Closed
Conversation
Adds Basic and Advanced PredicateClient implementations
🚨 Report Summary
For more details view the full report in OpenZeppelin Code Inspector |
There was a problem hiding this comment.
This PR is being reviewed by Cursor Bugbot
Details
Your team is on the Bugbot Free tier. On this plan, Bugbot will review limited PRs each billing cycle for each member of your team.
To receive Bugbot reviews on all of your PRs, visit the Cursor dashboard to activate Pro and start your 14-day free trial.
Member
Author
|
Wondering if we should rename |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Most teams using Predicate only need simple WHO-based access control (KYC, allowlists, time restrictions), but today they're forced to encode function signatures and handle parameters they don't actually use.
Solution
Split into two implementations:
Decision guide: "Do I need different rules based on WHAT users are doing, or just WHO is doing it?"
Note: to simplify the entire flow, we will need to modify the attestation API to ignore the data and msg_value fields
Note
Introduces a reusable
PredicateClientabstract mixin to validate attestations via aPredicateRegistry, with namespaced (ERC-7201) storage.PredicateClientmixin: init via_initPredicateClient, manage policy/registry with_setPolicyID,_setRegistry, getters,PredicateRegistryUpdated/PredicatePolicyIDUpdatedevents, andonlyPredicateRegistrymodifier_authorizeTransactionbuilds aStatementand callsIPredicateRegistry.validateAttestationIPredicateClientandIPredicateRegistryinterfaces, includingStatementandAttestationstructs and policy/validation methods^0.8.4across new/modified filesWritten by Cursor Bugbot for commit dea67aa. This will update automatically on new commits. Configure here.