Conversation
Addresses are lowercased before Set comparison to prevent case-variant duplicates from bypassing the uniqueness validation.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe PR modifies address uniqueness validation in the Ajv keyword validator. A single line change makes address uniqueness checks case-insensitive by lowercasing each address before computing the uniqueness set, preventing addresses that differ only in casing from being treated as distinct. ChangesAddress Validation
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|

Summary
validateUniqueAddresses(src/ajv.ts) by lowercasing addresses beforeSetcomparison.0xAbCd...vs0xabcd...) could pass client-side validation as two distinct operators.Context
Reported via bug bounty (OBL-01). The server-side API already normalizes via
getAddress()and theupdateClusterDefflow blocks duplicate operators from completing DKG, so this was not exploitable end-to-end. Applied as defense-in-depth.Test plan
yarn test)validatePayloadwithdefinitionSchemaSummary by CodeRabbit