Multi-admin quorum execution for treasury and registry actions - #1097
Open
ugoocreates-pixel wants to merge 17 commits into
Open
Multi-admin quorum execution for treasury and registry actions#1097ugoocreates-pixel wants to merge 17 commits into
ugoocreates-pixel wants to merge 17 commits into
Conversation
…and registry actions
|
@ugoocreates-pixel Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Cedarich
requested changes
Jul 24, 2026
Cedarich
left a comment
Contributor
There was a problem hiding this comment.
@ugoocreates-pixel Kindly fix failing workflow
Author
please check |
Contributor
Author
|
will fix it now boss |
Author
|
Boss please check |
Contributor
Contributor
Author
|
Please check. Also please review my application for issue number 865 |
Contributor
Author
|
check please |
Contributor
Cedarich
requested changes
Jul 29, 2026
Cedarich
left a comment
Contributor
There was a problem hiding this comment.
Remove the changes made to onchain.yml
Author
|
check please |
Contributor
|
review |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1041
This PR extracts the hardcoded multisig logic from the
treasurycontract into a reusable shared workspace crate (multisig-guard) and integrates it across all sensitive registry and treasury operations to require multi-admin approval on testnet.Changes Made
multisig-guardcrate: Extracted multisig logic, state management, errors, and events into a generic library that validates approvals based onsoroban_sdk::Vec<Val>payloads to prevent "blank check" vulnerabilities.treasurycontract:multisig-guard.storage::ProposalActionenum to carry fully strongly-typed arguments (e.g.SetAdmin(Address)).set_admin_via_multisig,rotate_beneficiary_via_multisig,set_multisig_config_via_multisig) to consume payload-specific approvals.protocol_registrycontract:multisig-guard.ProposalActionvariants for module registration, updates, deactivation, activation, pausing, unpausing, setting admin, and upgrading.register_module_via_multisig,update_module_via_multisig).project_registrycontract:multisig-guard.update_config,pause,unpause,set_admin, andupgrade.contributor_registrycontract:multisig.rsmodule with the sharedmultisig-guardcrate.update_reputation,grant_badge,revoke_badge,apply_reputation_penalty, andset_adminfunctions to use the new generic multi-admin quorum module.Acceptance Criteria Met