Skip to content

test: add security audit repo coverage and horizon diagnostics - #1215

Open
Ukorstack wants to merge 3 commits into
RevoraOrg:masterfrom
Ukorstack:test/security-audit-coverage-health-diagnostics
Open

Ukorstack wants to merge 3 commits into
RevoraOrg:masterfrom
Ukorstack:test/security-audit-coverage-health-diagnostics

Conversation

@Ukorstack

@Ukorstack Ukorstack commented Sep 28, 2026 •

Copy link
Copy Markdown

Summary

Closes #1078. Add a dedicated test suite for src/security/audit.ts and harden the health route diagnostics.

  • src/security/audit.test.ts (new, 63 tests): focused behavior coverage for InMemorySecurityAuditRepository (initial state, record/retrieve, ordering, limits, security-violation filtering, clear/re-populate transitions, instance isolation, capacity-eviction boundary, invalid inputs), DatabaseSecurityAuditRepository (SQL + parameter contract via mocked pool, row mapping, empty results, error propagation), SECURITY_AUDIT_EVENTS_SCHEMA DDL assertions, createSecurityAuditRepository env selection, and the module's hash-chain/scheduler re-export surface. All fixtures are deterministic — fixed IDs and timestamps, no wall-clock reads or sleeps.
  • src/routes/health.ts: report the last attempted Horizon endpoint in failure details.url so operators can identify a failing endpoint without exposing error internals; also removes an unused import and an implicit-any that tripped eslint.

Public contract

No production behavior changed beyond the additive details.url diagnostic field on Horizon health failures. Existing exports, SQL shapes, and schemas are asserted as-is.

Validation

Check Result
Focused suite npx jest src/security/audit.test.ts 63 passed
Surrounding suite npx jest src/security/ 10 suites, 151 tests passed
src/routes/health.test.ts 74 passed
Lint npx eslint on changed files clean (2 pre-existing errors in health.ts fixed in this PR)
Type check npx tsc --noEmit no errors in changed files (250 pre-existing errors in unrelated src/vaults/* files)

Security notes

  • Diagnostic url field exposes only the configured Horizon endpoint URL (public configuration); no error internals or secrets are leaked.
  • Audit tests verify parameterized SQL usage, fail-safe empty results for unknown lookups, and unchanged propagation of pool errors.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff noreply@codebuff.com

Ukorstack and others added 2 commits September 28, 2026 11:06
Add focused behavior tests for src/security/audit.ts covering the
in-memory and database audit repositories, schema DDL contract, and
factory/re-export surface (issue RevoraOrg#1078). Harden the health check to
report the last attempted Horizon endpoint in failure details so
operators can identify a failing endpoint without exposing internals.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
Remove unused Pool import and replace an implicit-any accumulator with
unknown, which the downstream classification call already accepts.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Ukorstack Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Ukorstack

Copy link
Copy Markdown
Author

kindly review please!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add focused behavior coverage for InMemorySecurityAuditRepository

1 participant