Skip to content

feat(core): harden GuildPass Core V2 for production readiness (#422) - #423

Open
rupesh-kumar-sah wants to merge 3 commits into
Adamantine-guild:mainfrom
rupesh-kumar-sah:feat/issue-422-harden-core-v2
Open

rupesh-kumar-sah wants to merge 3 commits into
Adamantine-guild:mainfrom
rupesh-kumar-sah:feat/issue-422-harden-core-v2

Conversation

@rupesh-kumar-sah

Copy link
Copy Markdown

Summary

Closes #422

Hardens GuildPass Core V2 for production readiness with end-to-end authorization boundaries, idempotency, structured redacted logging, typed error handling, sliding-window rate limiting, predictable Stellar transaction failure handling with circuit breakers, and observability probes.

Implemented Architecture & Controls

  1. Mutation Authorization Boundary (src/security/auth.ts):

    • Integrated @guildpass/capability-token to verify incoming Bearer capability tokens.
    • Enforced route guards (requireAuth, requireScopes, requireAnyScope) requiring explicit scopes (e.g., pass:issue, pass:revoke, stellar:submit) before any state mutation can proceed.
    • Unauthorized or unauthenticated mutations return controlled 401 AUTH_UNAUTHORIZED or 403 AUTH_FORBIDDEN errors.
  2. Idempotency Protection (src/plugins/idempotency.ts):

    • Integrated @guildpass/idempotency and @guildpass/canonical-json into a Fastify plugin.
    • Computes deterministic SHA-256 fingerprints across HTTP method, endpoint URL, and canonical JSON body.
    • Accurately identifies cached replays, returning cached responses with header Idempotent-Replay: true.
    • Protects against in-flight race conditions and payload mismatches by returning 409 IDEMPOTENCY_CONFLICT.
  3. Sensitive Value Redaction & Structured Logging (src/observability/logging.ts):

    • Integrated @guildpass/log-redaction across Fastify request and response hooks.
    • Automatically redacts authorization headers, cookies, API keys, private keys, seed phrases, and passwords recursively before writing to structured logs.
    • Propagates distributed x-correlation-id across all log entries and client responses.
  4. Sanitized Typed Error Hierarchy (src/errors/index.ts):

    • Implemented GuildPassError hierarchy (AuthenticationError, AuthorizationError, ValidationError, NotFoundError, ConflictError, RateLimitExceededError, IdempotencyConflictError, StellarTransactionError, InternalServerError).
    • Centralized errorHandlerPlugin sanitizes all public error payloads, masking stack traces, internal connection strings, and sensitive credentials while attaching correlation IDs.
  5. Sliding-Window Rate Limiting (src/plugins/rate-limit.ts):

    • Integrated @guildpass/rate-limit with sliding window counters.
    • Emits standard X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, and Retry-After headers.
    • Returns typed 429 RATE_LIMIT_EXCEEDED errors when limits are exceeded.
  6. Predictable Stellar Transaction Resilience (src/stellar/transaction-handler.ts):

    • Implemented classifyStellarError categorizing errors into permanent (e.g., tx_bad_auth, op_underfunded, tx_insufficient_fee) vs transient (e.g., tx_bad_seq, HTTP 503, connection timeouts).
    • Integrated @guildpass/retry-policy with exponential backoff and jitter to automatically retry transient errors while immediately fast-failing non-retryable errors.
    • Integrated @guildpass/circuit-breaker to trip to OPEN state after consecutive downstream RPC failures, protecting the service from connection pool exhaustion.
  7. Observability: Liveness & Readiness Probes (src/observability/health.ts):

    • /health: Fast liveness check returning { status: "ok", service: "guildpass-core-api" }.
    • /ready: Detailed readiness check evaluating memory consumption, system health, and external dependencies.
  8. Comprehensive Automated Test Suite (src/test/hardening.test.ts):

    • 22/22 unit and integration tests verifying all 8 production readiness acceptance criteria.

Acceptance Criteria Verification

  • Mutation authorization is explicitly enforced or delegated through a documented boundary.
  • Appropriate operations support idempotency.
  • Sensitive values are not exposed through logs or public errors.
  • Structured logging is available for important Core operations.
  • Infrastructure failures produce controlled typed errors.
  • Stellar transaction failure states are handled predictably.
  • Security-focused tests cover critical access and mutation paths.
  • CI passes all typecheck, test, build, and security-related checks required by the repository.

…tine-guild#422)

- Add mutation authorization boundaries with capability token validation and scope enforcement in src/security/auth.ts
- Add idempotency plugin for mutation endpoints with replay protection and conflict detection in src/plugins/idempotency.ts
- Add structured logging with recursive sensitive data redaction and correlation ID propagation in src/observability/logging.ts
- Add structured typed error hierarchy and centralized error sanitizer in src/errors/index.ts
- Add sliding-window rate limiting plugin with typed 429 errors in src/plugins/rate-limit.ts
- Add predictable Stellar transaction execution with error classification, exponential backoff, and circuit breaker in src/stellar/transaction-handler.ts
- Add liveness (/health) and readiness (/ready) observability probes in src/observability/health.ts
- Wire all plugins and hardened domain endpoints in apps/api/src/app.ts
- Add comprehensive test suite in apps/api/src/test/hardening.test.ts covering all acceptance criteria
@Lakes41

Lakes41 commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

This PR cannot be merged automatically because one or more workflow checks failed.

Please review the failed checks, push a fix, and wait for the workflows to pass.

After the checks pass and there are no merge conflicts, the automation can review it again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Harden GuildPass Core V2 for production readiness

2 participants