[WSAPI-5] Internal API endpoints + shared-secret auth #4
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feature/WSAPI-5"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Ticket
WSAPI-5 Internal API endpoints + shared-secret auth
Summary
GET /activity-feed,/positions,/accounts,/status,POST /sync/trigger) behind a new shared-secret bearer gate (bearer-auth/), all reading from Mongocaches (
lib/activity-feed-cache,lib/account-balances-cache,lib/sync-status) rather thanWealthsimple live — verified in tests by stubbing
fetchto throw if the GET routes ever call it.POST /sync/triggeris the one endpoint that calls Wealthsimple live: a small, debounced (10s + onetrailing run so a coalesced trigger's data still gets fetched) on-demand activity-feed sync
(
sync/activity-feed/), deliberately not a full sync engine (no mutex/rate-ceiling/retry-ladder —WSAPI-6 or a follow-up ticket's to add if needed).
error-handler/mapsZodError→400,SessionDeadError→503 (so a caller triggering a syncagainst a dead Wealthsimple session gets a distinguishable status), a body-parser failure's own 4xx
status is passed through, everything else→500.
lib/account-balances-cacheandlib/positions/accountstreat "nothing synced yet" (WSAPI-6 hasn'tshipped the balances sync) as a valid empty state, not an error.
lib/wealthsimple/CLAUDE.mdupdated for the new endpoints, auth gate, and architecture.🤖 Generated with Claude Code
https://claude.ai/code/session_01DSc34oDVEBXLz9TJWt26Nn