Prerelease - #150
Open
summitt wants to merge 4 commits into
Open
Prerelease#150summitt wants to merge 4 commits into
summitt wants to merge 4 commits into
Conversation
The peer review view (TrackChanges, prqueue=true) renders each field into a suneditor rich-text editor, which reads the textarea value and injects it as innerHTML. Output-encoding the textarea does not help there, so any stored HTML in the "notes" fields executed in a reviewer's browser. Sanitize desc_notes/rec_notes/detail_notes on Vulnerability and summary1_notes/summary2_notes on Comment, matching the existing description/recommendation/details handling. Comment.exportAssessment rebuilds each vulnerability through these setters on every display, so this also neutralizes notes stored before the fix. Track-changes markup is preserved. Adds NotesXssSanitizationTest and bumps the version to 1.8.14-SNAPSHOT.
It carried a local API key and base URL for a Codex MCP server. The key is being rotated; the file stays local and .codex/ is ignored from now on.
…load temp files - .github/codeql/codeql-config.yml ignores WebContent/plugins, bootstrap, fileupload, dist and src/scripts. Findings in third-party and generated front-end code were re-raised at new line numbers on every library bump; application code stays fully analyzed. Enabled through the repository property github-codeql-config-file. - tests.yml / semgrep.yml / assign.yml declare least-privilege permissions (actions/missing-workflow-permissions). - FSUtils.checkUploadedFile() verifies an uploaded File really lives in the servlet upload temp directory before it is read. Used by the extension upload/update actions and report upload (java/path-injection).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security fixes surfaced by CodeQL, plus the front-end library refresh they required.
desc_notes,rec_notes,detail_notes(Vulnerability) andsummary1_notes,summary2_notes(Comment) are sanitized on set. The TrackChanges page feeds these straight into suneditor, so output encoding alone did not help. Existing stored notes are neutralized on display.FSUtilswrites AES-GCM with a random salt and IV per value ($AESGCM$prefix). Values written before 1.8.14 (AES/ECB, constant salt) are still read and are re-encrypted on their next save.META-INF/services/com.faction.extender.*service. Disabled extensions are no longer class-loaded. Install, update, enable and disable are audit-logged.FSUtils.checkUploadedFile()verifies a multipart upload really lives in the servlet temp directory before it is read (extension upload/update, report upload)..error()callers moved to.fail()..github/codeql/codeql-config.ymlexcludes vendored/generated front-end paths (activated by the repo propertygithub-codeql-config-file); workflows declare least-privilege permissions.Verification
EntityUnitTest.testVulnerabilitySectionCI failure is pre-existing on main.Notes
.codex/config.tomlwas briefly committed with an API key and is removed in 122bdf7; the key is being rotated.jquery.dataTables.jsand clear once the config-file property is set on the repo.