mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 10:13:11 +00:00
Four confirmed findings from the 2026-06-17 security sweep: - register_user let any Slack user overwrite an extension already bound to a different user (account takeover). Add a DynamoDB ConditionExpression so a write only succeeds when the extension is unclaimed or already this user's; raise ExtensionAlreadyRegistered otherwise and surface a clear Slack message. - The `rate` subcommand was routed without the is_admin flag, so any user could set $0 pay rates. Gate _handle_rate on is_admin, matching the admin-command guard. - `/oncall pick` used a plain put_item (TOCTOU): two concurrent picks both won. Use the atomic claim_open_shift conditional claim so the loser gets an "already picked up" message. - swap-accept overwrote a shift independently claimed after the swap was initiated. Add reassign_if_held_by, a conditional write that only applies the swap while the override is still the requester's (or on the weekly fallback), and notify the accepter otherwise. Add tests for the register-ownership guard and the rate admin guard. Refs: INFRA |
||
|---|---|---|
| .. | ||
| conftest.py | ||
| test_app_home.py | ||
| test_handle_admin.py | ||
| test_handle_drop.py | ||
| test_handle_holiday.py | ||
| test_handle_holiday_actions.py | ||
| test_handle_pick.py | ||
| test_handle_register_rate.py | ||
| test_handle_swap.py | ||
| test_helpers.py | ||
| test_late_pickup.py | ||
| test_parse_date.py | ||
| test_pickup_button.py | ||
| test_swap_accept_decline.py | ||