Skip to content

fix: encode payment path identifiers - #1

Open
ElaineWorkspaceEcosystem wants to merge 1 commit into
AlfinAI:mainfrom
ElaineWorkspaceEcosystem:elaineworkspaceecosystem-payment-handler
Open

ElaineWorkspaceEcosystem wants to merge 1 commit into
AlfinAI:mainfrom
ElaineWorkspaceEcosystem:elaineworkspaceecosystem-payment-handler

Conversation

@ElaineWorkspaceEcosystem

Copy link
Copy Markdown

What

fix: URL-encode merchant, deal, and order identifiers in payment paths to prevent path traversal or malformed endpoint URLs.

Verification

  • New/changed behavior is covered by offline tests (pytest stays green, coverage ≥ 80%)
  • ruff check + ruff format --check + mypy src pass
  • Endpoint/behavior claims cite evidence (traffic, smali, or upstream commit); otherwise marked BELUM TERVERIFIKASI + TODO
  • No credentials, tokens, or device IDs committed (see .gitignore)
  • CHANGELOG.md updated (for user-facing changes)

Validation: full test suite passes with 100% coverage; Ruff and mypy pass for the payment service.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant