feat(security): add abuse controls and correlation IDs to mutation routes - #138
Open
woahwhattheheck wants to merge 8 commits into
Open
woahwhattheheck wants to merge 8 commits into
woahwhattheheck wants to merge 8 commits into
Conversation
…utes Bound transfer, user, quote, and admin mutation traffic with per-actor fixed-window limits, bounded limiter state, and safe 429 responses. Sanitize and propagate X-Request-Id / X-Correlation-Id without echoing secrets. Closes RemitFlow#131.
This was referenced Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #131.
Adds production-shaped abuse controls on transfer, user, quote, and admin mutation routes, plus sanitized correlation-id propagation so accepted commands can be traced without leaking account secrets.
Note: #133 already has an open solid PR (#137), so this targets the unassigned fallback issue #131 instead of reminting lifecycle concurrency work.
What
maxKeyseviction) used for the global/apibudget and for route-family mutation budgets.GET /api/quote.TRUST_PROXYgates whetherX-Forwarded-Forcan influence client identity (off by default).X-Request-Id/X-Correlation-Id, reject unsafe values, and echo on both response headers and error envelopes.docs/ABUSE_CONTROLS.md.Why
High-volume retries and automated abuse can exhaust provider quotas and make incidents hard to correlate. Route-specific actor limits bound bursts; sanitized correlation ids keep every accepted command traceable without putting tokens or account data into logs or headers.
How tested
npm test— 267 passing (includes newtest/abuseControls.test.js).Retry-After, actor isolation, proxy-trust forgery rejection, distinct forwarded IPs when trusted,maxKeysbound under identity flood, correlation echo on success/429 without token leakage, unsafe inbound correlation replacement.Design tradeoffs
429, rate-limit headers, correlation headers) stays the same.NODE_ENV=testunlessforceInTest/ENABLE_RATE_LIMIT_IN_TEST=1, so the functional suite stays independent of the abuse budget while dedicated regressions still run.