Skip to content

fix(awm): gate and authorize MPCv2 recovery - #271

Closed
ralph-bitgo[bot] wants to merge 1 commit into
masterfrom
wcn-1931-gate-mpcv2-recovery
Closed

ralph-bitgo[bot] wants to merge 1 commit into
masterfrom
wcn-1931-gate-mpcv2-recovery

Conversation

@ralph-bitgo

@ralph-bitgo ralph-bitgo Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

What

  • Enforce RECOVERY_MODE before MPCv2 recovery begins.
  • Require scoped mTLS authorization and operator approval for the requested wallet and transaction before key retrieval.
  • Verify returned key shares against the approved wallet.
  • Cover disabled mode, unauthorized requests, approval mismatches, share mismatches, and successful ETH/Cosmos signing; document operator setup and renew the expired synthetic test certificate.

Why

The MPCv2 recovery endpoint lacked its intended authorization boundary. This change makes recovery fail closed and requires scoped authorization plus an explicitly approved request before signing can proceed.

Deployment note

MPCv2 recovery now requires the new recovery authorization and transaction approval settings. Existing deployments must provision those controls before using this endpoint. Ordinary signing and other recovery endpoints are unchanged.

Test plan

  • TypeScript type-check, production build, and ESLint pass.
  • Focused recovery/config tests pass, including HTTPS authorization and synthetic-share signing coverage.
  • Built AWM smoke-tested disabled and unauthorized recovery paths.
  • Full repository test suite passed in GitHub CI. A single-process local suite load exited 137 before test output in this sandbox.

Ticket: WCN-1931

@ralph-bitgo
ralph-bitgo Bot force-pushed the wcn-1931-gate-mpcv2-recovery branch from 5a62803 to 16fa90e Compare September 24, 2026 15:32
@linear-code

linear-code Bot commented Sep 24, 2026

Copy link
Copy Markdown

WCN-1931

Comment thread src/__tests__/api/advancedWalletManager/recoveryMpcV2.test.ts Fixed
Comment thread src/__tests__/api/advancedWalletManager/recoveryMpcV2.test.ts Fixed
Comment thread src/__tests__/api/advancedWalletManager/recoveryMpcV2.test.ts Fixed
@ralph-bitgo
ralph-bitgo Bot force-pushed the wcn-1931-gate-mpcv2-recovery branch from 60beaaf to 9bad2dc Compare September 24, 2026 15:38
};
const app = advancedWalletManagerApp(cfg);
const server = https.createServer(
{ cert: testCert, key: testKey, ca: testCert, requestCert: true, rejectUnauthorized: false },
@pranavjain97
pranavjain97 force-pushed the wcn-1931-gate-mpcv2-recovery branch from 8dbeb30 to e0be195 Compare September 24, 2026 21:18
@pranavjain97

Copy link
Copy Markdown
Contributor

addressing as part of #270

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants