Verify a Smart Contract - General - Algorand
Verify a Smart Contract
post by bara on Apr 1, 2022
Hello guys,
As I said on a previous topic, I’m currently developing a dApp that should manage a simple Car Sharing application.
As of now, for each trip I will deploy a new app with an encrypted transaction note, and I will recover the trip list with the Algorand Indexer.
For security reasons, is it sufficient to check the application code hash with an expected one?
I would prefer to do something more like this: use a stateless contract to sign my applications and then accept only signed applications from the indexer, but I don’t know if it makes sense compared to checking the application code.
post by stephane on Apr 1, 2022
Have you gotten a solution for this particular issue yet? I am experiencing the same thing. I would prefer this feature to be included.
post by bara on Apr 2, 2022
Hi, actually I’m still searching for the best solution. If I can’t afford a better one, probably I’ll move on with simply checking the approval program and the clear state program code.
Hope that someone with more experience than I will give an answer.
post by fabrice on Apr 2, 2022
Yes, both for approval and clear program.
I see three options:
- Create a single big smart contract where each trip is actually a fresh new account that is rekeyed to the application account and that stores trip details. So now you have two types of accounts with local storage: the trip ones that are rekeyed to the application account (and used instead of global storage), and the current local storage account you’re using. See NFT marketplace general smart contract architecture question - #2 by fabrice
- Create a stateless contract (in contract account mode: Modes of use - Algorand Developer Portal) that would actually be the creator of the application and issue the application creation transaction. The stateless contract would verify the hash in the application transaction. You would then just need to check the creator of the application. Since the application creation transaction increases minimum balance and costs a transaction fee, the stateless smart contract can require to be called with a transaction paying for the above.
- Create a factory stateful smart contract: smart contracts can now issue any inner transaction and hence can create smart contracts from their application account (not to be confused with contract account that exists only for stateless contract). It works very similarly to the option above but you may hit size limits of code.
post by bara on Apr 3, 2022
Thanks a lot, I think that the second solution is what I need!
One last thing: I’ve already a stateless contract that is funded and created after the application creation to be used as an escrow. Maybe I should use that contract also to make these checks? Or is it better to keep these logics separated?
post by fabrice on Apr 3, 2022
I would recommend using the application account of the smart contract as escrow.
This is the modern and safer way to proceed.
post by bara on Apr 4, 2022
Ok, thanks a lot for your replies.
post by stephane on Apr 4, 2022
Thanks! This helped me also.