Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Document stellar-cli's RPC trust boundary

Open Beginner friendly
#2,781 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 2 days

Nobody has claimed this yet.

Assessment

Difficulty
1/5
Estimated time
1-3 hours
Newbie friendliness
85/100
Issue type
Documentation
Clarity
Clearly specified
Activity status
Active
Tech stack
rust

Research direction

Start with README and any existing security section to see where trust assumptions are documented. Add the RPC trust boundary, the implications of untrusted or plain-HTTP endpoints, and guidance to prefer trusted endpoints over TLS; done means the user-facing guidance is clear and complete.

Written by the indexing model from the issue text.

Description

The CLI treats the configured RPC endpoint as a trusted component: authorization entries are built from simulateTransaction, and the signature expiration is derived from getLatestLedger. This assumption isn't written down anywhere user-facing.

Add documentation (README / a security section) stating that the RPC endpoint is trusted, what that implies when pointing the CLI at an untrusted or plain-HTTP endpoint, and guidance to prefer endpoints you control or trust over TLS.

Dominant language
Rust
Stars
123
Forks
147
Avg merge
3d 11h
Merged PRs (30d)
39

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from stellar/stellar-cli

All issues in stellar/stellar-cli

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.