Take the shopper's identity only from the envelope, and state the headers once - #591
Merged
Merged
Conversation
…ion, not three strings The multi-location header was spelled out at each of the three call sites, and that is how one of them came to be missing it. epShopperHeaders is the single place that says what a shopper-facing call carries. The cart routes now apply it after the caller's own headers rather than before, so neither the header nor the account credential can be overridden per call. No caller passes either today, so behaviour is unchanged.
… envelope Eleven read inputs carried an optional auth field that nothing set and nothing advertised. The proxy route forwards the browser's JSON body verbatim into the target function, so a caller could have named their own credentials; only the order of two lines kept that shut, and nothing typed or tested that order. Deleting the field removes the hazard by construction. EpGetCartInput goes with it, since getCart now takes no argument. Closes #533
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #533.
Two corrections that have to land before any call site moves to the server
surface, because without them the move changes behaviour nobody asked to
change.
One place says what headers a shopper call carries. The multi-location
inventory header was written out at each of the three call sites, which is how
buildEpClientcame to be missing it.epShopperHeadersis now the singlestatement, used by the browser client, the server client builder and the cart
routes. The cart routes apply it after the caller's own headers instead of
before, so neither it nor the account credential can be overridden per call.
No caller passes either today, so nothing changes.
Identity comes only from the envelope. Eleven read inputs carried an
optional
authfield that nothing set and nothing advertised. The proxy routeforwards the browser's JSON body verbatim, so it was a way to name your own
credentials, held shut only by
getCurrentEpSession()happening to beevaluated before
?? inputAuth. Nothing typed that order and no test assertedit. The field is gone, so the property holds by construction. The two tests
that asserted the ordering are deleted rather than rewritten.
EpGetCartInputgoes with it:epGetCarttakes no argument, so the type hadnothing left to name. That is a removed export, which gates at the release.
Not in this PR
#587 was going to ride along, but the missing
placeOrderdispatch entry turnsout to be deliberate rather than an oversight, recorded in
KNOWN_UNWIREDinthe proxy parity test. Wiring it as-is is not safe, so that issue has been
rewritten as a decision to take rather than a patch to apply.