fix: deterministic portfolio pricing, config reinit, registry cleanup - #611
Merged
AbelOsaretin merged 3 commits intoSep 26, 2026
Merged
Conversation
- Replace Math.random() portfolio pricing with hour-seeded deterministic pricing via FNV-1a address hash and seededRandom (matches IoT pattern) - Refactor config to buildConfig() so initEnv() returns a fresh snapshot instead of the module-level singleton captured at import time - Move RpcDegradedError to registry.ts, remove dead isSimulationError guard - Fix duplicate simulateTransaction call and add missing metric tracks in getTotalProjects - Make MAX_PROJECT_ID configurable via env var (default 1M, was 100k) - Move cronTasks/scheduleCron declarations before first use - Harden batch score-update validation with explicit type checks - Update tests to align with new config/error shapes 🤖 Generated with Codebuff Co-Authored-By: Codebuff <noreply@codebuff.com>
|
@dunnidev Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Reconcile this branch's deterministic portfolio pricing, config-reinit and
registry-cleanup work with 112 commits of upstream changes. Keep the
branch's buildConfig()/initEnv() fresh-read refactor, the typed
simulateTransaction narrowing, and the shared anomaly history handler;
adopt upstream's MAX_PROJECT_ID contract, DB_*/IDEMPOTENCY_TTL_MS config,
the scoreService update path, and bun.lock as the sole lockfile
(package-lock.json removed).
Also fix what the resolution surfaced: duplicated imports and mocked-config
properties in several suites, and TRUST_PROXY defaulting to the string
"false" for app.set("trust proxy", ...), which made proxy-addr throw so the
server could not boot.
🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
CodeQL's js/insufficient-password-hash flags any fast digest applied to a
value it classifies as a password, and both inputs were run through
createHash("sha256") purely to normalise their lengths before
timingSafeEqual. The digest was only ever a length normaliser, never a
stored password hash, but the taint paths from generateApiKey(),
ADMIN_API_KEY, x-api-key and apiKeyHeader make the comparison
indistinguishable from an insecure password hash to the analysis, which
reports it as a high-severity alert on src/lib/timing-safe.ts:14.
Normalise the lengths with zero-padded fixed-size buffers instead, so no
fast digest is applied to a credential at all. The comparison stays
constant-time, never short-circuits, and both operands are still always
equal length: ordinary credentials are padded to the 512-byte window, so
neither their contents nor their length is observable. Values larger than
the window fall back to the longer of the two lengths, which stays
constant-time but reveals the order of magnitude of the longer input. The
length check is what keeps zero padding from letting "abc" collide with
"abc\u0000".
Adds coverage for that collision and for values past the window.
🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #496