Background
.env.example has fallen behind the code. DIRECT_DATABASE_URL (read at src/index.ts:5 and by the Prisma datasource), RATE_LIMIT_IP_MAX (index.ts:114), ORACLE_PAYMENT_ADDRESS_{TESTNET,MAINNET} and REFLECTOR_CONTRACT_ID are all missing.
Issue #25 ("document all environment variables") is closed, so re-documenting by hand just restarts the same decay. The useful version of this issue is the guard, not the list.
What to build
- A test that scans the source for
process.env.X reads and asserts each one appears in .env.example.
- An explicit, commented allow-list for variables that are deliberately undocumented — CI-only, platform-injected — so the test stays honest rather than being weakened when it first fails.
- Fix today's gaps as the first thing the new test catches.
Acceptance criteria
Drips Wave · Complexity: Easy · 100 points
Lens aggregates SDEX trades and AMM pool prices into VWAP, OHLCV and best-route data. Node/TypeScript, TimescaleDB, deployed on Render. Tests are vitest.
The repo is in better shape than most — clean typecheck, 400 passing tests, OpenAPI publishing, Prometheus metrics. Its recurring weakness is a seam: everything written since the dual-network work is network-aware, and almost everything written before it silently pools testnet and mainnet. Two issues below are on that seam.
Ground rules
- Every PR needs a test that fails before the change and passes after, unless the issue says otherwise.
- A price with the wrong units, the wrong network or the wrong timestamp is worse than no price. Prefer refusing to answer over answering confidently.
- Validate every hard-coded
C…/G… with StrKey.isValidContract / isValidEd25519PublicKey. A length or shape check is not validation.
- Do not widen a Prometheus label to something unbounded. Pairs and networks are fine; issuers and pool ids are not.
- Never log or render an RPC URL — provider keys live in the URL path.
- Fork PRs run no CI here, so a green or absent check is not evidence. Verify locally and say what you ran.
Two open issues are misleading, so do not be misled
#146 ("broken @stellar/stellar-sdk vitest mock") does not reproduce — it was fixed in 041c2fc/7e2716a and the issue is now closed. #151 (flaky suite) is real, reproduced with rotating victims; the root cause nobody has fixed is that src/config.ts:245-253 memoises each NetworkConfig in a module-level Map, and restoring process.env does not invalidate it — only vi.resetModules() does.
Required: Before submitting, join the contributor Telegram so your work can be tracked and counted toward the Stellar Wave: https://t.me/+fxHXq8f1SwlkZDBk
Background
.env.examplehas fallen behind the code.DIRECT_DATABASE_URL(read atsrc/index.ts:5and by the Prisma datasource),RATE_LIMIT_IP_MAX(index.ts:114),ORACLE_PAYMENT_ADDRESS_{TESTNET,MAINNET}andREFLECTOR_CONTRACT_IDare all missing.Issue #25 ("document all environment variables") is closed, so re-documenting by hand just restarts the same decay. The useful version of this issue is the guard, not the list.
What to build
process.env.Xreads and asserts each one appears in.env.example.Acceptance criteria
process.envread with no.env.exampleentry fails the testLens aggregates SDEX trades and AMM pool prices into VWAP, OHLCV and best-route data. Node/TypeScript, TimescaleDB, deployed on Render. Tests are vitest.
The repo is in better shape than most — clean typecheck, 400 passing tests, OpenAPI publishing, Prometheus metrics. Its recurring weakness is a seam: everything written since the dual-network work is network-aware, and almost everything written before it silently pools testnet and mainnet. Two issues below are on that seam.
Ground rules
C…/G…withStrKey.isValidContract/isValidEd25519PublicKey. A length or shape check is not validation.Two open issues are misleading, so do not be misled
#146 ("broken
@stellar/stellar-sdkvitest mock") does not reproduce — it was fixed in041c2fc/7e2716aand the issue is now closed. #151 (flaky suite) is real, reproduced with rotating victims; the root cause nobody has fixed is thatsrc/config.ts:245-253memoises eachNetworkConfigin a module-levelMap, and restoringprocess.envdoes not invalidate it — onlyvi.resetModules()does.Required: Before submitting, join the contributor Telegram so your work can be tracked and counted toward the Stellar Wave: https://t.me/+fxHXq8f1SwlkZDBk