feat: comparison share serving, TOTP 2FA, realtime analytics feed, and config knob fixes - #1327
Merged
nanaf6203-bit merged 3 commits intoSep 28, 2026
Conversation
…hboard feed, and config cleanup Resolves four open backend issues together because they share the auth, database and analytics wiring: MettaChain#1292 ComparisonShare - Add public GET /property-comparison/shares/:token that resolves the two compared properties without owner PII. - Enforce expiresAt and the new revokedAt, track viewCount/lastViewedAt, and add a creator-only revoke endpoint. Sharing URLs now point at the serving route, with e2e coverage for valid/expired/revoked tokens. MettaChain#1291 TOTP two-factor - Add trusted-device sessions (hashed tokens, TTL via TRUSTED_DEVICE_TTL_DAYS) so remembered devices can skip the challenge. - Add recovery-code regeneration plus device listing/revocation. - Add an admin force-disable endpoint for locked-out users. - Gate high-risk account operations behind a fresh second factor. - Trusted devices are revoked on password change, 2FA disable and admin reset. MettaChain#1297 Realtime dashboard feed - Add a cached aggregate snapshot service (queue depth, fraud alerts, property/transaction deltas) and an authenticated `analytics` Socket.IO namespace with heartbeat, using the existing Redis adapter. MettaChain#1290 Config knobs - Wire PGBOUNCER_POOL_TIMEOUT and CACHE_WARMING_INTERVAL into real behavior, reconcile the README/.env.example documentation, and add a config-docs smoke test. Closes MettaChain#1290 Closes MettaChain#1291 Closes MettaChain#1292 Closes MettaChain#1297
Adds integration coverage for the MettaChain#1291 two-factor lifecycle: enrollment via setup/verify, the login challenge across TOTP and recovery codes, trusted-device bypass, and one-time device token issuance.
|
@beulah7717108-eng Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves four backend issues that share the auth, database and analytics wiring.
#1292 — ComparisonShare serving and share URLs
GET /property-comparison/shares/:tokenresolving the two compared properties without owner PII.expiresAtand the newrevokedAt, tracksviewCount/lastViewedAt, and adds a creator-only revoke endpoint.#1291 — TOTP two-factor with trusted devices and recovery codes
TRUSTED_DEVICE_TTL_DAYS) let a remembered device skip the challenge.#1297 — Real-time dashboard metrics feed
analyticsSocket.IO namespace with a heartbeat, using the existing Redis adapter for multi-replica fan-out.#1290 — Declared-but-unused config values
PGBOUNCER_POOL_TIMEOUT(Prismapool_timeout) andCACHE_WARMING_INTERVAL(interval scheduler) into real behavior..env.exampledocumentation and adds a config-docs smoke test.Verification
npx jest src/auth src/property-comparison src/analytics test/unit/config-docs.spec.ts test/e2e/comparison-share.e2e.spec.ts --runInBandNote:
src/webhooks/webhooks.service.tscontains a pre-existing syntax error onmain(orphaned block from an earlier merge) that breakstsc/the webhooks suite independently of this change; it is left untouched here to keep this PR scoped.Closes #1290
Closes #1291
Closes #1292
Closes #1297