Goal
Let a passkey commit a bid only to the contract id and network stored when the passkey session was created.
Why this is High
The passkey panel, the web config, and the SDK client can each be pointed at a different contract. A session opened against testnet must not sign a mainnet commit. The binding has to be checked at submit time.
Requirements
- Record contract id, network passphrase, and account when the passkey session starts.
- Refuse a commit when any of those differ from the current SDK client.
- Surface a typed error in the panel instead of submitting.
- Keep the secret seed out of the error and out of the demo trace.
Acceptance criteria
Pointers
apps/web/src/components/PasskeyPanel.tsx
apps/web/src/passkey-config.ts
apps/web/src/lib/config.ts
packages/sdk/src/client.ts
packages/sdk/src/network.ts
Validation
- Web config tests and an SDK network mismatch test
Drips
- Drips Complexity: High
- Expected Drips Points: 200
- Add this issue from the Drips maintainer dashboard and set complexity to High.
- Do not apply the
Stellar Wave label on GitHub. That path defaults the issue to Trivial (100 points).
Goal
Let a passkey commit a bid only to the contract id and network stored when the passkey session was created.
Why this is High
The passkey panel, the web config, and the SDK client can each be pointed at a different contract. A session opened against testnet must not sign a mainnet commit. The binding has to be checked at submit time.
Requirements
Acceptance criteria
Pointers
apps/web/src/components/PasskeyPanel.tsxapps/web/src/passkey-config.tsapps/web/src/lib/config.tspackages/sdk/src/client.tspackages/sdk/src/network.tsValidation
Drips
Stellar Wavelabel on GitHub. That path defaults the issue to Trivial (100 points).