Description
The current behavior needs an explicit security boundary so privilege checks cannot drift. src/starknet/client.ts owns RPC retries, fee quotes, and chain interactions, but the current behavior does not yet define the contract tightly enough for safe maintenance. Design the change so the runtime path, tests, and docs all describe the same behavior.
Requirements and context
- Keep the contract specific to
src/starknet/client.ts and its existing callers.
- Add coverage for the success path and the failure or boundary path relevant to this issue.
- Preserve compatibility where older callers or existing tests already rely on the current shape.
- Keep the change easy to review and small enough for one focused PR.
Suggested execution
Fork the repo and create a branch
git checkout -b starknet-client-security-187
Implement changes
- Update/Write:
src/starknet/client.ts
- Write comprehensive tests:
src/starknet/client.test.ts
- Add documentation:
docs/starknet/client.md
- Keep any new helper names consistent with the rest of
src/
Test and commit
- Run
pnpm test
- Run
pnpm lint
- Add a note for any edge cases that are intentionally out of scope
Example commit message
security: tighten authorization and sensitive-data handling
Guidelines
- WCAG 2.1 AA is not relevant here; keep the focus on correctness and maintainability.
- Prefer a narrow, well-documented fix over a broad refactor.
- Timeframe: 96 hours
Description
The current behavior needs an explicit security boundary so privilege checks cannot drift.
src/starknet/client.tsowns RPC retries, fee quotes, and chain interactions, but the current behavior does not yet define the contract tightly enough for safe maintenance. Design the change so the runtime path, tests, and docs all describe the same behavior.Requirements and context
src/starknet/client.tsand its existing callers.Suggested execution
Fork the repo and create a branch
Implement changes
src/starknet/client.tssrc/starknet/client.test.tsdocs/starknet/client.mdsrc/Test and commit
pnpm testpnpm lintExample commit message
Guidelines