Skip to content

Check the declared payer for signed Tempo payments - #32

Merged
ksn-stripe merged 1 commit into
mainfrom
ksn/tempo-transaction-source
Sep 16, 2026
Merged

ksn-stripe merged 1 commit into
mainfrom
ksn/tempo-transaction-source

Conversation

@ksn-stripe

@ksn-stripe ksn-stripe commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

When a client submits a signed Tempo payment, it can also name the wallet that paid. We verified the payment but did not check that the named wallet matched the wallet that sent the tokens.

This change checks that the declared wallet address is valid, belongs to the expected chain, and matches the token sender. These are the same checks we already apply when a client submits a transaction hash. Clients can still omit the payer field.

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
@ksn-stripe ksn-stripe changed the title fix(tempo): validate transaction credential source Check that the claimed payer matches the Tempo transfer sender Sep 15, 2026
@ksn-stripe ksn-stripe changed the title Check that the claimed payer matches the Tempo transfer sender fix: check claimed payer matches the transfer sender Sep 15, 2026
@ksn-stripe
ksn-stripe marked this pull request as ready for review September 15, 2026 22:12
@ksn-stripe ksn-stripe changed the title fix: check claimed payer matches the transfer sender Check the declared payer for signed Tempo payments Sep 15, 2026
@ksn-stripe
ksn-stripe merged commit f2e8f64 into main Sep 16, 2026
15 of 16 checks passed
@ksn-stripe
ksn-stripe deleted the ksn/tempo-transaction-source branch September 16, 2026 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants