mirror of
https://github.com/pezkuwichain/pwap.git
synced 2026-08-12 03:30:57 +00:00
fix/function-authorization
two-factor-auth and notifications-manager run with the service role, so they
bypass RLS and whatever user id they act on is the entire authorisation
decision. Both read that id from the request body, and neither checked who was
calling. Access-Control-Allow-Origin was '*' on both.
Confirmed against the live endpoint: with only the public anon key and no user
session, from an arbitrary origin,
POST /functions/v1/two-factor-auth {"action":"check","userId":"<any-uuid>"}
-> 200 {"success":true,"enabled":false}
VERIFY_JWT is on and does not stop this, because the anon key is itself a valid
JWT and every browser has it. The same path reaches "disable", so anyone could
turn off another account's 2FA, and read, delete or forge their notifications.
The client already sends the signed-in user's token — functions.invoke puts the
session access token in the Authorization header — so the caller can simply be
read from it. Both functions now do that and ignore the body's userId. An
anon-key call carries no user, so it is rejected with 401.
create is the one action that may target someone else, because AdminPanel
notifies other users; that path now requires admin or super_admin in
admin_roles. CORS drops to the same allowlist the other functions here use.
No frontend change: the body may keep sending userId, it is simply not read.
Note: 2FA is not yet enforced at login — TwoFactorVerify is not referenced
anywhere and Login.tsx never checks it, so enrolling does not currently protect
sign-in. Tracked separately; this change is about the endpoints themselves.
Pezkuwi Web App Projects (PWAP)
Monorepo for Pezkuwi blockchain frontend applications.
Project Structure
pwap/
├── web/ # Main web application
├── mobile/ # Mobile application (React Native + Expo)
├── backend/ # Backend API services
├── shared/ # Shared code and utilities
└── package.json # Root package with build scripts
Related Repositories
| Repository | Description | URL |
|---|---|---|
| pezkuwi-sdk-ui | Blockchain Explorer & Developer Tools | https://github.com/pezkuwichain/pezkuwi-sdk-ui |
| pezkuwi-extension | Browser Wallet Extension | https://github.com/pezkuwichain/pezkuwi-extension |
Projects
1. web/ - Main Web Application
Status: ✅ Production Ready
The primary web interface for Pezkuwi blockchain at app.pezkuwichain.io
Tech Stack:
- React 18 + TypeScript
- Vite
- @pezkuwi/api
- Supabase (Auth & Database)
- Tailwind CSS + shadcn/ui
- i18next
Features:
- Wallet integration (Pezkuwi Extension)
- Live blockchain data
- Staking dashboard
- DEX/Swap interface
- P2P Fiat Trading with atomic escrow
- Transaction history
- Multi-language support (EN, TR, KMR, CKB, AR, FA)
- Governance with live blockchain integration
cd web
npm install
npm run dev
2. mobile/ - Mobile Application
Status: 🚧 In Development
React Native Expo app for iOS and Android.
Features:
- Welcome screen with language selection
- Multi-language support (6 languages with RTL)
- Authentication (Sign In/Up)
- Main dashboard navigation (5-tab bottom nav)
- Wallet integration with @pezkuwi/api
- Live blockchain data (HEZ, PEZ, USDT)
- Send/receive transactions
- Biometric authentication
cd mobile
npm install
npm start
3. backend/ - Backend Services
API services for the applications.
cd backend
npm install
npm run dev
4. shared/ - Shared Code
Common code, types, and utilities used across all platforms.
shared/
├── types/ # TypeScript type definitions
├── utils/ # Helper functions
├── blockchain/ # Blockchain utilities
├── constants/ # App constants
├── images/ # Shared images and logos
└── i18n/ # Internationalization
Quick Start
Prerequisites
- Node.js 18+
- npm
Installation
# Clone repository
git clone https://github.com/pezkuwichain/pwap.git
cd pwap
# Install all dependencies
npm install
# Or install individually
npm run install:web
npm run install:mobile
npm run install:backend
Build All Projects
npm run build
This builds:
web- Vite production buildpezkuwi-sdk-ui- Full SDK UI build (separate repo)mobile- Expo web export
Development
# Run web and mobile in parallel
npm run dev
# Or run individually
npm run dev:web
npm run dev:mobile
Multi-Language Support
All applications support:
- 🇬🇧 English (EN)
- 🇹🇷 Türkçe (TR)
- ☀️ Kurmancî (KMR)
- ☀️ سۆرانی (CKB)
- 🇸🇦 العربية (AR)
- 🇮🇷 فارسی (FA)
RTL support for CKB, AR, FA.
Scripts
| Command | Description |
|---|---|
npm run build |
Build all projects |
npm run dev |
Start development servers |
npm run lint |
Run linters |
npm run test |
Run tests |
npm run install:all |
Install all dependencies |
Links
- Website: https://app.pezkuwichain.io
- Website (alt): https://pex.mom
- Exchange: https://pex.network
- Documentation: https://docs.pezkuwichain.io
License
Apache-2.0
Languages
TypeScript
83.6%
PLpgSQL
8.7%
Rust
3.8%
JavaScript
2.3%
CSS
0.7%
Other
0.8%