Skip to content

Fix/1778 1781 config security observability - #1914

Merged
yusuftomilola merged 5 commits into
DistinctCodes:mainfrom
abdoolyaro:fix/1778-1781-config-security-observability
Sep 25, 2026
Merged

yusuftomilola merged 5 commits into
DistinctCodes:mainfrom
abdoolyaro:fix/1778-1781-config-security-observability

Conversation

@abdoolyaro

Copy link
Copy Markdown
Contributor

closes #1778
closes #1779
closes #1780
closes #1781

data-source.ts hardcoded the TypeORM/pg pool bounds, making it
impossible to tune per-environment (staging vs prod) without a code
change.

- Add DB_POOL_MIN / DB_POOL_MAX env vars (default 2 / 10, matching
  node-postgres's own defaults) to the CLI/migration DataSource in
  data-source.ts.
- Apply the same env vars to the runtime TypeOrmModule.forRootAsync
  config in app.module.ts, since that's what the running app actually
  connects with.
- Document the new vars in .env.example.
- Add data-source.spec.ts covering the default and explicit-env cases.
…des#1779)

http-exception.filter.ts passed HttpException#message straight through
to the client with no redaction, so a raw driver/library error that
happens to echo back a token, password, or DB connection string would
leak it in the response body.

- Add redactSensitive(), which strips key=value style tokens/secrets/
  passwords/auth headers, credentials embedded in scheme://user:pass@
  connection strings, and bare JWT-shaped strings, applied
  unconditionally (not just in non-dev) since a client-facing payload
  should never carry these.
- Apply it to the message before it's sent in the JSON response.
  Stack traces already only went to the server-side log line, never
  the response body — unchanged, just called out in a comment.
- Add http-exception.filter.spec.ts covering the redaction patterns
  and the filter's end-to-end behavior for both HttpException and
  plain Error inputs.
metrics.service.ts only tracked counts/gauges/summaries, with no way to
see p95/p99 latency per route — a slow endpoint had no signal until
someone noticed complaints or timeouts elsewhere.

- Add a histogram sample type and observeHistogram()/appendHistograms()
  to MetricsService, rendering standard Prometheus histogram output
  (_bucket/_sum/_count) with an 11-bucket range from 5ms to 10s.
- Add recordHttpRequestDuration(route, method, statusCode, durationMs),
  publishing managehub_http_request_duration_seconds keyed by route.
- Add RequestDurationInterceptor, registered as a global APP_INTERCEPTOR
  in app.module.ts, which times every HTTP request and records it using
  the matched Express route pattern (e.g. "/wallets/:id") rather than
  the raw URL, so label cardinality doesn't explode per path param
  value. Falls back to the raw path if no route was matched (e.g. a
  404). Records on both success and error so failed requests aren't
  missing from the histogram.
- Add metrics.service.spec.ts and request-duration.interceptor.spec.ts.
metrics.controller.ts exposed the Prometheus scrape endpoint with no
auth or network restriction, deliberately, leaving request volumes and
error rates by route publicly visible.

- Add MetricsAuthGuard: requires an `Authorization: Bearer
  <METRICS_ACCESS_TOKEN>` header (the standard shape for a Prometheus
  bearer_token scrape config), compared with a constant-time check.
  Fails closed in production if METRICS_ACCESS_TOKEN is unset; stays
  permissive in development (with a one-time warning) so local
  scraping keeps working without extra setup.
- Apply it to MetricsController via @UseGuards. Network-level
  restriction is still a valid complementary layer, just no longer the
  only one.
- Document METRICS_ACCESS_TOKEN in .env.example.
- Add metrics-auth.guard.spec.ts, and extend metrics.controller.spec.ts
  to assert the guard is actually attached to the controller.
@drips-wave

drips-wave Bot commented Sep 24, 2026

Copy link
Copy Markdown

@abdoolyaro Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@vercel

vercel Bot commented Sep 24, 2026

Copy link
Copy Markdown

@abdoolyaro is attempting to deploy a commit to the naijabuz's projects Team on Vercel.

A member of the Team first needs to authorize it.

…security-observability

# Conflicts:
#	backend/.env.example
#	backend/src/app.module.ts
#	backend/src/common/metrics.service.ts
@yusuftomilola
yusuftomilola merged commit cdb6432 into DistinctCodes:main Sep 25, 2026
1 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants