procurement-ingest/tests
seahaven-openswe[bot] 11bf0f5d12
Some checks are pending
Deploy / deploy (push) Waiting to run
fix(ses_auth): harden comment stripping and alarm evaluation window (#103)
SES-AR-01: treat ")" at depth 0 as an unmatched close, rejecting the
value as not well-formed so a ")(...)" pair cannot manufacture a depth-0
gap where a smuggled dkim=pass clause gets parsed.

SES-AR-02: emit a space when a comment is removed so comments act as
CFWS folding whitespace (RFC 5322). Without this, "dk(z)im=pass" would
become "dkim=pass" and an attacker comment could glue unrelated tokens.

Alarm: widen evaluation_periods from 3→6 (30-min window) with
datapoints_to_alarm still at 2, closing the sparse-outage residual where
rejections >10-15 min apart fail to place breaching datapoints in 2 of 3
consecutive periods.

Both ses_auth.py copies stay byte-identical. All 86 tests pass.

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-07-16 19:00:40 +00:00
..
conftest.py feat: template-first WO parser + Bedrock fallback, PO Bedrock switch (#99) 2026-07-16 12:45:11 -04:00
requirements.txt Land safe fixes from 2026-06-17 security sweep (#97) 2026-07-15 20:17:46 -04:00
test_pad_zip.py Add pytest suite and enable tests in CI (#95) 2026-07-15 19:06:20 -04:00
test_parse_raw_email.py Add pytest suite and enable tests in CI (#95) 2026-07-15 19:06:20 -04:00
test_po_merge.py Land safe fixes from 2026-06-17 security sweep (#97) 2026-07-15 20:17:46 -04:00
test_ses_auth.py fix(ses_auth): harden comment stripping and alarm evaluation window (#103) 2026-07-16 19:00:40 +00:00