Skip to content

Release: develop -> main - #4409

Merged
TaprootFreak merged 2 commits into
mainfrom
develop
Jul 27, 2026
Merged

Release: develop -> main#4409
TaprootFreak merged 2 commits into
mainfrom
develop

Conversation

@github-actions

Copy link
Copy Markdown

Automatic Release PR

This PR was automatically created after changes were pushed to develop.

Commits: 1 new commit(s)

Checklist

  • Review all changes
  • Verify CI passes
  • Approve and merge when ready for production

* feat(custody): account-scoped read endpoints for a shared Safe

* fix(custody): refuse an account-scoped read when holdings span several accounts

Reading resolves an account to its owner, because no per-account attribution of
balances and orders exists. If the owner holds more than one active account,
that would hand a grantee everything the owner holds, including what belongs to
the accounts they were not granted. There is no source of truth to filter by, so
the read refuses instead of returning either a fabricated subset or an
over-broad Safe. The owner keeps the aggregate view through the caller-scoped
endpoints.

* fix(custody): apply the multi-account refusal only to grantees, and count every account

The refusal exists because a grant covers one account while the data layer can
only return the owner's whole Safe. It counted active accounts only, so an owner
with one active and one closed account passed the check and a grantee received
the closed account's holdings as well - closing an account moves nothing. It now
counts every account of that owner.

It also refused the owner, who holds all of those rows anyway and reaches them
through the caller-scoped endpoints, which broke the equivalence these routes are
meant to have for the owner. The check now applies only when someone else asks.

* docs(custody): describe what the account-scoped responses return

The three new read routes declared their response type without a description,
the only routes in this controller that did. Each one now says that the data
belongs to the addressed account rather than the caller - the distinction that
separates them from the caller-scoped endpoints.
@TaprootFreak
TaprootFreak merged commit 476cd62 into main Jul 27, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant