feat(config): API prefix, JWT secret hardening, RPC/network check, secret providers - #354
Merged
EmmanuelOchaje merged 2 commits intoOct 4, 2026
Conversation
✅ Deploy Preview for stellarticketsbackend ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
…cret providers - API_PREFIX mounts every route under a path prefix via setGlobalPrefix, with GET /health excluded so probes keep working (StellarTickets#250). - JWT_SECRET must be 32+ characters everywhere; in production it must also not be a known placeholder and must have 10+ distinct characters (StellarTickets#251). - Boot fails when SOROBAN_RPC_URL names a different network than STELLAR_NETWORK, since the passphrase is derived from STELLAR_NETWORK; the passphrase table now lives in src/config/stellar-networks.ts (StellarTickets#252). - JWT_SECRET is resolved at boot through a pluggable SecretProvider: env (default), file (<KEY>_FILE), or a custom provider passed to SecretsModule.forRoot. Signing and verification share the resolved secret, and the strength rules apply to it whatever the source (StellarTickets#253). Closes StellarTickets#250 Closes StellarTickets#251 Closes StellarTickets#252 Closes StellarTickets#253
UFObject247
force-pushed
the
feat/250-253-config-hardening
branch
from
September 24, 2026 18:21
8411b8c to
5c9a3e4
Compare
|
@UFObject247 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #250
Closes #251
Closes #252
Closes #253
Summary
#250: configurable global API prefix
API_PREFIXsetting, e.g.api/v1.main.tsapplies it withsetGlobalPrefix, soPOST /auth/loginbecomesPOST /api/v1/auth/login.GET /healthis excluded and stays at the root..and..segments.src/config/api-prefix.spec.tsstarts a Nest app with supertest. It checks that routes are served under the prefix, that/healthstays at the root, and that nothing changes when the variable is unset.#251: fail startup when
JWT_SECRETis weakNODE_ENV=production, startup also fails when the secret contains a known placeholder (changeme,yoursecret,jwtsecret,example,password, …) or has fewer than 10 distinct characters.#252:
SOROBAN_RPC_URL/ network pairingSTELLAR_NETWORK. At boot, env validation now infers which network the RPC URL serves from its host or path (testnet,futurenet,mainnet,pubnet). If that network differs fromSTELLAR_NETWORK, startup fails.httporhttpsURL.StellarServicetosrc/config/stellar-networks.ts, so signing and validation use the same table.stellar-networks.spec.ts, plus mismatch and valid cases inenv.validation.spec.ts.#253: pluggable secret provider for the JWT secret
SecretProviderinterface and a globalSecretsModule. The provider is chosen withSECRETS_PROVIDER:env(default): reads theJWT_SECRETenvironment variable.file: reads the file atJWT_SECRET_FILE. This covers Docker/Kubernetes secrets and sidecars such as Vault Agent or the Secrets Store CSI drivers.custom: uses a class passed toSecretsModule.forRoot({ provider }).JwtSecretModuleresolves the secret once at boot.JwtModule(signing) andJwtStrategy(verification) now both get it from there instead of each readingJWT_SECRETfromConfigService.JWT_SECRETonly forenv, andJWT_SECRET_FILEonly forfile.docs/CONFIGURATION.md("Secret providers", with an example custom provider),.env.exampleanddocs/DEPLOYMENT.md.secrets.module.spec.tscovers choosing each provider, reading and trimming files, and the error whencustomhas no provider.jwt-secret.module.spec.tsresolves the secret through a custom provider and checks thatAuthModulesigns and verifies tokens with it.Testing
Rebased on the latest
main(after #349, #351 and #352).npx jest: 51 suites, 310 of 311 tests pass.mainalone has 47 suites and 244 tests. This PR adds the new specs, and all of them pass.main, and this PR doesn't touch them:bigint-serializer.interceptor.spec.ts: 1 test fails.pending-tx-cleanup.service.spec.ts: can't run because@nestjs/scheduleis not installed.npx eslinton all changed files: clean.npx tsc --noEmit: the same 15 errors asmain, none new and none in files this PR touches.Upgrade notes
.envfiles keep working.SECRETS_PROVIDERdefaults toenvandAPI_PREFIXdefaults to no prefix.JWT_SECRETis a placeholder, or whose RPC URL names a different network thanSTELLAR_NETWORK, will now refuse to start. This is intended.