Skip to content

Apply the SELL release gate to the ramp status endpoint - #1387

Merged
ebma merged 3 commits into
stagingfrom
fix/ramp-status-release-gate
Sep 29, 2026
Merged

ebma merged 3 commits into
stagingfrom
fix/ramp-status-release-gate

Conversation

@ebma

@ebma ebma commented Sep 29, 2026

Copy link
Copy Markdown
Member

Problem

GET /v1/ramp/{id}?showUnsignedTxs=true returned rampState.unsignedTxs unfiltered. For a SELL ramp that let a client fetch the user's source-of-funds transactions before every ephemeral presigned tx had been received and validated. The register and update responses withhold exactly those txs via filterUnsignedTxsForResponse. This is the case the gate exists for: an older SDK starting the user's transfer after the backend added ephemeral txs it cannot sign.

Fix

getRampStatus now returns filterUnsignedTxsForResponse(rampState, presignChecksPass || ephemeralPresignChecksPass(rampState)). That is the same predicate updateRamp uses, and it only runs when showUnsignedTxs is requested.

Tests

  • New ramp.service.get-ramp-status.test.ts case: a SELL ramp with its ephemeral presigns missing returns only the ephemeral txs. It fails without the fix.
  • Companion case: once presign checks have passed, all txs are returned.
  • Full api suite: 1927 pass / 0 fail (isolated test DB). tsc --noEmit clean.

Security spec

docs/security-spec/03-ramp-engine/transaction-validation.md now names all three responses that the gate covers.

GET /v1/ramp/{id}?showUnsignedTxs=true returned the raw unsignedTxs, so a
client could fetch the user's source-of-funds transactions for a SELL ramp
before every ephemeral presign was received and validated, bypassing the
gate that register and update enforce.
@netlify

netlify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for vortexfi canceled.

Name Link
🔨 Latest commit 6215421
🔍 Latest deploy log https://app.netlify.com/projects/vortexfi/deploys/6abbb7136b08df00088435f5

@netlify

netlify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for vortex-sandbox ready!

Name Link
🔨 Latest commit 6215421
🔍 Latest deploy log https://app.netlify.com/projects/vortex-sandbox/deploys/6abbb96b944e331873c8b85a
😎 Deploy Preview https://deploy-preview-1387--vortex-sandbox.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for vrtx-dashboard canceled.

Name Link
🔨 Latest commit 6215421
🔍 Latest deploy log https://app.netlify.com/projects/vrtx-dashboard/deploys/6abbb7138655fa00081be7da

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The predicate unnecessarily performs potentially chain-backed validation for BUY status requests despite being a SELL-only gate.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Applies SELL transaction-release filtering to ramp status responses.

Changes:

  • Gates status unsignedTxs using presign validation.
  • Adds SELL regression tests.
  • Updates the security specification.
File Description
ramp.service.ts Filters status transactions.
ramp.service.get-ramp-status.test.ts Tests withholding and release.
transaction-validation.md Documents status-response gating.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread apps/api/src/api/services/ramp/ramp.service.ts
The release gate only filters SELL responses, so validating presigns for a
BUY status request added latency and a chain API dependency for nothing.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The positive dynamic-validation branch is not exercised because its test short-circuits through the persisted flag.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)

Comment thread apps/api/src/api/services/ramp/ramp.service.get-ramp-status.test.ts Outdated
The release case persisted presignChecksPass, so it short-circuited before
ephemeralPresignChecksPass and a regression dropping the dynamic check would
have stayed green while SELL clients never received their transactions.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation consistently reuses the established gate and includes focused regression coverage.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@ebma
ebma merged commit abee2f1 into staging Sep 29, 2026
7 checks passed
@ebma
ebma deleted the fix/ramp-status-release-gate branch September 29, 2026 13:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants