pezkuwichain a8f41cd47f security(p2p): fix withdrawal BOLA, financial RLS exposure, admin dispute escrow
Critical/high audit remediation on the custodial P2P ledger. Auth model is
wallet-based; identity (citizen/visa) is cryptographically bound to a wallet
(People Chain tiki.citizenNft / active p2p_visa), which enables a correct fix.

- Withdrawal BOLA (CRITICAL): process-withdraw now requires a wallet-SIGNED
  challenge; server verifies signature (raw + <Bytes> forms), asserts the signer
  OWNS the identity, consumes a single-use nonce (replay), and derives user_id
  server-side — the client-supplied user_id is ignored. process-withdrawal (batch)
  now requires the service-role key (was: any bearer, incl. public anon key).
  request_withdraw is REVOKEd from anon/authenticated + service-role guarded.
- Financial RLS (HIGH): drop the blanket USING(true) SELECT on user_internal_balances,
  p2p_balance_transactions, p2p_deposit_withdraw_requests; lock p2p_user_payment_methods
  (IBAN PII) + p2p_fiat_disputes UPDATE to service_role; legitimate reads move behind
  scoped SECURITY DEFINER RPCs.
- Deposit integrity: verify-deposit now binds the on-chain sender to identity ownership
  before crediting.
- Admin dispute (CRITICAL fund-logic): DisputeResolutionPanel relabeled trades without
  moving escrow. New admin-signed resolve-dispute function + admin_resolve_dispute RPC
  moves escrow (release/refund/split) atomically with correct accounting (avoids the
  double-count in the legacy resolve_p2p_dispute). Client isAdmin documented as cosmetic.

DEPLOY RUNBOOK (gated; owner runs): 1) apply migrations 20260225/20260725* in order;
2) deploy edge functions process-withdraw, process-withdrawal, verify-deposit, resolve-dispute;
3) set edge secrets PEOPLE_RPC_ENDPOINT (+ optional ADMIN_WALLETS); 4) ship frontend.
Migrations + functions + frontend must go together or the app breaks.

KNOWN RESIDUAL (Round 2 — as severe as the withdrawal BOLA): release_/lock_/refund_
escrow_internal still have PUBLIC EXECUTE and the client calls release_escrow_internal
directly with the anon key from confirmPaymentReceived -> an anon caller can drain any
victim's LOCKED balance. Fix = a wallet-signed confirm-payment edge function (same
pattern as withdrawals) before revoking PUBLIC execute. Not yet fixed.
2026-07-25 00:09:03 -07:00
2025-10-22 18:05:19 -07:00

Pezkuwi Web App Projects (PWAP)

Monorepo for Pezkuwi blockchain frontend applications.

Project Structure

pwap/
├── web/                    # Main web application
├── mobile/                 # Mobile application (React Native + Expo)
├── backend/                # Backend API services
├── shared/                 # Shared code and utilities
└── package.json            # Root package with build scripts
Repository Description URL
pezkuwi-sdk-ui Blockchain Explorer & Developer Tools https://github.com/pezkuwichain/pezkuwi-sdk-ui
pezkuwi-extension Browser Wallet Extension https://github.com/pezkuwichain/pezkuwi-extension

Projects

1. web/ - Main Web Application

Status: Production Ready

The primary web interface for Pezkuwi blockchain at app.pezkuwichain.io

Tech Stack:

  • React 18 + TypeScript
  • Vite
  • @pezkuwi/api
  • Supabase (Auth & Database)
  • Tailwind CSS + shadcn/ui
  • i18next

Features:

  • Wallet integration (Pezkuwi Extension)
  • Live blockchain data
  • Staking dashboard
  • DEX/Swap interface
  • P2P Fiat Trading with atomic escrow
  • Transaction history
  • Multi-language support (EN, TR, KMR, CKB, AR, FA)
  • Governance with live blockchain integration
cd web
npm install
npm run dev

2. mobile/ - Mobile Application

Status: 🚧 In Development

React Native Expo app for iOS and Android.

Features:

  • Welcome screen with language selection
  • Multi-language support (6 languages with RTL)
  • Authentication (Sign In/Up)
  • Main dashboard navigation (5-tab bottom nav)
  • Wallet integration with @pezkuwi/api
  • Live blockchain data (HEZ, PEZ, USDT)
  • Send/receive transactions
  • Biometric authentication
cd mobile
npm install
npm start

3. backend/ - Backend Services

API services for the applications.

cd backend
npm install
npm run dev

4. shared/ - Shared Code

Common code, types, and utilities used across all platforms.

shared/
├── types/          # TypeScript type definitions
├── utils/          # Helper functions
├── blockchain/     # Blockchain utilities
├── constants/      # App constants
├── images/         # Shared images and logos
└── i18n/           # Internationalization

Quick Start

Prerequisites

  • Node.js 18+
  • npm

Installation

# Clone repository
git clone https://github.com/pezkuwichain/pwap.git
cd pwap

# Install all dependencies
npm install

# Or install individually
npm run install:web
npm run install:mobile
npm run install:backend

Build All Projects

npm run build

This builds:

  1. web - Vite production build
  2. pezkuwi-sdk-ui - Full SDK UI build (separate repo)
  3. mobile - Expo web export

Development

# Run web and mobile in parallel
npm run dev

# Or run individually
npm run dev:web
npm run dev:mobile

Multi-Language Support

All applications support:

  • 🇬🇧 English (EN)
  • 🇹🇷 Türkçe (TR)
  • ☀️ Kurmancî (KMR)
  • ☀️ سۆرانی (CKB)
  • 🇸🇦 العربية (AR)
  • 🇮🇷 فارسی (FA)

RTL support for CKB, AR, FA.

Scripts

Command Description
npm run build Build all projects
npm run dev Start development servers
npm run lint Run linters
npm run test Run tests
npm run install:all Install all dependencies

License

Apache-2.0

S
Description
No description provided
Readme MIT 123 MiB
Languages
TypeScript 87.9%
PLpgSQL 4.1%
Rust 4.1%
JavaScript 2.5%
CSS 0.7%
Other 0.6%