fix: route approve commands through proxy wallet - #42
Conversation
…e proxy - `approve check` now queries the correct wallet (proxy or EOA) based on --signature-type, so users see actual allowances instead of zeros - `approve set` with proxy signature type routes transactions through the Proxy Wallet Factory, batching USDC and CTF approvals per target - `ctf` commands now accept --signature-type for forward compatibility Fixes Polymarket#4 Related: Polymarket#1, Polymarket#24 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Prevents silent routing breakage if DEFAULT_SIGNATURE_TYPE is ever changed to a non-proxy value. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
approve check uses resolve_wallet_address which returns the derived Safe address for gnosis-safe, but approve set only handles proxy and falls through to the EOA path. This would silently approve on the wrong address. Add an early bail for gnosis-safe with guidance to use the Safe wallet interface instead.
|
Addressed the gnosis-safe check/set inconsistency in 09aaa7a. Re: the proxy check comparison - this is already comparing against the literal |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
- Replace hardcoded "proxy" string with config::DEFAULT_SIGNATURE_TYPE to stay consistent with auth.rs and prevent silent divergence - Update proxy approval label to "USDC + CTF" since the batch transaction includes both token approvals Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
approve set determined is_proxy by comparing the signature-type string against config::DEFAULT_SIGNATURE_TYPE, which conflates 'is the default' with 'is a proxy' and duplicates the mapping already in auth. It also let check and set disagree once check moved to resolve_wallet_address. Resolve the wallet once, then classify it by matching against derive_proxy_wallet and derive_safe_wallet, yielding a typed SignatureType. Both paths now agree by construction, and an address that matches none of the three fails loudly instead of silently taking the proxy branch.
|
Good catches, the first and fourth findings were the same root cause. Pushed 0518f04.
Now the wallet is resolved once and classified by matching it against Verified locally: The third finding, that the proxy path label does not mention the CTF |
Summary
Fixes
approveandctfcommands ignoring--signature-type proxy, which caused all on-chain transactions to go from the EOA instead of the proxy wallet.Fixes #4
Related: #1, #24
Changes
src/auth.rsresolve_wallet_address()that returns EOA, proxy, or Safe address based on signature typesrc/main.rssignature_typetoapproveandctfcommandssrc/commands/approve.rsapprove setthrough Proxy Wallet Factory when signature type isproxy; fixapprove checkto query the correct walletsrc/commands/ctf.rssignature_typeparameter for forward compatibilityHow it works
approve check: Now resolves the wallet address based on--signature-type. Withproxy, it queries allowances of the derived proxy wallet instead of the EOA, so users see their actual allowance status.approve set: With--signature-type proxy, encodes USDC approve and CTF setApprovalForAll calls as calldata and routes them through the Proxy Wallet Factory at0xaB45.... This batches both approvals per target into a single factory call, so the proxy wallet gets the approvals instead of the EOA.ctf: Accepts--signature-typebut does not yet route through proxy (marked for follow-up). This is a smaller, separable change.Test plan
cargo fmt --checkpassescargo clippy -- -D warningspassescargo test- all 131 tests passpolymarket approve check --signature-type proxyshows proxy wallet allowancespolymarket approve set --signature-type proxysends approvals through factoryThis contribution was developed with AI assistance (Claude Code).
Note
Medium Risk
Changes on-chain approval submission and which address owns allowances; proxy factory batching is correctness-critical for trading but scoped to the approve command with explicit Safe rejection.
Overview
Fixes
approve(and CLI wiring forctf) ignoring--signature-type, so proxy users were checking allowances and sending approvals from the EOA instead of the trading wallet.Adds
resolve_wallet_addressinauth.rsto map signature type to the EOA, derived proxy, or Gnosis Safe address.approve checkuses that owner when no explicit address is passed.approve setinfers wallet type from the resolved address: EOA keeps the existing direct USDC/CTF txs; proxy batches USDCapprove+ CTFsetApprovalForAllper target through the Proxy Wallet Factory; Gnosis Safe is rejected with guidance to use the Safe UI.main.rspassescli.signature_typeintoapproveandctf;ctfonly accepts the flag for forward compatibility (no proxy routing yet).Reviewed by Cursor Bugbot for commit 0518f04. Bugbot is set up for automated code reviews on this repo. Configure here.