Repository navigation
Add optional CLI validation of original ACH control totals - #1874
Merged
Merged
Conversation
Member
|
Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add
achcli -validate-totals file.ach [other.ach ...]to check the control totals stored in original raw ACH files before submission. The current description command accepts incorrect file counts, hashes and amounts with exit status 0; this optional command returns 1 if any input fails and reports each failing path.The command leaves input bytes unchanged and creates no output files. It rejects JSON because JSON parsing recalculates totals, validation options that waive count checks, and conflicting transformation or presentation flags. Existing commands retain their behaviour. Related to #1428; this proposes an optional CLI command rather than changing default validation.
Evidence
After: all five return 1 with the file path and mismatched field. All 69 executable CLI regression cases pass, covering multiple inputs, reader failures and options, missing controls, stored zero totals, nested batch totals, JSON rejection, LF, CRLF and EOF without a final newline, ADV, mixed PPD/IAT files, flag conflicts, help, syntax errors and input preservation. The five default-command controls still pass.
go test ./...passes. Linuxmake checkpasses, including the wasm build, lint, gitleaks and shuffled package tests. Project statement coverage is 93.9%, above the required 85%. Checks used Go 1.27.1; the unchanged baseline also passes both full checks.govulncheck -test ./...run passes with scanner v1.8.0 and reports no vulnerabilities found. The initialmake checkrun skipped this optional checker, so its aggregate success alone does not establish a vulnerability-scan result.Merge danger
Door: two-way. Blast radius: CLI.
The new mode reuses
readACHFileandFile.ValidateTotals; it adds no library API or dependency. It is limited to the checks those functions provide, including no recalculation of block counts or verification of padding consistency.Unverified
The Go 1.26 and native macOS CI variants, Docker integration, OpenAPI and web UI jobs have not run locally. Upstream CI is not yet verified. These parts are unchanged.