[Emergency Release] v1.22.27 - #965
Merged
Merged
Conversation
#964) (#966) When a classic asset was sent to a contract (C...) address, the Soroban transfer used `recipientAddress` as the invocation target. The token contract is a property of the asset, so this invoked whichever contract the destination address pointed at and moved the asset that contract governs rather than the selected one. The amount was also always scaled by the selected asset's decimals, which the invoked contract then reinterpreted with its own. Derive the target from the asset instead: its Stellar Asset Contract address, which follows deterministically from (code, issuer, network passphrase). Native XLM and custom Soroban tokens already resolved correctly and are unchanged. Also drop the surrounding try/catch, whose handler re-dispatched on `isCustomToken` inside a branch where it is provably false, and add a guard refusing to send a token to its own contract address — such a transfer is credited to an address with no spender. Tests cover all three branches so they cannot be transposed again. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
iOS Simulator preview build is ready: https://github.com/stellar/freighter-mobile/releases/tag/untagged-667a0c62a752bc54748a (SDF collaborators only — install instructions in the release description) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(send): derive the token contract from the asset (#966)