Skip to content

fix: restrict /metrics auth, harden exception filter, add issue templ… - #565

Merged
james2177 merged 2 commits into
stellar-vortex-protocol:mainfrom
Iceeyyou2:fix/298-304-309-318-security-and-infra
Sep 30, 2026
Merged

james2177 merged 2 commits into
stellar-vortex-protocol:mainfrom
Iceeyyou2:fix/298-304-309-318-security-and-infra

Conversation

@Iceeyyou2

@Iceeyyou2 Iceeyyou2 commented Sep 30, 2026 •

Copy link
Copy Markdown

…ates and OpenAPI drift check

Closes #298,
Closes #304,
Closes #309,
Closes #318

Summary

Related issue

Type of change

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI / tooling

Component

  • Contract (vortex-contract)
  • Backend (vortex-backend)
  • Frontend (vortex-frontend)

Checklist

  • My code follows the project's style and conventions
  • I ran lint / type-check / build locally and they pass
  • I added or updated tests where appropriate
  • I updated documentation where appropriate
  • My commits follow Conventional Commits

Screenshots / notes

Iceeyyou2 and others added 2 commits September 30, 2026 10:37
…ates and OpenAPI drift check

- fix(stellar-vortex-protocol#298): add Bearer-token auth guard to GET /metrics (METRICS_TOKEN env var,
  required + min-16-char in production; env disabled by default in dev/test)
- fix(stellar-vortex-protocol#304): replace verbatim custom-body passthrough in HttpExceptionFilter with
  an explicit allowlist (error, intentId, minDstAmount, fillAmount); strips any
  future accidental fields before they reach the client
- feat(stellar-vortex-protocol#309): add .github/ISSUE_TEMPLATE/ with bug_report.md, feature_request.md,
  and contributor_claim.md so contributors no longer open blank issues
- feat(stellar-vortex-protocol#318): add openapi-drift CI job that regenerates src/generated/ and fails
  the build if the checked-in files are stale

Closes stellar-vortex-protocol#298, stellar-vortex-protocol#304, stellar-vortex-protocol#309, stellar-vortex-protocol#318
…-security-and-infra

# Conflicts:
#	.env.example
#	.env.mainnet.example
#	.env.testnet.example
#	.github/workflows/ci.yml
#	src/common/http-exception.filter.spec.ts
#	src/common/http-exception.filter.ts
#	src/config/configuration.ts
#	src/config/env.validation.ts
#	src/metrics/metrics.controller.ts
@james2177
james2177 merged commit a938cf5 into stellar-vortex-protocol:main Sep 30, 2026
benedictworks-home added a commit to benedictworks-home/vortex-backend that referenced this pull request Oct 2, 2026
Restores content that was zeroed or lost in the interleaved merges and
applies the type/lint fixes `tsc --noEmit` and `npm run lint` require.
Highlights:

- env: enforce the stellar-vortex-protocol#298 METRICS_TOKEN contract (required, at least 16
  chars in production) that .env.example already documented, and add the
  token-persistence, price-feed, quote-auction and reputation-weight
  vars (stellar-vortex-protocol#565 stellar-vortex-protocol#566 stellar-vortex-protocol#570 stellar-vortex-protocol#444) with their configuration.ts wiring;
  DATASETS_* names are aligned with .env.example so check:env-drift is
  clean.
- intents: restore gateway handshake/heartbeat/eligibility-feed content
  (stellar-vortex-protocol#436 stellar-vortex-protocol#454 stellar-vortex-protocol#492 stellar-vortex-protocol#511), controller error paths (stellar-vortex-protocol#569 stellar-vortex-protocol#429 stellar-vortex-protocol#220) and
  sweeper backfill (stellar-vortex-protocol#62 stellar-vortex-protocol#437 stellar-vortex-protocol#269).
- soroban: signer, settlement client, module wiring and registry/bond
  services restored and type-clean; token repositories and module keep
  status handling (active/paused/delisted) intact end to end.
- abuse, common, health, metrics, tracing: guard, egress, validator and
  instrumentation repairs needed for a clean lint/typecheck pass.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants