Least Authority audit follow-up: require XMR quote refund addresses and validate all supplied refund addresses

Context

This MR follows up on Suggestion 3 from Least Authority’s XMR audit review:

Make refund_address required for requests to the quote endpoints.

Least Authority noted that both quote endpoints could return parsable memos without a refund address. That is unsafe for source chains such as XMR, where the sender cannot be reliably derived from the inbound transaction and therefore cannot serve as a fallback refund destination.

This implementation scopes the requirement to chains that require an explicit refund address (currently XMR) rather than making the field globally mandatory. When refund_address is supplied for any chain, it is validated against the source chain and configured network. XMR addresses must also use a supported address form.

Changes

  • Require refund_address for both swap and limit quotes when the source chain requires an explicit refund address.
  • Resolve THORName aliases before validation.
  • Validate supplied refund addresses against:
    • the actual source chain,
    • the configured network,
    • supported XMR address forms.
  • Preserve optional refund addresses for ordinary source chains and THOR-sourced assets such as XMR synths.
  • Preserve valid legacy UTXO address formats.
  • Include the resolved refund address in generated swap and limit-order memos.
  • Update protobuf and OpenAPI documentation and generated artifacts.
  • Repair XMR quote memo regression fixtures to use source-chain BTC refund addresses.

Test coverage

Covers both swap and limit quotes for:

  • missing XMR refund addresses,
  • wrong-chain and wrong-network addresses,
  • unsupported XMR address forms,
  • valid XMR standard addresses and subaddresses,
  • THORName resolution,
  • malformed addresses,
  • BTC bech32 and legacy addresses,
  • optional ordinary-chain refunds,
  • XMR synth source-chain behavior,
  • generated memo contents.

Merge request reports

Loading
Loading