Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
104 commits
Select commit Hold shift + click to select a range
1a5da04
Fix formatting of 'Stellar Card' in README
nursetechie Jul 27, 2026
1f10a0f
ci: optimize GitHub Actions caching
Obiajulu-gif Jul 28, 2026
31858f4
build: add commitlint and Husky hooks
Obiajulu-gif Jul 28, 2026
4aac268
ci: add automated accessibility audits
Obiajulu-gif Jul 28, 2026
d712a27
chore: consolidate lint and formatting configuration
Obiajulu-gif Jul 28, 2026
028895c
test(db): add unit tests for db.js schema and queries
unlimitedengineer Jul 28, 2026
ae33e12
Merge pull request #293 from unlimitedengineer/feat/test-task-48
devpeter999 Jul 28, 2026
8e393fd
feat(contract): pause circuit breaker, RBAC-gated pause, per-address …
davedumto Jul 28, 2026
0c151a2
fix: resolve merge conflicts from overlapping RBAC/pause/storage work
davedumto Jul 28, 2026
36ffd65
Merge pull request #237 from davedumto/fix/contract-pause-rbac-storag…
devpeter999 Jul 28, 2026
c5caf1d
chore: add CONTRIBUTING guide, commitlint config, husky hook, CI cach…
opascal221-design Jul 28, 2026
8da5cc9
Merge pull request #296 from opascal221-design/feat/issue-275-276-277…
devpeter999 Jul 28, 2026
d902891
feat(contract): token rescue, two-step admin transfer, temporary reen…
pre-cious-Igwealor Jul 28, 2026
c1f1aa0
Merge pull request #238 from pre-cious-Igwealor/fix/contract-rescue-a…
devpeter999 Jul 28, 2026
41e4cae
feat(contract): batch role granting, TTL threshold optimization, doc …
Wycode569 Jul 28, 2026
2be4f9b
Merge pull request #239 from Wycode569/fix/contract-batch-roles-ttl-t…
devpeter999 Jul 28, 2026
ac761e4
feat(tooling): add pre-commit and pre-push hooks with tests
KidDev88 Jul 28, 2026
1a6b111
ci: add reusable Node.js setup action and optimize caching
KidDev88 Jul 28, 2026
6bccbb4
ci: add automated accessibility audit workflow
KidDev88 Jul 28, 2026
23033f6
docs: update README and contributor guides
KidDev88 Jul 28, 2026
fb463f0
feat: consolidate tooling, add a11y CI, and improve e2e stability
Omoboi-dev Jul 28, 2026
544e1f7
Merge pull request #297 from KidDev88/feature/general-improvements
devpeter999 Jul 28, 2026
506e209
merge: resolve conflicts with upstream main
Omoboi-dev Jul 28, 2026
aad1059
Merge pull request #298 from Omoboi-dev/feature/tooling-qa-e2e-all
devpeter999 Jul 28, 2026
c111081
docs: review and update READMEs, docker-compose, cross-browser testin…
Emmy123222 Jul 28, 2026
3e5525a
Merge pull request #300 from Edoscoba/feature/docs-task-46
devpeter999 Jul 28, 2026
ddd6fb2
chore: consolidate lint/format configs, stabilize e2e pipeline, exten…
Akpolo Jul 28, 2026
b7c8cca
Merge pull request #299 from Akpolo/feature/tooling-259-260-261-262
devpeter999 Jul 28, 2026
33c080f
ci: extend cross-browser matrix, cache gaps, and compose env wiring
davidugorji Jul 28, 2026
fc0e70c
Merge pull request #301 from davidugorji/feature/qa-devops-docs-ci-ta…
devpeter999 Jul 28, 2026
966746b
fix(sdk): resync package-lock.json to fix broken npm ci in CI
davidugorji Jul 28, 2026
c63501c
chore: dedupe shared eslint rule, run Edge in e2e CI matrix, fix pre-…
tosin-zoffun Jul 28, 2026
a1b743e
Merge pull request #302 from davidugorji/feature/ci-cd-task-7
devpeter999 Jul 28, 2026
04b0abb
Merge pull request #303 from tosin-zoffun/feat/issues-247-248-249-250
devpeter999 Jul 28, 2026
0d5d1fa
implemented the documentation of the payment-handler.js flow
Dydex Jul 28, 2026
24997fc
implemented Standardize error handling middleware
Dydex Jul 28, 2026
d6596db
added rate limiting to public endpoints
Dydex Jul 28, 2026
ece191f
test(backend): expand db.js query coverage and fix the WAL pragma test
Olorunfemi20 Jul 28, 2026
fe6d893
feat(backend): wire up Sentry error tracking and harden its configura…
Olorunfemi20 Jul 28, 2026
144eeba
feat(backend): declarative request input validation with Zod
Olorunfemi20 Jul 28, 2026
cd8e417
refactor(backend): extract routing out of app.js into a route registry
Olorunfemi20 Jul 28, 2026
596aa73
feat(backend): Winston-backed structured logger, retire legacy deploy…
Chidimj Jul 28, 2026
6c9a04b
feat: unify local dev, harden dependabot, expand cross-browser and to…
Gbemi-programmer Jul 28, 2026
84c3832
Merge branch 'main' into feature/ci-cd-task-47
Jul 29, 2026
056de23
Merge branch 'main' into feature/tooling-task-48
Jul 29, 2026
2b55978
Merge branch 'main' into feature/qa-task-49
Jul 29, 2026
e7fe01b
Merge branch 'main' into feature/tooling-task-50
Jul 29, 2026
a305698
Merge pull request #304 from Dydex/feature/docs-task-40
devpeter999 Jul 29, 2026
a8467e3
Merge pull request #310 from Gbemi-programmer/feature/infra-part4
devpeter999 Jul 29, 2026
ae9e99d
Merge branch 'main' into feature/backend-tooling-4issues
devpeter999 Jul 29, 2026
237f189
Merge pull request #309 from Chidimj/feature/backend-tooling-4issues
devpeter999 Jul 29, 2026
ded1805
Merge pull request #291 from BigDella/feature/ci-cd-task-47
devpeter999 Jul 29, 2026
7f49845
Merge pull request #294 from BigDella/feature/qa-task-49
devpeter999 Jul 29, 2026
de354a5
Merge branch 'main' into feature/tooling-task-50
devpeter999 Jul 29, 2026
c735cf1
Merge pull request #295 from BigDella/feature/tooling-task-50
devpeter999 Jul 29, 2026
9ceef8c
Merge branch 'main' into feature/tooling-task-48
Jul 29, 2026
661be0d
Merge pull request #292 from BigDella/feature/tooling-task-48
devpeter999 Jul 29, 2026
3ed9d41
Merge pull request #234 from nursetechie/main
devpeter999 Jul 29, 2026
76576c0
feat(backend): add Swagger/OpenAPI documentation
0xDeon Jul 29, 2026
1789ebe
refactor(tooling): modernize scripts, fix cross-platform issues, reso…
KingFRANKHOOD Jul 29, 2026
ce83b30
Merge pull request #312 from UFObject247/feat/tooling-modern-node-p2
devpeter999 Jul 29, 2026
212a3c7
test(backend): add integration coverage for the dashboard API
zoffunjunior381-jpg Jul 29, 2026
d3bb306
backend: Zod request validation, db.js test coverage, wire up Sentry
prodbycorne Jul 29, 2026
7baa71e
Merge pull request #313 from zoffunjunior381-jpg/feat/issues-31-32-33-34
devpeter999 Jul 29, 2026
f5be3d4
Merge pull request #314 from prodbycorne/fix/backend-validation-tests…
devpeter999 Jul 29, 2026
67c9404
Merge branch 'main' into feature/refactor-task-36
Olorunfemi20 Jul 29, 2026
a756721
Merge pull request #308 from Olorunfemi20/feature/refactor-task-36
devpeter999 Jul 29, 2026
4471685
Merge pull request #305 from Olorunfemi20/feature/test-task-38
devpeter999 Jul 29, 2026
922e079
Merge branch 'main' into feature/monitoring-task-39
Olorunfemi20 Jul 29, 2026
21aba32
Merge pull request #306 from Olorunfemi20/feature/monitoring-task-39
devpeter999 Jul 29, 2026
99da13f
Merge branch 'main' into feature/security-task-37
Olorunfemi20 Jul 29, 2026
c64f1c6
Merge pull request #307 from Olorunfemi20/feature/security-task-37
devpeter999 Jul 29, 2026
615512c
Sentry Setup
JSE19 Jul 29, 2026
01d8a4d
feat(backend): harden API middleware and test coverage
Davidemulo Jul 29, 2026
4a1fcea
Document Payment Handler
JSE19 Jul 29, 2026
acfba7e
Comprehensive api test
JSE19 Jul 29, 2026
168f1a6
Merge pull request #316 from Davidemulo/codex/backend-11-12-13-14
devpeter999 Jul 29, 2026
4b75fd8
Error Hndling
JSE19 Jul 29, 2026
0550c1d
Merge branch 'main' into SentryFix
JSE19 Jul 29, 2026
cd9362e
Merge branch 'main' into ErrorHandling
JSE19 Jul 29, 2026
ad8b60c
Merge pull request #315 from JSE19/SentryFix
devpeter999 Jul 29, 2026
e3f06c8
Merge pull request #317 from JSE19/DocPaymentHandler
devpeter999 Jul 29, 2026
e372ba1
Merge branch 'main' into ApiTests
JSE19 Jul 29, 2026
7da1946
Merge branch 'main' into ErrorHandling
JSE19 Jul 29, 2026
d00c5d9
Merge pull request #318 from JSE19/ApiTests
devpeter999 Jul 29, 2026
9b0a450
Merge branch 'main' into ErrorHandling
JSE19 Jul 29, 2026
26dcaaa
Merge pull request #319 from JSE19/ErrorHandling
devpeter999 Jul 29, 2026
370fd1a
refactor(backend): finish extracting routing logic out of app.js
Joycejay17 Jul 29, 2026
45a62c3
feat(backend): consolidate request validation on Zod and extend it to…
Joycejay17 Jul 29, 2026
90d0b80
test(backend): cover the db.js query shapes that fail silently
Joycejay17 Jul 29, 2026
f606cae
feat(backend): publish an OpenAPI document and serve Swagger UI
Joycejay17 Jul 29, 2026
02e2b1b
Merge pull request #321 from Joycejay17/feature/backend-tasks-15-18
devpeter999 Jul 29, 2026
4a6bd01
docs: document payment-handler.js flow
Jul 29, 2026
13d07fb
Merge pull request #322 from emwulrd/feature/docs-task-10
devpeter999 Jul 29, 2026
6b3fff0
fix(backend): standardize error middleware logging
0xsamuel1 Jul 29, 2026
adf3736
feat(tooling,a11y): partial implementation for ESLint consolidation a…
edehvictor Jul 29, 2026
9b2ec69
Merge pull request #324 from Odkinggjnr/feature/monitoring-task-4
devpeter999 Jul 29, 2026
6f53dd7
Merge origin/main into feature/docs-task-35
0xDeon Jul 29, 2026
08f9b58
Merge pull request #323 from charlesedeh021-cell/feat/tooling-a11y-27…
devpeter999 Jul 29, 2026
7846ec8
Merge pull request #311 from 0xDeon/feature/docs-task-35
devpeter999 Jul 29, 2026
9c2247b
Implement comprehensive cross-browser testing (Part 3)
Menjay7 Jul 29, 2026
7ca04bd
Merge branch 'main' into menjay
Menjay7 Jul 29, 2026
618c639
Enhance docker-compose setup with optional databases and documentation
Menjay7 Jul 29, 2026
9725190
docs: update READMEs with Docker Compose information across all services
Menjay7 Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
15 changes: 15 additions & 0 deletions .commitlintrc.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
{
"extends": ["@commitlint/config-conventional"],
"rules": {
"type-enum": [
2,
"always",
["feat", "fix", "docs", "test", "chore", "refactor", "ci", "build", "perf", "revert"]
],
"scope-case": [2, "always", "lower-case"],
"subject-case": [2, "never", ["sentence-case", "start-case", "pascal-case", "upper-case"]],
"subject-empty": [2, "never"],
"subject-full-stop": [2, "never", "."],
"header-max-length": [2, "always", 100]
}
}
12 changes: 12 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
node_modules
.git
.gitignore
.next
dist
build
coverage
*.log
.env
.env.local
stellar_card.db
*.sqlite
86 changes: 86 additions & 0 deletions .env.docker.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
# =============================================================================
# Stellar Card Docker Compose Environment Variables
# Copy to .env and fill in values. Never commit .env to version control.
# =============================================================================

# =============================================================================
# Backend Configuration
# =============================================================================
# Server port
PORT=4000

# Node environment
NODE_ENV=development

# Database path (SQLite default)
DB_PATH=/app/data/stellar_card.db

# =============================================================================
# Stellar Configuration
# =============================================================================
# Stellar network: testnet or mainnet
STELLAR_NETWORK=testnet

# USDC issuer address
STELLAR_USDC_ISSUER=GA5ZSEJYB37JRC5AVCIA5MOP4RHTM335X2KGX3IHOJAPP5RE34K4KZVN

# Treasury secret key (generate with: soroban key generate)
# WARNING: Never commit real secret keys
STELLAR_XLM_SECRET=

# Soroban receiver contract ID
RECEIVER_CONTRACT_ID=

# =============================================================================
# VCC Fulfillment Service
# =============================================================================
VCC_API_BASE=https://vcc.ctx.com
CARDS402_BASE_URL=http://localhost:4000

# Secret for verifying HMAC-signed callbacks from VCC
# Generate with: openssl rand -hex 32
VCC_CALLBACK_SECRET=

# =============================================================================
# Frontend Configuration
# =============================================================================
NEXT_PUBLIC_API_BASE_URL=http://localhost:4000
NEXT_PUBLIC_STELLAR_NETWORK=testnet

# =============================================================================
# PostgreSQL Configuration (Optional - when using --profile db)
# =============================================================================
POSTGRES_HOST=postgres
POSTGRES_PORT=5432
POSTGRES_USER=stellar_card
POSTGRES_PASSWORD=stellar_card_dev
POSTGRES_DB=stellar_card

# =============================================================================
# Redis Configuration (Optional - when using --profile db)
# =============================================================================
REDIS_HOST=redis
REDIS_PORT=6379

# =============================================================================
# CORS Configuration
# =============================================================================
# Comma-separated allowed origins for the agent API
CORS_ORIGINS=http://localhost:3000

# =============================================================================
# Internal Dashboard Access
# =============================================================================
# Comma-separated emails allowed to access /internal/* routes
# INTERNAL_EMAILS=ops@example.com,eng@example.com

# =============================================================================
# Error Tracking (Optional)
# =============================================================================
# SENTRY_DSN=https://examplePublicKey@o0.ingest.sentry.io/0

# =============================================================================
# Development Settings
# =============================================================================
# SDK development - allow insecure base URL for local testing
CARDS402_ALLOW_INSECURE_BASE_URL=1
22 changes: 22 additions & 0 deletions .github/CICD.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,12 @@ Jobs:

- **type-matrix**: Tests TypeScript compatibility with multiple versions (5.0 - 5.3)

### 1a. E2E Tests (`e2e.yml`)

Runs the Playwright suite in `stellar_card-frontend/e2e/` across a CI matrix covering `chromium`, `firefox`, `webkit`, `Mobile Chrome`, and `Mobile Safari` — mirroring every project defined in `playwright.config.ts` except `Microsoft Edge`, which needs a system-installed Edge browser that isn't available on the `ubuntu-latest` runner image and is left as a local-only / self-hosted-runner project.

`Mobile Chrome` and `Mobile Safari` are device-emulation presets, not separate browser engines — they render on `chromium` and `webkit` respectively, so the workflow resolves each matrix entry to its underlying engine before installing or caching browser binaries.

