Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Priority: P1 — canonical-identity completeness audit after #433: every remaining boundary where a raw mint string becomes a key.

Open
#501 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
32/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
go
Domain
backend

Research direction

Start by tracing the listed boundaries in src/tollwallet/tollwallet.go, src/config_manager, src/merchant/{lightning.go,merchant.go}, and src/cli/, then audit gonuts wallet.go as specified. Build the requested boundary inventory and check each key, comparison, and persistence path for canonical mint identity. Done means all rows are fixed or justified, the property and integration tests pass, and the stated failure-injection cases are covered.

Written by the indexing model from the issue text.

Description

Priority: P1 — canonical-identity completeness audit after #433: every remaining boundary where a raw mint string becomes a key.

Problem

#433 fixed canonicalization for the wallet wrapper (registry keys, MintURLMatches, read-side alias merge in balances/drain). The class is wider than that fix: several persistence and comparison boundaries still key or match on raw or partially-normalized strings, and gonuts-internal maps key by their own url.Parse().String() discipline (which preserves trailing slashes), so wrapper-canonical ≠ internal-canonical unless proven at every hand-off.

Why it matters

#480 proved the concrete cost: one trailing-slash difference in one storage layer forked the derivation counter lineage. Every boundary not proven canonical is a future phantom-balance / rejected-token / split-wallet incident. The audit should produce a checked inventory, not another spot fix.

Current behavior — candidate boundaries to verify (source refs)

  1. src/tollwallet/tollwallet.go:143-177 — wrapper registry is canonical; but w.wallet.AddMint(canonical) hands to gonuts which re-keys internally (wallet/wallet.go w.mints[url.Parse(u).String()]) — prove no spelling can reach gonuts that re-parses differently.
  2. Lightning quotes (src/merchant/lightning.go, quote_store.go) — is the quote record's MintURL canonical at write, and matched canonically at grant time?
  3. src/config_manager — config load/normalize: are accepted_mints canonicalized at load (write-side) or only at use? (#481's fix direction also touches this set.)
  4. Reseller/upstream flows (src/upstream_session_manager, merchant Fund/CreatePaymentToken paths) — mint URL provenance is config vs upstream advertisement vs token; check all three converge.
  5. Drain journal keys + CLI wallet path selection (src/cli/server_drain*.go).
  6. merchant.go calculateAllotment mint lookup — currently MintURLMatches? verify (pricing by wrong spelling = mispriced payment).

Desired invariant

A mint URL crosses exactly one canonicalization boundary (as early as possible — config load and token decode), and every key, comparison, persistence, and log line downstream uses the canonical form. Internal library maps either share the form or are proven isomorphic.

Proposed scope

  1. Produce the boundary inventory as a table (boundary, current form, canonical?, test) in the PR.
  2. Fix the non-canonical ones; add normalizeMintURL calls at config load (write-side) so stored config converges too.
  3. Property test: for a fuzz set of spellings, registry + gonuts map + quote store + pricing lookup all resolve to one identity.

Areas / files

src/tollwallet/tollwallet.go, src/config_manager, src/merchant/{lightning.go,merchant.go}, src/cli/, gonuts wallet.go (map-key audit only).

Acceptance criteria

  • Inventory table merged; all rows green or explicitly waived with rationale.
  • Property test in CI; mixed-spelling cloud-lab config lane passes (register, pay, quote, drain under alias spellings).

Required tests

  • Unit: boundary table; property/fuzz spellings.
  • Integration: alias-spelling lane (config mixed-case + token canonical).

Failure-injection tests

  • Re-register under alias at runtime (config reload) → single wallet, single DB identity.
  • Quote created under spelling A, grant looked up under spelling B → found.

Compatibility

Write-side config canonicalization changes stored config files — one-time, idempotent, release-note it.

Dependencies

G03's gonuts storage canonicalization (aligned forms).

Out of scope

  • Rust repo (its own issue, Amperstrand/tollgate-module-basic-rust#10).
Dominant language
Go
Stars
12
Forks
14
Avg merge
1d 6h
Merged PRs (30d)
211

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from OpenTollGate/tollgate-module-basic-go

All issues in OpenTollGate/tollgate-module-basic-go

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.