Skip to content

feat: security middleware, API docs, and comprehensive test suite (#23, #24, #25, #26) - #36

Merged
Levi-Ojukwu merged 21 commits into
mainfrom
feat/security-middleware-api-docs-tests
Jul 11, 2026
Merged

Levi-Ojukwu merged 21 commits into
mainfrom
feat/security-middleware-api-docs-tests

Conversation

@TheCodingChef-eth

Copy link
Copy Markdown
Contributor

Summary

Resolves issues #23, #24, #25, and #26 by adding security hardening, API documentation, and a full test suite.

Changes

** closes #23 — Request validation middleware**

  • Per-endpoint rate limiting: 200/15min global, 20/15min auth, 5/15min login
  • Account lockout after 5 failed login attempts (15min cooldown)
  • IP-based and user-based rate limiting via keyGenerator
    ** closes Add comprehensive input sanitization #24 — Input sanitization**
  • XSS protection via sanitize-html middleware on all body/query/params
  • Dangerous URL blocking (javascript:, data:, vbscript:, file:)
  • Content-Type validation and file size limits
  • Prisma already handles SQL injection via parameterized queries
    ** closes Create API documentation with OpenAPI/Swagger #25 — OpenAPI/Swagger docs**
  • Swagger UI at /api-docs with full OpenAPI 3.0 spec
  • JSDoc annotations on all 17 endpoints across 4 route files
  • Documented schemas: User, Invoice, Escrow, Auth requests/responses
  • Auth requirements and error codes documented per endpoint
    ** closes Set up Vitest test suite with unit and integration tests #26 — Vitest test suite**
  • 106 tests across 8 test files (88 unit + 29 integration)
  • Unit tests: config, all Zod schemas, pagination utils, error classes, sanitization
  • Integration tests: auth flows (register/login/logout/me), invoice CRUD, escrow lifecycle
  • Test fixtures with mock users, invoices, escrows, and payments
  • Prisma and Stellar service fully mocked for isolated testing

SweetBoy-eth and others added 21 commits July 11, 2026 09:13
@Levi-Ojukwu
Levi-Ojukwu merged commit e9141c5 into main Jul 11, 2026
1 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants