BazaRb#balance converts the response body with String#to_f without checking whether the response is numeric. Ruby turns a nonnumeric or empty string into 0.0, so a malformed HTTP 200 response is indistinguishable from a real zero balance.
Steps to reproduce:
- Have
GET /account/balance return HTTP 200 with not-a-balance.
- Call
BazaRb#balance.
Actual result: the method returns 0.0.
Expected result: it should reject an empty or nonnumeric response body instead of returning a valid-looking zero balance.
The unchecked conversion is in lib/baza-rb.rb, in BazaRb#balance. This is separate from the malformed job ID and exit-code responses covered by #458.
BazaRb#balanceconverts the response body withString#to_fwithout checking whether the response is numeric. Ruby turns a nonnumeric or empty string into0.0, so a malformed HTTP 200 response is indistinguishable from a real zero balance.Steps to reproduce:
GET /account/balancereturn HTTP 200 withnot-a-balance.BazaRb#balance.Actual result: the method returns
0.0.Expected result: it should reject an empty or nonnumeric response body instead of returning a valid-looking zero balance.
The unchecked conversion is in
lib/baza-rb.rb, inBazaRb#balance. This is separate from the malformed job ID and exit-code responses covered by #458.