mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-07 13:58:54 +00:00
Harden Flask dev server auth and escaping
- Add hosted domain check to _verify_google_token (mirror Lambda) - Gate auth on config (client_id presence), not request body — prevents bypass by omitting google_id_token when auth is configured - Add discount percentage clamping to match Lambda handler - Add </script> escaping to google_client_id_json
This commit is contained in:
parent
5db992b0be
commit
fa9ac6974e
2 changed files with 10 additions and 3 deletions
|
|
@ -90,6 +90,8 @@ def _verify_google_token(token: str, client_id: str) -> dict | None:
|
||||||
data = json.loads(resp.read())
|
data = json.loads(resp.read())
|
||||||
if data.get("aud") != client_id:
|
if data.get("aud") != client_id:
|
||||||
return None
|
return None
|
||||||
|
if data.get("hd") != "seahavenind.com":
|
||||||
|
return None
|
||||||
return {"name": data.get("name", ""), "email": data.get("email", "")}
|
return {"name": data.get("name", ""), "email": data.get("email", "")}
|
||||||
except Exception:
|
except Exception:
|
||||||
return None
|
return None
|
||||||
|
|
@ -101,9 +103,12 @@ def submit_order():
|
||||||
if not data:
|
if not data:
|
||||||
return jsonify({"error": "No data received"}), 400
|
return jsonify({"error": "No data received"}), 400
|
||||||
|
|
||||||
|
client_id = _get_google_client_id()
|
||||||
google_token = data.get("google_id_token")
|
google_token = data.get("google_id_token")
|
||||||
if google_token:
|
|
||||||
client_id = _get_google_client_id()
|
if client_id:
|
||||||
|
if not google_token:
|
||||||
|
return jsonify({"error": "Google authentication is required"}), 403
|
||||||
user_info = _verify_google_token(google_token, client_id)
|
user_info = _verify_google_token(google_token, client_id)
|
||||||
if not user_info:
|
if not user_info:
|
||||||
return jsonify({"error": "Invalid or unauthorized Google account"}), 403
|
return jsonify({"error": "Invalid or unauthorized Google account"}), 403
|
||||||
|
|
@ -126,6 +131,8 @@ def submit_order():
|
||||||
TWO_PLACES = Decimal("0.01")
|
TWO_PLACES = Decimal("0.01")
|
||||||
bulk_pct = Decimal(str(config.get("bulk_discount_percent", 0)))
|
bulk_pct = Decimal(str(config.get("bulk_discount_percent", 0)))
|
||||||
subsidy_pct = Decimal(str(config.get("company_subsidy_percent", 0)))
|
subsidy_pct = Decimal(str(config.get("company_subsidy_percent", 0)))
|
||||||
|
bulk_pct = max(Decimal("0"), min(Decimal("100"), bulk_pct))
|
||||||
|
subsidy_pct = max(Decimal("0"), min(Decimal("100"), subsidy_pct))
|
||||||
bulk_mult = Decimal("1") - (bulk_pct / Decimal("100"))
|
bulk_mult = Decimal("1") - (bulk_pct / Decimal("100"))
|
||||||
subsidy_mult = Decimal("1") - (subsidy_pct / Decimal("100"))
|
subsidy_mult = Decimal("1") - (subsidy_pct / Decimal("100"))
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -56,7 +56,7 @@ def generate_form(
|
||||||
api_key_json = json.dumps(api_key).replace("</", "<\\/")
|
api_key_json = json.dumps(api_key).replace("</", "<\\/")
|
||||||
has_discount = bulk_discount > 0 or company_subsidy > 0
|
has_discount = bulk_discount > 0 or company_subsidy > 0
|
||||||
use_google_auth = bool(google_client_id)
|
use_google_auth = bool(google_client_id)
|
||||||
google_client_id_json = json.dumps(google_client_id)
|
google_client_id_json = json.dumps(google_client_id).replace("</", "<\\/")
|
||||||
|
|
||||||
if use_google_auth:
|
if use_google_auth:
|
||||||
auth_section_html = """ <div class="employee-info">
|
auth_section_html = """ <div class="employee-info">
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue