Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Priority: P1 — canonical-identity completeness audit after #433: every remaining boundary where a raw mint string becomes a key.

Aperta
#501 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
32/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
go
Ambito
backend

Direzione di ricerca

Start by tracing the listed boundaries in src/tollwallet/tollwallet.go, src/config_manager, src/merchant/{lightning.go,merchant.go}, and src/cli/, then audit gonuts wallet.go as specified. Build the requested boundary inventory and check each key, comparison, and persistence path for canonical mint identity. Done means all rows are fixed or justified, the property and integration tests pass, and the stated failure-injection cases are covered.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Priority: P1 — canonical-identity completeness audit after #433: every remaining boundary where a raw mint string becomes a key.

Problem

#433 fixed canonicalization for the wallet wrapper (registry keys, MintURLMatches, read-side alias merge in balances/drain). The class is wider than that fix: several persistence and comparison boundaries still key or match on raw or partially-normalized strings, and gonuts-internal maps key by their own url.Parse().String() discipline (which preserves trailing slashes), so wrapper-canonical ≠ internal-canonical unless proven at every hand-off.

Why it matters

#480 proved the concrete cost: one trailing-slash difference in one storage layer forked the derivation counter lineage. Every boundary not proven canonical is a future phantom-balance / rejected-token / split-wallet incident. The audit should produce a checked inventory, not another spot fix.

Current behavior — candidate boundaries to verify (source refs)

  1. src/tollwallet/tollwallet.go:143-177 — wrapper registry is canonical; but w.wallet.AddMint(canonical) hands to gonuts which re-keys internally (wallet/wallet.go w.mints[url.Parse(u).String()]) — prove no spelling can reach gonuts that re-parses differently.
  2. Lightning quotes (src/merchant/lightning.go, quote_store.go) — is the quote record's MintURL canonical at write, and matched canonically at grant time?
  3. src/config_manager — config load/normalize: are accepted_mints canonicalized at load (write-side) or only at use? (#481's fix direction also touches this set.)
  4. Reseller/upstream flows (src/upstream_session_manager, merchant Fund/CreatePaymentToken paths) — mint URL provenance is config vs upstream advertisement vs token; check all three converge.
  5. Drain journal keys + CLI wallet path selection (src/cli/server_drain*.go).
  6. merchant.go calculateAllotment mint lookup — currently MintURLMatches? verify (pricing by wrong spelling = mispriced payment).

Desired invariant

A mint URL crosses exactly one canonicalization boundary (as early as possible — config load and token decode), and every key, comparison, persistence, and log line downstream uses the canonical form. Internal library maps either share the form or are proven isomorphic.

Proposed scope

  1. Produce the boundary inventory as a table (boundary, current form, canonical?, test) in the PR.
  2. Fix the non-canonical ones; add normalizeMintURL calls at config load (write-side) so stored config converges too.
  3. Property test: for a fuzz set of spellings, registry + gonuts map + quote store + pricing lookup all resolve to one identity.

Areas / files

src/tollwallet/tollwallet.go, src/config_manager, src/merchant/{lightning.go,merchant.go}, src/cli/, gonuts wallet.go (map-key audit only).

Acceptance criteria

  • Inventory table merged; all rows green or explicitly waived with rationale.
  • Property test in CI; mixed-spelling cloud-lab config lane passes (register, pay, quote, drain under alias spellings).

Required tests

  • Unit: boundary table; property/fuzz spellings.
  • Integration: alias-spelling lane (config mixed-case + token canonical).

Failure-injection tests

  • Re-register under alias at runtime (config reload) → single wallet, single DB identity.
  • Quote created under spelling A, grant looked up under spelling B → found.

Compatibility

Write-side config canonicalization changes stored config files — one-time, idempotent, release-note it.

Dependencies

G03's gonuts storage canonicalization (aligned forms).

Out of scope

  • Rust repo (its own issue, Amperstrand/tollgate-module-basic-rust#10).
Lingua principale
Go
Stelle
12
Fork
14
Merge medio
1g 6h
PR unite (30g)
217

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di OpenTollGate/tollgate-module-basic-go

Tutte le issue di OpenTollGate/tollgate-module-basic-go

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.