Repository navigation
Conversation
|
@sandyhash Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
|
Thanks for the contribution! We reviewed this PR while merging the open queue and couldn't merge it yet. Here's what needs fixing:
Once these are fixed, push to this branch and we'll take another look. |
447b5e2 to
b58bcac
Compare
|
@greatest0fallt1me — thanks for the review. I rebased this branch onto the latest
The diff is now 5 files, +75/−10, with no deletions. Please take another look when you have a moment. |
BillingService.getByRequestId now filters by user_id in SQL so a request id resolves only for its owner; both lookup routes pass the authenticated user id and non-owned ids return the same 404 as missing ones. Restores the deleted billing test suites and adds owner-scoping coverage that actually runs.
|
@greatest0fallt1me Thanks for the review — both points are addressed on the current head:
Verified locally on this branch head with Node 20:
Please take another look. |
Overview
This PR scopes billing request lookups to the requesting user. Previously
GET /api/billing/deduct/request/:requestIdreturnedusageEventId,stellarTxHash, andstatusfor anyrequestId, regardless of owner, becauseBillingService.getByRequestIddid not filter byuser_id. Since request ids are often predictable (UUIDs logged by clients or proxies), any user could enumerate other users' charges and transaction hashes. The lookup now filters byuser_idin SQL and surfaces a 404 for non-owned rows to avoid existence leaks.Related Issue
Changes
🔒 Owner-Scoped Billing Lookups
[MODIFY]
src/services/billing.tsgetByRequestIdnow accepts auserIdparameter and filters withWHERE request_id = $1 AND user_id = $2, so ownership is enforced in SQL rather than in JS.[MODIFY]
src/routes/billing/deduct.tsgetByRequestIdand returns 404 when the record is not owned by the caller.✅ Tests
[MODIFY]
src/routes/billing/deduct.test.ts[MODIFY]
src/services/billing.test.tsgetByRequestIdfiltering byuser_id, including owned and non-owned cases.[MODIFY]
src/__tests__/billing-credits.test.ts,src/__tests__/billing-index.test.ts,src/__tests__/billingDeductMetrics.test.tsuserIdparameter and owner-scoped behavior.Verification Results
WHERE request_id = $1 AND user_id = $2ingetByRequestIddeduct.test.tsandbilling.test.tsSecurity and Failure Modes
requestIdyields no row and the route responds 404 — the same response as a missing id, avoiding existence leaks.Closes #1253