DEV Community

Junzi Xu
Junzi Xu

Posted on Fully Autonomous

An observed coupon is not a verified coupon: auditing timestamps and CSV exports in Python

Disclosure: This article and the accompanying code were prepared with AI assistance. The described tests were run locally; coupon redemption was not tested.

A discount page can remain online after its campaign ends. A source observation therefore needs its own timestamp, independently from any stated expiry. Missing expiry must stay unknown, rather than becoming a promise of indefinite validity.

A small offline audit

The example project is eSIM Offer Audit Kit. Its dated historical fixture comes from my eSIM deals website. It contains no customer accounts or activation QR codes. The fixture is an example, not a list of currently valid coupons.

After downloading the repository, run these commands from its directory:

python -m unittest -v
python audit.py observations.json --csv audit.csv
Enter fullscreen mode Exit fullscreen mode

The CLI uses Python's standard library and performs no network calls. Each output row preserves a source URL and collection time and adds review flags.

Observation age and offer expiry are different

Age in hours is calculated as:

age = (now - timestamp(offer['fetched_at'])).total_seconds() / 3600
Enter fullscreen mode Exit fullscreen mode

A negative age is a clock or data problem, not a fresh record. The configurable 30-hour default is an editorial recheck policy, not the provider's validity period. Timezone-free timestamps are rejected to avoid silently interpreting them as local time.

The flags distinguish several cases:

  • future_timestamp: collection time is later than the audit time.
  • stale_observation: the observation exceeds the configured review interval.
  • expiry_unknown: no explicit expiry is recorded.
  • expired: a recorded expiry is at or before the audit time.

Unknown expiry stays a review flag. It never becomes evidence that an offer lasts forever.

CSV quoting is not formula protection

Another boundary is spreadsheets. CSV quoting alone does not stop a formula from being evaluated when someone opens a file. The exporter prefixes an apostrophe when text begins with =, +, - or @, including when those characters are preceded by whitespace:

def csv_safe(value):
    value = str(value if value is not None else '')
    return "'" + value if value.lstrip().startswith(('=', '+', '-', '@')) else value
Enter fullscreen mode Exit fullscreen mode

This is a defensive export step, not a guarantee across every spreadsheet application's import settings. Inspect imports as text when handling untrusted data.

The regression tests exercise formula-prefix handling alongside stale observations, malformed source URL shapes, explicit expiry and missing expiry.

What this audit cannot prove

The output deliberately has no "verified coupon" column. HTTPS URL syntax does not prove domain ownership, a percentage does not establish a comparable final price, and a downloaded source hash does not establish a successful checkout.

Manual review still needs plan eligibility, destination, device compatibility, subscription terms and final payment. An automated check should identify what needs review without claiming evidence it never collected.

Top comments (0)