Protocol
Authorization
Detailed breakdown of require_auth checks and administrative privileges.
The SplitPay contract enforces cryptographic authority at the Soroban host boundary. No entity can act on behalf of another address without explicit signatures.
Soroban Authorization Model
Soroban requires authorization via Address::require_auth(). If a transaction payload is submitted without a valid signature corresponding to that address, the contract execution immediately aborts with an authorization failure.
Permission Matrix
| Method | Required Authorizer | Code Check |
|---|---|---|
| initialize | Contract Administrator | admin.require_auth() |
| create_pool | Designated Pool Owner | owner.require_auth() |
| add_member | Pool Owner | pool.owner.require_auth() |
| remove_member | Pool Owner | pool.owner.require_auth() |
| update_member_share | Pool Owner | pool.owner.require_auth() |
| set_pool_status | Pool Owner | pool.owner.require_auth() |
| create_payment | Payer | payer.require_auth() |
| settle_payment | Payment Payer | payment.payer.require_auth() |
Impersonation Prevention
Even if an attacker passes an arbitrary address to owner or payer, the runtime check rejects the transaction unless the corresponding cryptographic key signed the operation.