Verifiable, Blockchain-Based Freelance Code Escrow & Deployment Binding Platform on BNB Smart Chain (BSC Testnet).
Freelance software transactions involve risks for both clients and developers, including unverified source code, unreliable delivery, and payment disputes. GitLock addresses these risks by verifying source-code integrity and deployment consistency, then using a blockchain-based escrow smart contract to hold payment until the client approves the delivery and ownership of the verified GitHub repository is transferred to them.
sequenceDiagram
autonumber
actor Dev as Developer
participant GL as GitLock Backend
actor Client as Client
participant SC as GitLock Escrow
Dev->>GL: Submit project ZIP, repository, commit hash, staging URL
GL->>GL: Verify source hash and deployment
Client->>GL: Test staging demo and approve
Client->>SC: Deposit BNB into escrow
Dev->>Client: Transfer repository ownership
GL->>GL: Verify ownership using GitHub API
GL->>GL: Sign oracle attestation
Client->>SC: Submit attestation
SC->>SC: Verify attestation
SC->>Dev: Release BNB payment
SC->>Client: Unlock code access
- Project Submission: Developer submits the source ZIP, GitHub repository, commit hash, and deployment URL.
- Verification: GitLock verifies source-code integrity (ZIP CRC/SHA-256 vs GitHub commit archive) and deployment consistency (GitHub Deployments API).
- Client Approval: Client tests the live deployment URL and approves it.
- Escrow Funding: Client deposits BNB into the
GitLockEscrowsmart contract on BNB Smart Chain Testnet. - Repository Transfer: Developer transfers GitHub repository ownership to the client.
- Ownership Verification: GitLock backend verifies the transfer via the GitHub API and cryptographically signs an EIP-191 oracle attestation.
- Payment Release: Smart contract verifies the oracle attestation signature and releases BNB to the developer, while the platform unlocks the decrypted source code for the client.
The smart contract is written in Solidity 0.8.20 and utilizes all fundamental and advanced Solidity concepts:
- Inheritance & Abstract Contracts:
IGitLockEscrow: Core interface defining data structures, enums, errors, events, and functions.EscrowBase: Abstract contract managing storage mappings, modifiers, and access control.AttestationVerifier: Abstract contract implementing cryptographic hashing, EIP-191 message prefixing, andecrecoversignature verification.GitLockEscrow: Main contract inheriting fromEscrowBaseandAttestationVerifier.
- Structs:
Deal: Stores deal ID, client, developer, amount, status, repository name, and timestamps.OwnershipAttestation: Encapsulates oracle attestation data (dealId, developer, client, repoFullName, nonce, deadline).
- Enums:
DealState { None, Created, Funded, Approved, Completed, Refunded }
- Custom Errors:
DealNotFound,DealAlreadyExists,InvalidState,InvalidDepositAmount,Unauthorized,InvalidZeroAddress,InvalidOracleSignature,AttestationExpired,NonceAlreadyUsed,TransferFailed,ReentrancyGuardReentrantCall.
- Modifiers:
onlyOwner,onlyClient,onlyDeveloper,inState,validDeal,nonReentrant.
- Events:
DealCreated,EscrowFunded,DeploymentApproved,OwnershipAttested,PaymentReleased,EscrowRefunded,OracleUpdated.
- Payable Functions:
createAndFundDeal(bytes32, address, string)(payable)fundEscrow(bytes32)(payable)releasePaymentWithAttestation(...)(transfers BNB via secure.call)refund(bytes32)(refunds BNB)receive(),fallback()(payable)
- View & Pure Functions:
getDeal(bytes32)(view)isNonceUsed(bytes32)(view)getOracle()(view)hashAttestation(...)(pure)getEthSignedMessageHash(...)(pure)recoverSigner(...)(pure)splitSignature(...)(pure assembly)verifyAttestationSignature(...)(pure)projectIdToDealId(...)(pure)
- Mappings:
mapping(bytes32 => Deal) internal deals;mapping(bytes32 => bool) public usedNonces;(replay attack protection)mapping(address => uint256) public totalFundedByClient;mapping(address => uint256) public totalEarnedByDeveloper;
- Network: BNB Smart Chain Testnet (BSC Testnet)
- Chain ID:
97(0x61) - Contract Address:
0x1642fb0220915E10b9e21cC18EFE10297154C67A - Oracle Signer Address:
0x392e227Bf9201A328f9ebD8DBee33f3cBDB15b37 - Minimal Test Amount:
0.0001 tBNB(designed to conserve testnet faucet funds) - BscScan Explorer: https://testnet.bscscan.com
cd contracts
forge test -vvvAll 11 unit & integration tests pass with 100% success rate:
test_InitialState: Verifies oracle and owner initializationtest_CreateAndFundDeal: Verifies deposit and deal creationtest_RevertWhen_ZeroDeposit: Reverts on zero deposittest_RevertWhen_SelfDealing: Reverts if client == developertest_ApproveDeployment: Verifies client live deployment approvaltest_ReleasePaymentWithValidAttestation: Verifies cryptographic oracle attestation and BNB transfertest_RevertWhen_InvalidOracleSignature: Reverts on forged or unauthorized signaturetest_RevertWhen_AttestationExpired: Reverts on expired deadlinetest_RevertWhen_NonceReused: Reverts on replay attackstest_Refund: Verifies client refundtest_AdminUpdateOracle: Verifies access control on oracle rotation
cd backend
node scripts/verifyBlockchainEscrowE2E.jsExecutes the full 7-step lifecycle live on BSC Testnet with minimal gas and verifies balance release.
- Smart Contracts: Solidity
^0.8.20, Foundry (forge,cast), BNB Smart Chain Testnet - Backend: Node.js, Express.js, Ethers.js v6, PostgreSQL, Octokit / GitHub REST API, AES-256 / RSA Hybrid Encryption
- Frontend: Next.js 16 (App Router), React 19, Tailwind CSS, Lucide React, Ethers.js v6 Web3 integration with MetaMask