mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-09-30 06:33:11 +00:00
enhance(email): improve detection of allowed Gusto URLs in email classification
Resolves code scanning alert #2
This commit is contained in:
parent
2a98bd51bb
commit
0f8ade37b4
1 changed files with 19 additions and 2 deletions
|
|
@ -36,6 +36,24 @@ const formatCurrency = (v) =>
|
|||
currency: "USD",
|
||||
}).format(Number(v || 0));
|
||||
|
||||
function isAllowedGustoHost(hostname) {
|
||||
const h = (hostname || "").toLowerCase();
|
||||
return h === "gusto.com" || h.endsWith(".gusto.com");
|
||||
}
|
||||
|
||||
function bodyMentionsAllowedGustoUrl(text) {
|
||||
const urlMatches = (text || "").match(/\bhttps?:\/\/[^\s<>"')]+/gi) || [];
|
||||
for (const rawUrl of urlMatches) {
|
||||
try {
|
||||
const parsed = new URL(rawUrl);
|
||||
if (isAllowedGustoHost(parsed.hostname)) return true;
|
||||
} catch {
|
||||
// Ignore malformed URLs in email text.
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
function classifyEmail(from, subject, text) {
|
||||
const fromAddr = (from?.text || from || "").toLowerCase();
|
||||
const subj = (subject || "").toLowerCase();
|
||||
|
|
@ -54,8 +72,7 @@ function classifyEmail(from, subject, text) {
|
|||
}
|
||||
|
||||
const strippedSubj = subj.replace(/^fwd?:\s*/i, "");
|
||||
const body = (text || "").toLowerCase();
|
||||
const bodyMentionsGusto = body.includes("gusto.com");
|
||||
const bodyMentionsGusto = bodyMentionsAllowedGustoUrl(text || "");
|
||||
|
||||
if (bodyMentionsGusto && strippedSubj.includes("payroll confirmation")) {
|
||||
return "employee";
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue