From 9de16babe4ded99e2cc3219248c189335f447b64 Mon Sep 17 00:00:00 2001 From: Schalli Date: Sat, 27 Jun 2026 17:22:09 +0200 Subject: [PATCH] fix(07): WR-04 sanitise Exchange UniqueId in invoice number fallback Exchange EWS UniqueIds are base64-encoded and can contain +, /, = characters. When used as the fallback rechnungsnummer (email-{uid}), a slash would cause path.join() to resolve into a subdirectory, making writeFileSync fail silently. Sanitise uid to [a-zA-Z0-9-] before it reaches the filesystem write path. --- apps/api/src/dkv/dkv.service.ts | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/apps/api/src/dkv/dkv.service.ts b/apps/api/src/dkv/dkv.service.ts index ec2d26b..0376add 100644 --- a/apps/api/src/dkv/dkv.service.ts +++ b/apps/api/src/dkv/dkv.service.ts @@ -619,8 +619,11 @@ export class DkvService { private _extractInvoiceNumber(subject: string, uid: number | string): string { const match = subject?.match(/(\d{2}-\d{9}-\d{3})/); if (match?.[1]) return match[1]; - // Fallback when invoice number cannot be parsed from subject - return `email-${String(uid)}`; + // Fallback when invoice number cannot be parsed from subject. + // Exchange UniqueIds are base64 and can contain '+', '/', '=' which would + // introduce path separators into the generated filename (WR-04). + // Sanitise to [a-zA-Z0-9-] before the value reaches the filesystem. + return `email-${String(uid).replace(/[^a-zA-Z0-9\-]/g, '_')}`; } /**