Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 0 additions & 2 deletions apps/sdp-api/src/app.ts
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,6 @@ import health from "@/routes/health";
import heliusRings from "@/routes/helius-rings";
import internalCustody from "@/routes/internal-custody";
import internalHeliusRings from "@/routes/internal-helius-rings";
import internalRpc from "@/routes/internal-rpc";
import issuance from "@/routes/issuance";
import llms from "@/routes/llms";
import members from "@/routes/members";
Expand Down Expand Up @@ -424,7 +423,6 @@ export function createApp(deps: AppDeps): Hono<{ Bindings: Env }> {
// public OpenAPI and AI discovery surfaces.
app.route("/internal/playground", playgroundInternal);
app.route("/internal/dashboard/custody", internalCustody);
app.route("/internal/dashboard/rpc", internalRpc);
app.route("/internal/dashboard/helius-rings", internalHeliusRings);

// Admin routes (internal)
Expand Down
272 changes: 0 additions & 272 deletions apps/sdp-api/src/db/migrations/rpc-connection-ownership.test.ts

This file was deleted.

4 changes: 0 additions & 4 deletions apps/sdp-api/src/lib/errors.ts
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,6 @@ export type ErrorCode =
| "MAX_SUPPLY_EXCEEDED"
| "SOLANA_RPC_ERROR"
| "SOLANA_RPC_TIMEOUT"
| "UPSTREAM_RESPONSE_TOO_LARGE"
| "CUSTODY_ERROR"
// Transaction errors
| "TRANSACTION_FAILED"
Expand Down Expand Up @@ -104,7 +103,6 @@ const ERROR_STATUS_CODES: Record<ErrorCode, number> = {
MAX_SUPPLY_EXCEEDED: 400,
SOLANA_RPC_ERROR: 502,
SOLANA_RPC_TIMEOUT: 504,
UPSTREAM_RESPONSE_TOO_LARGE: 502,
CUSTODY_ERROR: 502,
// Transaction errors
TRANSACTION_FAILED: 400,
Expand Down Expand Up @@ -161,8 +159,6 @@ const DEFAULT_ERROR_MESSAGES: Record<ErrorCode, string> = {
MAX_SUPPLY_EXCEEDED: "Operation would exceed maximum supply",
SOLANA_RPC_ERROR: "Error communicating with Solana RPC",
SOLANA_RPC_TIMEOUT: "The RPC upstream did not answer in time; the request's outcome is unknown",
UPSTREAM_RESPONSE_TOO_LARGE:
"The RPC upstream answered with a body larger than the relay returns",
CUSTODY_ERROR: "Custody provider error",
// Transaction errors
TRANSACTION_FAILED: "Transaction failed",
Expand Down
15 changes: 9 additions & 6 deletions apps/sdp-api/src/middleware/credential-admin-auth.ts
Original file line number Diff line number Diff line change
Expand Up @@ -19,18 +19,21 @@ export function credentialAdminAuthMiddleware() {
}

/**
* RPC connections hold organization-wide egress credentials rather than
* signing material, so they gate on `org:admin` (HOO-1092) instead of
* `custody:admin`. API keys are refused for the same reason as custody: a
* credential administration surface must be tied to a person.
* Gate for surfaces that hold organization-wide egress endpoints rather than
* signing material (Helius Rings connections), so they require `org:admin`
* (HOO-1092) instead of `custody:admin`. API keys are refused for the same
* reason as custody: a credential administration surface must be tied to a
* person.
*
* @returns Hono middleware that authenticates the caller and requires an organization administrator.
*/
export function rpcAdminAuthMiddleware() {
export function organizationCredentialAdminAuthMiddleware() {
const authenticate = unifiedAuthMiddleware();

return async (c: Context<{ Bindings: Env }>, next: Next) => {
await authenticate(c, async () => {
if (!canManageOrganizationCredentials(getAuth(c))) {
throw forbidden("RPC connection administration requires an organization administrator");
throw forbidden("Connection administration requires an organization administrator");
}
await next();
});
Expand Down
2 changes: 1 addition & 1 deletion apps/sdp-api/src/openapi/paths/onboarding.ts
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ export function registerOnboardingPaths(registry: OpenAPIRegistry) {
summary: "Complete organization onboarding",
operationId: "completeOrganizationOnboarding",
description:
"Marks organization onboarding complete after verifying an RPC selection and the selected default custody wallet for the default sandbox project.",
"Marks organization onboarding complete after verifying the selected default custody wallet for the default sandbox project.",
security: [{ apiKeyAuth: [] }],
request: {
body: {
Expand Down
2 changes: 0 additions & 2 deletions apps/sdp-api/src/openapi/paths/responses.ts
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,6 @@ import {
projectResponseSchema,
revokeApiKeyResponseSchema,
rotateApiKeyResponseSchema,
rpcProvidersResponseSchema,
rpcRelayResponseSchema,
signerCheckResponseSchema,
successResponseSchema,
Expand Down Expand Up @@ -167,7 +166,6 @@ export const listProjectsResponse = successResponseSchema(listProjectsResponseSc
export const listProjectMembersResponse = successResponseSchema(listProjectMembersResponseSchema);
export const projectMemberResponse = successResponseSchema(projectMemberResponseSchema);
export const listProjectApiKeysResponse = successResponseSchema(listProjectApiKeysResponseSchema);
export const rpcProvidersResponse = successResponseSchema(rpcProvidersResponseSchema);
export const rpcRelayResponse = successResponseSchema(rpcRelayResponseSchema);

export const tokenResponse = successResponseSchema(tokenResponseSchema);
Expand Down
Loading
Loading