Skip to content

Commit

Permalink
feat: reject linkings based on wallet geo country (#2580)
Browse files Browse the repository at this point in the history
  • Loading branch information
clD11 authored Jun 26, 2024
1 parent a5c6d12 commit 45df6ac
Show file tree
Hide file tree
Showing 6 changed files with 80 additions and 4 deletions.
19 changes: 19 additions & 0 deletions libs/clients/reputation/client.go
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ type Client interface {
IsWalletOnPlatform(ctx context.Context, id uuid.UUID, platform string) (bool, error)
UpsertReputationSummary(ctx context.Context, paymentID, geoCountry string) error
UpdateReputationSummary(ctx context.Context, paymentID string, verifiedWallet bool) error
GetReputationSummary(ctx context.Context, paymentID uuid.UUID) (RepSummaryResponse, error)
}

// HTTPClient wraps http.Client for interacting with the reputation server
Expand Down Expand Up @@ -347,3 +348,21 @@ func (c *HTTPClient) UpdateReputationSummary(ctx context.Context, paymentID stri

return nil
}

type RepSummaryResponse struct {
GeoCountry string `json:"geoCountry"`
}

func (c *HTTPClient) GetReputationSummary(ctx context.Context, paymentID uuid.UUID) (RepSummaryResponse, error) {
req, err := c.client.NewRequest(ctx, http.MethodGet, "v1/reputation-summary/"+paymentID.String(), nil, nil)
if err != nil {
return RepSummaryResponse{}, err
}

var resp RepSummaryResponse
if _, err := c.client.Do(ctx, req, &resp); err != nil {
return RepSummaryResponse{}, err
}

return resp, nil
}
14 changes: 14 additions & 0 deletions libs/clients/reputation/instrumented_client.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

16 changes: 16 additions & 0 deletions libs/clients/reputation/mock/mock.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions services/wallet/controllers_v3.go
Original file line number Diff line number Diff line change
Expand Up @@ -505,6 +505,8 @@ func LinkSolanaAddress(s *Service) handlers.AppHandler {
return handlers.WrapError(model.ErrChallengeExpired, "linking challenge expired", http.StatusUnauthorized)
case errors.Is(err, model.ErrWalletNotFound):
return handlers.WrapError(model.ErrWalletNotFound, "rewards wallet not found", http.StatusNotFound)
case errors.Is(err, errDisabledRegion):
return handlers.WrapError(errDisabledRegion, "region is currently disabled for linking", http.StatusBadRequest)
case errors.Is(err, ErrTooManyCardsLinked):
return handlers.WrapError(ErrTooManyCardsLinked, "too many wallets linked", http.StatusConflict)
case errors.As(err, &solErr):
Expand Down
16 changes: 15 additions & 1 deletion services/wallet/controllers_v3_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,10 @@ import (
"time"

"github.com/brave-intl/bat-go/libs/altcurrency"
"github.com/brave-intl/bat-go/libs/clients/reputation"
mock_reputation "github.com/brave-intl/bat-go/libs/clients/reputation/mock"
appctx "github.com/brave-intl/bat-go/libs/context"
"github.com/brave-intl/bat-go/libs/custodian"
"github.com/brave-intl/bat-go/libs/handlers"
"github.com/brave-intl/bat-go/libs/httpsignature"
walletutils "github.com/brave-intl/bat-go/libs/wallet"
Expand Down Expand Up @@ -519,9 +521,21 @@ func (suite *WalletControllersTestSuite) TestLinkSolanaAddress_Success() {
AllowedOrigins: []string{"https://my-dapp.com", "https://my-dapp-2.com"},
}

s, err := wallet.InitService(pg, nil, chlRep, allowList, nil, nil, nil, nil, nil, nil, dac)
// mock reputation client
ctrl := gomock.NewController(suite.T())
defer ctrl.Finish()

repClient := mock_reputation.NewMockClient(ctrl)
repClient.EXPECT().GetReputationSummary(gomock.Any(), paymentID).Return(reputation.RepSummaryResponse{GeoCountry: "US"}, nil)

s, err := wallet.InitService(pg, nil, chlRep, allowList, repClient, nil, nil, nil, nil, nil, dac)
suite.Require().NoError(err)

cr := custodian.Regions{Solana: custodian.GeoAllowBlockMap{
Allow: []string{"US"},
}}
s.SetCustodianRegions(cr)

// create linking message
solPub, msg, solSig := createAndSignMessage(suite.T(), w.ID, priv, chl.Nonce)

Expand Down
17 changes: 14 additions & 3 deletions services/wallet/service.go
Original file line number Diff line number Diff line change
Expand Up @@ -227,7 +227,7 @@ func SetupService(ctx context.Context) (context.Context, *Service) {

// setup reputation client
repClient, err := reputation.New()
// it's okay to not fatally fail if this environment is local and we cant make a rep client
// it's okay to not fatally fail if this environment is local, and we cant make a rep client
if err != nil && os.Getenv("ENV") != "local" {
l.Panic().Err(err).Msg("failed to initialize wallet service")
}
Expand Down Expand Up @@ -326,7 +326,7 @@ func SetupService(ctx context.Context) (context.Context, *Service) {
return ctx, s
}

func (service *Service) setCustodianRegions(custodianRegions custodian.Regions) {
func (service *Service) SetCustodianRegions(custodianRegions custodian.Regions) {
service.crMu.Lock()
defer service.crMu.Unlock()
service.custodianRegions = custodianRegions
Expand Down Expand Up @@ -734,11 +734,22 @@ func (service *Service) LinkUpholdWallet(ctx context.Context, wallet uphold.Wall
return country, nil
}

const errDisabledRegion model.Error = "disabled region"

func (service *Service) LinkSolanaAddress(ctx context.Context, paymentID uuid.UUID, req linkSolanaAddrRequest) error {
if err := isWalletWhitelisted(ctx, service.Datastore.RawDB(), service.allowListRepo, paymentID); err != nil {
return err
}

repSum, err := service.repClient.GetReputationSummary(ctx, paymentID)
if err != nil {
return err
}

if !service.custodianRegions.Solana.Verdict(repSum.GeoCountry) {
return errDisabledRegion
}

ctx, txn, rollback, commit, err := getTx(ctx, service.Datastore)
if err != nil {
return err
Expand Down Expand Up @@ -911,7 +922,7 @@ func (service *Service) RefreshCustodianRegionsWorker(ctx context.Context) (bool
return true, fmt.Errorf("error running refresh custodian regions: %w", err)
}
// write custodian regions to service
service.setCustodianRegions(*custodianRegions)
service.SetCustodianRegions(*custodianRegions)
return true, nil
}
}
Expand Down

0 comments on commit 45df6ac

Please sign in to comment.