Fix stability, security, and performance quick wins#158
Open
Sparksx wants to merge 1 commit into
Open
Conversation
- Remove duplicate SIGTERM/SIGINT handlers (prisma.js vs index.js race) - Enable Content Security Policy headers in production - Fix open redirect in payment checkout (validate origin against whitelist) - Wrap clan rank management (promote/demote/kick) in transactions to prevent race conditions that could allow privilege escalation - Validate expedition reward values before distributing (guard NaN/negative) - Early-return on empty expedition members to avoid wasted DB operations - Optimize clan listing endpoint: use _count instead of loading all members - Add composite index on Expedition(status, endsAt) for timer queries - Fix chat crash on deleted users (null-safe serialization) - Raise Socket.io compression threshold from 1KB to 4KB (reduce CPU on small messages) - Catch unhandled promise rejection in token cleanup interval Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DoxYEXoRR2mhPGwqJd7Wdj
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Comprehensive codebase audit identified 23 improvements across security, stability, performance, and functionality. This PR implements the 10 highest-priority quick wins — high impact, low risk, minimal code change.
Stability fixes
prisma.jsandindex.jsboth registered shutdown handlers, causing a race whereprisma.jscalledprocess.exit(0)beforeindex.jscould flush Socket.io connections and close the HTTP server cleanlyrewardXp/rewardGoldfrom data corruption; early-return when no members joinedsetInterval(asyncFn)silently dropped rejections, potentially leaking memorySecurity fixes
contentSecurityPolicy: false) — defense-in-depth against XSSreq.headers.originwas used raw to build Stripe success/cancel URLs; now validated against an explicit allowlistPerformance fixes
/api/clansloaded every member's full gameState for all 25 clans just to show a list; now uses_countonly (members are loaded on detail view)Expedition(status, endsAt)for the lazy-resolution timer queryMinor fixes
username: undefinedcrash in conversation member listTest plan
npm test)npm run lint)npm run build)Remaining items from audit (not in this PR)
🤖 Generated with Claude Code
https://claude.ai/code/session_01DoxYEXoRR2mhPGwqJd7Wdj
Generated by Claude Code