Skip to content

hardening(server): validate owner_token is a UUID at ParseScheduledEvent boundary #1524

Description

@cristim

Context

Surfaced while completing #261 (PR #1516). Deferred out of #1516 to let that PR converge; the change is written but held (not merged into the feature branch).

Idea

ParseScheduledEvent (internal/server/handler.go) should reject a non-empty owner_token that is not a valid UUID, failing loud. asyncInvokeSelf only ever sends uuid.New(), so a non-UUID token is a corrupt/forged payload; validating at the boundary turns it into an explicit error instead of relying on the downstream uuid-cast in the token-guarded clear/mark SQL (which already fails loud at the DB layer, so this is defense-in-depth, not a correctness gap).

Scope

  • Boundary validation in ParseScheduledEvent: non-empty token must parse as UUID, else error.
  • Tests: malformed / empty / valid token, plus an end-to-end assertion that a valid token reaches CollectRecommendations.

Small, self-contained; can land as its own PR with the standard plan -> implement -> review gate.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions