Repository navigation
Conversation
An inquiry is quoted by a number of the same shape as an order's: a prefix, the date and eight characters of Crockford's alphabet. The generator moves out of the order code so that both use it, with a test of the shape it makes and of how one is recognised under its own prefix.
Phase 1's last piece, which the owner decided is the shop plugin's to build (design §11, decision 10). A form on the cart page takes who to answer and a message, and posts to cart/inquiry. The route stores the cart as an inquiry with its lines as a snapshot, queues the job that owes its emails, and empties the cart, in one batch; it answers with a redirect to the cart page, which shows the inquiry's number to the browser whose cart it was. A part with no price can be asked about, so a product page now offers a form for a size without one. The write is conditional on the cart still having lines and on the visitor being under five inquiries an hour, both asked inside the statement, so two forms at once store one inquiry and a refused one leaves the cart alone. The seller is told by email, answerable to the buyer, and reads inquiries in a panel of the admin: to mark, export as CSV, or delete. The email confirming to the buyer is built and off by default, because the form has no challenge in front of it: Mallok has nowhere to draw one on a plugin's page.
The design gains the owner's decision and §18. The security notes say what personal data an inquiry holds, what stands in place of a challenge, and what that does not stop.
…ependent review found The review found the guards inside the inquiry's write sound, and these around them: - A cart that changed between being read and being written lost the change: a part added in between was in neither the inquiry nor the cart. The write is now conditional on the cart being exactly what is sent, and a cart that changed is answered with cart_changed and left alone. - An address could carry a mailto link's own syntax, which the admin links as stored. It is held to a list of what an address may be made of. - A browser let through what the server refused, and the form came back empty: a name of spaces, a tab in a name, a message whose line breaks the field counted once. The name has a pattern, white space in a one-line field becomes one space, a line break is counted once. - A semicolon let a formula through the CSV export where it is the list separator. Every piece that could begin a cell is made text. - A request with no mark of its visitor was not limited. They are counted together, as Mallok's own rate limit counts them. - A cart refused for the limit inside the write could be told it was sent. - The export scanned every line for every inquiry. And the tests of the two races proved less than they claimed: Promise.all interleaves two requests about half the time here, and the other half never reaches the guard. They now hold both requests at the write (holdWrites), and each guard, broken, is red every time.
An email handed to Mallok keeps what a buyer typed in Mallok's own queue, where deleting the inquiry does not reach it. The security notes, the guidance file and the design said otherwise; they say what is true now, with what an operator has to do about it. The design gains what the independent review of the inquiry cart found and what changed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this is
Phase 1's last piece: the cart, sent as one request for a quote. The owner decided it is the shop plugin's to build (design §11, decision 10; what was built and found is §18).
How it works, in short
POST cart/inquirynever renders: it answers 303 to the cart page with the inquiry's number, or the kind of reason none was made. Nothing a person typed travels in an address.SECURITY.md. Because of it the email confirming to the buyer is built and off by default.An independent review, and what it found
The finished work was given to a second reviewer with the properties it must hold and no account of how. It found the guards sound and eleven things wrong around them; each was checked before it was acted on. The ones that mattered most:
Promise.allinterleave about half the time in this harness; the other half never reaches the guard inside the write. They now hold both requests at the write, and each guard, broken, is red every time.mailto:link's own syntax, which the admin links as stored.How it was verified
Not verified