Skip to content

feat: validate ledger ranges for historical event queries - #894

Merged
Abd-Standard merged 2 commits into
Core-Foundry:mainfrom
StephenMero:feature/ledger-range-validation
Oct 2, 2026
Merged

Abd-Standard merged 2 commits into
Core-Foundry:mainfrom
StephenMero:feature/ledger-range-validation

Conversation

@StephenMero

Copy link
Copy Markdown
Contributor

Validate ledger ranges for historical event queries

Introduces input validation for ledger ranges used in historical event queries, preventing
invalid, inverted, or excessively large requests from reaching the RPC node or event registry.

───────────────────────────────────────────────────────────────────────────────────────────────

What changed

  • ledger-range-validator.ts — new utility with three exports:

    • validateLedgerRange — throws ValidationError with per-field issues if start/end are not
      positive integers, start > end, or range width exceeds 10 000 ledgers
    • safeLedgerRangeValidation — non-throwing wrapper returning { valid, reason, issues }
    • parseLedgerRangeParams — parses fromLedger/toLedger query-string params and validates in
      one step
  • GET /api/events/history?fromLedger=N&toLedger=N — new endpoint returning in-registry events
    filtered by ledger range. Returns 400 with structured field-level error details on invalid
    input; 200 with { count, startLedger, endLedger, events } on success. Works via the /api/v1/
    version prefix.

  • EventRegistry.getEventsByLedgerRange — new method for inclusive ledger-range filtering, used
    by the history endpoint.

  • EventSubscriber.resolveBackfillStartLedger — wired safeLedgerRangeValidation to guard against
    invalid computed start-ledger values (e.g. from an extreme or malformed RPC tip response). The
    API range-width cap is intentionally not applied here since the backfill's own maxLedgers
    config governs that.

Pre-existing fixes included (were blocking compilation/tests):

  • Corrupted JSDoc inside generateCorrelationId in request-id.ts
  • Duplicate TemplateService/handleTemplateRoutes imports in events-server.ts
  • Duplicate processableEvents declaration in event-subscriber.ts
  • Missing validateRpcResponse in the backfill test's event-utils mock

───────────────────────────────────────────────────────────────────────────────────────────────

Tests

┌───────────────────────────────────┬───────┬────────────────────┐
│ Suite │ Tests │ Status │
├───────────────────────────────────┼───────┼────────────────────┤
│ ledger-range-validator.test.ts │ 49 │ ✅ new │
├───────────────────────────────────┼───────┼────────────────────┤
│ events-server.history.test.ts │ 25 │ ✅ new │
├───────────────────────────────────┼───────┼────────────────────┤
│ event-subscriber-backfill.test.ts │ 12 │ ✅ fixed & passing │
└───────────────────────────────────┴───────┴────────────────────┘

Coverage includes: valid ranges, invalid types (float, string, null, NaN, Infinity),
zero/negative ledgers, overflow values, inverted ranges, ranges exactly at and one over the 10
000-ledger cap, missing query params, response envelope shape, and the guarantee that oversized
requests never reach the registry.

closes #827

- Add ledger-range-validator.ts with validateLedgerRange,
  safeLedgerRangeValidation, and parseLedgerRangeParams helpers.
  Rules: positive integers, start <= end, width <= 10 000 ledgers.
- Expose GET /api/events/history?fromLedger=N&toLedger=N endpoint.
  Returns 400 with structured field-level errors on invalid input;
  200 with { count, startLedger, endLedger, events } on success.
- Add getEventsByLedgerRange to EventRegistry for inclusive range
  filtering used by the new history endpoint.
- Wire safeLedgerRangeValidation into EventSubscriber backfill path
  to guard against invalid computed start-ledger values.
- Fix pre-existing parse errors: corrupted generateCorrelationId JSDoc
  in request-id.ts, duplicate imports in events-server.ts, duplicate
  processableEvents declaration in event-subscriber.ts.
- Fix pre-existing missing validateRpcResponse mock in backfill test.
- Add 74 new tests (49 unit + 25 integration); backfill suite now
  passes (12 tests) after pre-existing fixes.
@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@StephenMero Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Abd-Standard
Abd-Standard merged commit d580176 into Core-Foundry:main Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add Ledger Range Validation

2 participants