Skip to content

bug(api/purchases): capacity_percent is decorative and can silently disagree with the actual rec counts #647

Description

@cristim

The frontend scales rec counts client-side then sends capacity_percent as an audit-only field (frontend/src/recommendations.ts:3113-3124, app.ts:340-352); the backend explicitly ignores it for math (handler_purchases.go:1044-1048). Because the backend never cross-checks that the scaled counts match the recorded percent, the audit record can claim e.g. "50% capacity" while the recs sum to 100%. The audit trail for a financial action can be wrong.

Fix: either validate that capacity_percent is consistent with the summed counts at submit time (reject/warn on mismatch), or derive it server-side from the counts rather than trusting the client value.

Dedup: no existing issue. New. Surfaced in the purchase-workflow trace.

Activity

  1. cristim commented on May 22, 2026

    @cristim
    MemberAuthor

    Fixed in PR #655 (merged into feat/multicloud-web-frontend on 2026-05-22). Closing manually since GitHub does not auto-close on non-default-branch merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions