Skip to content

fix: resolve issues #521 #522 #523 #526 - #542

Merged
DeFiVC merged 2 commits into
ChainLearnOfficial:mainfrom
TheHalalHunter:fix/521-522-523-526-health-recommendations-audit-credits
Oct 1, 2026
Merged

DeFiVC merged 2 commits into
ChainLearnOfficial:mainfrom
TheHalalHunter:fix/521-522-523-526-health-recommendations-audit-credits

Conversation

@TheHalalHunter

@TheHalalHunter TheHalalHunter commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Closes #521, Closes #522, Closes #523, Closes #526

#521 - Separate health check readiness from Stellar dependency checks

  • /health/live: always 200 (liveness probe)
  • /health/ready: DB + Redis only, Stellar removed (readiness probe)
  • /health: full status including Stellar Horizon + Soroban RPC (monitoring)
  • Add getSorobanServer() accessor to StellarClient
  • Update README with three-tier health check documentation

#522 - Optimise recommendation queries (6 queries -> <=3)

  • Implement getRecommendedCourses with merged user-context JOIN query
  • Peer collaborative signal collapsed to single subquery JOIN, cached 24h
  • Candidate courses + enrollment counts in one query via correlated subquery
  • Add migration 0006 with 3 missing indexes for recommendation query paths
  • Add GET /api/courses/recommended route with scoring and reason tags

#523 - Make audit logging non-blocking with buffered writes

  • Replace fire-and-forget db.insert with AuditLogger class
  • In-memory buffer flushed periodically (AUDIT_FLUSH_INTERVAL_MS) or on
    capacity (AUDIT_BUFFER_SIZE); flushing guard prevents concurrent races
  • Timer is unref'd so it does not block clean process exit
  • stopAuditLogger() awaits final flush before DB connection closes
  • Add auth.login and auth.login_failed audit events to auth.service.ts
  • Add AUDIT_BUFFER_SIZE and AUDIT_FLUSH_INTERVAL_MS to config

#526 - Fix TOCTOU race condition in deductCredits (negative balances)

  • Build admin module: adminGuard, types, service, controller, routes
  • deductCredits uses single atomic UPDATE...WHERE credits >= amount RETURNING
    eliminating the read-check-write gap that allowed negative balances
  • On zero rows: EXISTS check distinguishes 404 (no user) vs 422 (low balance)
  • grantCredits uses same single-statement pattern
  • adminGuard uses crypto.timingSafeEqual to prevent timing oracle attacks
  • Add ADMIN_API_KEY to config (min 32 chars, placeholder-rejected)
  • Both operations emit structured audit events and invalidate user cache

…inLearnOfficial#523 ChainLearnOfficial#526

ChainLearnOfficial#521 - Separate health check readiness from Stellar dependency checks
- /health/live: always 200 (liveness probe)
- /health/ready: DB + Redis only, Stellar removed (readiness probe)
- /health: full status including Stellar Horizon + Soroban RPC (monitoring)
- Add getSorobanServer() accessor to StellarClient
- Update README with three-tier health check documentation

ChainLearnOfficial#522 - Optimise recommendation queries (6 queries -> <=3)
- Implement getRecommendedCourses with merged user-context JOIN query
- Peer collaborative signal collapsed to single subquery JOIN, cached 24h
- Candidate courses + enrollment counts in one query via correlated subquery
- Add migration 0006 with 3 missing indexes for recommendation query paths
- Add GET /api/courses/recommended route with scoring and reason tags

ChainLearnOfficial#523 - Make audit logging non-blocking with buffered writes
- Replace fire-and-forget db.insert with AuditLogger class
- In-memory buffer flushed periodically (AUDIT_FLUSH_INTERVAL_MS) or on
  capacity (AUDIT_BUFFER_SIZE); flushing guard prevents concurrent races
- Timer is unref'd so it does not block clean process exit
- stopAuditLogger() awaits final flush before DB connection closes
- Add auth.login and auth.login_failed audit events to auth.service.ts
- Add AUDIT_BUFFER_SIZE and AUDIT_FLUSH_INTERVAL_MS to config

ChainLearnOfficial#526 - Fix TOCTOU race condition in deductCredits (negative balances)
- Build admin module: adminGuard, types, service, controller, routes
- deductCredits uses single atomic UPDATE...WHERE credits >= amount RETURNING
  eliminating the read-check-write gap that allowed negative balances
- On zero rows: EXISTS check distinguishes 404 (no user) vs 422 (low balance)
- grantCredits uses same single-statement pattern
- adminGuard uses crypto.timingSafeEqual to prevent timing oracle attacks
- Add ADMIN_API_KEY to config (min 32 chars, placeholder-rejected)
- Both operations emit structured audit events and invalidate user cache
@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@TheHalalHunter Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@DeFiVC
DeFiVC merged commit 6cdfac1 into ChainLearnOfficial:main Oct 1, 2026
3 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants