Release: develop -> main - #4409
Merged
Merged
Conversation
* feat(custody): account-scoped read endpoints for a shared Safe * fix(custody): refuse an account-scoped read when holdings span several accounts Reading resolves an account to its owner, because no per-account attribution of balances and orders exists. If the owner holds more than one active account, that would hand a grantee everything the owner holds, including what belongs to the accounts they were not granted. There is no source of truth to filter by, so the read refuses instead of returning either a fabricated subset or an over-broad Safe. The owner keeps the aggregate view through the caller-scoped endpoints. * fix(custody): apply the multi-account refusal only to grantees, and count every account The refusal exists because a grant covers one account while the data layer can only return the owner's whole Safe. It counted active accounts only, so an owner with one active and one closed account passed the check and a grantee received the closed account's holdings as well - closing an account moves nothing. It now counts every account of that owner. It also refused the owner, who holds all of those rows anyway and reaches them through the caller-scoped endpoints, which broke the equivalence these routes are meant to have for the owner. The check now applies only when someone else asks. * docs(custody): describe what the account-scoped responses return The three new read routes declared their response type without a description, the only routes in this controller that did. Each one now says that the data belongs to the addressed account rather than the caller - the distinction that separates them from the caller-scoped endpoints.
github-actions
Bot
requested review from
TaprootFreak and
davidleomay
as code owners
July 27, 2026 16:30
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automatic Release PR
This PR was automatically created after changes were pushed to develop.
Commits: 1 new commit(s)
Checklist