Context
Surfaced while completing #261 (PR #1516). Deferred out of #1516 to let that PR converge; the change is written but held (not merged into the feature branch).
Idea
ParseScheduledEvent (internal/server/handler.go) should reject a non-empty owner_token that is not a valid UUID, failing loud. asyncInvokeSelf only ever sends uuid.New(), so a non-UUID token is a corrupt/forged payload; validating at the boundary turns it into an explicit error instead of relying on the downstream uuid-cast in the token-guarded clear/mark SQL (which already fails loud at the DB layer, so this is defense-in-depth, not a correctness gap).
Scope
- Boundary validation in ParseScheduledEvent: non-empty token must parse as UUID, else error.
- Tests: malformed / empty / valid token, plus an end-to-end assertion that a valid token reaches CollectRecommendations.
Small, self-contained; can land as its own PR with the standard plan -> implement -> review gate.
Context
Surfaced while completing #261 (PR #1516). Deferred out of #1516 to let that PR converge; the change is written but held (not merged into the feature branch).
Idea
ParseScheduledEvent(internal/server/handler.go) should reject a non-emptyowner_tokenthat is not a valid UUID, failing loud.asyncInvokeSelfonly ever sendsuuid.New(), so a non-UUID token is a corrupt/forged payload; validating at the boundary turns it into an explicit error instead of relying on the downstream uuid-cast in the token-guarded clear/mark SQL (which already fails loud at the DB layer, so this is defense-in-depth, not a correctness gap).Scope
Small, self-contained; can land as its own PR with the standard plan -> implement -> review gate.