procurement-ingest/cdk
Adam Moussa e97e740c5a Gate web UIs behind auth and escape currency XSS
The po-web-ui and workorder-web-ui handlers had no auth: any
invocation path returned the full PO/WO DB. Add a fail-closed
shared-secret gate (X-Auth-Token / Bearer, constant-time compared to
WEB_UI_AUTH_TOKEN) so a future re-attached Function URL cannot
re-expose the data (URLs removed under INFRA-74). Wire the token from
the SSM String param /procurement-ingest/web-ui-auth-token.

Also fix stored XSS in po-web-ui fmt_currency: the non-numeric
fallback returned str(val) unescaped, so a prompt-injected email
could make Claude emit total_amount as <script>. Escape it.

Refs: INFRA-74
2026-06-17 11:37:49 -04:00
..
app.py Merge workorder-ingest into unified procurement repo (#22) 2026-05-12 15:21:06 -04:00
cdk.json Initial commit: PO email ingestion pipeline 2026-04-07 12:12:30 -04:00
po_stack.py Gate web UIs behind auth and escape currency XSS 2026-06-17 11:37:49 -04:00
requirements.txt Bump aws-cdk-lib in /cdk in the minor-and-patch group across 1 directory (#65) 2026-06-16 20:57:49 +00:00
wo_stack.py Gate web UIs behind auth and escape currency XSS 2026-06-17 11:37:49 -04:00