Skip to content

feat: add per-wallet rate limiting and JWT sub wallet address - #58

Merged
Chucks1093 merged 1 commit into
StellarState:mainfrom
Darkvader-ship-it:feat/jwt-subject-expiry-tests
Jul 27, 2026
Merged

feat: add per-wallet rate limiting and JWT sub wallet address#58
Chucks1093 merged 1 commit into
StellarState:mainfrom
Darkvader-ship-it:feat/jwt-subject-expiry-tests

Conversation

@Darkvader-ship-it

Copy link
Copy Markdown
Contributor

Set JWT sub claim to wallet address instead of internal user ID. Update getCurrentUser to lookup by stellar address. Add per-wallet rate limiting middleware.
Apply rate limits: 10 req/60s for investment, 5 req/60s for invoice publish. 429 responses include Retry-After header.
Add tests for JWT subject/expiry/tampered/expired tokens. Add rate limit tests: wallet isolation, Retry-After, window reset.

Description

Closes #44
closes #45
closes #55
closes #54

Type of Change

  • 🐛 Bug fix (non-breaking change which fixes an issue)
  • ✨ New feature (non-breaking change which adds functionality)
  • 💥 Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • 📝 Documentation update
  • 🎨 UI/UX improvement
  • ♻️ Code refactoring
  • ✅ Test addition or update
  • 🔧 Configuration change

Checklist

  • All GitHub Actions workflows are green on this PR (required for merge)
  • Commit messages follow Conventional Commits (feat:, fix:, chore:, etc.) — enforced by CI
  • No secrets, API keys, .env, or credentials committed (see CONTRIBUTING.md)
  • My code follows the code style of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • Any dependent changes have been merged and published

Testing

How to Test

  1. Step one
  2. Step two
  3. Step three

Test Coverage

  • Unit tests added/updated
  • Integration tests added/updated
  • E2E tests added/updated (if applicable)
  • Manual testing completed

Screenshots (if applicable)

Additional Notes

For Reviewers

  • Code quality and readability
  • Test coverage
  • Security implications
  • Performance impact
  • Breaking changes

Set JWT sub claim to wallet address instead of internal user ID.
Update getCurrentUser to lookup by stellar address.
Add per-wallet rate limiting middleware.
Apply rate limits: 10 req/60s for investment, 5 req/60s for invoice publish.
429 responses include Retry-After header.
Add tests for JWT subject/expiry/tampered/expired tokens.
Add rate limit tests: wallet isolation, Retry-After, window reset.
@drips-wave

drips-wave Bot commented Jul 27, 2026

Copy link
Copy Markdown

@Darkvader-ship-it Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Chucks1093
Chucks1093 merged commit bdbcad4 into StellarState:main Jul 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment