Skip to content

test: lock XEC addresses to ecash/ectest prefixes - #10

Merged
nghiacc merged 1 commit into
mainfrom
chore/xec-address-format-guard
Sep 17, 2026
Merged

nghiacc merged 1 commit into
mainfrom
chore/xec-address-format-guard

Conversation

@nghiacc

@nghiacc nghiacc commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Summary

Checked every XEC address path in the code and the deployed data, then locked the behavior in with a regression test. No bitcoincash: address is generated or stored anywhere.

Findings

Path Result
Encoder (wallet-core encodeHashAddress) Uses COIN_CONFIGS.xec.protocolPrefix -> ecash: livenet / ectest: testnet
Server derivation Wallet-core only; addressService no longer derives (removed in #2) and the API dropped @bcpros/crypto-wallet-core
Web No bitcore Address usage (only PrivateKey for WIF/pubkey)
Deployed Postgres 45 XEC addresses: 45 ecash:, 0 bitcoincash:, 0 ectest:, 0 prefixless
Repo occurrences 3 total: two test normalization helpers and one migration-doc row (comparison tolerance, not generation)

Change

crypto.test.ts now asserts:

  • livenet XEC encodes with ecash:, testnet with ectest:
  • generated addresses never contain bitcoincash
  • a valid legacy bitcoincash:-prefixed cashaddr (re-encoded, since the prefix is part of the checksum) still decodes to the same script — paste-in compatibility only

Test plan

  • pnpm --filter @bcpros/abcpay-wallet-core test — 43 passed
  • pnpm --filter @bcpros/abcpay-wallet-core type-check
  • Deployed DB prefix audit (SQL above)

Asserts that livenet XEC addresses are encoded with the ecash: prefix, testnet with ectest:, that generated addresses never contain bitcoincash, and that a valid legacy bitcoincash-prefixed cashaddr still decodes to the same script (paste-in compatibility only). The prefix participates in the cashaddr checksum, so the legacy vector is re-encoded rather than prefix-swapped.
@coderabbitai

coderabbitai Bot commented Sep 17, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 3 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 3cd71b91-b405-448e-a323-ba4f97403628

📥 Commits

Reviewing files that changed from the base of the PR and between 0d77ac4 and e372ee7.

📒 Files selected for processing (1)
  • packages/abcpay-wallet-core/src/__tests__/crypto.test.ts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nghiacc
nghiacc merged commit 45efeff into main Sep 17, 2026
2 checks passed
@nghiacc
nghiacc deleted the chore/xec-address-format-guard branch September 17, 2026 14:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant