Skip to content

Add stellar token set-authorized subcommand - #2719

Open
fnando wants to merge 2 commits into
mainfrom
token-set-authorized
Open

fnando wants to merge 2 commits into
mainfrom
token-set-authorized

Conversation

@fnando

@fnando fnando commented Sep 4, 2026 •

Copy link
Copy Markdown
Member

What

Adds stellar token set-authorized, a SAC-admin write subcommand that authorizes or deauthorizes an account to hold and transact a token. --source signs and authorizes the change, --account is the target, and --authorize <true|false> sets the state. Returns a JSON receipt with the tx hash.

Why

Part of #2620 (typed SEP-41 + SAC client), completing the SAC-admin group (mint/set-admin/clawback/set-authorized). A thin wrapper over contract invoke reusing args::invoke_by_position and args::not_deployed_error. Like the other transaction commands it flattens config::Args, so the signer comes from the standard --source (env STELLAR_ACCOUNT, optional with stellar keys use); the signer only authorizes and is not a set_authorized argument, so only [account, authorize] are passed positionally. set_authorized is part of the SAC StellarAssetInterface, not SEP-41. The happy-path test verifies the change behaviorally via the SAC's authorized getter.

Known limitations

Muxed (M…) source accounts are rejected with a clear error (same constraint as transfer, see #2645). Deauthorizing an existing trustline requires the issuer to have AUTH_REVOCABLE set — an asset-configuration prerequisite, not enforced by the command.

Copilot AI balanced review requested due to automatic review settings September 4, 2026 20:07
@github-project-automation github-project-automation Bot moved this to Backlog (Not Ready) in DevX Sep 4, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds the SAC-admin token set-authorized command.

Changes:

  • Implements authorization updates with structured receipts and errors.
  • Registers CLI routing, help documentation, and JSON handling.
  • Adds integration coverage for success and error paths.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
FULL_HELP_DOCS.md Documents the command and options.
cmd/soroban-cli/src/commands/token/set_authorized.rs Implements the command.
cmd/soroban-cli/src/commands/token/mod.rs Registers and dispatches the subcommand.
cmd/soroban-cli/src/cli.rs Enables structured JSON errors.
cmd/crates/soroban-test/tests/it/integration/token/set_authorized.rs Tests behavior and failures.
cmd/crates/soroban-test/tests/it/integration/token/mod.rs Registers the integration tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread cmd/soroban-cli/src/commands/token/set_authorized.rs
@fnando
fnando force-pushed the token-set-authorized branch from 48a8677 to 237bb06 Compare September 8, 2026 13:34
@fnando
fnando force-pushed the token-set-authorized branch from 237bb06 to 6088135 Compare September 8, 2026 15:17
@fnando
fnando force-pushed the token-set-authorized branch from 6088135 to 547fff9 Compare September 8, 2026 16:05
@fnando
fnando force-pushed the token-set-authorized branch from 547fff9 to e8d7195 Compare September 8, 2026 17:14
@fnando
fnando force-pushed the token-set-authorized branch from e8d7195 to 0f48d67 Compare September 8, 2026 18:01
Copilot AI review requested due to automatic review settings September 8, 2026 19:43
@fnando
fnando force-pushed the token-set-authorized branch from 0f48d67 to 8c5d73e Compare September 8, 2026 19:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated no new comments.

Copilot AI review requested due to automatic review settings September 28, 2026 21:51
@fnando
fnando force-pushed the token-set-authorized branch from 8c5d73e to 2bf8aab Compare September 28, 2026 21:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation follows existing token-admin patterns and includes appropriate behavioral and failure-path coverage.

Review effort: Balanced
Findings: None

Copilot AI review requested due to automatic review settings September 28, 2026 22:23
@fnando
fnando force-pushed the token-set-authorized branch from 2bf8aab to 4295e30 Compare September 28, 2026 22:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Muxed target accounts are advertised and passed through even though SAC set_authorized rejects them.

Review effort: Balanced
Findings: 1 High severity

Open (1)

Comment on lines +156 to +160
let account = self
.account
.clone()
.resolve(&config.locator, &network.network_passphrase, None)?
.to_string();
Copilot AI review requested due to automatic review settings September 28, 2026 23:50
@fnando
fnando force-pushed the token-set-authorized branch from 4295e30 to 5091095 Compare September 28, 2026 23:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The core reauthorization transition is not behaviorally tested.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)

Comment on lines +83 to +88
// The account is now deauthorized on-chain.
assert!(
!sac_authorized(sandbox, &sac, &test),
"account should be deauthorized after set-authorized false"
);
}
@fnando
fnando force-pushed the token-set-authorized branch from 5091095 to 5518d57 Compare September 28, 2026 23:57
Copilot AI review requested due to automatic review settings September 29, 2026 00:21
@fnando
fnando force-pushed the token-set-authorized branch from 5518d57 to 13c09f4 Compare September 29, 2026 00:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The help advertises muxed source accounts even though the command always rejects them.

Review effort: Balanced
Findings: 1 High severity · 2 Low severity

Open (3)

Comment thread FULL_HELP_DOCS.md

###### **Transaction Options:**

- `-s`, `--source-account <SOURCE_ACCOUNT>` [alias: `source`] — Account that where transaction originates from. Alias `source`. Can be an identity (--source alice), a public key (--source GDKW...), a muxed account (--source MDA…), a secret key (--source SC36…), or a seed phrase (--source "kite urban…"). If `--build-only` was NOT provided, this key will also be used to sign the final transaction. In that case, trying to sign with public key will fail
@fnando
fnando force-pushed the token-set-authorized branch from 13c09f4 to 27fe146 Compare September 29, 2026 00:24
Base automatically changed from token-set-admin to main September 29, 2026 08:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog (Not Ready)

Development

Successfully merging this pull request may close these issues.

3 participants