Skip to content

Require signed auth for Otto trading writes#33

Open
lawyered0 wants to merge 1 commit intoJejuNetwork:mainfrom
lawyered0:codex/otto-auth
Open

Require signed auth for Otto trading writes#33
lawyered0 wants to merge 1 commit intoJejuNetwork:mainfrom
lawyered0:codex/otto-auth

Conversation

@lawyered0
Copy link

Summary\n- require signed wallet auth headers for launch create, bonding buy/sell, and trading swap/bridge endpoints outside localnet\n- add x-jeju-* headers to CORS allowlist\n\n## Testing\n- not run (not requested)

@lawyered0
Copy link
Author

Why this change: Otto write endpoints (launch/bonding/trading) only trusted x-wallet-address. This enforces signed x-jeju-* headers outside localnet so actions can’t be spoofed, while leaving read endpoints untouched.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant