Skip to content

Prerelease - #150

Open
summitt wants to merge 4 commits into
mainfrom
prerelease
Open

summitt wants to merge 4 commits into
mainfrom
prerelease

Conversation

@summitt

@summitt summitt commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Security fixes surfaced by CodeQL, plus the front-end library refresh they required.

  • Stored XSS in peer review notes: desc_notes, rec_notes, detail_notes (Vulnerability) and summary1_notes, summary2_notes (Comment) are sanitized on set. The TrackChanges page feeds these straight into suneditor, so output encoding alone did not help. Existing stored notes are neutralized on display.
  • At-rest encryption: FSUtils writes AES-GCM with a random salt and IV per value ($AESGCM$ prefix). Values written before 1.8.14 (AES/ECB, constant salt) are still read and are re-encrypted on their next save.
  • Extension installs: JARs must carry a manifest with Title/Author/Version/URL and register at least one META-INF/services/com.faction.extender.* service. Disabled extensions are no longer class-loaded. Install, update, enable and disable are audit-logged.
  • Upload handling: FSUtils.checkUploadedFile() verifies a multipart upload really lives in the servlet temp directory before it is read (extension upload/update, report upload).
  • Output escaping in header, TrackChanges, cms, client and register JSPs; title and assessment-type names reject HTML.
  • Front end: jQuery 2.1.4 → 3.7.1 (+ Migrate 3.6), Bootstrap 3.3.4 → 3.4.1 (required for jQuery 3), DataTables 1.10.7 → 1.13.11. jqXHR .error() callers moved to .fail().
  • CodeQL hygiene: .github/codeql/codeql-config.yml excludes vendored/generated front-end paths (activated by the repo property github-codeql-config-file); workflows declare least-privilege permissions.
  • Version bumped to 1.8.14-SNAPSHOT.

Verification

  • New tests: CryptoTests, NotesXssSanitizationTest, UploadedFileGuardTest.
  • Headless browser pass on the built app: 18 pages, zero JS errors, zero jQuery Migrate deprecation warnings; DataTables sort/search, Bootstrap modals, title validation and extension upload rejection behave. Real uploads through Tomcat pass the new guard.
  • The EntityUnitTest.testVulnerabilitySection CI failure is pre-existing on main.

Notes

  • .codex/config.toml was briefly committed with an API key and is removed in 122bdf7; the key is being rotated.
  • Remaining CodeQL alerts on this PR are all in the vendored jquery.dataTables.js and clear once the config-file property is set on the repo.

The peer review view (TrackChanges, prqueue=true) renders each field into a
suneditor rich-text editor, which reads the textarea value and injects it as
innerHTML. Output-encoding the textarea does not help there, so any stored
HTML in the "notes" fields executed in a reviewer's browser.

Sanitize desc_notes/rec_notes/detail_notes on Vulnerability and
summary1_notes/summary2_notes on Comment, matching the existing
description/recommendation/details handling. Comment.exportAssessment rebuilds
each vulnerability through these setters on every display, so this also
neutralizes notes stored before the fix. Track-changes markup is preserved.

Adds NotesXssSanitizationTest and bumps the version to 1.8.14-SNAPSHOT.
Comment thread src/com/fuse/actions/appstore/InstallExtensionController.java Fixed
Comment thread src/com/fuse/actions/appstore/InstallExtensionController.java Fixed
Comment thread src/com/fuse/utils/FSUtils.java Dismissed
It carried a local API key and base URL for a Codex MCP server. The key is
being rotated; the file stays local and .codex/ is ignored from now on.
…load temp files

- .github/codeql/codeql-config.yml ignores WebContent/plugins, bootstrap,
  fileupload, dist and src/scripts. Findings in third-party and generated
  front-end code were re-raised at new line numbers on every library bump;
  application code stays fully analyzed. Enabled through the repository
  property github-codeql-config-file.
- tests.yml / semgrep.yml / assign.yml declare least-privilege permissions
  (actions/missing-workflow-permissions).
- FSUtils.checkUploadedFile() verifies an uploaded File really lives in the
  servlet upload temp directory before it is read. Used by the extension
  upload/update actions and report upload (java/path-injection).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants