Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
178 commits
Select commit Hold shift + click to select a range
0b7d4f4
fix(backend): degrade gracefully when Soroban RPC is unreachable at s…
Aug 24, 2026
dd293cd
fix(backend): sync package-lock.json for the api-schemas file dependency
Aug 24, 2026
bd520de
fix(backend): resolve eslint errors blocking npm run lint
Aug 24, 2026
1b66d2b
fix(backend): add missing EventOutbox/AdminConfigChange/FeatureFlagOv…
Aug 24, 2026
f712d17
fix(backend): fix crashing scoped-admin-token test and off-by-zero TT…
Aug 24, 2026
b6176aa
docs: standardize repo workflows and governance
ReinaMaze Aug 24, 2026
195c5d8
fix(backend): apply non-breaking npm audit fixes
Aug 24, 2026
00c95b2
fix(backend): upgrade OpenTelemetry packages to clear remaining audit…
Aug 24, 2026
1412333
feat: operational safety, strategy validation, governance, and roundi…
ReinaMaze Aug 24, 2026
fb6abdb
fix(backend): stop crashing when DATABASE_URL is a non-sqlite connect…
Aug 24, 2026
e247999
feat(frontend): derive real settlement status for transaction history…
zipporahgeorge88-oss Aug 24, 2026
4dd0bfa
feat(frontend): add strategy detail page with risk, yield and history…
zipporahgeorge88-oss Aug 24, 2026
5db5f6e
feat: implement tenant boundaries, schema validation, operational met…
ReinaMaze Aug 24, 2026
db10883
feat(frontend): error-aware empty states and strategy data fallback (…
zipporahgeorge88-oss Aug 24, 2026
ec260de
feat(frontend): surface on-chain transaction hash and explorer link a…
zipporahgeorge88-oss Aug 24, 2026
dc3de2d
fix(backend): avoid SQLite table rebuild in migration, fix migration-…
Aug 24, 2026
6e69c99
fix(backend): stop crashing test /health checks against a database no…
Aug 24, 2026
97eaf54
fix(backend): sync API contract schemas with the actual response shapes
Aug 24, 2026
964ca9b
fix(backend): missing 404 handler, missing await, stale impersonation…
Aug 24, 2026
b385518
fix(backend): replace invalid shared test wallet fixtures with real E…
Aug 24, 2026
5c0c35a
fix(backend): correct wrong auth header and invalid webhook event typ…
Aug 24, 2026
cf9454f
fix(backend): fix remaining isolated test bugs (bad fixture, missing …
Aug 24, 2026
1507fc9
fix(ci): missing shared-schemas build step, unlocked cargo-audit install
Aug 24, 2026
f2aa34b
fix(backend): correct wrong table name in apySnapshot's raw APY read
Aug 24, 2026
1b91deb
fix(ci): install cargo-fuzz under the nightly toolchain, not the pinn…
Aug 25, 2026
e445f21
fix(backend): resolve remaining CI test failures and doc drift
Aug 25, 2026
6a5a115
feat(contracts): liquidation safeguards, recovery sequencing, and gat…
Samuel1-ona Aug 25, 2026
1a73865
feat: Add ConfirmationModal component for large transaction confirmation
SamuelStave Aug 25, 2026
9ee31ea
feat: Add useTransactionRetry hook for transaction retry logic
SamuelStave Aug 25, 2026
eac2cda
feat: Add TransactionRetryPanel component for retry and cancellation UI
SamuelStave Aug 25, 2026
eb511e3
feat: Add NetworkSwitchNotification component for Stellar network mis…
SamuelStave Aug 25, 2026
dfdfb5c
feat: Add useKeyboardNavigation hook for focus management
SamuelStave Aug 25, 2026
a56fbc4
feat: Add IconButton component with ARIA labels
SamuelStave Aug 25, 2026
6e2e74f
feat: Add AccessibleFormControl component with proper labeling
SamuelStave Aug 25, 2026
cbe9eea
feat: Add accessibility CSS for focus states and reduced motion
SamuelStave Aug 25, 2026
c1a59b9
feat: all task that has to do vault on both contract and backend
Eniola3321 Aug 25, 2026
972bc84
feat: all issues on yieldrwa has been completed
olawale880 Aug 25, 2026
94040be
Merge pull request #1208 from Awosdot/fix/issue-1162-graceful-degrada…
Junirezz Aug 25, 2026
09b83cb
Merge pull request #1209 from ReinaMaze/feat/governance-standardization
Junirezz Aug 25, 2026
9fb0b9c
Merge pull request #1220 from olawale880/yieldrwx
Junirezz Aug 25, 2026
ab9790e
Merge pull request #1219 from Eniola3321/vaultxz
Junirezz Aug 25, 2026
0fc8df7
Merge branch 'main' into feat/operational-safety-validation-governanc…
Junirezz Aug 25, 2026
aeafcbd
Merge pull request #1210 from Prz-droid/feat/operational-safety-valid…
Junirezz Aug 25, 2026
1284f34
Merge pull request #1224 from SamuelStave/feature/accessibility-impro…
Junirezz Aug 25, 2026
ddc9c46
Merge pull request #1223 from SamuelStave/feature/network-switch-noti…
Junirezz Aug 25, 2026
5b3f048
Merge pull request #1217 from Awosdot/claude/pr-1208-ci-checks-1lf9dm
Junirezz Aug 25, 2026
af8baa6
Merge pull request #1213 from zipporahgeorge88-oss/feat/1112-empty-st…
Junirezz Aug 25, 2026
f5a30bb
Merge pull request #1222 from SamuelStave/feature/tx-retry-messaging-…
Junirezz Aug 25, 2026
77d0733
Merge pull request #1211 from zipporahgeorge88-oss/feat/1121-transact…
Junirezz Aug 25, 2026
5c6f27e
Merge pull request #1212 from zipporahgeorge88-oss/feat/1120-strategy…
Junirezz Aug 25, 2026
f2f8ed9
Merge pull request #1221 from SamuelStave/feature/confirmation-modal-…
Junirezz Aug 25, 2026
647341e
Merge pull request #1215 from zipporahgeorge88-oss/feat/1111-tx-statu…
Junirezz Aug 25, 2026
899ce9c
Merge branch 'main' into feat/vault-recovery-telemetry-backup-validation
Junirezz Aug 25, 2026
f835460
Merge pull request #1218 from Samuel1-ona/feat/vault-recovery-telemet…
Junirezz Aug 25, 2026
bc3af33
Merge pull request #1214 from De-hunterJS/feature/tenant-boundaries-s…
Junirezz Aug 25, 2026
53ffa49
feat: persist wallet state and document frontend ux
Obiajulu-gif Aug 25, 2026
8d81524
feat: all vault issues assigned resolved
Treasure332 Aug 25, 2026
ae84320
feat: add vault health and webhook API contracts
Obiajulu-gif Aug 25, 2026
5536552
Merge pull request #1256 from prissca/fix/prissca-vault-governance-ap…
Junirezz Aug 25, 2026
4a803cf
Merge pull request #1255 from Treasure332/rwaz
Junirezz Aug 25, 2026
d529be5
Merge pull request #1254 from Obiajulu-gif/fix/obiajulu-frontend-wall…
Junirezz Aug 25, 2026
58acda9
feat: all vault-rwa issues fixed
BIGIN1 Aug 25, 2026
c926a0b
Merge branch 'main' into rawx
Junirezz Aug 25, 2026
b1362eb
Merge pull request #1257 from BIGIN1/rawx
Junirezz Aug 25, 2026
5dfc5ac
feat: add observability and auth infrastructure
ReinaMaze Aug 25, 2026
f914046
docs: add comprehensive branch summary and implementation guide
ReinaMaze Aug 25, 2026
b160700
docs: add implementation checklist and quality assurance guide
ReinaMaze Aug 25, 2026
feef25a
docs: add final completion report and statistics
ReinaMaze Aug 25, 2026
faa0ab6
fixed issues
bentechnology03-ops Aug 25, 2026
b2f5f45
ci(security): gate CI on cargo-deny advisories, add Slack alert on fa…
solaawojobi00-bit Aug 25, 2026
1128aae
ci(security): pin cargo-deny to a version compatible with rustc 1.85.0
solaawojobi00-bit Aug 25, 2026
a27f037
style(contracts): apply cargo fmt to fix pre-existing formatting drift
solaawojobi00-bit Aug 25, 2026
9bf5d81
Add per-route error boundaries with Sentry reporting
solaawojobi00-bit Aug 25, 2026
0f3a696
improved repo-wide document
victorEdeh Aug 25, 2026
7c25245
Merge pull request #1263 from victorEdeh/feat/fixed
Junirezz Aug 25, 2026
4df91a9
feat: implement issues #1109-1119 - responsive vault cards, route err…
esthertitilayo-dev Aug 25, 2026
aad278d
feat: strategy cooldown, withdrawal receipts, vault caching, gasless …
OtowoSamuel Aug 25, 2026
d175617
Merge pull request #1258 from Priscy-bells/feature/observability-and-…
Junirezz Aug 25, 2026
24a643e
Merge pull request #1262 from solaawojobi00-bit/fix/issue-1242-route-…
Junirezz Aug 25, 2026
96a6ec6
Merge pull request #1261 from solaawojobi00-bit/fix/issue-1240-securi…
Junirezz Aug 25, 2026
9310dc2
Merge branch 'main' into fix/issues-1109-1119
Junirezz Aug 25, 2026
5935bb7
Merge pull request #1265 from esthertitilayo-dev/fix/issues-1109-1119
Junirezz Aug 25, 2026
a3f7ba6
Merge pull request #1264 from OtowoSamuel/feat/strategy-cooldown-rece…
Junirezz Aug 25, 2026
db6a7f0
Merge pull request #1259 from bentechnology03-ops/feat/fix
Junirezz Aug 25, 2026
4c9fec6
Add StrategyCardSkeleton component
solaawojobi00-bit Aug 26, 2026
21648c9
fix(#1167): implement oracle heartbeat validation, stale data checks,…
Aug 26, 2026
36ded1b
feat(vault): add utilization-based dynamic fee adjustment
solaawojobi00-bit Aug 26, 2026
e376f40
Add dark mode, mobile layout, toasts, and query cache
miss-yusrah Aug 26, 2026
eebaa45
fix: resolve DataKey scope for oracle validation
Aug 26, 2026
3f92947
feat(frontend): add offline and slow-network fallback messaging patte…
Aug 26, 2026
b06c10b
Add i18n, Zod validation, Prisma migrations, and webhooks
king-aj-the-first Aug 26, 2026
881a06e
docs(security): add encryption review and data handling checklist (#1…
Aug 26, 2026
122b34c
Add vault invariants, risk limits, oracle failure tests, and nightly …
amanosiadnan-cmyk Aug 26, 2026
3652e67
Add a11y, motion, rate limits, and API versioning
success-OG Aug 26, 2026
dd0ce67
feat: implement loading skeletons, Zod form validation, CI security s…
Aug 26, 2026
1390239
feat: observability, unified errors, OpenAPI docs, and dashboard rede…
Aug 26, 2026
192364e
feat: implement release checklist, incident runbook, and frontend enh…
kingksjo Aug 26, 2026
07d625e
Merge pull request #1286 from solaawojobi00-bit/fix/issue-1247-loadin…
Junirezz Aug 26, 2026
383826a
Merge pull request #1287 from Awosdot/fix/issue-1167-stale-oracle-data
Junirezz Aug 26, 2026
7285867
Merge pull request #1288 from solaawojobi00-bit/fix/issue-1243-dynami…
Junirezz Aug 26, 2026
fe07bf7
Merge pull request #1289 from miss-yusrah/feat/ui
Junirezz Aug 26, 2026
b3235c0
Merge pull request #1290 from Awosdot/feature/issue-980-offline-fallback
Junirezz Aug 26, 2026
8154517
Fix outstanding vault issue set
euniceotowo Aug 26, 2026
675739e
Add i18n, Zod validation, Prisma migrations, and webhooks
king-aj-the-first Aug 26, 2026
2f13594
Merge pull request #1292 from Awosdot/feature/issue-1161-encryption-r…
Junirezz Aug 26, 2026
d665551
Add vault invariants, risk limits, oracle failure tests, and nightly …
amanosiadnan-cmyk Aug 26, 2026
70e96bd
Merge success-OG/feat/rate: a11y, motion, rate limits, API versioning
Aug 26, 2026
b2c08c3
Merge pull request #1295 from maccoder374-sudo/feat/issues-1273-1272-…
Junirezz Aug 26, 2026
0f8fd26
Merge pull request #1296 from kingksjo/feat/issues-1146-1149-979-983
Junirezz Aug 26, 2026
b5ab2f7
Merge branch 'main' into feat/issue-1229-1230-1241-1225
euniceotowo Aug 26, 2026
2323045
feat: implement issues #1228, #1239, #1227, #1238
trinnode Aug 27, 2026
ab5f41e
feat: all issues on vault issues fixed
Aishat004 Aug 27, 2026
8aad49d
feat: all vaultrwaissues completed
Zainab5970 Aug 27, 2026
ad87bbd
Merge pull request #1297 from euniceotowo/feat/issue-1229-1230-1241-1225
Junirezz Aug 27, 2026
88dee35
Merge pull request #1301 from Zainab5970/wazx
Junirezz Aug 27, 2026
7a68f1b
Merge pull request #1300 from Aishat004/vauxz
Junirezz Aug 27, 2026
3a00601
Merge branch 'main' into issues-resolved-batch3
Junirezz Aug 27, 2026
d1bd401
Merge ayomideadeniran/feat/989-1266-1267-1270: observability, unified…
Aug 27, 2026
e6e4ea9
Merge pull request #1299 from trinnode/issues-resolved-batch3
Junirezz Aug 27, 2026
0359532
Merge remote-tracking branch 'origin/main'
Aug 27, 2026
bedaae5
Merge remote-tracking branch 'origin/main'
Aug 27, 2026
a328ce8
Merge branch 'main' into hardening
Junirezz Aug 29, 2026
2350649
Merge pull request #1293 from amanosiadnan-cmyk/hardening
Junirezz Aug 29, 2026
c600277
Merge branch 'main' into issues
Junirezz Aug 29, 2026
3704f28
Merge pull request #1291 from king-aj-the-first/issues
Junirezz Aug 29, 2026
4d2395b
fix(backend): add vault, allocation, tenant and transaction fields to…
godamongstmen897 Sep 25, 2026
a8f883c
fix(backend): add IdempotencyKey model, regenerate contract snapshots…
godamongstmen897 Sep 25, 2026
5464240
fix(contracts): restore compilation across all four contract crates
broda-spendy Sep 25, 2026
d23664e
ci(contracts): type-check every contract crate before merge
broda-spendy Sep 25, 2026
93caf98
feat: implement issues #1313, #1315, #1316, #1317
Sep 25, 2026
fe65bc9
chore: run prisma generate before tsc
samolusey Sep 25, 2026
aa27aa0
chore: build api-schemas before tsc
samolusey Sep 25, 2026
097427b
feat: add error and warn methods to Logger
samolusey Sep 25, 2026
8d87d6d
ci(contracts): ensure rustfmt is installed so the fmt gate actually runs
broda-spendy Sep 26, 2026
868c658
feat(contracts): verify bridge-compat ABI shape in CI
broda-spendy Sep 26, 2026
4b81309
ci: enforce backend types and contract formatting
kingeligma Sep 26, 2026
417d05b
fix: validate cache hook returns, optional polling health, otel mock,…
kingksjo Sep 27, 2026
13ec7be
chore(deps): add general label to all dependabot ecosystems (#1460)
amehsamuel200225-sketch Sep 27, 2026
dd010c4
chore(vscode): add recommended extensions and editor settings (#1462)
amehsamuel200225-sketch Sep 27, 2026
90f9a05
chore(commits): enforce lower-case conventional commit types (#1461)
amehsamuel200225-sketch Sep 27, 2026
725f1d3
perf(devx): lint only staged files in pre-commit (#1463)
amehsamuel200225-sketch Sep 27, 2026
a58585b
fix: prevent sync throws in async Express handlers to avoid hung requ…
Otaiki1 Sep 27, 2026
420d66f
Work on #1366: Schema snapshots drift when new health-check fields are a
Otaiki1 Sep 27, 2026
0cdb9de
fixed all issues
Benalex8797 Sep 27, 2026
e8550e5
feat: Flaky test detector workflow is missing so the same 3 tests fai…
Treasure332 Sep 28, 2026
37429cc
Merge pull request #1483 from Treasure332/feat/vaulx
Junirezz Sep 28, 2026
6e82033
Merge pull request #1481 from Otaiki1/prmaster/1368-1366-1365-1329-4-…
Junirezz Sep 28, 2026
76f4739
Merge branch 'main' into fix/1461-commitlint-case
Junirezz Sep 28, 2026
3dc539f
Merge pull request #1479 from amehsamuel200225-sketch/fix/1461-commit…
Junirezz Sep 28, 2026
e8dd3f4
Merge pull request #1426 from kingksjo/fix/issues-1369-1364-1363-1321
Junirezz Sep 28, 2026
5432f43
Merge pull request #1477 from amehsamuel200225-sketch/fix/1460-depend…
Junirezz Sep 28, 2026
a12173e
Merge pull request #1478 from amehsamuel200225-sketch/chore/1462-vsco…
Junirezz Sep 28, 2026
cad6928
Merge branch 'main' into perf/1463-lint-staged-precommit
Junirezz Sep 28, 2026
70b3bee
Merge pull request #1480 from amehsamuel200225-sketch/perf/1463-lint-…
Junirezz Sep 28, 2026
536d147
Merge pull request #1424 from broda-spendy/fix/1305-bridge-abi-check
Junirezz Sep 28, 2026
9f40c33
Merge pull request #1420 from samolusey/issue-no-1327
Junirezz Sep 28, 2026
2f13f96
feat: Pnpm workspace package.json has duplicate test scripts with di…
olawale880 Sep 28, 2026
7300a48
Merge branch 'main' into feat/issues-1313-1315-1316-1317
Junirezz Sep 28, 2026
b9fbdc3
Merge pull request #1418 from serverlessdomain-hash/feat/issues-1313-…
Junirezz Sep 28, 2026
b159d5d
Merge pull request #1484 from olawale880/feat/junix
Junirezz Sep 28, 2026
36125b9
Merge branch 'main' into feat/1456-1459
Junirezz Sep 28, 2026
cf76d20
Merge pull request #1416 from broda-spendy/fix/1303-rust-merge-corrup…
Junirezz Sep 28, 2026
e9cc190
Merge pull request #1417 from broda-spendy/fix/1304-enforce-cargo-check
Junirezz Sep 28, 2026
a649f4b
Merge pull request #1421 from samolusey/issue-no-1326
Junirezz Sep 28, 2026
ce1ac57
Merge branch 'main' into fix/1302-fmt-gate
Junirezz Sep 28, 2026
d58e143
Merge pull request #1423 from broda-spendy/fix/1302-fmt-gate
Junirezz Sep 28, 2026
13b5f86
Merge pull request #1482 from bbgoldsani-oss/feat/1456-1459
Junirezz Sep 28, 2026
94e861e
Merge branch 'main' into issue-no-1328
Junirezz Sep 28, 2026
f5233e1
Merge pull request #1419 from samolusey/issue-no-1328
Junirezz Sep 28, 2026
4c7fb5f
Merge branch 'main' into fix/contract-snapshots-idempotency-prisma
Junirezz Sep 28, 2026
990845b
Merge pull request #1414 from francisdouglas-ux/fix/contract-snapshot…
Junirezz Sep 28, 2026
5605d85
feat: Renovate or Dependabot config is missing, so transitive lodash …
BIGIN1 Sep 28, 2026
68c552c
Merge branch 'main' into fix/984-add-guided-onboarding-checklist-for-…
Junirezz Sep 28, 2026
41d1af8
Merge pull request #1425 from kingeligma/fix/984-add-guided-onboardin…
Junirezz Sep 28, 2026
9a15975
Merge branch 'main' into fix/prisma-vault-allocation-tenant-fields
Junirezz Sep 28, 2026
06109ff
Merge pull request #1413 from godamongstmen897/fix/prisma-vault-alloc…
Junirezz Sep 28, 2026
d33674e
Merge pull request #1485 from BIGIN1/feat/codex
Awosdot Sep 28, 2026
4eb75c8
fix(ci): add pnpm lockfile and scope security audit gate to productio…
Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
* text=auto eol=lf
6 changes: 4 additions & 2 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,10 @@
* @YieldVault-RWA/core-maintainers

# Tier 1: Smart Contracts & Value Transfer
/contracts/ @YieldVault-RWA/contracts-maintainers @YieldVault-RWA/security-team
/contracts/**/src/ @YieldVault-RWA/contracts-maintainers @YieldVault-RWA/security-team
/contracts/ @Junirezz @contract-reviewers
/contracts @Junirezz @contract-reviewers
/contracts/**/src/ @Junirezz @contract-reviewers
*.rs @rust-reviewers
/deployments/ @YieldVault-RWA/contracts-maintainers

# Tier 2: Backend Services & API Layer
Expand Down
52 changes: 52 additions & 0 deletions .github/ISSUE_TEMPLATE/perf_regression.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
---
name: Performance Regression
about: Report a backend latency regression, memory leak, or throughput degradation
title: 'Perf: [Short description of performance regression]'
labels: 'type: perf, scope: backend, status: needs-triage'
assignees: 'YieldVault-RWA/backend-maintainers'
---

## ⚑ Summary
Provide a concise overview of the performance regression, when it was detected, and its impact on backend latency, throughput, or resource consumption.

## 🎯 Endpoint & Scope
- **Endpoint**: e.g. `POST /api/v1/vault/deposit` or `GET /api/v1/transactions`
- **Component Scope**: `scope: backend`
- **Environment**: Production / Staging / Testnet / Local
- **Deployment / Commit**: e.g. `sha-abcdef1` or `v1.4.2`

## ⏱️ Latency & Performance Metrics (p95 before/after)
- **p95 Before**: e.g. `45 ms` (historical baseline)
- **p95 After**: e.g. `380 ms` (observed degraded latency)
- **p99 Before / After**: e.g. `80 ms` / `750 ms`
- **Memory / CPU Impact**: e.g. Node process memory grew from 250MB to 1.8GB (suspected memory leak)

## 🚦 Traffic & Load (QPS)
- **QPS**: e.g. `250 req/s` (or traffic rate during regression)
- **Concurrency**: e.g. `50 concurrent connections`

## 🎯 Expected SLO
- **Expected SLO**: e.g. `Read P95 < 200 ms` / `Write P95 < 500 ms` (as defined in `docs/api/SLA_SLO.md` and `docs/nfr-baselines.json`)
- **Error Budget Impact**: e.g. Consuming 15% of monthly error budget / SLO breach

## πŸ—„οΈ DB Query Plan
Attach the `EXPLAIN ANALYZE` execution plan, Prisma query trace, or slow query log below:

```sql
-- Paste EXPLAIN ANALYZE or slow query plan here
```

## πŸ”„ Repro Steps
1. Configure load generator or HTTP client:
2. Execute command or load script (e.g. `k6 run load-test.js` or `autocannon -c 50 -d 30s <endpoint>`):
3. Send payload:
4. Observe latency metric spike or memory growth in metrics dashboard:

## πŸ“Š Profiling & Diagnostic Evidence
- **Flamegraph / Profiler Trace**: (Attach SVG or link to CPU flamegraph/pprof trace)
- **Heap Snapshot / Memory Profile**: (Attach snapshot or leak analysis)
- **Grafana / Prometheus Dashboard Link**:
- **APM Trace IDs / OpenTelemetry Span**:

## πŸ“ Additional Context
Include any relevant recent PRs, schema migrations, database index changes, third-party RPC bottlenecks, or potential root cause hypotheses.
153 changes: 112 additions & 41 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -1,14 +1,91 @@
# Pull Request Template

## πŸ“‹ Description
Add a complete environment variable matrix (`docs/ENV_VARIABLE_MATRIX.md`) covering every env var consumed across the backend and frontend, with defaults, required flags, and production recommendations. Update `README.md` and `ENV_QUICK_REFERENCE.md` to link to the new document.
<!-- Provide a clear, concise summary of the goal and changes in this PR -->

### Goal
<!-- What problem does this solve? Reference issue: Closes #123 -->

### Changes
<!-- Bullet points explaining the key modifications -->
-

## πŸ”— Type of Change
- [ ] πŸ› Bug fix (non-breaking change that fixes an issue)
- [ ] ✨ New feature (non-breaking change that adds functionality)
- [ ] ⚠️ Breaking change (fix or feature that would cause existing functionality to change)
- [x] πŸ“š Documentation update
- [ ] 🌊 Wave submission (contract migration, architectural wave release, or protocol upgrade)
- [ ] πŸ“š Documentation update
- [ ] πŸ”’ Security improvement
- [ ] ⚑ Performance optimization

---

## πŸ›‘οΈ Risk Assessment

<!-- Mandatory for all PRs to evaluate blast radius, particularly contract migrations & Wave submissions -->

### Risk Level
- [ ] 🟒 **Low**: Non-breaking change, documentation, style, or isolated helper refactoring
- [ ] 🟑 **Medium**: API enhancement, frontend workflow update, non-critical dependency upgrade
- [ ] 🟠 **High**: Core contract logic change, access control modification, financial accounting / share math
- [ ] πŸ”΄ **Critical**: Wave submission, contract storage migration, protocol upgrade touching vault funds

### Blast Radius & Impact Analysis
- [ ] Contract storage layout / data key migration involved
- [ ] Value transfer, deposit/withdraw flow, or vault share calculation affected
- [ ] External integration (Oracle, Soroban RPC, Bridge, Token contract) affected
- [ ] Database schema migration or data backfill required
- [ ] Breaking API or interface change affecting downstream clients
- [ ] Zero blast radius (isolated tooling / documentation only)

**Detailed Risk & Blast Radius Notes:**
<!-- Describe specific failure modes, edge cases, affected components, and risk mitigations -->
```
```

---

## πŸ”„ Rollback Plan

<!-- Detail the exact steps and strategy to revert this change if unexpected failures occur in production -->

### Rollback Strategy & Feasibility
- [ ] **Clean Git Revert**: Revertable with zero persistent state drift
- [ ] **Contract Upgrade Rollback**: Tested rollback to previous contract WASM hash / implementation
- [ ] **Database Migration Revert**: Reversible migration down-script tested and verified
- [ ] **Feature Flag / Circuit Breaker**: Feature can be toggled off instantly without redeployment
- [ ] **Emergency Pause**: Contract pause / freeze mechanism available to halt affected functions
- [ ] **Forward-Only / Irreversible**: State migration cannot be cleanly reversed; emergency recovery runbook linked below

### Rollback Trigger Criteria
<!-- What specific conditions, metrics, or alerts will trigger an immediate rollback? (e.g. error rate > 1%, oracle divergence, tx reverts) -->
-

### Step-by-Step Rollback Procedure
<!-- List the exact operational sequence required to execute a rollback -->
1.
2.
3.

---

## ⚑ Performance Impact

<!-- Evaluate gas usage, execution compute units, latency, throughput, and bundle size impact -->

### Performance & Resource Assessment
- [ ] Smart contract gas / compute units benchmarked (no regression > 5%, or justified below)
- [ ] Backend API latency (p95/p99) and database query execution plans verified
- [ ] Database indexing verified for newly queried columns (no table scans)
- [ ] Frontend bundle size and Time to Interactive (TTI) verified
- [ ] Memory allocation and leak checks verified (no memory leaks in long-running services)
- [ ] No measurable performance impact (documentation, tests, or trivial changes)

**Performance & Gas Profiling Summary:**
<!-- Include before/after gas consumption numbers, query explain plans, or benchmark output -->
```
```

---

Expand All @@ -28,7 +105,6 @@ See [`docs/SECURITY_CHECKLIST.md`](/docs/SECURITY_CHECKLIST.md) for detailed gui

**If any checkbox cannot be verified, explain below:**
```
N/A β€” this PR contains only documentation changes. No smart contract code was modified.
```

### Slither Static Analysis Results
Expand All @@ -41,7 +117,6 @@ See [`docs/SECURITY_CHECKLIST.md`](/docs/SECURITY_CHECKLIST.md) for detailed gui

**If this PR has security findings, document them below:**
```
N/A β€” documentation-only PR. No contract or runtime code changed.
```

### Handling Security Findings
Expand All @@ -51,7 +126,6 @@ See [`docs/SECURITY_CHECKLIST.md`](/docs/SECURITY_CHECKLIST.md) for detailed gui
- [ ] Test case added to verify fix
- [ ] Explain fix below:
```
N/A
```

#### Option B: False Positive 🟑
Expand All @@ -62,7 +136,6 @@ See [`docs/SECURITY_CHECKLIST.md`](/docs/SECURITY_CHECKLIST.md) for detailed gui
- Evidence (code snippet, test case, or reference)
- [ ] Reference number (e.g., FP-001):
```
N/A
```
- [ ] Inline suppression added to code:
```solidity
Expand All @@ -75,53 +148,47 @@ See [`docs/SECURITY_CHECKLIST.md`](/docs/SECURITY_CHECKLIST.md) for detailed gui
- [ ] Added to Slither exclusions
- [ ] Explain below:
```
N/A
```

---

## πŸ“ Testing

### Functional Testing
- [x] Unit tests added/updated for changes
- [x] Integration tests passing
- [x] Manual testing completed and documented below:
- [ ] Unit tests added/updated for changes
- [ ] Integration tests passing
- [ ] End-to-end (E2E) tests passing
- [ ] Manual testing completed and documented below:
```
- Verified all variable names, defaults, and required flags against source files:
backend/src/index.ts, rateLimiter.ts, auth.ts, tracing.ts
- Cross-checked every .env.example, .env.local.example, .env.production.example
in both backend/ and frontend/
- Confirmed links in README.md and ENV_QUICK_REFERENCE.md resolve correctly
- No runtime code changed; no functional regression possible
```

### Security Testing
- For state-changing functions:
- [ ] Reentrancy test (if applicable): Verify re-entry is blocked
- [ ] Access control test: Verify unauthorized access is rejected
- [ ] Boundary test: Verify edge cases are handled
- [ ] Boundary / Edge-case test: Verify limits, zero-amounts, and rounding behavior

- For external integrations:
- [ ] Return value verification test
- [ ] Failure scenario test
- [ ] Failure / timeout scenario test

### Test Coverage
- [x] All new code paths have test coverage
- [x] Security-critical paths have comprehensive test cases
- [x] Coverage report: `N/A β€” documentation only, no executable code added`
- [ ] All new code paths have test coverage
- [ ] Security-critical paths have comprehensive test cases
- [ ] Coverage report:
```
```

---

## πŸš€ Deployment Notes

No deployment steps required. This PR adds a Markdown file and updates two existing Markdown files only.

### Mainnet Readiness
- [ ] This code is ready for production deployment
- [x] All critical tests pass
- [ ] All critical tests pass
- [ ] Security review approved
- [x] No temporary debug code
- [x] No TODO comments
- [ ] No temporary debug code
- [ ] No TODO comments

### Breaking Changes
If this PR introduces breaking changes:
Expand All @@ -136,10 +203,9 @@ If this PR introduces breaking changes:
<!-- GitHub Actions will update this section -->

### Slither Analysis
- βœ“ Status: N/A β€” no contract code changed
- βœ“ Status:
- πŸ”΄ High/Medium findings: 0
- 🟑 Low/Informational findings: 0
- 🟒 No issues detected: documentation-only PR

### Related Documentation
- [Security Checklist](docs/SECURITY_CHECKLIST.md) β€” Use for code review
Expand All @@ -150,17 +216,19 @@ If this PR introduces breaking changes:

## βœ… Reviewer Checklist

**For code reviewers** (use this to guide your security-focused review):
**For code reviewers** (use this to guide your review):

- [x] PR author completed security checklist βœ“
- [x] All findings documented and categorized (fixed/false positive/excluded)
- [x] Inline security comments are clear and justified
- [ ] PR author completed Risk Assessment and Rollback Plan βœ“
- [ ] Performance and gas impact evaluated and verified βœ“
- [ ] PR author completed security checklist βœ“
- [ ] All findings documented and categorized (fixed/false positive/excluded)
- [ ] Inline security comments are clear and justified
- [ ] Tests cover security-critical code paths
- [ ] No external calls bypass return value checks
- [ ] Access control is properly enforced
- [ ] State updates follow CEI pattern
- [ ] Input validation is comprehensive
- [x] Follow-up actions (if any) tracked in issues
- [ ] Follow-up actions (if any) tracked in issues

---

Expand All @@ -176,15 +244,18 @@ If this PR introduces breaking changes:

Before marking PR as ready for review:

- [x] Description is clear and concise
- [x] All security checklist items checked (βœ… or explanation provided)
- [x] All tests passing locally: `npm test`
- [x] Linter passing: `npm run lint`
- [ ] Description, Goal, and Changes are clearly stated
- [ ] Risk Assessment completed with appropriate risk tier and blast radius
- [ ] Rollback Plan completed with concrete steps and trigger criteria
- [ ] Performance Impact assessed with gas / compute benchmarks
- [ ] All security checklist items checked (βœ… or explanation provided)
- [ ] All tests passing locally: `npm test`
- [ ] Linter passing: `npm run lint`
- [ ] Slither passing locally OR findings documented: `slither . --config-file slither.config.json`
- [x] Code follows project style guide
- [x] No merge conflicts
- [x] Commits are clean and well-documented
- [x] Branch is up-to-date with main/develop
- [ ] Code follows project style guide
- [ ] No merge conflicts
- [ ] Commits are clean and well-documented
- [ ] Branch is up-to-date with main/develop
- [ ] For **release PRs**: `docs/RELEASE_READINESS_CHECKLIST.md` completed and linked in PR description

---
Expand Down
44 changes: 44 additions & 0 deletions .github/SECURITY_REVIEW_CHECKLIST.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
# Security Review Checklist β€” Secrets, PII & Transport

**Use for:** any PR that adds/changes a data store, secret, credential, external integration, or network-facing endpoint.
**Companion doc:** [`docs/security/encryption-review.md`](../docs/security/encryption-review.md) β€” full current-state review this checklist enforces going forward.
**Not this checklist:** smart-contract vulnerability classes (reentrancy, access control, gas/DoS) are covered by [`docs/SECURITY_CHECKLIST.md`](../docs/SECURITY_CHECKLIST.md).

---

## 1. Secrets & Credentials

- [ ] No secret, API key, private key, or credential is hardcoded or committed (checked by `gitleaks` in CI, but review the diff yourself too)
- [ ] New secrets are read from `process.env` / GitHub Actions `secrets.*`, never from a config file checked into the repo
- [ ] Any new required secret is documented in [`docs/ENV_VARIABLE_MATRIX.md`](../docs/ENV_VARIABLE_MATRIX.md)
- [ ] Secrets that must exist in production fail startup loudly if missing or weak (follow the pattern in `backend/src/auth.ts`'s `assertJwtSecretValid()`) rather than silently falling back to a dev default
- [ ] Tokens/keys are persisted as one-way hashes (SHA-256/HMAC or stronger), never in plaintext

## 2. Data at Rest

- [ ] New sensitive fields (PII, tokens, wallet-linked identifiers) are added to the correct model with the retention category noted in [`docs/DATA_RETENTION_DELETION_POLICY.md`](../docs/DATA_RETENTION_DELETION_POLICY.md)
- [ ] Any new database, cache, or file-based store this PR introduces is confirmed to write to the *intended* backing store β€” verify the Prisma datasource / connection string actually points where you think it does (see `docs/security/encryption-review.md` Β§4 F1 for a real example of this silently going wrong)
- [ ] No secret or PII value is written to logs, error messages, or audit trails in plaintext β€” check against `backend/src/auditRedaction.ts`'s redaction patterns

## 3. Data in Transit

- [ ] All new outbound calls (webhooks, RPC, third-party APIs) use `https://` / `wss://`, never plaintext `http://`
- [ ] New database or cache connection strings enforce TLS (`sslmode=require` for Postgres, `rediss://` for Redis) where the backing service supports it
- [ ] New cookies (if any) set `Secure`, `HttpOnly`, and an explicit `SameSite` β€” this repo's auth model currently uses Bearer tokens, not cookies, so introducing a cookie is a deliberate change worth flagging in the PR description
- [ ] CORS changes stay within an explicit origin allowlist β€” no `*` or broad regex in `CORS_ALLOWED_ORIGINS`

## 4. PII & Sensitive Data Handling

- [ ] User-identifying data (wallet address, email, IP) is only collected/stored where there's a documented purpose in [`docs/DATA_RETENTION_DELETION_POLICY.md`](../docs/DATA_RETENTION_DELETION_POLICY.md)
- [ ] Frontend `localStorage`/`sessionStorage` usage stores no private keys, JWTs, or API keys β€” only public/non-sensitive values (wallet address, UI prefs, session timestamps)
- [ ] New admin or export endpoints that expose PII/financial data are gated by the correct RBAC role and rate-limited

## 5. If This PR Touches Any of the Findings in `docs/security/encryption-review.md`

- [ ] Confirm which finding (F1–F6) this PR addresses, if any
- [ ] Update the finding's status in `docs/security/encryption-review.md` in the same PR
- [ ] If this PR resolves a finding, note it in the PR description so reviewers can verify against the documented evidence

---

**If any box above cannot be checked**, explain why in the PR description rather than leaving it silently unchecked β€” a documented exception is reviewable; a missing explanation is not.
Loading
Loading