### 2. Security Audit (`security.yml`)

Runs:
Expand Down Expand Up @@ -156,6 +162,22 @@ Add to README:
2. Check `.github/dependabot.yml` syntax
3. Verify package manager is detected (run actions manually)

## Caching Strategy

All workflows cache dependencies and build artifacts to keep CI fast:

| Workflow | Cache | Key basis |
|----------|-------|-----------|
| `test.yml`, `a11y.yml` | npm store + Node modules (via `.github/actions/setup-node`) | OS, Node version, `package-lock.json` hash |
| `test.yml` | TypeScript `.tsbuildinfo` | OS, Node version, `src/**` + `tsconfig*.json` hash |
| `e2e.yml`, `a11y.yml` | Playwright browser binaries (`~/.cache/ms-playwright`) | OS, installed `@playwright/test` version, matrix project |
| `sdk-validate.yml`, `publish.yml`, `release.yml` | npm store (via `actions/setup-node@v4` `cache: npm`) | `package-lock.json` hash |
| `security.yml` | npm store (via `actions/setup-node@v4` `cache: npm`) | `package-lock.json` hash per audited directory |

Playwright caches are keyed per browser project so each matrix job (`chromium`, `firefox`, `webkit`) only restores its own binaries — a cache hit still runs `playwright install-deps` to pull OS-level shared libraries, which don't persist inside the cached path.

Use the reusable `.github/actions/setup-node` composite action for any new workflow that runs `npm ci` — it wires up both the npm store cache and `actions/setup-node`'s built-in lockfile cache with a consistent key format.

## Best Practices

1. **Always run tests locally before pushing**
Expand Down
8 changes: 8 additions & 0 deletions .github/actions/setup-node-project/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
# Setup Node project action

This composite action centralizes Node setup and caching for repository
workflows. The npm download cache is keyed by the selected lockfile, while
reusable tool output is isolated by operating system, Node version, an
explicit cache schema version, and the lockfile hash.

Increment `cache-version` after changing the cached directory layout.
35 changes: 35 additions & 0 deletions .github/actions/setup-node-project/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: Setup Node project
description: Configure Node and restore deterministic npm and build caches

inputs:
node-version:
description: Node.js version
required: true
working-directory:
description: Project directory containing package-lock.json
required: true
cache-version:
description: Increment to invalidate build caches
default: v1

runs:
using: composite
steps:
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: ${{ inputs.node-version }}
cache: npm
cache-dependency-path: ${{ inputs.working-directory }}/package-lock.json

- name: Restore project build cache
uses: actions/cache@v4
with:
path: |
${{ inputs.working-directory }}/.eslintcache
${{ inputs.working-directory }}/.next/cache
${{ inputs.working-directory }}/node_modules/.cache
${{ inputs.working-directory }}/*.tsbuildinfo
key: node-build-${{ runner.os }}-${{ inputs.node-version }}-${{ inputs.cache-version }}-${{ hashFiles(format('{0}/package-lock.json', inputs.working-directory)) }}
restore-keys: |
node-build-${{ runner.os }}-${{ inputs.node-version }}-${{ inputs.cache-version }}-
32 changes: 32 additions & 0 deletions .github/actions/setup-node/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
name: Setup Node.js with caching

description: |
Composite action that sets up Node.js with optimized caching.
Reusable across all workflows to keep cache keys consistent.

inputs:
node-version:
description: 'Node.js version to use'
default: '20.x'
working-directory:
description: 'Directory containing package-lock.json'
default: '.'

runs:
using: 'composite'
steps:
- name: Setup Node.js ${{ inputs.node-version }}
uses: actions/setup-node@v4
with:
node-version: ${{ inputs.node-version }}
cache: npm
cache-dependency-path: '${{ inputs.working-directory }}/package-lock.json'

- name: Cache npm store
uses: actions/cache@v4
with:
path: ~/.npm
key: npm-${{ runner.os }}-node${{ inputs.node-version }}-${{ hashFiles(format('{0}/package-lock.json', inputs.working-directory)) }}
restore-keys: |
npm-${{ runner.os }}-node${{ inputs.node-version }}-
npm-${{ runner.os }}-
Loading