Skip to content

docs: bind sellToken and buyToken into EIP-712 signature (COW-1272) - #8

Merged
jean-neiverth merged 1 commit into
mainfrom
docs/cow-1272-bind-tokens-in-signature
Aug 21, 2026
Merged

jean-neiverth merged 1 commit into
mainfrom
docs/cow-1272-bind-tokens-in-signature

Conversation

@jean-neiverth

Copy link
Copy Markdown
Contributor

Summary

  • Update ProposalData struct in the design document from 7 to 9 fields (sellToken, buyToken added)
  • Update execute() signature in contracts reference: remove separate _sellToken/_buyToken parameters (tokens are now in the signed proposal struct)
  • Update sequence diagrams to reflect the 3-parameter execute(proposal, route, signature)
  • Update sub-solver integration guide field count and pre-launch checklist

Context

Companion to bleu/byos-contracts#39 (COW-1272 audit findings). The audit identified that _buyToken was free calldata — not part of the EIP-712 signature — allowing a signature to theoretically be reused with an unrelated measurement token. Both trade tokens are now bound into the signed struct.

Test plan

  • Verify ProposalData struct matches the contract's ITrampoline.sol
  • Verify execute() signature matches the contract interface
  • Verify sequence diagrams are consistent with the new call shape
  • Verify field count in integration guide matches

…(COW-1272)

Reflect the contract change that binds sellToken and buyToken into the
EIP-712 signed ProposalData struct (9 fields, up from 7) and removes
the separate token parameters from execute().
@linear-code

linear-code Bot commented Aug 20, 2026

Copy link
Copy Markdown

COW-1272

@yvesfracari yvesfracari left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The documentation update is directionally correct once the companion contract and service changes land. Please keep the dependency tracked before exposing this flow to sub-solvers.

Comment thread design-document.md
```solidity
struct ProposalData {
bytes32 orderUidHash; // keccak256(order_uid) — ties to a specific order
address sellToken; // the trade's sell token, signed to prevent cross-pair reuse

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should — byos-contracts#40 doesn't add buyToken into the signed interface. Don't forget to add it in a next PR.

@jean-neiverth
jean-neiverth merged commit 40cd6c9 into main Aug 21, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants