Skip to content

feat: readiness probe, shared cursor pagination, rate limit docs, and… - #391

Merged
Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
utilityjnr035-rgb:dev-branch
Sep 28, 2026
Merged

Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
utilityjnr035-rgb:dev-branch

Conversation

@utilityjnr035-rgb

Copy link
Copy Markdown

… sponsor negative tests

This commit resolves issues #336, #334, #341, and #337:

  1. Readiness endpoint distinct from liveness (Closes Add a /health/ready endpoint distinct from liveness that checks DB and Horizon reachability #336)
  • Added GET /health/ready endpoint in crates/api/src/lib.rs distinct from the cheap GET /health liveness probe.
  • Implemented Store::ping in crates/store/src/lib.rs executing a lightweight SELECT 1 against the Postgres connection pool.
  • Implemented Horizon::check_reachability in crates/api/src/horizon.rs probing the root endpoint with a 3-second timeout.
  • Returns HTTP 200 with structured JSON (status: ready, database: ok, horizon: ok) when all dependencies are healthy.
  • Returns HTTP 503 with structured JSON naming failed dependencies when degraded.
  • Added documentation in docs/architecture.md covering liveness vs readiness semantics for orchestrators.
  • Added integration tests covering reachable 200 and degraded 503 scenarios for DB and Horizon.
  1. Shared cursor pagination helper (Closes Consolidate the four near-identical cursor-pagination query patterns into one shared helper #334)
  • Extracted keyset cursor pagination query construction into cursor_pagination_query(table, filter_column) in crates/store/src/lib.rs.
  • Refactored list_wallets_for_user_page, list_addresses_page, list_transactions_page, and list_payment_links to use the shared helper, eliminating SQL query drift while preserving exact pagination semantics.
  • Added isolated unit test in crates/store/tests/store_tests.rs asserting query shape and keyset comparison invariants.
  1. Documented rate limit reference table (Closes Document rate-limit thresholds for every limited endpoint in one reference table #341)
  • Extracted rate limit thresholds and windows into public named constants in crates/api/src/rate_limit.rs.
  • Updated crates/api/src/auth.rs and crates/api/src/routes/payment_links.rs to reference the centralized constants.
  • Added comprehensive reference table to docs/api.md detailing every limited endpoint, HTTP method, key scope (per-IP, per-user), limit, window, and code constant name.
  • Included process note mandating updates to the table for future rate limit additions.
  1. Negative-path coverage for sponsor endpoint (Closes Add negative-path tests for sponsor.rs covering budget-exceeded and self-sponsorship rejection #337)
  • Added focused negative-path integration tests in crates/api/tests/sponsor_e2e_tests.rs:
    • sponsor_rejects_when_sponsorship_is_disabled_for_the_wallet (HTTP 403)
    • sponsor_rejects_a_max_fee_above_the_per_tx_cap (HTTP 400)
    • sponsor_rejects_a_self_sponsoring_inner_transaction (HTTP 400)
    • sponsor_rejects_once_the_daily_budget_is_exhausted (HTTP 429)
    • sponsor_rejects_for_a_client_custody_wallet_with_no_gas_tank (HTTP 403)
  • Added create_wallet_without_gas_tank helper to reliably exercise the client-custody unprovisioned gas tank rejection path.

Summary

Related step / issue

Checklist

  • cargo fmt --all -- --check passes
  • cargo clippy --workspace --all-targets -- -D warnings passes
  • cargo test --workspace passes
  • No secrets (seeds/keys) logged or persisted in plaintext
  • Added/updated tests (test vectors for crypto/derivation changes)
  • Updated docs / CHANGELOG if behavior changed

How to test

… sponsor negative tests

This commit resolves issues Octo-Protocol-org#336, Octo-Protocol-org#334, Octo-Protocol-org#341, and Octo-Protocol-org#337:

1. Readiness endpoint distinct from liveness (Closes Octo-Protocol-org#336)
- Added GET /health/ready endpoint in crates/api/src/lib.rs distinct from the cheap GET /health liveness probe.
- Implemented Store::ping in crates/store/src/lib.rs executing a lightweight SELECT 1 against the Postgres connection pool.
- Implemented Horizon::check_reachability in crates/api/src/horizon.rs probing the root endpoint with a 3-second timeout.
- Returns HTTP 200 with structured JSON (status: ready, database: ok, horizon: ok) when all dependencies are healthy.
- Returns HTTP 503 with structured JSON naming failed dependencies when degraded.
- Added documentation in docs/architecture.md covering liveness vs readiness semantics for orchestrators.
- Added integration tests covering reachable 200 and degraded 503 scenarios for DB and Horizon.

2. Shared cursor pagination helper (Closes Octo-Protocol-org#334)
- Extracted keyset cursor pagination query construction into cursor_pagination_query(table, filter_column) in crates/store/src/lib.rs.
- Refactored list_wallets_for_user_page, list_addresses_page, list_transactions_page, and list_payment_links to use the shared helper, eliminating SQL query drift while preserving exact pagination semantics.
- Added isolated unit test in crates/store/tests/store_tests.rs asserting query shape and keyset comparison invariants.

3. Documented rate limit reference table (Closes Octo-Protocol-org#341)
- Extracted rate limit thresholds and windows into public named constants in crates/api/src/rate_limit.rs.
- Updated crates/api/src/auth.rs and crates/api/src/routes/payment_links.rs to reference the centralized constants.
- Added comprehensive reference table to docs/api.md detailing every limited endpoint, HTTP method, key scope (per-IP, per-user), limit, window, and code constant name.
- Included process note mandating updates to the table for future rate limit additions.

4. Negative-path coverage for sponsor endpoint (Closes Octo-Protocol-org#337)
- Added focused negative-path integration tests in crates/api/tests/sponsor_e2e_tests.rs:
  - sponsor_rejects_when_sponsorship_is_disabled_for_the_wallet (HTTP 403)
  - sponsor_rejects_a_max_fee_above_the_per_tx_cap (HTTP 400)
  - sponsor_rejects_a_self_sponsoring_inner_transaction (HTTP 400)
  - sponsor_rejects_once_the_daily_budget_is_exhausted (HTTP 429)
  - sponsor_rejects_for_a_client_custody_wallet_with_no_gas_tank (HTTP 403)
- Added create_wallet_without_gas_tank helper to reliably exercise the client-custody unprovisioned gas tank rejection path.
@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@utilityjnr035-rgb Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

# Conflicts:
#	crates/api/src/lib.rs
#	crates/store/tests/store_tests.rs
#	docs/api.md
#	docs/architecture.md
@Emmyt24
Emmyt24 merged commit 4759541 into Octo-Protocol-org:dev-branch Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment