Files
opensourcepos/app
jekkosandobjecttothis f90adab493 fix(taxes): reject invalid characters in tax code, category, and jurisdiction names (#4733)
* fix(taxes): reject invalid characters in tax code, category, and jurisdiction names

Apply the same unicode_alpha_numeric_punct validation already used for
item tax names to the three tax save endpoints, so stored-XSS payloads
(<, >) are rejected with a validation error instead of being saved.

Mirrors the Items fix and adds a TaxesControllerTest regression suite.

* fix(taxes): permit slash and CJK in tax names, add regression tests

The unicode_alpha_numeric_punct guard rejected '/' (char type Po), which
blocks legitimate slash-separated tax names such as 'GST/HST' and 'VAT/GST'
from being saved. Add '/' to the allowed punctuation set and document it.

Also add regression tests proving acceptance of a slash name (GST/HST) and a
CJK name (消費税) across the tax save endpoints. Addresses CodeRabbit review
on #4679.

* test(4679): adopt test{Method}_{Purpose} naming convention

Align test method names with the convention from #4730
(testPostSaveTaxCodes_RejectsMaliciousName, etc.), per review.

* fix(taxes): allow parentheses in names, make name optional

Address CodeRabbit review on #4733:
- Permit parentheses in tax names (e.g. "VAT (20%)"); slash was
  already allowed, so both "GST/HST" and "VAT (20%)" now pass while
  < and > are still rejected.
- Drop the  rule from tax_code_name, jurisdiction_name and
  tax_category so a code with a blank name can be saved, matching the
  form (the form does not require the name).
- Add regression tests for the parentheses and blank-name cases.

---------

Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-10-07 23:14:48 +02:00
..
2024-06-15 17:19:15 +02:00
2024-06-15 17:19:15 +02:00