|
| 1 | +# YieldVault Backend API |
| 2 | + |
| 3 | +Express.js backend server for YieldVault Stellar RWA platform with rate limiting and health monitoring. |
| 4 | + |
| 5 | +## Features |
| 6 | + |
| 7 | +- **Health Check Endpoint** (`/health`) - Real-time service health status |
| 8 | +- **Readiness Endpoint** (`/ready`) - Dependency status for deployment orchestration |
| 9 | +- **Rate Limiting** - Per-IP and per-API-key rate limiting to prevent abuse |
| 10 | +- **Dependency Monitoring** - Checks for cache and Stellar RPC availability |
| 11 | +- **Error Handling** - Consistent JSON error responses |
| 12 | +- **TypeScript** - Full type safety with TypeScript |
| 13 | + |
| 14 | +## Quick Start |
| 15 | + |
| 16 | +### Setup |
| 17 | + |
| 18 | +```bash |
| 19 | +# Install dependencies |
| 20 | +npm install |
| 21 | + |
| 22 | +# Create environment file |
| 23 | +cp .env.example .env |
| 24 | +``` |
| 25 | + |
| 26 | +### Development |
| 27 | + |
| 28 | +```bash |
| 29 | +# Start development server with auto-reload |
| 30 | +npm run dev |
| 31 | +``` |
| 32 | + |
| 33 | +The server will start on `http://localhost:3000`. |
| 34 | + |
| 35 | +### Production |
| 36 | + |
| 37 | +```bash |
| 38 | +# Build TypeScript |
| 39 | +npm run build |
| 40 | + |
| 41 | +# Start production server |
| 42 | +npm start |
| 43 | +``` |
| 44 | + |
| 45 | +## Configuration |
| 46 | + |
| 47 | +Rate limiting and other settings are configurable via environment variables: |
| 48 | + |
| 49 | +| Variable | Default | Description | |
| 50 | +|----------|---------|-------------| |
| 51 | +| `PORT` | 3000 | Server port | |
| 52 | +| `NODE_ENV` | development | Environment mode | |
| 53 | +| `RATE_LIMIT_WINDOW_MS` | 900000 | Global rate limit window (15 min) | |
| 54 | +| `RATE_LIMIT_MAX_REQUESTS` | 100 | Global requests per window | |
| 55 | +| `API_RATE_LIMIT_WINDOW_MS` | 60000 | API rate limit window (1 min) | |
| 56 | +| `API_RATE_LIMIT_MAX_REQUESTS` | 30 | API requests per window | |
| 57 | +| `STELLAR_RPC_URL` | https://soroban-testnet.stellar.org | Stellar RPC endpoint | |
| 58 | + |
| 59 | +## API Endpoints |
| 60 | + |
| 61 | +### Health Check |
| 62 | + |
| 63 | +``` |
| 64 | +GET /health |
| 65 | +``` |
| 66 | + |
| 67 | +Returns service health status with dependency checks. |
| 68 | + |
| 69 | +**Response (200 OK):** |
| 70 | +```json |
| 71 | +{ |
| 72 | + "status": "healthy", |
| 73 | + "timestamp": "2026-03-26T10:30:00.000Z", |
| 74 | + "uptime": 3600.5, |
| 75 | + "environment": "development", |
| 76 | + "checks": { |
| 77 | + "api": "up", |
| 78 | + "cache": "up", |
| 79 | + "stellarRpc": "up" |
| 80 | + } |
| 81 | +} |
| 82 | +``` |
| 83 | + |
| 84 | +### Readiness Check |
| 85 | + |
| 86 | +``` |
| 87 | +GET /ready |
| 88 | +``` |
| 89 | + |
| 90 | +Returns service readiness state. Checks all critical dependencies before reporting ready. |
| 91 | + |
| 92 | +**Response (200 OK - Ready):** |
| 93 | +```json |
| 94 | +{ |
| 95 | + "ready": true, |
| 96 | + "timestamp": "2026-03-26T10:30:00.000Z", |
| 97 | + "dependencies": { |
| 98 | + "cache": true, |
| 99 | + "stellarRpc": true |
| 100 | + } |
| 101 | +} |
| 102 | +``` |
| 103 | + |
| 104 | +**Response (503 Unavailable - Not Ready):** |
| 105 | +```json |
| 106 | +{ |
| 107 | + "ready": false, |
| 108 | + "timestamp": "2026-03-26T10:30:00.000Z", |
| 109 | + "dependencies": { |
| 110 | + "cache": false, |
| 111 | + "stellarRpc": false |
| 112 | + } |
| 113 | +} |
| 114 | +``` |
| 115 | + |
| 116 | +### Rate Limit Exceeded |
| 117 | + |
| 118 | +``` |
| 119 | +Status: 429 Too Many Requests |
| 120 | +``` |
| 121 | + |
| 122 | +```json |
| 123 | +{ |
| 124 | + "error": "Too many requests", |
| 125 | + "status": 429, |
| 126 | + "message": "Rate limit exceeded. Please try again later.", |
| 127 | + "retryAfter": 1711432200000 |
| 128 | +} |
| 129 | +``` |
| 130 | + |
| 131 | +## Rate Limiting |
| 132 | + |
| 133 | +### Global Rate Limiting |
| 134 | + |
| 135 | +Applied to all requests except `/health` and `/ready`: |
| 136 | +- Window: 15 minutes (configurable) |
| 137 | +- Max: 100 requests per window (configurable) |
| 138 | +- Per: IP address |
| 139 | + |
| 140 | +### API Endpoint Rate Limiting |
| 141 | + |
| 142 | +Stricter limits for API endpoints (e.g., `/api/vault/summary`): |
| 143 | +- Window: 1 minute (configurable) |
| 144 | +- Max: 30 requests per window (configurable) |
| 145 | +- Per: API key (from `x-api-key` header) or IP address |
| 146 | + |
| 147 | +## Testing |
| 148 | + |
| 149 | +```bash |
| 150 | +# Run all tests |
| 151 | +npm test |
| 152 | + |
| 153 | +# Run tests in watch mode |
| 154 | +npm test -- --watch |
| 155 | + |
| 156 | +# Run with coverage |
| 157 | +npm test -- --coverage |
| 158 | +``` |
| 159 | + |
| 160 | +## Issues Addressed |
| 161 | + |
| 162 | +### Issue #145: Rate Limiting |
| 163 | +- ✅ Global rate limiting per IP |
| 164 | +- ✅ Per-user/API-key rate limiting |
| 165 | +- ✅ Configurable via environment variables |
| 166 | +- ✅ Clear 429 responses with retry information |
| 167 | +- ✅ Tests included for rate limiting behavior |
| 168 | + |
| 169 | +### Issue #148: Health & Readiness Endpoints |
| 170 | +- ✅ `/health` endpoint for service health |
| 171 | +- ✅ `/ready` endpoint for deployment readiness |
| 172 | +- ✅ Dependency health checks (cache, RPC) |
| 173 | +- ✅ CI smoke test setup via npm scripts |
| 174 | +- ✅ Consistent response formats |
| 175 | + |
| 176 | +## CI/CD Integration |
| 177 | + |
| 178 | +### Smoke Test (CI Pipeline) |
| 179 | + |
| 180 | +```bash |
| 181 | +# Build and start server |
| 182 | +npm run test:smoke |
| 183 | + |
| 184 | +# The server will start in background, ready for health checks |
| 185 | +# Call: curl http://localhost:3000/health |
| 186 | +# Call: curl http://localhost:3000/ready |
| 187 | +``` |
| 188 | + |
| 189 | +### Docker Deployment |
| 190 | + |
| 191 | +Example Dockerfile: |
| 192 | + |
| 193 | +```dockerfile |
| 194 | +FROM node:20-alpine |
| 195 | +WORKDIR /app |
| 196 | +COPY package*.json ./ |
| 197 | +RUN npm ci --only=production |
| 198 | +COPY dist ./dist |
| 199 | +EXPOSE 3000 |
| 200 | +HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ |
| 201 | + CMD node -e "require('http').get('http://localhost:3000/health', (r) => r.statusCode === 200 ? process.exit(0) : process.exit(1))" |
| 202 | +CMD ["npm", "start"] |
| 203 | +``` |
| 204 | + |
| 205 | +## Monitoring |
| 206 | + |
| 207 | +Headers returned in responses: |
| 208 | + |
| 209 | +- `RateLimit-Limit` - Request limit |
| 210 | +- `RateLimit-Remaining` - Requests remaining |
| 211 | +- `RateLimit-Reset` - Reset timestamp |
| 212 | + |
| 213 | +Example: |
| 214 | +``` |
| 215 | +RateLimit-Limit: 100 |
| 216 | +RateLimit-Remaining: 95 |
| 217 | +RateLimit-Reset: 1711432200 |
| 218 | +``` |
| 219 | + |
| 220 | +## License |
| 221 | + |
| 222 | +MIT |
0 commit comments