Verify a Smart Contract - General - Algorand

Verify a Smart Contract

post by bara on Apr 1, 2022

Hello guys,

As I said on a previous topic, I’m currently developing a dApp that should manage a simple Car Sharing application.

As of now, for each trip I will deploy a new app with an encrypted transaction note, and I will recover the trip list with the Algorand Indexer.

For security reasons, is it sufficient to check the application code hash with an expected one?

I would prefer to do something more like this: use a stateless contract to sign my applications and then accept only signed applications from the indexer, but I don’t know if it makes sense compared to checking the application code.

post by stephane on Apr 1, 2022

Have you gotten a solution for this particular issue yet? I am experiencing the same thing. I would prefer this feature to be included.

post by bara on Apr 2, 2022

Hi, actually I’m still searching for the best solution. If I can’t afford a better one, probably I’ll move on with simply checking the approval program and the clear state program code.

Hope that someone with more experience than I will give an answer.

post by fabrice on Apr 2, 2022

Yes, both for approval and clear program.

I see three options:

post by bara on Apr 3, 2022

Thanks a lot, I think that the second solution is what I need!

One last thing: I’ve already a stateless contract that is funded and created after the application creation to be used as an escrow. Maybe I should use that contract also to make these checks? Or is it better to keep these logics separated?

post by fabrice on Apr 3, 2022

I would recommend using the application account of the smart contract as escrow.

This is the modern and safer way to proceed.

post by bara on Apr 4, 2022

Ok, thanks a lot for your replies.

post by stephane on Apr 4, 2022

Thanks! This helped me also.