Skip to content

security: document the fail-open vs fail-closed behavior of every read-only compliance check #463

Description

@Idaonoli

Scope

denylist-gate::check's doc comment explicitly calls out its fail-open risk on TTL archival ("check() would return true... a fail-open footgun"). The other contracts' equivalent read paths (is_allowed, is_permitted_jurisdiction, is_frozen) don't have the same explicit fail-open/fail-closed analysis documented.

Acceptance criteria

  • Audit is_allowed, is_permitted_jurisdiction, is_frozen, and compliance-aggregator/policy-engine's composed checks for their fail-open/fail-closed behavior under storage archival or misconfiguration, and document each explicitly

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programcomplexity: highSignificant design/security surface, deep Soroban knowledge neededdocumentationImprovements or additions to documentationhelp wantedExtra attention is needed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions