Skip to content

bug(purchases): token-path cancel allows cancelling running/approved/paused executions with no in-flight guard (session path is stricter) #645

Description

@cristim

Asymmetric + unsafe cancel: loadCancelableExecution (internal/purchase/approvals.go:191-193, token/email path) only rejects completed/cancelled, so it ALLOWS cancelling running/approved/paused/failed/expired. The session path cancelPurchaseViaSession (handler_purchases.go:512-514) rejects everything except pending/notified. So an email-link holder can cancel an in-flight/approved execution that the dashboard user cannot, and there's no guard that the AWS purchase isn't already mid-flight (cancelling a row whose commitment is being created leaves DB and cloud out of sync).

Fix: align the token path with the session path (only pending/notified cancelable), and add an explicit guard against cancelling a row that is mid-execution. Tests for both paths.

Dedup: not #621/#632. No existing issue. New. Surfaced in the purchase-workflow trace.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions