Repository navigation
Fix Kaufland request signing; scope MOTIS_URL to Deutsche Bahn - #959
Merged
Merged
Conversation
…apters Kaufland signs METHOD\nURL\nBODY\nTIMESTAMP with no trailing newline and with the query string in the URL. The adapter template added a newline and the engine signed the URL without its query, so every call failed with 401 "Request signature is corrupted". Also point list_storefronts at /info/storefront, drop list_shipments (no such endpoint) and correct the embedded values the order tools advertise. The cloud's operator-provided MOTIS_URL was merged into every catalog install; only adapters that declare the variable get it now.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A Kaufland seller on Cloud reported that every call fails with 401 "Request signature is corrupted" even though the keys are right. They were right: the signature was wrong on our side. They also noticed a
MOTIS_URLvariable on their Kaufland connector, which belongs to Deutsche Bahn only.Changes
rest.engine.ts):${url}and${path}now include the query string that is actually sent, and the serializer is pinned so the signed query is the one on the wire. The default template no longer ends with a newline.\n(Kaufland joins method, URL, body and timestamp with newlines and adds nothing after the timestamp).kaufland_list_storefrontsnow calls/info/storefront(/storefrontsis a 404).kaufland_list_shipmentsis removed because/shipmentsdoesn't exist.list_ordersloses anembeddedparam that Kaufland ignores, andget_ordernow lists the values Kaufland accepts (order_invoices,delivery,kss_delivery).cloud-managed-env.ts):MOTIS_URLused to be merged into every catalog install. Now only adapters that declare it get it, and a value posted under that name for any other adapter is dropped.Type
Testing
da0b65f5…2e2a), plus a test that a query-string request signs the URL axios really builds. Added a static check that the adapter only uses endpoints that exist, and tests for the env-var scoping.Commands (in
packages/backendunless noted):npm run lint: 0 errors (12 existing warnings; unrelated--fixrewrites reverted)npx tsc --noEmit -p tsconfig.json: cleannpm test: 480 suites passed, 10418 tests passednode scripts/validate-adapters.mjs --warnexits 0, no Kaufland warnings;node scripts/adapter-count.mjs --checkOKCloud audit (read-only): the only HMAC connector in production is the Kaufland install that reported this, so changing what
${url}means affects nobody else. 834 connectors on other adapters carry a strayMOTIS_URL. This PR stops new ones; existing rows need a separate cleanup.Cloud and self-hosted behave the same. On self-hosted,
MOTIS_URLonly applies whenMOTIS_INTERNAL_URLis set.After deploy
Existing installs keep the old template stored in their encrypted
authConfig, and the reconciler doesn't touch auth or endpoints. The one affected connector needs its template patched and a full catalog resync (new storefronts path, removed shipments tool).Checklist
npm test)