feat: validate ledger ranges for historical event queries - #894
Merged
Abd-Standard merged 2 commits intoOct 2, 2026
Merged
Conversation
- Add ledger-range-validator.ts with validateLedgerRange,
safeLedgerRangeValidation, and parseLedgerRangeParams helpers.
Rules: positive integers, start <= end, width <= 10 000 ledgers.
- Expose GET /api/events/history?fromLedger=N&toLedger=N endpoint.
Returns 400 with structured field-level errors on invalid input;
200 with { count, startLedger, endLedger, events } on success.
- Add getEventsByLedgerRange to EventRegistry for inclusive range
filtering used by the new history endpoint.
- Wire safeLedgerRangeValidation into EventSubscriber backfill path
to guard against invalid computed start-ledger values.
- Fix pre-existing parse errors: corrupted generateCorrelationId JSDoc
in request-id.ts, duplicate imports in events-server.ts, duplicate
processableEvents declaration in event-subscriber.ts.
- Fix pre-existing missing validateRpcResponse mock in backfill test.
- Add 74 new tests (49 unit + 25 integration); backfill suite now
passes (12 tests) after pre-existing fixes.
|
@StephenMero Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Validate ledger ranges for historical event queries
Introduces input validation for ledger ranges used in historical event queries, preventing
invalid, inverted, or excessively large requests from reaching the RPC node or event registry.
───────────────────────────────────────────────────────────────────────────────────────────────
What changed
ledger-range-validator.ts — new utility with three exports:
positive integers, start > end, or range width exceeds 10 000 ledgers
one step
GET /api/events/history?fromLedger=N&toLedger=N — new endpoint returning in-registry events
filtered by ledger range. Returns 400 with structured field-level error details on invalid
input; 200 with { count, startLedger, endLedger, events } on success. Works via the /api/v1/
version prefix.
EventRegistry.getEventsByLedgerRange — new method for inclusive ledger-range filtering, used
by the history endpoint.
EventSubscriber.resolveBackfillStartLedger — wired safeLedgerRangeValidation to guard against
invalid computed start-ledger values (e.g. from an extreme or malformed RPC tip response). The
API range-width cap is intentionally not applied here since the backfill's own maxLedgers
config governs that.
Pre-existing fixes included (were blocking compilation/tests):
───────────────────────────────────────────────────────────────────────────────────────────────
Tests
┌───────────────────────────────────┬───────┬────────────────────┐
│ Suite │ Tests │ Status │
├───────────────────────────────────┼───────┼────────────────────┤
│ ledger-range-validator.test.ts │ 49 │ ✅ new │
├───────────────────────────────────┼───────┼────────────────────┤
│ events-server.history.test.ts │ 25 │ ✅ new │
├───────────────────────────────────┼───────┼────────────────────┤
│ event-subscriber-backfill.test.ts │ 12 │ ✅ fixed & passing │
└───────────────────────────────────┴───────┴────────────────────┘
Coverage includes: valid ranges, invalid types (float, string, null, NaN, Infinity),
zero/negative ledgers, overflow values, inverted ranges, ranges exactly at and one over the 10
000-ledger cap, missing query params, response envelope shape, and the guarantee that oversized
requests never reach the registry.
closes #827