mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-02 17:43:11 +00:00
Use full email as order slug for defense-in-depth
Replace email-prefix slug with full lowercase email to eliminate any possibility of cross-domain collisions, per senior review sign-off.
This commit is contained in:
parent
fa2b4b7616
commit
406aa9b95d
2 changed files with 13 additions and 12 deletions
|
|
@ -226,7 +226,7 @@ def handle_submit(event):
|
|||
|
||||
total = float(sum(Decimal(str(i["subtotal"])) for i in filtered_items).quantize(TWO_PLACES, rounding=ROUND_HALF_UP))
|
||||
|
||||
slug = email.split("@")[0].lower().replace(".", "-")
|
||||
slug = email.lower()
|
||||
|
||||
order_data = {
|
||||
"employee_name": name,
|
||||
|
|
|
|||
|
|
@ -585,7 +585,7 @@ def test_submit_invalid_api_key(
|
|||
def test_slug_from_email(
|
||||
mock_gcid, mock_secret, mock_settings, mock_week, mock_status, mock_put, mock_lam
|
||||
):
|
||||
"""'Adam.Moussa@seahavenind.com' -> slug 'adam-moussa'."""
|
||||
"""'Adam.Moussa@seahavenind.com' -> slug 'adam.moussa@seahavenind.com'."""
|
||||
from submit_order_handler import lambda_handler
|
||||
|
||||
items = _make_items([(10.00, 1)])
|
||||
|
|
@ -597,7 +597,7 @@ def test_slug_from_email(
|
|||
|
||||
# put_order is called with (week, slug, order_data)
|
||||
slug = mock_put.call_args[0][1]
|
||||
assert slug == "adam-moussa", f"Slug should be 'adam-moussa', got '{slug}'"
|
||||
assert slug == "adam.moussa@seahavenind.com", f"Slug should be 'adam.moussa@seahavenind.com', got '{slug}'"
|
||||
|
||||
|
||||
@patch("submit_order_handler._lambda")
|
||||
|
|
@ -610,26 +610,27 @@ def test_slug_from_email(
|
|||
def test_slug_edge_cases(
|
||||
mock_gcid, mock_secret, mock_settings, mock_week, mock_status, mock_put, mock_lam
|
||||
):
|
||||
"""Slug edge cases: multiple dots, already-hyphenated."""
|
||||
"""Slug uses full lowercase email, preserving uniqueness across domains."""
|
||||
from submit_order_handler import lambda_handler
|
||||
|
||||
# Test 1: "first.middle.last@x.com" -> "first-middle-last"
|
||||
# Test 1: full email preserved
|
||||
items = _make_items([(10.00, 1)])
|
||||
event = _submit_event(items, employee_name="First Middle Last", employee_email="first.middle.last@x.com")
|
||||
event = _submit_event(items, employee_name="First Middle Last", employee_email="First.Middle.Last@x.com")
|
||||
lambda_handler(event, None)
|
||||
slug_1 = mock_put.call_args[0][1]
|
||||
assert slug_1 == "first-middle-last", (
|
||||
f"Slug for 'first.middle.last@x.com' should be 'first-middle-last', got '{slug_1}'"
|
||||
assert slug_1 == "first.middle.last@x.com", (
|
||||
f"Slug should be full lowercase email, got '{slug_1}'"
|
||||
)
|
||||
|
||||
# Test 2: "already-hyphenated@x.com" -> "already-hyphenated"
|
||||
# Test 2: different domains produce different slugs (no collision)
|
||||
mock_put.reset_mock()
|
||||
event = _submit_event(items, employee_name="Already Hyphenated", employee_email="already-hyphenated@x.com")
|
||||
event = _submit_event(items, employee_name="Bob Smith", employee_email="Bob@other.com")
|
||||
lambda_handler(event, None)
|
||||
slug_2 = mock_put.call_args[0][1]
|
||||
assert slug_2 == "already-hyphenated", (
|
||||
f"Slug for 'already-hyphenated@x.com' should be 'already-hyphenated', got '{slug_2}'"
|
||||
assert slug_2 == "bob@other.com", (
|
||||
f"Slug should be full lowercase email, got '{slug_2}'"
|
||||
)
|
||||
assert slug_1 != slug_2, "Different emails must produce different slugs"
|
||||
|
||||
|
||||
# ===========================================================================
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue