Repository navigation
Conversation
The multi-endpoint failover rewrite (RevoraOrg#894) dropped the `url` field from the stellar-horizon dependency details on the failure path, breaking the "exposes only safe Stellar metadata" contract test that asserts the configured endpoint URL is present alongside failureClass and upstreamStatus. The success path still exposes `url`; the failure path now reports the last-probed endpoint (or the first configured endpoint when no probe completed), keeping the health dependency graph observable for k8s failover diagnostics. 🤖 Generated with Codebuff Co-Authored-By: Codebuff <noreply@codebuff.com>
- Add multi-tier rate limiting to POST /api/v1/startup/register
- standard: 5 req/15min (default, IP-keyed)
- trusted: 10 req/15min (requires x-revora-tier-secret)
- internal: 25 req/15min (requires x-revora-tier-secret)
- Implement InMemoryRateLimitStore with fixed-window algorithm
- Implement createStartupAuthTierLimiter with fail-safe secret downgrade
- Emit X-RateLimit-{Limit,Remaining,Reset,Tier} and Retry-After headers
- 100% statement/branch/function/line coverage on both middleware files
- 171 tests pass across unit, integration, and property-based suites
- Fix health.ts: include url in failed Stellar horizon dependency details
- Add comprehensive security docs with abuse/failure scenarios
- Mark all 10 spec tasks complete in tasks.md
|
@Ukorstack Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
…ls-url fix: restore Horizon endpoint URL in Stellar failure details
Author
|
kindly review please! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
closes #1090
Summary
Implements the Rate Limiter Tier Policies capability (BE-011) on
POST /api/v1/startup/register.What changed
Core middleware (already wired — no new files needed)
src/middleware/rateLimit.ts— Fixed-windowInMemoryRateLimitStoreandcreateRateLimitMiddlewarewith per-IP and per-user keying, standard rate-limit headers (X-RateLimit-Limit/Remaining/Reset), andRetry-Afteron 429.src/middleware/startupAuthRateTierPolicy.ts—createStartupAuthTierLimiterwith three tiers (standard 5, trusted 10, internal 25 req/15 min), shared-secret gate on elevated tiers, fail-safe downgrade on wrong/absent secret,X-RateLimit-Tierheader.Bug fix
src/routes/health.ts— failed Stellar horizon dependency check now includesurlindetails, fixing a pre-existing assertion in the integration test suite.Documentation
docs/rate-limiter-tier-policies.md— tier table, implementation NatSpec, request/response headers, 7 security assumptions, 6 abuse scenarios, 5 failure paths,RateLimitStoreinterface contract for distributed deployments, deployment checklist..kiro/specs/rate-limiter-tier-policies/tasks.md— all 10 tasks marked complete.Test results
171 tests pass, 0 failures across 8 test suites:
src/middleware/rateLimit.test.tssrc/middleware/startupAuthRateTierPolicy.test.tssrc/middleware/__tests__/rateLimitStore.property.test.tssrc/middleware/__tests__/resolveTier.property.test.tssrc/middleware/__tests__/rateLimitMiddleware.property.test.tssrc/routes/health.test.tsCoverage
Exceeds the ≥95% requirement.
Security assumptions validated
x-revora-rate-tieris always untrusted client input — never acted on without a validx-revora-tier-secret.standard— no oracle signal returned to the client.startup-auth:<tier>:) prevents cross-tier exhaustion attacks.app.set('trust proxy', 1)is set increateAppfor stable IP-based keying behind a proxy.RateLimitStorebefore horizontal scale-out.closes Add regression coverage for DistributionSchedulerOptions failure handling #1090