fix(07): WR-04 sanitise Exchange UniqueId in invoice number fallback
Exchange EWS UniqueIds are base64-encoded and can contain +, /, = characters.
When used as the fallback rechnungsnummer (email-{uid}), a slash would cause
path.join() to resolve into a subdirectory, making writeFileSync fail silently.
Sanitise uid to [a-zA-Z0-9-] before it reaches the filesystem write path.
This commit is contained in:
@@ -619,8 +619,11 @@ export class DkvService {
|
|||||||
private _extractInvoiceNumber(subject: string, uid: number | string): string {
|
private _extractInvoiceNumber(subject: string, uid: number | string): string {
|
||||||
const match = subject?.match(/(\d{2}-\d{9}-\d{3})/);
|
const match = subject?.match(/(\d{2}-\d{9}-\d{3})/);
|
||||||
if (match?.[1]) return match[1];
|
if (match?.[1]) return match[1];
|
||||||
// Fallback when invoice number cannot be parsed from subject
|
// Fallback when invoice number cannot be parsed from subject.
|
||||||
return `email-${String(uid)}`;
|
// Exchange UniqueIds are base64 and can contain '+', '/', '=' which would
|
||||||
|
// introduce path separators into the generated filename (WR-04).
|
||||||
|
// Sanitise to [a-zA-Z0-9-] before the value reaches the filesystem.
|
||||||
|
return `email-${String(uid).replace(/[^a-zA-Z0-9\-]/g, '_')}`;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
Reference in New Issue
Block a user