Skip to content

feat(rfq): add production module audit and service hardening #67

Description

@0xMuang

Goal

Add production RFQ module evidence and service-security seams without turning the reference service into a hosted dealer.

Scope

  • pricing snapshot/freshness and inventory-risk result envelope
  • PII-free quote audit record with module/key-reference versions
  • local verification of external signer output before response
  • authenticated taker/client binding, request-size limit and rate-limit seams
  • metrics and incident/reconciliation hooks
  • scaffold documentation showing where operators supply TLS, secret manager and WORM export

Acceptance criteria

  • stale pricing/risk dependencies fail before nonce/signing
  • caller cannot choose maker, amountOut, nonce or module version
  • secrets never enter config, logs, images or audit records
  • quote issuance and rejected requests expose bounded operational metrics
  • Router fill-time compliance remains the only final settlement gate

Depends on #64. Production pricing strategy, legal approval and hosted infrastructure are out of scope.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions