procurement-ingest/lambdas
Adam Moussa f175323939 Validate sender and require Secrets Manager key
The PO and WO email processors acted on email from any sender — the
public addresses (amazon_po@, apm@) accept mail from anyone, so an
attacker could forge POs/WOs. Reject email whose verified sender
domain is not on a configurable allowlist (ALLOWED_SENDER_DOMAINS),
and drop messages with an explicit SES SPF/DKIM/spam/virus failure.

Also remove the silent fallback to a plaintext ANTHROPIC_API_KEY env
var; require ANTHROPIC_API_KEY_SECRET_ARN and raise if absent so a
misconfigured deploy fails loudly instead of using an unmanaged key.
2026-06-17 11:37:29 -04:00
..
po Validate sender and require Secrets Manager key 2026-06-17 11:37:29 -04:00
wo Validate sender and require Secrets Manager key 2026-06-17 11:37:29 -04:00