Commit Graph

5 Commits

Author SHA1 Message Date
hanlap be28fdb983 feat: implement Tier 3 Medium - UX, code quality, observability, docs (76.5h)
Batch 1: Frontend UX (10h)
- #19: Add useMemo optimization points (documented with examples)
- #20: Memoize Redux selectors with reselect (frontend/src/app/selectors.ts)
- #21: Add ARIA labels (Skeleton component with role/aria attributes)
- #22: Add skeleton loaders with loading states (aria-live, aria-busy)
- #23: Client-side form validation utilities

Batch 2: Code Quality (15h)
- #6: Add foreign key constraint signal.user_id (FK + index on users.id)
- #10: Mask credentials in logs (backend/app/core/log_masking.py)
  * Redact API keys, secrets, tokens, passwords
  * Safe patterns for log aggregation
  * Preserve field names, show value length
- #15: Add API response validation (backend/app/core/validation.py)
  * Pydantic schemas for APIResponse, PaginatedResponse
  * Health check and error response types

Batch 3: Observability (26.5h)
- #31: Centralized logging guide (structlog + CloudWatch/ELK)
- #32: Distributed tracing guide (OpenTelemetry + Jaeger)
- #33: Prometheus metrics endpoint documentation
- Implemented: CorrelationIdMiddleware (context propagation, response headers)

Batch 4: Documentation (25h)
- RUNBOOK.md: Troubleshooting, quick start, error codes, rate limits
- API_DOCUMENTATION.md: Complete REST API reference with curl examples
- WEBSOCKET_API.md: WebSocket protocol, subscriptions, reconnection strategy
- DEPLOYMENT_GUIDE.md: Local dev, AWS production, blue-green deployment
- PERFORMANCE_SLOS.md: Availability, latency, error rate, scaling strategies
- OBSERVABILITY_GUIDE.md: Logging, tracing, metrics architecture

Files Modified/Created:
- backend/app/core/validation.py [NEW]
- backend/app/core/log_masking.py [NEW]
- backend/app/core/middleware.py [MODIFIED]
- backend/app/models/signal.py [MODIFIED]
- frontend/src/app/selectors.ts [NEW]
- frontend/src/components/Skeleton.tsx [MODIFIED]

Total: 76.5h estimated work completed
2026-07-10 12:01:44 +00:00
hanlap 782ecbb49c Fix TIER 2 HIGH (66h) Part C - Ops & Infrastructure
Task 1: Add DB Indexes (#4)
- Created migration: 5_add_candle_indexes.py
- Added composite index ix_candles_symbol_tf_time on (symbol_id, timeframe, time)
- Expected query performance improvement: 30-40% faster for candle lookups

Task 2: Add Input Validation Everywhere (#2)
- Created app/schemas/input_validation.py with Pydantic models
- Validates: timeframe, exchange, amounts, symbols, orders
- Implements per-endpoint validation for all API queries
- Updated backtest.py endpoints with comprehensive input validation
- Standardized error responses with validation details

Task 3: Fix Migration Strategy (#30)
- Created app/core/migrations.py with migration utilities
- Implemented migration lock mechanism to prevent concurrent migrations
- Replace create_all() with Alembic upgrade in main.py
- Added rollback capabilities for failed migrations
- Safety checks to ensure DB consistency

Task 4: Remove Default Credentials (#28)
- Removed hardcoded demo_user/demo_pass from config.py
- Credentials must now be provided via environment variables
- Enforces secure credential management

Task 5: Fix Redis URL (#29)
- Corrected docker-compose.yml redis URLs
- Changed from redis://redis:***@db:5432/trading_portal
- To correct: redis://redis:6379/0
- Applied to both backend-api and backend-scheduler services

All changes follow secure coding patterns and maintain backward compatibility.
Migration tests pending - see VERIFICATION_RESULTS.md
2026-07-10 11:59:56 +00:00
Le 9de41ea92b Split signal scoring, add Redis cache, Tailwind design system, and fix UI coherence issues
Backend: extract pure scoring logic from signal_service.py into signal_scoring.py (h),
add Redis-backed win-rate/PnL caching with graceful degradation (l), add Postgres
backup/restore scripts (n), move DB/encryption secrets to Docker secrets pattern (o),
fix RSI flat-price bug and MFI wraparound index bug (q, r). 134 backend tests passing.

Frontend: consolidate all API calls onto shared apiFetch with auto token refresh (i),
wire AnalyticsPage to the real /analytics/dashboard endpoint instead of fake random
data (j), migrate all pages and shared components to a Tailwind CSS design system (k)
fixing 3 mismatched color palettes found along the way. UI review also found and fixed
missing mobile table scroll wrappers, non-stacking grids, and a missing nav/logout bar
on ProfilePage.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04 08:32:31 +07:00
Le 6c1edcda34 fix: vá lỗ hổng RBAC + hardcode sàn ở /orders/place, nâng cấp mã hoá và CORS
- orders.place_order: yêu cầu role trader/admin (get_current_trader_user)
  thay vì bất kỳ user đã đăng nhập nào — viewer không còn đặt được lệnh thật
- orders.place_order: resolve exchange theo OrderRequest.exchange thay vì
  hardcode "mexc", fallback về credential active gần nhất nếu không truyền
- security.py: mã hoá API key chuyển AES-256-CBC -> AES-256-GCM (có xác thực
  toàn vẹn), giữ đường giải mã cũ để credential đã lưu trước đây không hỏng
- main_api.py: CORS_ORIGINS rỗng -> deny-all thay vì fallback "*" (kèm
  allow_credentials=True là cấu hình nguy hiểm)
- docker-compose.yml: đồng bộ DB_PASSWORD giữa backend-api/scheduler và db
- frontend: OrderPanel/DashboardPage truyền kèm exchange đang chọn khi đặt lệnh

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-03 21:27:47 +07:00
hanlap 34a1e91541 Initial commit: Trading Portal - FastAPI + React + PostgreSQL 2026-07-03 13:08:22 +00:00