Repository navigation
feat(core): harden GuildPass Core V2 for production readiness (#422) - #423
Open
rupesh-kumar-sah wants to merge 3 commits into
Open
rupesh-kumar-sah wants to merge 3 commits into
rupesh-kumar-sah wants to merge 3 commits into
Conversation
…tine-guild#422) - Add mutation authorization boundaries with capability token validation and scope enforcement in src/security/auth.ts - Add idempotency plugin for mutation endpoints with replay protection and conflict detection in src/plugins/idempotency.ts - Add structured logging with recursive sensitive data redaction and correlation ID propagation in src/observability/logging.ts - Add structured typed error hierarchy and centralized error sanitizer in src/errors/index.ts - Add sliding-window rate limiting plugin with typed 429 errors in src/plugins/rate-limit.ts - Add predictable Stellar transaction execution with error classification, exponential backoff, and circuit breaker in src/stellar/transaction-handler.ts - Add liveness (/health) and readiness (/ready) observability probes in src/observability/health.ts - Wire all plugins and hardened domain endpoints in apps/api/src/app.ts - Add comprehensive test suite in apps/api/src/test/hardening.test.ts covering all acceptance criteria
Contributor
|
This PR cannot be merged automatically because one or more workflow checks failed. Please review the failed checks, push a fix, and wait for the workflows to pass. After the checks pass and there are no merge conflicts, the automation can review it again. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #422
Hardens GuildPass Core V2 for production readiness with end-to-end authorization boundaries, idempotency, structured redacted logging, typed error handling, sliding-window rate limiting, predictable Stellar transaction failure handling with circuit breakers, and observability probes.
Implemented Architecture & Controls
Mutation Authorization Boundary (
src/security/auth.ts):@guildpass/capability-tokento verify incoming Bearer capability tokens.requireAuth,requireScopes,requireAnyScope) requiring explicit scopes (e.g.,pass:issue,pass:revoke,stellar:submit) before any state mutation can proceed.AUTH_UNAUTHORIZEDor 403AUTH_FORBIDDENerrors.Idempotency Protection (
src/plugins/idempotency.ts):@guildpass/idempotencyand@guildpass/canonical-jsoninto a Fastify plugin.Idempotent-Replay: true.IDEMPOTENCY_CONFLICT.Sensitive Value Redaction & Structured Logging (
src/observability/logging.ts):@guildpass/log-redactionacross Fastify request and response hooks.x-correlation-idacross all log entries and client responses.Sanitized Typed Error Hierarchy (
src/errors/index.ts):GuildPassErrorhierarchy (AuthenticationError,AuthorizationError,ValidationError,NotFoundError,ConflictError,RateLimitExceededError,IdempotencyConflictError,StellarTransactionError,InternalServerError).errorHandlerPluginsanitizes all public error payloads, masking stack traces, internal connection strings, and sensitive credentials while attaching correlation IDs.Sliding-Window Rate Limiting (
src/plugins/rate-limit.ts):@guildpass/rate-limitwith sliding window counters.X-RateLimit-Limit,X-RateLimit-Remaining,X-RateLimit-Reset, andRetry-Afterheaders.RATE_LIMIT_EXCEEDEDerrors when limits are exceeded.Predictable Stellar Transaction Resilience (
src/stellar/transaction-handler.ts):classifyStellarErrorcategorizing errors into permanent (e.g.,tx_bad_auth,op_underfunded,tx_insufficient_fee) vs transient (e.g.,tx_bad_seq, HTTP 503, connection timeouts).@guildpass/retry-policywith exponential backoff and jitter to automatically retry transient errors while immediately fast-failing non-retryable errors.@guildpass/circuit-breakerto trip toOPENstate after consecutive downstream RPC failures, protecting the service from connection pool exhaustion.Observability: Liveness & Readiness Probes (
src/observability/health.ts):/health: Fast liveness check returning{ status: "ok", service: "guildpass-core-api" }./ready: Detailed readiness check evaluating memory consumption, system health, and external dependencies.Comprehensive Automated Test Suite (
src/test/hardening.test.ts):Acceptance Criteria Verification