Skip to content

check onchain order owner in ban list - #5001

Merged
AryanGodara merged 3 commits into
mainfrom
check-banned-onchain-user
Sep 30, 2026
Merged

AryanGodara merged 3 commits into
mainfrom
check-banned-onchain-user

Conversation

@MartinquaXD

Copy link
Copy Markdown
Contributor

Description

Currently the scan to filter out orders from banned users does not check the onchain account that placed an onchain order. So if a malicious actor creates an ethflow order it would not get flagged.
The respective field gets populated by this query here.

Changes

Also check the onchain_user address for ban status.
Refactored the code slightly to have 1 place to define all the relevant addresses and use them in 1 places.

How to test

extended existing unit test

@MartinquaXD
MartinquaXD requested a review from a team as a code owner September 30, 2026 06:28
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @MartinquaXD's task in 1m 6s —— View job


PR Review: check onchain order owner in ban list

I reviewed the change to find_banned_user_orders. This is a correct and clean fix.

Summary

  • The added onchain_user check is correct: it's Option<Address>, chains cleanly, and closes the gap where a banned actor placing an on-chain order (e.g. ethflow) would previously slip through since owner is the ethflow contract rather than the actual user.
  • The users_to_check refactor removes the duplication between the pre-fetch pass and the filter pass — good simplification.
  • The extended unit test covers each combination (owner / receiver / onchain_user banned, all-clean, all-banned) and correctly asserts a banned order is only reported once.

One minor point (posted inline): the function's doc comment still only mentions "owners or receivers" and should be updated to reflect that onchain_user is now also checked.

Nothing blocking — LGTM aside from the stale doc comment.

Comment thread crates/autopilot/src/solvable_orders.rs
@MartinquaXD MartinquaXD added the hotfix Labels PRs that should be applied into production right away label Sep 30, 2026

@AryanGodara AryanGodara left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@AryanGodara
AryanGodara added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit e01b2d4 Sep 30, 2026
40 of 41 checks passed
@AryanGodara
AryanGodara deleted the check-banned-onchain-user branch September 30, 2026 07:59
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 30, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

hotfix Labels PRs that should be applied into production right away

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants