Skip to content

fix: security hardening and input validation across auth, oracle, and stellar services - #634

Merged
nonsobethel0-dev merged 4 commits into
Parashield-Protocol:mainfrom
KidDev88:fix/security-and-validation-issues
Sep 25, 2026
Merged

nonsobethel0-dev merged 4 commits into
Parashield-Protocol:mainfrom
KidDev88:fix/security-and-validation-issues

Conversation

@KidDev88

Copy link
Copy Markdown
Contributor

Closes #542, Closes #533, Closes #532, Closes #531

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • Security fix

Summary

Addresses 4 security and validation issues across the backend:

Motivation / Context

Closes #542, Closes #533, Closes #532, Closes #531

Testing

  • All auth middleware tests pass with truncated address output (verified GCO4G742...SATT format in logs)
  • Pre-existing test failures in oracle.service and stellar.service specs are unrelated to these changes

Changes

File Change
src/auth/auth.middleware.ts Added truncateAddress() helper; all 11 log messages now use truncated addresses
src/oracle/oracle.controller.ts Added explicit month range check (1-12) in fetchRainfall
src/stellar/stellar.service.ts Removed operation field from HttpException in withTimeout
src/oracle/oracle.service.ts Added confidence range validation in persistReading; fixed pre-existing uncommented #548 reference

…eware log messages

Wallet addresses are now logged as first 8 + last 4 characters
(e.g., GBARCZTW...XLDL) to prevent user tracking and deanonymization
via production log streams.
…ainfall controller

Add defense-in-depth validation that month is an integer between 1 and
12 in the POST /oracle/fetch/rainfall endpoint, matching the validation
already present in the query-param getRainfall endpoint.
…acing timeout error

The withTimeout method previously included the internal RPC operation
name (e.g., 'sendTransaction', 'getAccount') in the HttpException
response, which could expose implementation details to clients. The
error message is now generic.
…ding before database write

Add validation that confidence is a finite number between 0 and 100
before persisting an oracle reading. Invalid confidence values are
rejected with an error log to prevent corrupted downstream aggregation.

Also fix pre-existing syntax error: uncommented Parashield-Protocol#548 issue reference
in onFailure method.
@drips-wave

drips-wave Bot commented Sep 25, 2026

Copy link
Copy Markdown

@KidDev88 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@nonsobethel0-dev
nonsobethel0-dev merged commit 706cd3f into Parashield-Protocol:main Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants