View Issue Details

IDProjectCategoryView StatusLast Update
0009349Talerchallengerpublic2025-03-06 21:28
ReporterChristian Grothoff Assigned Tosebasjm  
PriorityhighSeverityfeatureReproducibilityN/A
Status assignedResolutionopen 
Platformi7OSDebian GNU/LinuxOS Versionsqueeze
Product Versiongit (master) 
Target Version1.0 stretch goals 
Summary0009349: enforce read-only address data in challenger SPA
DescriptionWhen the address object has the field "read_only: true" set, the SPA should not permit the user to edit the address and only show it.

Afterwards, the backend should also be modified to ensure that the address is not changed (as we cannot trust the SPA).
TagsNo tags attached.

Activities

sebasjm

2025-03-06 13:54

developer   ~0024168

I don't have instructions to create a scenario where this value is returned neither the API reflect where it is.

Christian Grothoff

2025-03-06 21:27

manager   ~0024171

This is what should happen when the KYC-SPA/exchange triggers challenger to validate an address it got from the KYC-SPA forms (say VQF.*). The idea is that challenger should ONLY validate the address, and it would be bad if the user edited it.

You should be able to trigger it by giving "/setup" a body with the address (see https://docs.taler.net/core/api-challenger.html#setup), or (theoretically, I could never test it!) by submitting the simple "natural person" VQF form to the exchange and then having the KYC process trigger the challenger-based physical address validation.

Issue History

Date Modified Username Field Change
2024-11-22 15:01 Christian Grothoff New Issue
2024-11-22 15:01 Christian Grothoff Status new => assigned
2024-11-22 15:01 Christian Grothoff Assigned To => sebasjm
2025-03-06 13:54 sebasjm Assigned To sebasjm => Christian Grothoff
2025-03-06 13:54 sebasjm Status assigned => feedback
2025-03-06 13:54 sebasjm Note Added: 0024168
2025-03-06 21:27 Christian Grothoff Note Added: 0024171
2025-03-06 21:28 Christian Grothoff Assigned To Christian Grothoff => sebasjm
2025-03-06 21:28 Christian Grothoff Status feedback => assigned