Add stellar token set-admin subcommand - #2718
Conversation
There was a problem hiding this comment.
Pull request overview
Adds stellar token set-admin for transferring SAC administration through the existing contract invocation pipeline.
Changes:
- Adds command routing, typed errors, receipts, and help documentation.
- Adds integration coverage for transfer, undeployed SACs, and muxed sources.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
FULL_HELP_DOCS.md |
Documents the subcommand. |
cmd/soroban-cli/src/commands/token/set_admin.rs |
Implements administration transfer. |
cmd/soroban-cli/src/commands/token/mod.rs |
Registers and dispatches the command. |
cmd/soroban-cli/src/cli.rs |
Enables JSON error formatting. |
cmd/crates/soroban-test/tests/it/integration/token/set_admin.rs |
Adds integration tests. |
cmd/crates/soroban-test/tests/it/integration/token/mod.rs |
Registers the test module. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
0b373b0 to
f8ba62a
Compare
f8ba62a to
f33eb70
Compare
f33eb70 to
8ca4c47
Compare
8ca4c47 to
7264b1a
Compare
7264b1a to
eca4411
Compare
eca4411 to
903d339
Compare
903d339 to
b5298c8
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Accepting a muxed successor can leave administration unusable through the current CLI, and the administrator documentation is inaccurate.
Review effort: Balanced
Findings: 1
Open (5)
Reject muxed successor addresses until admin signing is supported · New Clarify help text that issuer is only the initial admin · New Clarify issuer is only the initial SAC administrator · New The acceptednativetoken reference is missing from this help text.UnresolvedTokenparses… This generated help entry omits the supportednativereference, unlike every other token command.…
b5298c8 to
3246d87
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Muxed successor addresses are advertised and forwarded even though the SAC set_admin parameter rejects them.
Review effort: Balanced
Findings: 1
Open (6)
Reject muxed successor addresses until admin signing is supported Remove unsupported muxed successor from help text · New Clarify issuer is only the initial SAC administrator Clarify help text that issuer is only the initial admin The acceptednativetoken reference is missing from this help text.UnresolvedTokenparses… This generated help entry omits the supportednativereference, unlike every other token command.…
3246d87 to
8029cce
Compare
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The implementation follows established token-admin patterns and includes comprehensive integration coverage.
Review effort: Balanced
Findings: 1
Open (4)
Reject muxed successor addresses until admin signing is supported Remove unsupported muxed successor from help text The acceptednativetoken reference is missing from this help text.UnresolvedTokenparses… This generated help entry omits the supportednativereference, unlike every other token command.…
Resolved since last review (2)
8029cce to
b73d46d
Compare
b73d46d to
d7091b9
Compare
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The help text omits the accepted native token target.
Review effort: Balanced
Findings: 1
Open (4)
Reject muxed successor addresses until admin signing is supported Remove unsupported muxed successor from help text The acceptednativetoken reference is missing from this help text.UnresolvedTokenparses… This generated help entry omits the supportednativereference, unlike every other token command.…
d7091b9 to
d47073b
Compare
d47073b to
239fb87
Compare
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The command is consistently integrated, validates current limitations, and has comprehensive integration coverage.
Review effort: Balanced
Findings: None
Resolved since last review (4)
Reject muxed successor addresses until admin signing is supported Remove unsupported muxed successor from help text The acceptednativetoken reference is missing from this help text.UnresolvedTokenparses… This generated help entry omits the supportednativereference, unlike every other token command.…



What
Adds
stellar token set-admin, a SAC-admin write subcommand that transfers administration of a token.--source(the current admin) signs and authorizes the change, and--new-adminis the successor. Returns a JSON receipt with the tx hash.Why
Part of #2620 (typed SEP-41 + SAC client), a SAC-admin command alongside
mint/clawback. A thin wrapper overcontract invokereusingargs::invoke_by_positionandargs::not_deployed_error. Like the other transaction commands it flattensconfig::Args, so the signer comes from the standard--source(envSTELLAR_ACCOUNT, optional withstellar keys use); like the other admin commands, the signer only authorizes and is not aset_adminargument, so only[new_admin]is passed positionally. The happy-path test verifies control transferred behaviorally — afterset-admin, the new admin canmint.Known limitations
Muxed (
M…) source accounts are rejected with a clear error (same constraint astransfer, see #2645).