Document stellar-cli's RPC trust boundary
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 85/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- rust
- Domain
- cli, documentation, security
Research direction
Start with README and any existing security section to see where trust assumptions are documented. Add the RPC trust boundary, the implications of untrusted or plain-HTTP endpoints, and guidance to prefer trusted endpoints over TLS; done means the user-facing guidance is clear and complete.
Written by the indexing model from the issue text.
Description
The CLI treats the configured RPC endpoint as a trusted component: authorization entries are built from simulateTransaction, and the signature expiration is derived from getLatestLedger. This assumption isn't written down anywhere user-facing.
Add documentation (README / a security section) stating that the RPC endpoint is trusted, what that implies when pointing the CLI at an untrusted or plain-HTTP endpoint, and guidance to prefer endpoints you control or trust over TLS.
- Dominant language
- Rust
- Stars
- 123
- Forks
- 147
- Avg merge
- 3d 11h
- Merged PRs (30d)
- 39
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from stellar/stellar-cli
-
Display the full authorization tree before signing auth entriesPossibly taken @DeadZen claimed this 3 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
stellar/stellar-cli#2779 ·
Maintainers usually reply within 2 days
-
`tx update sequence-number next` fails when the transaction source is a muxed accountPossibly taken @neimasilk-arch claimed this 2 days ago. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
stellar/stellar-cli#2774 ·
Maintainers usually reply within 2 days
-
`tx edit` fails on transaction XDR that is wrapped across multiple linesPossibly taken @neimasilk-arch claimed this 2 days ago. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
stellar/stellar-cli#2773 ·
Maintainers usually reply within 2 days
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
stellar/stellar-cli#2770 · 1 comment ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
stellar/stellar-cli#2753 ·
Maintainers usually reply within 2 days
All issues in stellar/stellar-cli
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 80/100
Devolutions/picky-rs#546 · 1 comment ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
zcashlabs/thus-spoke-zakura#153 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 79/100
topgrade-rs/topgrade#2395 ·
Maintainers usually reply within 1 day