enhance(email): improve detection of allowed Gusto URLs in email classification

Resolves code scanning alert #2
This commit is contained in:
Adam Moussa 2026-07-23 16:18:53 -04:00
parent 2a98bd51bb
commit 0f8ade37b4
No known key found for this signature in database

View file

@ -36,6 +36,24 @@ const formatCurrency = (v) =>
currency: "USD",
}).format(Number(v || 0));
function isAllowedGustoHost(hostname) {
const h = (hostname || "").toLowerCase();
return h === "gusto.com" || h.endsWith(".gusto.com");
}
function bodyMentionsAllowedGustoUrl(text) {
const urlMatches = (text || "").match(/\bhttps?:\/\/[^\s<>"')]+/gi) || [];
for (const rawUrl of urlMatches) {
try {
const parsed = new URL(rawUrl);
if (isAllowedGustoHost(parsed.hostname)) return true;
} catch {
// Ignore malformed URLs in email text.
}
}
return false;
}
function classifyEmail(from, subject, text) {
const fromAddr = (from?.text || from || "").toLowerCase();
const subj = (subject || "").toLowerCase();
@ -54,8 +72,7 @@ function classifyEmail(from, subject, text) {
}
const strippedSubj = subj.replace(/^fwd?:\s*/i, "");
const body = (text || "").toLowerCase();
const bodyMentionsGusto = body.includes("gusto.com");
const bodyMentionsGusto = bodyMentionsAllowedGustoUrl(text || "");
if (bodyMentionsGusto && strippedSubj.includes("payroll confirmation")) {
return "employee";