Skip to content

feat: correlate requests, paginate audit, sign webhooks - #390

Merged
Cjay-Cyber-2 merged 9 commits into
ASTROIDX556:mainfrom
aetheron06:feature/issues-55-57-61
Oct 2, 2026
Merged

Cjay-Cyber-2 merged 9 commits into
ASTROIDX556:mainfrom
aetheron06:feature/issues-55-57-61

Conversation

@aetheron06

Copy link
Copy Markdown
Contributor

Closes #55
Closes #61
Closes #57

  • Validate and propagate request IDs through request context, events, and queued job metadata.
  • Add bounded cursor pagination and filters to audit history.
  • Sign outbound webhook body bytes using versioned, event-bound HMAC-SHA256. Keep endpoint secrets out of queued jobs and disclose them only on create or rotation.

Webhook verification example (use the endpoint secret returned at creation or rotation; retain the raw request body):

import { createHmac, timingSafeEqual } from 'node:crypto';

const input = Buffer.concat([
  Buffer.from(`v1.${timestamp}.${eventId}.`, 'utf8'),
  rawBody,
]);
const expected = createHmac('sha256', secret).update(input).digest();
const match = /^v1=([0-9a-f]{64})$/.exec(signatureHeader);
const actual = match && Buffer.from(match[1], 'hex');
const valid = !!actual &&
  actual.length === expected.length &&
  timingSafeEqual(actual, expected);

@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@aetheron06 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Cjay-Cyber-2

Cjay-Cyber-2 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

CI is failing in build-and-test during TypeScript compilation. Please update the stale test fixtures to the current APIs: SorobanSimulationResult no longer accepts id, error values use the { code, message } shape, remove unused injected service mocks, use the current transaction input (asset plus required metadata) instead of assetCode-only payloads, and replace assertions for the removed StellarService.simulateTransaction method with the current simulation API/response shape. Push the fixes and rerun CI.

@Cjay-Cyber-2

Copy link
Copy Markdown
Contributor

CI Checks Failed - Action Needed. build-and-test fails on stale TypeScript tests against the current API. Update fixtures and mocks to current contracts: use asset and the current transaction result shape, remove obsolete simulateTransaction and getTransactionInfo references, fix the Redis/Nest test setup, and remove unused variables/imports. Push and rerun CI.

@Cjay-Cyber-2
Cjay-Cyber-2 merged commit 2089a5e into ASTROIDX556:main Oct 2, 2026
1 check passed
@aetheron06
aetheron06 deleted the feature/issues-55-57-61 branch October 3, 2026 10:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants