HelPhone is a React + Vite community emergency response application built on Stellar. It combines wallet-gated help requests, Soroban smart contracts, local ZK privacy proofs, WebAuthn Passkeys, and automated contract storage state backups.
- CLI Exporter:
scripts/export-contract-state.shextracts complete contract storage dumps usingstellar contract inspector JSON-RPC queries. - Node.js/TypeScript Exporter:
server/indexer/exporter.tsindexes storage entries into versioned JSON snapshots (./snapshots/snapshot-<ledgerSeq>.json). - Automated Backup Cron:
server/index.tsautomatically runs daily state export tasks to back up contract storage. - Disaster Recovery Runbook: See
docs/disaster-recovery.mdfor state restoration procedures.
- Husky & lint-staged: Intercepts
git commitvia.husky/pre-committo automatically run linters and type-checkers on staged files. - Quality Verification:
npm run lint(eslint .) - Code style & quality checks.npm run typecheck(tsc --noEmit) - Strict TypeScript validation without building output.npm test- Vitest test suite execution.
- GitHub Actions CI:
.github/workflows/ci.ymlenforces quality, linting, type-checking, state export verification, and crypto matrix tests on all pull requests and pushes.
- Feature Flag Engine:
src/lib/featureFlags.tsevaluates feature flag toggles dynamically. - Remote Config: Fetches rulesets from
/config.jsonwithout requiring application rebuilds. - Percentage Hashing: Deterministically hashes user IDs / device IDs for 0-100% canary rollouts.
- React Hook Integration: Components use
useFeatureFlag('flag_name')for conditional rendering.
- Cryptographic Suite:
src/lib/crypto.tsprovides Ed25519 signature verification, WebAuthn P-256 (ECDSA SHA-256) parsing, and AES-256-GCM encryption/decryption. - Passkey Manager:
src/lib/passkey.tshandles browser WebAuthn credential registration and authentication. - Auth Middleware:
server/middleware/auth.tsenforces anti-replay timestamp freshness and cryptographic header verification. - Test Matrix:
test/crypto-verification.test.jscovers positive & negative boundary tests (tampered payload, invalid key, expired signature).
- HTTP Keep-Alive:
server/middleware/keepAlive.tsholds sockets open for 65 s (above the balancer's 60 s idle timeout) so sequential API and WebSocket traffic reuses one TCP connection. Seedocs/performance-optimization.md. - Map Overlay Rendering:
src/lib/offscreenCanvas.ts+src/workers/canvas-worker.jsanimate map markers in a Web Worker via OffscreenCanvas, with a main-thread fallback and measured FPS. Seedocs/performance-optimization.md. - Client Storage Encryption:
src/lib/pbkdf2Key.ts+src/lib/secureStorage.tsderive an AES-256-GCM key via PBKDF2 (100k iterations, per-device salt in IndexedDB) to encrypt local data. Seedocs/security-architecture.md. - Network Resilience Testing:
tests/e2e/throttling.spec.tsemulates 2G, 3G, a 500 kbps cap, and offline via CDP, with a CI matrix leg per profile. Seedocs/network-resilience.md.
- Auditor:
scripts/audit-deps.jsauditspackage-lock.jsonandserver/package-lock.json(zero dependencies, offline) and fails CI on unauthorized copyleft licenses (GPL/AGPL/SSPL/EUPL/OSL/CPAL/RPL not inscripts/security/license_policy.jsEXCEPTIONS), unlisted or suspicious install scripts, and hijack indicators (untrusted registry host,http:///git sources, missing or non-sha512 integrity). - Report: a deterministic
licenses.json;npm run security:audit-depsregenerates it andnpm run security:audit-deps:check(CI) fails when it is stale. - Runbook: docs/security-runbook.md.
- Tests:
test/dep-audit.test.js.
# Install dependencies
npm install
# Run local development server & indexer
npm run dev
# Run code quality & type checking
npm run lint
npm run typecheck
# Run complete Vitest test suite
npm test
# Export Soroban contract storage state manually
npm run export:stateConfigure .env:
VITE_MAPBOX_TOKEN=...
VITE_AEGIS_VAULT_ID=...
SOROBAN_RPC_URL=https://soroban-testnet.stellar.org
CONTRACT_ID=CC325F37QW7N2F5M3QGHL4A4O7J2K9L0M1N2O3P4Q5R6S7T8U9V0- Server Blueprint: Managed via
render.yamlwith web service and daily snapshot cron jobs. - CI/CD Pipeline: GitHub Actions workflow at
.github/workflows/ci.yml.