fix: billing tenant isolation, invoice status validation, SMTP password masking
H2: list_invoices now passes tenant_id (from current_user) to get_invoices;
get_invoices applies WHERE tenant_id filter for non-global-admin users;
get_invoice_endpoint returns 404 when tenant mismatch for non-admins.
H3: InvoiceStatusUpdate.status changed to Literal["draft","sent","paid","cancelled"]
for schema-level validation; guard also added in update_invoice_status service.
H5: _settings_to_out masks smtp_password as "***" when set, "" when empty;
update_settings skips writing when value is the "***" sentinel.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -232,7 +232,7 @@ def _settings_to_out(raw: dict[str, str]) -> SettingsOut:
|
||||
smtp_host=raw.get("smtp_host", ""),
|
||||
smtp_port=int(raw.get("smtp_port", "587")),
|
||||
smtp_user=raw.get("smtp_user", ""),
|
||||
smtp_password=raw.get("smtp_password", ""),
|
||||
smtp_password="***" if raw.get("smtp_password", "") else "",
|
||||
smtp_from_address=raw.get("smtp_from_address", ""),
|
||||
scene_linear_deflection=float(raw.get("scene_linear_deflection", "0.1")),
|
||||
scene_angular_deflection=float(raw.get("scene_angular_deflection", "0.1")),
|
||||
@@ -357,7 +357,7 @@ async def update_settings(
|
||||
updates["smtp_port"] = str(body.smtp_port)
|
||||
if body.smtp_user is not None:
|
||||
updates["smtp_user"] = body.smtp_user
|
||||
if body.smtp_password is not None:
|
||||
if body.smtp_password is not None and body.smtp_password != "***":
|
||||
updates["smtp_password"] = body.smtp_password
|
||||
if body.smtp_from_address is not None:
|
||||
updates["smtp_from_address"] = body.smtp_from_address
|
||||
|
||||
Reference in New Issue
Block a user