fix(07): WR-04 sanitise Exchange UniqueId in invoice number fallback
Tessera CI/CD / Lint & Type Check (push) Waiting to run
Tessera CI/CD / Tests (push) Blocked by required conditions
Tessera CI/CD / Build & Deploy (push) Blocked by required conditions

Exchange EWS UniqueIds are base64-encoded and can contain +, /, = characters.
When used as the fallback rechnungsnummer (email-{uid}), a slash would cause
path.join() to resolve into a subdirectory, making writeFileSync fail silently.
Sanitise uid to [a-zA-Z0-9-] before it reaches the filesystem write path.
This commit is contained in:
2026-06-27 17:22:09 +02:00
parent 338655c57b
commit 9de16babe4
+5 -2
View File
@@ -619,8 +619,11 @@ export class DkvService {
private _extractInvoiceNumber(subject: string, uid: number | string): string {
const match = subject?.match(/(\d{2}-\d{9}-\d{3})/);
if (match?.[1]) return match[1];
// Fallback when invoice number cannot be parsed from subject
return `email-${String(uid)}`;
// Fallback when invoice number cannot be parsed from subject.
// Exchange UniqueIds are base64 and can contain '+', '/', '=' which would
// introduce path separators into the generated filename (WR-04).
// Sanitise to [a-zA-Z0-9-] before the value reaches the filesystem.
return `email-${String(uid).replace(/[^a-zA-Z0-9\-]/g, '_')}`;
}
/**