Enforce paper-only research mode - #1
Open
yxuan629-lab wants to merge 4 commits into
Open
Conversation
yxuan629-lab
marked this pull request as ready for review
July 20, 2026 07:36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PAPER_ONLY = Trueexecution boundaryWhy
The baseline project exposed real-trading and credential-handling paths that are inappropriate for a strict research build. This change makes the branch fail closed: live credentials reject startup, exchange and Web3 execution implementations are absent, and no configuration switch can restore real trading.
User and developer impact
This branch supports simulated trading and strategy research only. It does not connect a wallet, create real orders, use real funds, sign transactions, or redeem on chain.
CLAWBY_API_KEYremains optional for read-only market data; without it the service starts in a restricted data mode.Validation
requirements-dev.txt53 passed, 2 warningspip check: no broken requirementspy-clob-clientandweb3: not installed127.0.0.1:8643/healthand/admin: HTTP 200Known follow-ups
The dependency audit records one high Vite advisory aggregate and one moderate esbuild advisory affecting development-server scenarios. No forced fix or major-version upgrade was applied; upgrading Vite should be evaluated separately with compatibility and browser regression testing.
See
SECURITY_AUDIT.md,PAPER_ONLY_MIGRATION.md,DEPENDENCY_AUDIT.md, andTEST_REPORT.mdfor detailed evidence.