Skip to content

Validate JSON requests and protect email preview source records - #1

Closed
katalinawinemixer wants to merge 1 commit into
mainfrom
codex/repository-review-20261004
Closed

katalinawinemixer wants to merge 1 commit into
mainfrom
codex/repository-review-20261004

Conversation

@katalinawinemixer

Copy link
Copy Markdown
Owner

Non-object JSON bodies could produce handler errors, and email payload fields could replace records already resolved from stored IDs. Share JSON-object validation between Node and Worker handlers, return HTTP 400 for malformed or non-object bodies, and place trusted source records after payload fields in both API paths and the frontend fallback. Add HTTP regressions and CI, patch compatible frontend dependencies, and declare the frontend package as an ES module.

Validation: 16 backend tests against a temporary synthetic data store, frontend production build, 6 smoke checks against the bundled Worker with synthetic KV, workflow YAML validation, and git diff --check. Worker checks cover bad JSON, protected source records, and read-only write blocking. No production data was changed.

Remaining issue: frontend npm audit reports 2 moderate package findings in the React Router 6 chain. npm proposes a major upgrade to resolve them; that route migration is outside this compatible patch. The app remains a synthetic demo without production authentication.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying studychaser with  Cloudflare Pages  Cloudflare Pages

Latest commit: 0c8f896
Status:⚡️  Build in progress...

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant