feat(backend): resolve issues #1426 #1427 #1428 — fraud detection & w… - #1593
Merged
emdevelopa merged 1 commit intoSep 30, 2026
Conversation
…opa#1428 — fraud detection & webhook improvements Closes emdevelopa#1426 Closes emdevelopa#1427 Closes emdevelopa#1428 ## emdevelopa#1428 — Add Prometheus alert metrics and health telemetry to Fraud Detection Engine - Added 6 new Prometheus metrics to metrics.js: * fraudDetectionAlertsFired (Counter) — tracks high-risk alert events by merchant/risk level * fraudDetectionHealthStatus (Gauge) — engine & cache health (1=healthy, 0=degraded) * fraudDetectionRuleHits (Counter) — per-rule trigger counts (large_amount, stale_payment, etc.) * fraudDetectionEngineLatency (Histogram) — per-evaluation latency with p99 tracking * fraudDetectionCacheHealth (Gauge) — cache size and capacity telemetry * fraudDetectionAnomalyScore (Histogram) — risk score distribution per merchant - Instrumented analyzePayment() with latency timers, rule hit counters, alert firing, and anomaly score observation - Added getFraudDetectionHealthStatus() export for health endpoint integration - Added Prometheus alert rules file: backend/docs/alerts/fraud-detection-engine.rules.yml * FraudDetectionEngineHighAlertRate (critical, >10 alerts/sec for 2m) * FraudDetectionEngineDegraded (critical, engine health == 0 for 1m) * FraudDetectionCacheNearCapacity (warning, >90% full for 5m) * FraudDetectionHighLatency (warning, p99 > 100ms for 5m) * FraudDetectionSuspiciousAnomalySpike (warning, rule hits > 50/sec for 3m) * FraudDetectionErrorRate (critical, errors > 1/sec for 2m) ## emdevelopa#1427 — Implement payload sanitization and strict validation for Fraud Detection Engine - New file: backend/src/lib/fraud-detection-sanitizer.js * Zod-based strict schema validation (fraudDetectionPayloadSchema) * Stellar address format validation (/^G[A-Z2-7]{55}$/) * Payment status whitelist (pending/completed/failed/expired/refunded) * Amount validation (positive numeric string, up to 7 decimal places) * Memo sanitization (max 200 chars, control char stripping) * Prototype pollution prevention (strips __proto__, constructor, prototype keys) * Metadata sanitization via existing sanitize-metadata utility * String truncation guard (max 1000 chars per value) * Merchant ID validation (/^[a-zA-Z0-9_\-:.@]+$/, max 128 chars) - Integrated sanitizeAndValidateFraudPayload() at the entry point of analyzePayment() - Integrated validateMerchantId() guard in clearCache() - Returns structured validation errors with field paths for observability - New test file: backend/src/lib/fraud-detection-sanitizer.test.js * 20+ test cases covering valid payloads, XSS, prototype pollution, edge cases ## emdevelopa#1426 — Add comprehensive integration and stress test suite for Webhook Event Dispatcher - New file: backend/tests/integration/webhook-event-dispatcher.integration.test.js - Integration tests (WebhookEventCache): * Payload store/retrieve, TTL expiry, LRU eviction * Delivery deduplication (first=false, repeat=true, overflow guard) * Subscription cache CRUD and invalidation * Circuit breaker open/close/reset/per-merchant isolation * Cache stats shape validation, clearAll atomicity * Payload integrity (nested objects, unicode, large payloads) * Special character IDs, overwrite behavior - Stress tests: * 5000 sequential writes < 500ms * 5000 sequential reads < 100ms * 1000 concurrent deduplication checks (Promise.all) * Cache size enforcement under overflow pressure * 50 merchants × 100 subscriptions cached * Circuit breaker operations for 100 merchants < 200ms * 10000 cache lookups < 200ms throughput SLO * Mixed read/write/delete stability under 2000 ops ## Housekeeping - Updated .gitignore to exclude test-results/, __snapshots__/, *.snap, playwright-report/, tsconfig.tsbuildinfo, output.txt, logs/, coverage/, .env.local, temp files, IDE artifacts
|
@ke747 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
|
@ke747 is attempting to deploy a commit to the Emmanuel's projects Team on Vercel. A member of the Team first needs to authorize it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
…ebhook improvements
Closes #1426
Closes #1427
Closes #1428
#1428 — Add Prometheus alert metrics and health telemetry to Fraud Detection Engine
#1427 — Implement payload sanitization and strict validation for Fraud Detection Engine
#1426 — Add comprehensive integration and stress test suite for Webhook Event Dispatcher
Housekeeping