Skip to content

fix: harden payment checks and sensitive data handling - #29

Merged
vildanbina merged 2 commits into
developfrom
PYT-44-security-fixes
Oct 5, 2026
Merged

vildanbina merged 2 commits into
developfrom
PYT-44-security-fixes

Conversation

@vildanbina

Copy link
Copy Markdown
Collaborator

Summary

payment verdict -> HTTP success + explicit status 190
curl credentials/body -> escaped stdin config
masked log formatting failure -> fixed omission marker

Preserves the existing high-level response flags and form-verifier contract. No new dependencies or public API changes.

Evidence

  • Before: unpaid/missing statuses counted as successful; curl exposed headers/body in argv; malformed log bodies bypassed masking.
    After: regression tests reject unpaid statuses, real local curl requests preserve bytes without argv secrets, and masking failures omit the body.
  • 2,532 tests passed locally; 98% coverage. Lint, format, wheel/sdist build and metadata checks passed.
  • Independent compatibility and security reviews approved the final diff.

Merge Danger

Door: two-way. Code-only changes; no migration.

Blast Radius: SDK. Low-level unpaid payment checks now return false; masked logging omits unsupported bodies. Live merchant deployments were not exercised.

- Require explicit paid status in the low-level payment predicate
- Pass curl credentials and request bodies through escaped stdin config
- Omit log bodies when masking cannot safely process them
- Cover security regressions and preserve high-level success flags
- Move regression tests into the existing HTTP, model and service test files
- Share the loopback fixture in unit conftest and remove standalone test modules
@vildanbina
vildanbina merged commit a9e9c5d into develop Oct 5, 2026
6 checks passed
@vildanbina
vildanbina deleted the PYT-44-security-fixes branch October 5, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants