Pre-deploy security/correctness fixes (port log E17)
- Remove dead kitchen->KDS internal API (api/internal.py, verify_internal_secret) — KDS reads kitchen_db directly (E16), nothing ever called this endpoint - Add expires_at to dispute_attachments; public attachment links now expire after 30 days instead of staying valid forever (A4) - Add services/upload_validation.py: sniff real file content via python-magic instead of trusting the client-supplied Content-Type header, plus a 20MB cap. Applied across invoices/logbook/food_flags/credit_notes/disputes upload endpoints (A5) — disputes previously had no file-type check at all - Fix nginx client_max_body_size drift (800m -> the plan's intended 20m) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
78744278f8
commit
bcc94024e3
15 changed files with 124 additions and 109 deletions
|
|
@ -17,6 +17,10 @@ azure-ai-formrecognizer==3.3.0
|
|||
# Image processing
|
||||
Pillow==10.2.0
|
||||
|
||||
# Real content-type sniffing for uploads (A5) — trusts file bytes, not the
|
||||
# client-supplied Content-Type header. Needs libmagic1 (see Dockerfile).
|
||||
python-magic==0.4.27
|
||||
|
||||
# PDF processing (highlighting non-stock items)
|
||||
PyMuPDF==1.23.8
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue