Skip to content

feat(rpc): add IsInvitationCodeValid endpoint - #2748

Merged
kkovaacs merged 3 commits into
0xMiden:nextfrom
0xnullifier:feat/rpc/invitation-code-validation
Oct 8, 2026
Merged

kkovaacs merged 3 commits into
0xMiden:nextfrom
0xnullifier:feat/rpc/invitation-code-validation

Conversation

@0xnullifier

@0xnullifier 0xnullifier commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

This PR adds IsInvitationCodeValid, a read-only gRPC method on NodeService that reports whether an invitation code can still be used for registration. It returns true when allowlist enforcement is disabled, or when the code exists in the registry and no account has registered with it. Unknown and consumed codes return false. With enforcement enabled, an empty code is rejected with INVALID_ARGUMENT. Full nodes forward the query to their upstream sequencer, as they do for IsAccountAllowed and RegisterAccount.

Clients currently have no way to check a code before they build an account and call RegisterAccount. A sign-up flow has to construct the account first and only learns that the code is unknown or already used from the registration error. This endpoint lets a client validate the code up front, mirroring what IsAccountAllowed already offers for account IDs.

Points worth attention:

  • The request carries the plaintext invitation code, so the message is excluded from derived Debug in both prost config and the Decoded* generation, with hand-written redacting Debug impls. This follows the existing RegisterAccountRequest pattern and is covered by a test. The handler also does not record the code on its tracing span.
  • The response is a plain bool and never reveals which account holds a code. Only "unused" is reported as valid; a registered code returns false so the answer matches what RegisterAccount would accept for a new account.
  • When enforcement is disabled the handler returns true without touching the database or validating the code, consistent with IsAccountAllowed and with RegisterAccount accepting any code in that mode.

Changelog

[[entry]]
scope       = "rpc"
impact      = "added"
description = "Add `IsInvitationCodeValid` endpoint that reports whether an invitation code is unused or allowlist enforcement is disabled."

Add a read-only gRPC method that reports whether an invitation code
can still be used for registration. It returns true when allowlist
enforcement is disabled or when the code exists and no account has
registered with it. Unknown and consumed codes return false.

The request type is excluded from derived Debug so invitation codes
never reach logs, following the RegisterAccountRequest pattern. Full
nodes forward the query to the sequencer.
@kkovaacs
kkovaacs merged commit e3fdd25 into 0xMiden:next Oct 8, 2026
22 of 24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants