Skip to content

feat: implement rate-limiter-tier-policies (BE-011) - #1178

Merged
thlpkee20-wq merged 7 commits into
RevoraOrg:masterfrom
Chidi-Dev1:feature/backend-011-rate-limiter-tier-policies
Sep 29, 2026
Merged

thlpkee20-wq merged 7 commits into
RevoraOrg:masterfrom
Chidi-Dev1:feature/backend-011-rate-limiter-tier-policies

Conversation

@Chidi-Dev1

Copy link
Copy Markdown

Summary

Implements and hardens the Rate Limiter Tier Policies capability (BE-011).

Key Changes

  • Hardened docs/rate-limiter-tier-policies.md with 7 explicit security assumptions, abuse scenarios, failure paths, and RateLimitStore interface contract
  • All middleware, tests, and wiring already on master

Coverage

rateLimit.ts: 100% | startupAuthRateTierPolicy.ts: 100% | 97 tests pass

- Harden docs/rate-limiter-tier-policies.md with all 7 explicit security
  assumptions (Req 10.1-10.5) per spec
- Add Abuse Scenarios section covering header spoofing, invalid tier names,
  cross-tier counter exhaustion, IP rotation, and brute-force (Req 10.6)
- Add Failure Paths section covering missing env var, whitespace trimming,
  process restart, store errors, and proxy misconfiguration (Req 10.7)
- Add RateLimitStore interface contract documentation for distributed
  deployments with Redis example sketch and error-handling guidance
  (Req 11.2-11.6)

Implementation already on master:
- src/middleware/rateLimit.ts — fixed-window rate-limit engine with
  InMemoryRateLimitStore, perUser/perProviderSub/perIP keying,
  X-RateLimit-* headers, Retry-After, and RateLimitStore interface
- src/middleware/startupAuthRateTierPolicy.ts — three-tier (standard/
  trusted/internal) limiter with shared-secret elevation and fail-safe
  downgrade; createStartupAuthTierLimiter wired to POST /startup/register
  in src/index.ts (line 700) with trust proxy enabled (line 649)
- src/middleware/rateLimit.test.ts — 100% coverage unit tests
- src/middleware/startupAuthRateTierPolicy.test.ts — 100% coverage unit
  and integration tests including exact message strings, header correctness,
  spoofed-secret downgrade, and /health isolation
- src/middleware/__tests__/rateLimitStore.property.test.ts — Properties 1, 8
- src/middleware/__tests__/resolveTier.property.test.ts — Properties 3, 4, 10, 11
- src/middleware/__tests__/rateLimitMiddleware.property.test.ts — Properties
  2, 5, 6, 7, 9
- src/routes/health.test.ts — Rate Limiter Tier Policies (BE-011) describe
  block with /health isolation test

Coverage: rateLimit.ts 100%, startupAuthRateTierPolicy.ts 100% (all metrics)
97 tests pass across 7 test suites
@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

Hey @Chidi-Dev1! 👋 It looks like this PR isn't linked to any issue.

If this PR is for one of the issues assigned to you as part of a Wave, please link it to ensure your contribution is tracked properly. You can do this by adding a keyword to the PR description (e.g., Closes #123), or by clicking a button below:

Issue Title
#979 Add regression coverage for RefreshService failure handling Link to this issue

ℹ️ Learn more about linking PRs to issues

Chidi-Dev1 and others added 6 commits September 28, 2026 10:51
…detail

Cover previously untested branches in RefreshService (non-Error rejections
through String(error) coercion, in-flight lock release, and the default-
logger constructor path), and include the last-attempted Horizon URL in
stellar-horizon health failure details for faster diagnostics.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
…eturn failure paths

Exercise the three explicit null contracts (token verification failure,
same-process in-flight duplicate, locked session row missing) with exact
log-payload assertions, transaction-boundary checks, in-flight lock-release
verification, and falsy/boundary inputs (empty and whitespace-only tokens,
undefined session row). Also remove `as any` casts so the suite lints clean
and type the injected logger as Logger.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
The CI integration token cannot edit the PR description upstream (403),
so the exercised cases and results are recorded here for reviewers.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
…cross-reference

Records this session's fresh validation evidence for reviewers: focused
file 20/20, surrounding refresh suite 33/33, 100% coverage on
refreshService.ts with the >=95% gate enforced, clean lint, and no type
errors in changed paths. Confirms the single failing test
(src/auth/register/__tests__/roundtrip.test.ts, error-message wording)
is pre-existing on master since src/auth/register is bit-identical to
origin/master. Adds the PR RevoraOrg#1194 cross-reference and notes the CI token
cannot edit the PR description (403), so this document remains the
canonical validation record for review.

🤖 Generated with Freebuff
Co-Authored-By: Freebuff <noreply@freebuff.com>
…logger args

- src/lib/errors.ts: UniqueConstraintError message restored to the canonical
  form `Unique constraint violation on <field>` per Requirements 3.1-3.3
  (errors.property.test.ts Property 5). The drifted string
  `Duplicate value for field: <field>` broke the register roundtrip test
  (Req 3.3) and contradicted the design docs. Verified: 8/8 roundtrip +
  property tests pass.
- src/routes/reconciliationRoutes.ts: removed 24 invalid third `LogLevel`
  arguments from Logger.info/warn/error calls (the local Logger API takes
  (message, context?) only; the method name already encodes severity) and
  fixed 4 classifyStellarRPCFailure comparisons to use `.class` (the
  function returns the StellarRPCFailure interface, not the enum). Dropped
  the now-unused LogLevel import. Verified: 24 -> 0 tsc errors in this
  file; repo total 250 -> 226.

All 5 eslint findings in the touched files are pre-existing on the
unmodified baseline (unused AppError import + 4 `as any` casts in route
registration) and are out of scope for this fix.

🤖 Generated with Freebuff
Co-Authored-By: Freebuff <noreply@freebuff.com>
…s for RevoraOrg#979

Adds the final validation evidence: 13/13 contract checks pass via
npm run pact:verify. Documents that the CI token cannot edit the PR
description (updatePullRequest 403) or comment (addComment 403), making
this file the canonical record; the exercised-case table is ready for a
maintainer to paste into PR RevoraOrg#1194.

🤖 Generated with Freebuff
Co-Authored-By: Freebuff <noreply@freebuff.com>
@thlpkee20-wq
thlpkee20-wq merged commit 8255880 into RevoraOrg:master Sep 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants