meal-order-manager/functions
Adam Moussa 311eab35c0
fix(auth): require Google authentication in cloud mode (#90)
* fix(auth): require Google authentication in cloud mode

Remove the public shared-key mechanism and fail closed on Google auth while adding submit-route throttling.

* fix(auth): address review follow-ups

Fail closed on whitespace-only Google configuration and centralize shared authentication behavior.

* test(auth): use non-secret Google client fixture

Make the public test identifier explicit so secret scanning does not misclassify it as an API key.

* test(auth): avoid OAuth-shaped fixture

Use a format-neutral audience value so secret scanning can distinguish the fixture from a real client identifier.

* chore(security): suppress public OAuth fixture

Document the scanner false positive without suppressing any runtime credential flow.
2026-08-03 13:51:12 -04:00
..
admin_authorizer chore(deps): bump boto3 (#99) 2026-08-03 13:28:21 -04:00
aggregate_orders chore(deps): bump boto3 (#97) 2026-08-03 13:26:26 -04:00
close_form chore(deps): bump boto3 (#100) 2026-08-03 13:34:16 -04:00
email_report chore(deps): bump boto3 (#101) 2026-08-03 13:39:39 -04:00
slack_notifier chore(deps): bump boto3 (#102) 2026-08-03 13:39:40 -04:00
submit_order fix(auth): require Google authentication in cloud mode (#90) 2026-08-03 13:51:12 -04:00
sync_roster Fix ruff lint and format violations, update README (#5) 2026-05-12 19:31:27 -04:00