D bluemoon role based - #248
Merged
Merged
Conversation
|
@D-Bluemoon is attempting to deploy a commit to the chonilius' projects Team on Vercel. A member of the Team first needs to authorize it. |
|
@D-Bluemoon Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #247
Description
This PR resolves critical production security vulnerabilities by introducing a fully structured Role-Based Access Control (RBAC) layer. It moves the backend from a purely JWT-authenticated environment to a granular, role-scoped security architecture. All administrative, maintainer-only, and sponsor-privileged actions are now explicitly guarded.🛠️
Key Changes
Core Security Infrastructure:
Created roles.decorator.ts to assign access permissions seamlessly via meta-tagging (@roles()).
Implemented a unified RolesGuard to parse route metadata, intercept incoming payloads, validate session profiles, and block unauthorized users with strict 403 Forbidden exceptions.
Registered RolesGuard as a universal controller bouncer inside app.module.ts via the APP_GUARD provider context.
Controller Level Lockdown:
Bounties Module: Secured create, fund, refund, and added brand new approve and reject route checkpoints strictly scoped to UserRole.MAINTAINER and UserRole.SPONSOR.
Milestones Module: Integrated create, fund, addIssue, resolveIssue, and introduced the missing allocateBudget endpoint under strict maintainer access criteria.
Escrow Module: Encapsulated release and refund operations inside a fresh, secure routing layer matching native state validation parameters.
Maintenance Pool Module:
Created a dedicated controller scaffold locking the assign-funds execution loop to verified system maintainers.
Workspace Optimization:
Adjusted global tsconfig.json mappings to resolve strict property initialization compile warnings across TypeORM entity structures.
Patched third-party type extraction lint loops (@IsUUID()) and balanced dangling braces inside the core bounties.service.ts data layout.
Closes #245
Pull Request Summary:
Implement Multi-Tier Rate Limiting on Critical Endpoints
Description
This PR resolves high-priority security vulnerabilities by introducing a comprehensive, granular rate-limiting layer across authentication, high-value mutations, and resource-heavy query routes. Using @nestjs/throttler, these changes protect the backend infrastructure from OAuth brute-force enumeration, idempotency key exhaustion, distributed denial-of-service (DoS) vectors, and Soroban RPC/database thread pool starvation.
Key Changes
Closes #244
Title
fix: resolve compilation errors and secure github token storage
Description
This PR resolves critical TypeScript compilation issues across multiple application core layer services and addresses the open security vulnerability regarding plaintext GitHub OAuth token storage.
Key Implementations
1. Security & Token Encryption
2. Source Code & Structural Repair
Verification Status
Closes #246
Description
Verification Plan