Least Authority audit follow-up: require XMR quote refund addresses and validate all supplied refund addresses
Context
This MR follows up on Suggestion 3 from Least Authority’s XMR audit review:
Make
refund_addressrequired for requests to the quote endpoints.
Least Authority noted that both quote endpoints could return parsable memos without a refund address. That is unsafe for source chains such as XMR, where the sender cannot be reliably derived from the inbound transaction and therefore cannot serve as a fallback refund destination.
This implementation scopes the requirement to chains that require an explicit refund address (currently XMR) rather than making the field globally mandatory. When refund_address is supplied for any chain, it is validated against the source chain and configured network. XMR addresses must also use a supported address form.
Changes
- Require
refund_addressfor both swap and limit quotes when the source chain requires an explicit refund address. - Resolve THORName aliases before validation.
- Validate supplied refund addresses against:
- the actual source chain,
- the configured network,
- supported XMR address forms.
- Preserve optional refund addresses for ordinary source chains and THOR-sourced assets such as XMR synths.
- Preserve valid legacy UTXO address formats.
- Include the resolved refund address in generated swap and limit-order memos.
- Update protobuf and OpenAPI documentation and generated artifacts.
- Repair XMR quote memo regression fixtures to use source-chain BTC refund addresses.
Test coverage
Covers both swap and limit quotes for:
- missing XMR refund addresses,
- wrong-chain and wrong-network addresses,
- unsupported XMR address forms,
- valid XMR standard addresses and subaddresses,
- THORName resolution,
- malformed addresses,
- BTC bech32 and legacy addresses,
- optional ordinary-chain refunds,
- XMR synth source-chain behavior,
- generated memo contents.