Skip to content

Pre-launch member removal + address-bound invites (spec) - #186

Closed
franrolotti wants to merge 1 commit into
devfrom
spec/approval-flow-member-removal
Closed

franrolotti wants to merge 1 commit into
devfrom
spec/approval-flow-member-removal

Conversation

@franrolotti

Copy link
Copy Markdown
Contributor

Summary

Contract-side spec for the general invite link / creator-approval flow (app-stacks#99). Implementation will land on this branch.

The spec (docs/specs/approval-flow-upgrade.md) covers:

  • removeMember(id, member) — owner-only, callable strictly before start() (isActive guard closes the window atomically at launch). No refund logic needed: deposits are onlyActive, so pre-start circles hold no member funds.
  • Address-bound invites — typehash becomes Invite(uint256 id,uint256 nonce,address member) and _hashInvite signs msg.sender, so an approved invite is only redeemable by the vetted wallet (closes the bearer-token hole in the approval flow).
  • Why an upgrade is required — the deployed contract has no member-removal path and its invites are bearer tokens; neither is fixable off-chain.
  • Why the upgrade is storage-safe — zero new storage (only existing mappings are written), the typehash is a constant in bytecode, EIP-712 domain state untouched, no reinitializer. Hard gate: identical forge inspect SavingCircles storage-layout between dev and this branch.
  • Layer split — acceptance-criteria table mapping each item of Check issues regarding wallet connections on the app #99 to contract / app / Supabase; the contract stays the enforcement layer only.
  • Execution path — implement + tests (unit, invariant handler, integration), layout check, then the upgrade scripts from 104-deploy-guardrails (commit 9f3de5f, not yet on dev) to execute ProxyAdmin.upgradeAndCall.

Implementation checklist

  • removeMember + MemberRemoved event in SavingCircles and ISavingCircles
  • Member-bound _INVITE_TYPEHASH / _hashInvite
  • Update app/invites.tsx + app/invites.test.ts to the new typed data
  • Unit tests (happy path incl. memberIndex fix-up; revert paths)
  • Invariant handler action for removeMember
  • Integration test: approve → redeem → remove → re-invite → start
  • forge inspect storage-layout diff empty vs dev
  • Merge/cherry-pick upgrade scripts from 104-deploy-guardrails

Coordinated release note: unredeemed old-format invite links stop validating at the upgrade (InvalidSigner), so the app-stacks change that signs member-bound invites ships in the same window.

Contract-side spec for app-stacks#99 (general invite link with creator
approval): adds removeMember (callable strictly before start) and binds
invite signatures to the approved wallet, explains why an upgrade is
required, why it is storage-safe, and how the contract, app, and
Supabase changes together close the issue.
@franrolotti
franrolotti deleted the spec/approval-flow-member-removal branch July 17, 2026 16:56
@franrolotti

Copy link
Copy Markdown
Contributor Author

Repeated. Closing in favour of #185

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant