You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Custom-domain setup currently relies on a presentation-time checkout check, and replacing a domain can remove the working registration before the replacement is known to be valid.
On main 6722c6b, SetupController#show skips checkout whenever a session_id parameter is present; it does not retrieve or verify that Checkout session. SetupController#update handles domain_connect without checking active_subscription? at all. An authenticated owner without an active subscription can therefore reach the domain-registration operation without established payment entitlement. This is a source-confirmed authorization gap; no live checkout or domain registration was attempted during the audit.
Separately, add_domain destroys the account's existing domains before Domain.register validates/registers the replacement. The model preflight added in #77 cannot preserve registrations already deleted by the controller.
Acceptance:
Enforce account entitlement at each operation that registers or purchases a domain; never use presence of an unverified query parameter as proof of payment.
Handle legitimate checkout-return/webhook timing with verified, account-scoped payment state. Test missing, arbitrary, foreign, unpaid, paid, expired and replayed session IDs, plus direct update requests.
Preserve the active domain when replacement validation or the provider fails. Define replacement/reconciliation semantics for partial provider success and retries.
Test existing-domain replacement, malformed/new long-TLD host, provider timeout/failure, duplicate, cancellation, and ownership isolation using provider doubles.
Custom-domain setup currently relies on a presentation-time checkout check, and replacing a domain can remove the working registration before the replacement is known to be valid.
On main
6722c6b,SetupController#showskips checkout whenever asession_idparameter is present; it does not retrieve or verify that Checkout session.SetupController#updatehandlesdomain_connectwithout checkingactive_subscription?at all. An authenticated owner without an active subscription can therefore reach the domain-registration operation without established payment entitlement. This is a source-confirmed authorization gap; no live checkout or domain registration was attempted during the audit.Separately,
add_domaindestroys the account's existing domains beforeDomain.registervalidates/registers the replacement. The model preflight added in #77 cannot preserve registrations already deleted by the controller.Acceptance: