Skip to content

Take the shopper's identity only from the envelope, and state the headers once - #591

Merged
field123 merged 3 commits into
masterfrom
fix/533-shopper-envelope-only
Sep 25, 2026
Merged

field123 merged 3 commits into
masterfrom
fix/533-shopper-envelope-only

Conversation

@field123

Copy link
Copy Markdown
Collaborator

Closes #533.

Two corrections that have to land before any call site moves to the server
surface, because without them the move changes behaviour nobody asked to
change.

One place says what headers a shopper call carries. The multi-location
inventory header was written out at each of the three call sites, which is how
buildEpClient came to be missing it. epShopperHeaders is now the single
statement, used by the browser client, the server client builder and the cart
routes. The cart routes apply it after the caller's own headers instead of
before, so neither it nor the account credential can be overridden per call.
No caller passes either today, so nothing changes.

Identity comes only from the envelope. Eleven read inputs carried an
optional auth field that nothing set and nothing advertised. The proxy route
forwards the browser's JSON body verbatim, so it was a way to name your own
credentials, held shut only by getCurrentEpSession() happening to be
evaluated before ?? inputAuth. Nothing typed that order and no test asserted
it. The field is gone, so the property holds by construction. The two tests
that asserted the ordering are deleted rather than rewritten.

EpGetCartInput goes with it: epGetCart takes no argument, so the type had
nothing left to name. That is a removed export, which gates at the release.

Not in this PR

#587 was going to ride along, but the missing placeOrder dispatch entry turns
out to be deliberate rather than an oversight, recorded in KNOWN_UNWIRED in
the proxy parity test. Wiring it as-is is not safe, so that issue has been
rewritten as a decision to take rather than a patch to apply.

…ion, not three strings

The multi-location header was spelled out at each of the three call sites, and
that is how one of them came to be missing it. epShopperHeaders is the single
place that says what a shopper-facing call carries.

The cart routes now apply it after the caller's own headers rather than before,
so neither the header nor the account credential can be overridden per call. No
caller passes either today, so behaviour is unchanged.
… envelope

Eleven read inputs carried an optional auth field that nothing set and nothing
advertised. The proxy route forwards the browser's JSON body verbatim into the
target function, so a caller could have named their own credentials; only the
order of two lines kept that shut, and nothing typed or tested that order.

Deleting the field removes the hazard by construction. EpGetCartInput goes with
it, since getCart now takes no argument.

Closes #533
@field123
field123 merged commit a0771ae into master Sep 25, 2026
9 checks passed
@field123
field123 deleted the fix/533-shopper-envelope-only branch September 25, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set EP-Inventories-Multi-Location server-side and delete the inert auth? inputs

1 participant