security: validate billing address structure in Order model #24
No reviewers
Labels
No labels
P1
P2
P3
PHP
agent-ready
bug
clotho
discovery
docs
refactor
review
security
testing
athena
athena-gemini
audit
clotho
clotho-gemini
codex
darbs-claude
security
wiki
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: core/php-commerce#24
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feat/validate-billing-address"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
validateBillingAddress()method toOrdermodel, triggered oncreatingandupdatingeventsline1,city,postcode,country(ISO 3166-1 alpha-2)line2,statecommerce.checkout.require_billing_addressconfig — when disabled,nullis permitted but non-null values must still conformBILLING_ADDRESS_REQUIRED_FIELDSandBILLING_ADDRESS_ALLOWED_FIELDSexposed for external validationFixes #12
Test plan
country) — should throwValidationExceptionnullbilling address whenrequire_billing_addressistrue— should thrownullbilling address whenrequire_billing_addressisfalse— should succeedcountrymust be exactly 2 characters (ISO code)🤖 Generated with Claude Code
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.