Skip to content

feat(backend): soft-delete retention, notification DLQ, request sanit… - #1268

Merged
Ceejaytech25 merged 2 commits into
ceejaylaboratory:mainfrom
godamongstmen897:feat/issue-batch-soft-delete-dlq-sanitize-swagger
Oct 1, 2026
Merged

Ceejaytech25 merged 2 commits into
ceejaylaboratory:mainfrom
godamongstmen897:feat/issue-batch-soft-delete-dlq-sanitize-swagger

Conversation

@godamongstmen897

Copy link
Copy Markdown
Contributor

Overview

This Pull Request resolves four core backend data retention, messaging resilience, security sanitization, and API documentation issues in AnchorPoint:

  1. Implements a compliance-ready soft-delete mechanism for KYC customers with automated 7-year data retention purging.
  2. Introduces a BullMQ Dead-Letter Queue (DLQ) with exponential backoff retries and admin inspection/re-queue endpoints.
  3. Expands global input sanitization to strip malicious script tags and HTML entities across req.body, req.query, and req.params.
  4. Completes 100% OpenAPI 3.0 JSDoc specification coverage across all SEP endpoints (SEP-6, SEP-12, SEP-24, SEP-31, SEP-38, SEP-40) with an automated CI validation step.

Linked Issues


Summary of Changes

1. Soft-Delete Mechanism & 7-Year Retention Purge (#1197)

  • Schema Migration: Added deletedAt DateTime? to the KYC customer record with dedicated migration and rollback scripts.
  • Query Interception & Restorations: Soft-deleted records are automatically filtered from standard customer lookups (backend/src/utils/soft-delete.ts). Added explicit checks to SEP-12 GET /customer and KYC webhooks (returning 404 for deleted profiles). Updated DELETE /sep12/customer/:account to flag deletedAt = now() instead of executing a hard delete, and re-submitting KYC restores the profile.
  • Lifecycle Purge Job: Configured a daily cron job scheduled at 03:00 UTC to permanently purge records soft-deleted for longer than 7 years.

2. Notification Dead-Letter Queue (DLQ) & Admin Controls (#1199)

  • BullMQ Backoff & DLQ: Configured default notification job options with 3 attempts and exponential backoff starting at 1,000ms. Created the isolated notification-dlq queue with routeFailedNotificationToDlq forwarding exhaustively failed jobs.
  • Admin Management Endpoints:
    • GET /api/admin/queues/notification-dlq: Inspects failed jobs, error traces, and timestamps.
    • POST /api/admin/queues/notification-dlq/:jobId/retry: Re-injects failed DLQ jobs back into the active notification queue.

3. Comprehensive Request Input Sanitization (#1203)

  • Full Parameter Protection: Upgraded the sanitization middleware (sanitizeRequestMiddleware) from body-only inspection to recursively sanitize string values across req.body, req.query, and route req.params (including nested router contexts).
  • Global Injection: Mounted globally in backend/src/index.ts to neutralize stored and reflected XSS payloads before route handlers execute.

4. OpenAPI 3.0 SEP Specifications & Validation Gate (#1205)

  • Complete Schema Coverage: Authored complete OpenAPI 3.0 JSDoc specifications across SEP-6, SEP-31, SEP-38, and SEP-40. Completed missing schemas for SEP-12 and notifications (PATCH /api/notifications/history), and corrected YAML indentation errors in SEP-24 routes.
  • Automated CI Validation: Added npm run swagger:validate utilizing @apidevtools/swagger-parser to validate schema compliance across 92 endpoints, integrating it into the CI verification pipeline.

Verification Logs

  • Swagger Validation: npm run swagger:validate successfully validated the complete OpenAPI 3.0 document across 92 paths with 0 syntax or reference errors.
  • New Test Suites: All newly introduced tests covering soft-deletion, retention purging, DLQ routing, and parameter sanitization pass cleanly.
  • Regression Baseline: Maintained parity against the pre-existing test baseline; 0 regressions introduced.

Notes for Maintainers

  • Pre-Existing Failures on Upstream main:
    • Upstream backend/prisma/schema.prisma contains duplicate models and unresolved git merge conflict artifacts (fix/issue-batch 1, =======). Testing was verified locally using a cleaned single-schema instance; deletedAt was added across all model copies to maintain forward compatibility.
    • Several pre-existing compilation errors (sep24.controller.ts, sep31/service.ts, admin.schemas.ts, relayer.service.test.ts) and 48 legacy test suite failures exist on upstream main and remain isolated from this branch's diff.
  • Worker Consumer Registration: The routeFailedNotificationToDlq handler is implemented and ready to be bound as the failed listener once the notification consumer worker is provisioned.

…ization, SEP OpenAPI specs

- Add KycCustomer.deletedAt, filter soft-deleted rows from default reads via a
  Prisma query extension, soft-delete on SEP-12 DELETE, and purge records past
  the 7-year retention period with a daily cron job (ceejaylaboratory#1197)
- Configure notification queue retries (3 attempts, exponential 1s backoff),
  route exhausted jobs to notification-dlq, and add admin endpoints to list and
  retry DLQ jobs (ceejaylaboratory#1199)
- Sanitize query and route params in addition to the request body (ceejaylaboratory#1203)
- Complete OpenAPI 3.0 annotations for SEP-6/12/24/31/38/40 routes, fix invalid
  YAML in existing blocks, and add a CI step validating the spec (ceejaylaboratory#1205)

Closes ceejaylaboratory#1197
Closes ceejaylaboratory#1199
Closes ceejaylaboratory#1203
Closes ceejaylaboratory#1205

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 24, 2026 13:17
@drips-wave

drips-wave Bot commented Sep 24, 2026

Copy link
Copy Markdown

@godamongstmen897 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Ceejaytech25

Copy link
Copy Markdown
Contributor

Nice implementation, LGTM! 🚀 Great work on this contribution — the approach is clean and well thought out. Thanks for contributing to AnchorPoint!

@Ceejaytech25
Ceejaytech25 merged commit e2f5ed8 into ceejaylaboratory:main Oct 1, 2026
5 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants