Authorization
Protocol

Authorization

Detailed breakdown of require_auth checks and administrative privileges.

The SplitPay contract enforces cryptographic authority at the Soroban host boundary. No entity can act on behalf of another address without explicit signatures.

Soroban Authorization Model

Soroban requires authorization via Address::require_auth(). If a transaction payload is submitted without a valid signature corresponding to that address, the contract execution immediately aborts with an authorization failure.

Permission Matrix

MethodRequired AuthorizerCode Check
initializeContract Administratoradmin.require_auth()
create_poolDesignated Pool Ownerowner.require_auth()
add_memberPool Ownerpool.owner.require_auth()
remove_memberPool Ownerpool.owner.require_auth()
update_member_sharePool Ownerpool.owner.require_auth()
set_pool_statusPool Ownerpool.owner.require_auth()
create_paymentPayerpayer.require_auth()
settle_paymentPayment Payerpayment.payer.require_auth()

Impersonation Prevention

Even if an attacker passes an arbitrary address to owner or payer, the runtime check rejects the transaction unless the corresponding cryptographic key signed the operation.