mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 09:33:15 +00:00
The PO and WO email processors acted on email from any sender — the public addresses (amazon_po@, apm@) accept mail from anyone, so an attacker could forge POs/WOs. Reject email whose verified sender domain is not on a configurable allowlist (ALLOWED_SENDER_DOMAINS), and drop messages with an explicit SES SPF/DKIM/spam/virus failure. Also remove the silent fallback to a plaintext ANTHROPIC_API_KEY env var; require ANTHROPIC_API_KEY_SECRET_ARN and raise if absent so a misconfigured deploy fails loudly instead of using an unmanaged key. |
||
|---|---|---|
| .. | ||
| po | ||
| wo | ||