Skip to content

fix: security enhancements — timing protection, JWT rotation, CORS, audit logging - #543

Merged
DeFiVC merged 3 commits into
ChainLearnOfficial:mainfrom
oomokaro1:fix/security-enhancements
Oct 1, 2026
Merged

DeFiVC merged 3 commits into
ChainLearnOfficial:mainfrom
oomokaro1:fix/security-enhancements

Conversation

@oomokaro1

Copy link
Copy Markdown
Contributor

Closes #489, Closes #490, Closes #491, Closes #492

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Refactoring (no functional or behavioral changes)
  • Performance improvement
  • Documentation update
  • Build / CI configuration change
  • Dependency update
  • Other:

Summary

This PR addresses four security-related issues: timing attack protection for sensitive token comparisons (#492), JWT signing key rotation support (#489), stricter CORS configuration for non-production environments (#490), and audit logging for sensitive operations (#491). It also fixes a pre-existing syntax error in the config test-mode fallback that prevented tests from running.

Motivation / Context

Closes #489, Closes #490, Closes #491, Closes #492

…hainLearnOfficial#492)

Use crypto.timingSafeEqual() for stellarAddress and nonce comparisons
to prevent timing side-channel attacks. Add reusable safeEqual() helper
in src/utils/crypto.ts.
…LearnOfficial#489)

Allow configuring previous JWT secrets so tokens signed with old keys
remain valid during a rotation window. New tokens are always signed
with the current JWT_SECRET.
)

Log failed auth attempts, successful logins, rate limit violations,
and cache invalidation events. Add rate_limit.exceeded and
cache.invalidated audit event types.
@drips-wave

drips-wave Bot commented Oct 1, 2026

Copy link
Copy Markdown

@oomokaro1 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@DeFiVC
DeFiVC merged commit 9626ad3 into ChainLearnOfficial:main Oct 1, 2026
2 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants