Repository navigation
sec(purchases): remove token from scheduled purchase email query-string links - #581
Conversation
…ng links (closes #406) scheduledPurchaseTemplate embedded the approval token in all three action links (Review & Edit, Pause Plan, Cancel) as dashboard SPA query-string parameters. This caused the token to appear in browser history, CloudFront access logs, and Referer headers sent to any analytics / font / tracking resource loaded by the SPA. Changes: - Review & Edit and Pause Plan links now point at the dashboard root with no token. These actions require an authenticated session; the user logs in through the normal flow and takes action from there. - Cancel This Purchase link now uses the direct API path pattern from the companion purchaseApprovalRequestTemplate: /purchases/cancel/<executionID>?token=<token> This goes to the API endpoint rather than the SPA, so no third-party scripts load with the token in the Referer header. - buildNotificationData now sets ExecutionID on NotificationData so the cancel link can render the execution ID (was missing before). - Three test files updated to match the new template shape: template_renderers_test.go, coverage_test.go (existing assertions), and templates_test.go (new regression test explicitly asserting the token does not appear on review/pause lines).
|
Warning Review limit reached
More reviews will be available in 59 minutes and 53 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (9)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai full review |
✅ Actions performedFull review triggered. |
|
@coderabbitai full review |
✅ Actions performedFull review triggered. |
…chase URLs (refs #406) Follow-up to #581: PR #581 stripped the approval token from the Review & Edit and Pause Plan links to fix the token-leak in #406, but degraded UX by dropping the user at the dashboard root. They had to hunt for the specific execution they were notified about. Re-introduce a safe deeplink: the URLs now carry the ExecutionID (Review & Edit) and PlanID (Pause Plan). Both are UUIDs - not sensitive on their own; the user still authenticates via the normal session cookie, and the SPA scrolls to / highlights the matching row. Changes: - scheduledPurchaseTemplate Review & Edit now points at /purchases#history?execution=<id>, which the existing applyExecutionDeepLink handler in history.ts picks up and uses to scroll + highlight the matching row in the Purchase History table / Approval queue card. - Pause Plan now points at /plans?plan=<plan-id>. The Plans tab deeplink handler is filed as a separate follow-up; for now the user lands on the right tab and can act on the row manually. - NotificationData gains a PlanID field, populated from plan.ID in buildNotificationData. - Regression test extended: assert the new deeplink shapes are present AND the token is still NOT embedded in the Review / Pause lines (the #406 guard).
…ecution deeplinks The scheduled-purchase email's Review & Edit link (#581 follow-up) and the Recommendations suppression badge both deeplink to #history?execution=<id>. The applyExecutionDeepLink handler already scrolled + added a `history-row-highlight` class to the matching row, but two gaps showed up while wiring the email deeplink: 1. The .history-row-highlight CSS class was referenced but never defined - the row got tagged but the user saw no visual feedback. Add a yellow tint with a brief flash animation; the existing 4- second `classList.remove` in history.ts fades it cleanly. Also override the table-wide tr:hover so the highlight persists while the user mouses over the row. 2. When the deeplink target wasn't in the rendered list (e.g. the user's date filter excludes it), the handler returned silently and the user was left wondering why the page didn't jump. Show a non-blocking info toast pointing at the filter, and strip the ?execution= param from the hash so a subsequent re-render doesn't re-fire the same toast on every state change. Also exports `applyExecutionDeepLink` (unit-test coverage) and adds four new tests: - no-op when no execution id in hash; - success path scrolls, highlights, schedules fade-out; - miss path emits info toast + clears the hash; - CSS.escape neutralises selector-metacharacter exec IDs.
|
Added execution + plan deeplinks so the Review & Edit and Pause Plan buttons land users on the specific row they were notified about, instead of the dashboard root. URL shape (no token — only non-sensitive UUIDs):
Authentication unchanged — the user still authenticates via the normal session cookie. If logged out, the existing login flow's Frontend gaps fixed at the same time:
Tests:
@coderabbitai review |
|
✅ Actions performedReview triggered.
|
|
@coderabbitai full review |
✅ Actions performedFull review triggered. |
Summary
scheduledPurchaseTemplateininternal/email/templates.goto stop embedding the approval token in Review & Edit and Pause Plan URLs (closes sec: scheduledPurchaseTemplate embeds token in dashboard query-string link (not in direct API call) #406)/purchases/cancel/<executionID>?token=<token>(same pattern aspurchaseApprovalRequestTemplate), avoiding SPA load with token in Referer headerbuildNotificationDataininternal/purchase/notifications.gonow setsExecutionIDon the notification data (was missing, needed for the cancel link)templates_test.goasserts token does not appear on review/pause lines; updatedtemplate_renderers_test.goandcoverage_test.goto match new template shapeCloses #406