diff --git a/apps/api/src/dkv/dkv.service.ts b/apps/api/src/dkv/dkv.service.ts index ec2d26b..0376add 100644 --- a/apps/api/src/dkv/dkv.service.ts +++ b/apps/api/src/dkv/dkv.service.ts @@ -619,8 +619,11 @@ export class DkvService { private _extractInvoiceNumber(subject: string, uid: number | string): string { const match = subject?.match(/(\d{2}-\d{9}-\d{3})/); if (match?.[1]) return match[1]; - // Fallback when invoice number cannot be parsed from subject - return `email-${String(uid)}`; + // Fallback when invoice number cannot be parsed from subject. + // Exchange UniqueIds are base64 and can contain '+', '/', '=' which would + // introduce path separators into the generated filename (WR-04). + // Sanitise to [a-zA-Z0-9-] before the value reaches the filesystem. + return `email-${String(uid).replace(/[^a-zA-Z0-9\-]/g, '_')}`; } /**