Skip to content

feat(passkey): bind passkey session to contract and network (#390) - #454

Merged
karagozemin merged 2 commits into
Sub-Rosa-Issue:mainfrom
nazteeemba:feat/390-bind-passkey-session
Oct 1, 2026
Merged

karagozemin merged 2 commits into
Sub-Rosa-Issue:mainfrom
nazteeemba:feat/390-bind-passkey-session

Conversation

@nazteeemba

@nazteeemba nazteeemba commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

closes #390.

Ensures a passkey session can only commit a bid to the specific contract ID, network passphrase, and account captured when the session was created. If any of these differ from the target SDK client at submit time, submission is rejected and a typed error is surfaced.

Changes

  • SDK Session Binding & Validation:

    • Defined PasskeySessionBinding and SessionBindingTarget in @sub-rosa/sdk.
    • Added validatePasskeySession() to verify contract ID, network passphrase, and account before simulation or submission.
    • Added session to SubRosaClientConfig and CommitParams.
    • Enforced session validation in SubRosaClient.commit() and SubRosaClient.preflightCommit().
    • Exported typed SubRosaSessionMismatchError (subclassing SubRosaNetworkMismatchError).
    • Added automatic secret seed redaction (/\bS[A-Z2-7]{55}\b/g) to prevent private keys/seeds from leaking in mismatch errors.
    • Updated SDK public API snapshot with all new exports.
  • Web App Session Management & Verification:

    • Updated passkey-config.ts with createPasskeySession() and safe dual-environment support (import.meta.env / process.env).
    • Added public config mismatch detection between VITE_PASSKEY_CONTRACT_ID / VITE_PASSKEY_NETWORK_PASSPHRASE and contract/network settings in apps/web/src/lib/config.ts.
    • Updated PasskeyPanel.tsx to record session binding upon credential creation / wallet deployment and reject swapped client targets with a typed alert (data-testid="passkey-error").
    • Added secret seed scrubbing to ensure no seed is displayed in the panel or recorded in demo traces (trace-health-check.ts).

Acceptance Criteria

  • A matching session can commit in the fixture test.
  • A swapped contract id does not submit.
  • A swapped passphrase does not submit.
  • The error text does not contain the fixture seed.
  • Validated with web config tests and SDK network mismatch tests.

Test Results

  • SDK tests: 221/221 passing (pnpm sdk:test)
  • SDK typecheck: 0 errors (pnpm sdk:typecheck)
  • Web tests: 108/108 passing (pnpm web:test)
  • Web typecheck: 0 errors (pnpm web:typecheck)
  • Web build: Successful Vite production build (pnpm web:build)

…-Issue#390)

- Record contract ID, network passphrase, and account when passkey session starts
- Refuse commits when contract ID, network passphrase, or account differ from target client
- Surface typed SubRosaSessionMismatchError in passkey panel instead of submitting
- Scrub raw secret seeds from all error text and demo traces
- Add web fixture tests and SDK network mismatch validation tests
@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@nazteeemba Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@karagozemin
karagozemin merged commit 524333b into Sub-Rosa-Issue:main Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bind a passkey session to the contract and network it may commit to

2 participants