Skip to content

feat: implement audit logging, Stellar wallet verification, and enhanced error handling - #38

Merged
Levi-Ojukwu merged 20 commits into
mainfrom
feature/audit-logging-wallet-verification-error-handling
Jul 11, 2026
Merged

Levi-Ojukwu merged 20 commits into
mainfrom
feature/audit-logging-wallet-verification-error-handling

Conversation

@SweetBoy-eth

Copy link
Copy Markdown
Contributor

Summary

This PR implements three major features for the StellFlow backend:

  • closes Add audit logging for sensitive operations #29 - Audit Logging for Sensitive Operations
  • New files: src/services/audit.service.ts, src/controllers/audit.controller.ts, src/routes/audit.routes.ts
  • Prisma schema: Added AuditLog model with AuditAction enum covering 18 action types (PAYMENT_CREATED, ESCROW_FUNDED, ACCOUNT_UPDATED, WALLET_VERIFIED, etc.)
  • Audit service: logAudit() and logAuditFromRequest() functions capture user ID, action, resource, IP address, user agent, and custom metadata
  • Audit endpoints: GET /api/audit-logs (admin only), GET /api/audit-logs/my (user's own logs), GET /api/audit-logs/:id
  • Controllers updated with audit logging:
    • escrow.controller.ts — ESCROW_CREATED, ESCROW_FUNDED, ESCROW_RELEASED, ESCROW_REFUNDED
    • payment.controller.ts — PAYMENT_CREATED, PAYMENT_VERIFIED, PAYMENT_FAILED
    • invoice.controller.ts — INVOICE_CREATED, INVOICE_UPDATED, INVOICE_STATUS_CHANGED, INVOICE_DELETED
    • user.controller.ts — ACCOUNT_UPDATED, ACCOUNT_DELETED
    • auth.controller.ts — USER_REGISTERED, USER_LOGIN
      closes Implement Stellar wallet verification endpoint #28 - Stellar Wallet Verification Endpoint
  • New files: src/services/wallet-verification.service.ts, src/controllers/wallet.controller.ts, src/routes/wallet.routes.ts, src/validators/wallet.schema.ts
  • Challenge-response flow:
    1. POST /api/wallet/challenge — generates a random 32-byte hex challenge with 5-minute expiry
    2. POST /api/wallet/verify — verifies signed challenge, validates Stellar account exists on network, links wallet to user
    3. POST /api/wallet/unlink — removes linked wallet from account
  • Validates Stellar account existence via Horizon API before linking
  • Prevents wallet address conflicts (unique per user)
  • Records audit logs for wallet verification and unlinking
    closes Add error handling middleware and custom error classes #27 - Error Handling Middleware and Custom Error Classes
  • Enhanced src/utils/AppError.ts:
    • Added code field to AppError base class for machine-readable error codes
    • Added RateLimitError (429) and InternalError (500) classes
    • All error classes now include standardized error codes: NOT_FOUND, UNAUTHORIZED, FORBIDDEN, VALIDATION_ERROR, CONFLICT, BAD_REQUEST, RATE_LIMIT_EXCEEDED, INTERNAL_ERROR
  • Enhanced src/middleware/errorHandler.ts:
    • Structured JSON logging with timestamp, method, path, IP, userId, statusCode, message, code, and stack trace
    • Consistent error response format with success, error.message, and error.code
    • Environment-aware stack trace inclusion (production vs development)
      Branch: feature/audit-logging-wallet-verification-error-handling

@Levi-Ojukwu
Levi-Ojukwu merged commit 67cd41c into main Jul 11, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add audit logging for sensitive operations Implement Stellar wallet verification endpoint Add error handling middleware and custom error classes

2 participants