feat: implement grace period protection for reputation-weighted voting - #220
Merged
dDevAhmed merged 2 commits intoMay 30, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Close #173
Summary
This PR implements a Grace Period for Reputation Updates to prevent last-minute reputation manipulation in the TruthBounty voting system.
Previously, users could artificially increase their voting influence by updating their reputation immediately before participating in claim verification. This change introduces a configurable grace period window that restricts recently updated reputation scores from affecting voting power.
When a reputation update occurs within the configured grace period relative to a claim’s creation timestamp, the voter’s effective reputation defaults to the baseline score instead of using the updated value.
Default grace period: 2 days
Problem
Users were able to:
This created a vulnerability in the reputation-weighted verification model.
Solution
Implemented a symmetric grace period window around claim creation:
Behavior
This applies independently per voter.
Contracts Updated
IReputationOracle.solAdded:
getLastReputationUpdate(address user)MockReputationOracle.solAdded timestamp tracking for reputation updates
Added:
lastUpdateTimestampgetLastReputationUpdate()TruthBountyWeighted.solAdded grace period configuration constants
Added:
reputationUpdateGracePeriod_getReputationScoreWithGracePeriod()setReputationUpdateGracePeriod()Updated
vote()to enforce grace period checksAdded governance events and validation errors
Governance Configuration
Defaults
2 days1 hour30 daysGovernance Setter
Testing
Unit Tests
Added comprehensive unit coverage for:
Invariant Tests
Added Foundry invariants ensuring:
Security Impact
Prevented Attacks
Guarantees
Backward Compatibility
This implementation maintains backward compatibility through graceful degradation using
try/catchfor oracle implementations that do not yet support reputation update timestamps.Existing integrations remain functional.
Performance Impact
Test Commands