Repository navigation
Validate JSON requests and protect email preview source records - #1
Closed
katalinawinemixer wants to merge 1 commit into
Closed
katalinawinemixer wants to merge 1 commit into
katalinawinemixer wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Non-object JSON bodies could produce handler errors, and email payload fields could replace records already resolved from stored IDs. Share JSON-object validation between Node and Worker handlers, return HTTP 400 for malformed or non-object bodies, and place trusted source records after payload fields in both API paths and the frontend fallback. Add HTTP regressions and CI, patch compatible frontend dependencies, and declare the frontend package as an ES module.
Validation: 16 backend tests against a temporary synthetic data store, frontend production build, 6 smoke checks against the bundled Worker with synthetic KV, workflow YAML validation, and
git diff --check. Worker checks cover bad JSON, protected source records, and read-only write blocking. No production data was changed.Remaining issue: frontend npm audit reports 2 moderate package findings in the React Router 6 chain. npm proposes a major upgrade to resolve them; that route migration is outside this compatible patch. The app remains a synthetic demo without production authentication.