Rolling train/test folds over 3 years of data auto-optimize the three
cheap-to-tune trading parameters (STRONG/BUY score thresholds, max hold
time) via grid search on each fold's train window, then evaluate purely
on the held-out test window. Stitching all out-of-sample results gives
an honest performance estimate uninflated by tuning against the same
data used to score it.
Split signal_scoring.py's expensive 13-algorithm scoring from its cheap
final threshold classification so grid search can replay many parameter
combinations without recomputing indicators each time. Moved the
backtest engine (fetch/precompute/simulate) out of the API layer into
app/services/backtest_engine.py so both /backtest/run and the new
walk-forward optimizer share one implementation instead of drifting
copies — same rationale as the earlier signal_service.py split (item h).
Also merges two long-diverged Alembic migration heads discovered while
adding the walk_forward_results table, so `alembic upgrade head` has a
single target again.
New: POST/GET/DELETE /walk-forward/* endpoints, a Walk-Forward tab on
the Backtest page (fold table, out-of-sample equity curve, run history).
19 new backend tests (153 total, all passing).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Backend: extract pure scoring logic from signal_service.py into signal_scoring.py (h),
add Redis-backed win-rate/PnL caching with graceful degradation (l), add Postgres
backup/restore scripts (n), move DB/encryption secrets to Docker secrets pattern (o),
fix RSI flat-price bug and MFI wraparound index bug (q, r). 134 backend tests passing.
Frontend: consolidate all API calls onto shared apiFetch with auto token refresh (i),
wire AnalyticsPage to the real /analytics/dashboard endpoint instead of fake random
data (j), migrate all pages and shared components to a Tailwind CSS design system (k)
fixing 3 mismatched color palettes found along the way. UI review also found and fixed
missing mobile table scroll wrappers, non-stacking grids, and a missing nav/logout bar
on ProfilePage.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Xac nhan: git log -p tren origin/master cho 0 lan xuat hien ca 4 mat khau
cu sau khi force-push lich su da rewrite. Cap nhat SECURITY_INCIDENT doc
va ARCHITECTURE.md phan anh trang thai da dong, ghi lai bai hoc quy trinh
cho lan sau (nen tam dung push vao nhanh dich TRUOC khi chuan bi rewrite,
khong phai sau khi chuan bi xong).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Nhanh history-rewrite-2026-07-03 truoc do bi xoa ma chua force-push vao
master. Da tao lai (lan 3) dua tren tip moi nhat cua master (9d0a32c),
verify lai 0 lan xuat hien mat khau cu. Chi con cho ban force-push.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- SECURITY_INCIDENT_GITEA_CREDENTIALS.md: rewrite lich su git da hoan
tat va day len nhanh history-rewrite-2026-07-03, chi con cho force-push
vao master (thao tac can ban tu chay)
- theo_doi_trading-portal_v4.md: fix (p), test indicator_service +
signal_service async (122 test tong), phat hien (q)/(r), ghi nhan
su co quy trinh (s) -- loi build TypeScript do replace_all khong khop
het 2 vi tri thut le khac nhau, da duoc hanlap va kip thoi
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- test_indicator_service.py (33 test): sma, ema, rsi, bollinger_bands,
macd, atr, vwap, obv, obv_signal, mfi, detect_market_regime. Phat hien
2 quirk nho (chua fix, can quyet dinh cua team):
(q) rsi() tra ~98 thay vi 50 khi gia hoan toan di ngang (rs=50 sentinel
van bi dua qua cong thuc RSI thay vi tra thang 50)
(r) mfi() bi wraparound index o diem tinh dau tien cua chuoi (j-1=-1),
tac dong thuc te gan bang 0 vi signal_service chi doc mfi_data[-1]
- test_signal_service_async.py (7 test): close_stale_trades (time limit,
stop loss, take profit, trailing stop) + expire_old_signals. Cac ham
nay tu mo session rieng qua async_session_factory (khong nhan db lam
tham so) nen test monkeypatch bien module-level nay sang SQLite in-memory.
- conftest.py: them fixture session_factory (async_sessionmaker thay vi 1
session) + _UTCDateTime TypeDecorator de SQLite giu duoc tzinfo UTC qua
round-trip (SQLite khong ho tro luu tz-aware datetime nhu Postgres).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Phat hien (p) khi viet test cho trade_executor: khi kiem tra hybrid
eviction, PnL cua TAT CA cac trade dang mo (o nhieu symbol khac nhau) bi
tinh bang current_price cua tin hieu dang xu ly, thay vi gia thuc cua
tung symbol. Fix bang cach lookup gia moi nhat theo tung
symbol/exchange/timeframe (batched query, cung pattern da dung dung trong
close_stale_trades), ap dung cho ca xep hang loser LAN gia dong lenh cuoi
cung.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Ghi lai toan bo qua trinh: danh gia kien truc/uu-nhuoc diem ban dau (v0),
fix RBAC + order routing + DB password (v1), fix AES-GCM + CORS + huong
dan xu ly lo mat khau Gitea (v2), va bo test 81 cases cho phan logic
rui ro cao nhat (v3).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Backend truoc day chi co script goi httpx vao server dang chay that
(test_auth.py, test_full_api.py), khong phai pytest that. Them bo test
chay doc lap bang SQLite in-memory (khong can Postgres/Docker):
- test_rbac_deps.py: RBAC chain + regression-guard cho fix vai tro o /orders/place
- test_order_exchange_routing.py: routing dung san theo credential
- test_security_encryption.py: AES-GCM round-trip + tuong thich nguoc AES-CBC
- test_cors_config.py: CORS fail-closed khi thieu cau hinh
- test_risk_manager.py: Kelly sizing + SL/TP adaptive theo tung regime
- test_trade_executor.py: STRONG-only, dedup, reversal, volatility filter,
hybrid eviction FIFO -- toan bo quy tac mo/dong trade
- test_signal_service_scoring.py: he thong cham diem 13 thuat toan
Them .gitea/workflows/backend-tests.yml chay pytest tu dong khi push/PR
dung vao backend/** (can Gitea Actions + runner da duoc bat tren instance).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bang mat khau 4 tai khoan Gitea (hanlap, nguyendao, tulinh, namcunguyen) da
bi lo trong lich su git ke tu commit 85ca5c4. Go khoi ban hien tai va them
huong dan xu ly day du (rotate mat khau + tuy chon rewrite lich su git) --
viec rotate mat khau that tren Gitea van can admin thuc hien thu cong.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- orders.place_order: yêu cầu role trader/admin (get_current_trader_user)
thay vì bất kỳ user đã đăng nhập nào — viewer không còn đặt được lệnh thật
- orders.place_order: resolve exchange theo OrderRequest.exchange thay vì
hardcode "mexc", fallback về credential active gần nhất nếu không truyền
- security.py: mã hoá API key chuyển AES-256-CBC -> AES-256-GCM (có xác thực
toàn vẹn), giữ đường giải mã cũ để credential đã lưu trước đây không hỏng
- main_api.py: CORS_ORIGINS rỗng -> deny-all thay vì fallback "*" (kèm
allow_credentials=True là cấu hình nguy hiểm)
- docker-compose.yml: đồng bộ DB_PASSWORD giữa backend-api/scheduler và db
- frontend: OrderPanel/DashboardPage truyền kèm exchange đang chọn khi đặt lệnh
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>