Skip to content

fix: resolve issues #298, #304, #309, #318 - #540

Merged
james2177 merged 3 commits into
stellar-vortex-protocol:mainfrom
Iceeyyou2:fix/issues-298-304-309-318
Sep 30, 2026
Merged

james2177 merged 3 commits into
stellar-vortex-protocol:mainfrom
Iceeyyou2:fix/issues-298-304-309-318

Conversation

@Iceeyyou2

Copy link
Copy Markdown

closes #298 — Restrict GET /metrics

  • Add MetricsTokenGuard with bearer-token auth (METRICS_TOKEN env var)
  • Fail-closed in production when METRICS_TOKEN is unset (returns 401)
  • Allow unauthenticated scraping in non-production for local Prometheus stacks
  • Wire guard onto MetricsController with @UseGuards
  • Add METRICS_TOKEN to env.validation.ts and all .env.*.example files
  • Add MetricsTokenGuard unit tests (7 cases)

closes #304 — Sanitise HttpExceptionFilter custom-shaped-body passthrough

  • Introduce CUSTOM_BODY_ALLOWLIST (error, intentId, fillAmount, minDstAmount)
  • Strip unlisted fields and emit logger.warn so contributors learn about leaks
  • Inject requestId into custom-shaped responses (was missing)
  • Add spec cases: allowlist forwarding, unknown-field stripping, requestId injection

closes #309 — Add .github/ISSUE_TEMPLATE/ directory

  • bug-report.yml: structured bug report with reproduction steps, environment
  • feature-request.yml: problem/solution/alternatives with area dropdown
  • contributor-claim.yml: Drips Wave item claim form with implementation plan
  • config.yml: disable blank issues; redirect security reports to advisory flow

closes #318 — OpenAPI drift-check CI job

  • Add openapi-drift job to ci.yml (runs on pull_request only)
  • Builds the app, regenerates the client, and diffs src/generated/
  • Fails with an actionable error if openapi.json or api-types.ts are stale

Summary

Related issue

Type of change

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI / tooling

Component

  • Contract (vortex-contract)
  • Backend (vortex-backend)
  • Frontend (vortex-frontend)

Checklist

  • My code follows the project's style and conventions
  • I ran lint / type-check / build locally and they pass
  • I added or updated tests where appropriate
  • I updated documentation where appropriate
  • My commits follow Conventional Commits

Screenshots / notes

…col#304, stellar-vortex-protocol#309, stellar-vortex-protocol#318

stellar-vortex-protocol#298 — Restrict GET /metrics
- Add MetricsTokenGuard with bearer-token auth (METRICS_TOKEN env var)
- Fail-closed in production when METRICS_TOKEN is unset (returns 401)
- Allow unauthenticated scraping in non-production for local Prometheus stacks
- Wire guard onto MetricsController with @UseGuards
- Add METRICS_TOKEN to env.validation.ts and all .env.*.example files
- Add MetricsTokenGuard unit tests (7 cases)

stellar-vortex-protocol#304 — Sanitise HttpExceptionFilter custom-shaped-body passthrough
- Introduce CUSTOM_BODY_ALLOWLIST (error, intentId, fillAmount, minDstAmount)
- Strip unlisted fields and emit logger.warn so contributors learn about leaks
- Inject requestId into custom-shaped responses (was missing)
- Add spec cases: allowlist forwarding, unknown-field stripping, requestId injection

stellar-vortex-protocol#309 — Add .github/ISSUE_TEMPLATE/ directory
- bug-report.yml: structured bug report with reproduction steps, environment
- feature-request.yml: problem/solution/alternatives with area dropdown
- contributor-claim.yml: Drips Wave item claim form with implementation plan
- config.yml: disable blank issues; redirect security reports to advisory flow

stellar-vortex-protocol#318 — OpenAPI drift-check CI job
- Add openapi-drift job to ci.yml (runs on pull_request only)
- Builds the app, regenerates the client, and diffs src/generated/
- Fails with an actionable error if openapi.json or api-types.ts are stale
@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Iceeyyou2 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@james2177
james2177 merged commit 38fe266 into stellar-vortex-protocol:main Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants