALLOW_STUB_IN_PRODUCTION=true` is also set.

## References

- `src/utils/misc.rs` (`stub_mode_enabled`)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.