chore: strip advisory IDs from code comments and changelog (#4720)

Per the project's policy of treating security advisory IDs as
secret-like, remove the identifiers embedded in source/test comments
and CHANGELOG entries. Each keeps its human-readable description (and
PR number where present), so traceability is preserved. No logic changes.
This commit is contained in:
jekkos authored and GitHub committed 2026-09-30 15:49:18 +02:00
1 parent 5d56c2cecd
commit 9eaa2f34f3
15 files changed
+25 -25

No files matched your search

+6 -6
View File
@@ -101,7 +101,7 @@ All notable changes to this project will be documented in this file.
- Fix: Preserve CHECKBOX attribute state when adding attributes (#4385) by @jekkos
- Fix payment type becoming null when editing sales by @Ollama
- Fix broken SQL injection fix - use havingLike() instead of having() with named params by @Ollama
- Fix mass assignment vulnerability in bulk edit (GHSA-49mq-h2g4-grr9) by @Ollama
- Fix mass assignment vulnerability in bulk edit by @Ollama
- Sync language files (#3468) by @Ollama
- Add workflow to auto-update issue templates with releases by @Ollama
- Update SECURITY.md with published security advisories by @Ollama
@@ -109,15 +109,15 @@ All notable changes to this project will be documented in this file.
- Add filter persistence for table views via URL query string (#4400) by @jekkos
- Fix filter persistence javascript issues (#4400) by @jekkos
- Fix PHPUnit test configuration for database connectivity (#4430) by @jekkos
- Fix IDOR vulnerability in password change (GHSA-mcc2-8rp2-q6ch) (#4427) by @jekkos
- Fix IDOR vulnerability in password change (#4427) by @jekkos
- Fix XSS vulnerability in tax invoice view (#4432) by @jekkos
- Fix permission bypass in Sales.getManage() access control (#4428) by @jekkos
- Update SECURITY.md with published security advisories (#4431) by @jekkos
- Fix SQL injection in suggestions column configuration (#4421) by @jekkos
- Fix PHPUnit environment variables not being set (#4434) by @jekkos
- Fix DECIMAL attribute not respecting locale format (#4422) by @jekkos
- Fix stored XSS vulnerability in Attribute Definitions (GHSA-rvfg-ww4r-rwqf) (#4429) by @jekkos
- Fix: Host Header Injection vulnerability (GHSA-jchf-7hr6-h4f3) by @Ollama
- Fix stored XSS vulnerability in Attribute Definitions (#4429) by @jekkos
- Fix: Host Header Injection vulnerability by @Ollama
- Fix stored XSS in gcaptcha_site_key on login page by @Ollama
- Fix stored XSS via stock location name by @Ollama
- Fix Token_lib::render() for PHP 8.4 compatibility by @Ollama
@@ -149,7 +149,7 @@ All notable changes to this project will be documented in this file.
- fix: Use file-based session until database is migrated by @Ollama
- feat: Improve migration UX on login page by @Ollama
- Disable opencode workflow + run docker build by @jekkos
- Fix negative price/quantity/discount validation (GHSA-wv3j-pp8r-7q43) (#4450) by @Nozomu Sasaki (Paul)
- Fix negative price/quantity/discount validation (#4450) by @Nozomu Sasaki (Paul)
- fix(ci): replace / with _ in branch names for Docker tags by @Ollama
- fix(security): prevent command injection in sendmail path configuration by @Ollama
- fix(security): prevent SQL injection in tax controller sort columns by @Ollama
@@ -254,7 +254,7 @@ All notable changes to this project will be documented in this file.
- fix(validation): broaden sendmail path regex, expand i18n, strip advisory IDs by @objecttothis
- fix(security): handle special characters in `.env` key values and improve insertion logic (#4656) by @objecttothis
- fix(locale): validate language_code against known locales to block path traversal (#4704) by @jekkos
- Fix GHSA-frx7-c5vv-m3mr: recompute cashup total server-side and force owner identity (#4706) by @jekkos
- Fix: recompute cashup total server-side and force owner identity (#4706) by @jekkos
- feat(security): add THROTTLE_KEY env-var fallback for throttle.key (#4707) by @jekkos
- fix(i18n): translate remaining English labels in Swiss German Items.php (#4701) by @Rayan Abdul Cader
- fix(ci): stop stamping app version onto master and branch Docker tags (#4709) by @jekkos
+1 -1
View File
@@ -307,7 +307,7 @@ class App extends BaseConfig
/**
* Validates and returns a trusted hostname.
*
* Security: Prevents Host Header Injection attacks (GHSA-jchf-7hr6-h4f3)
* Security: Prevents Host Header Injection attacks
* by validating the HTTP_HOST against a whitelist of allowed hostnames.
*
* In production: Fails fast if allowedHostnames is not configured.
+1 -1
View File
@@ -529,7 +529,7 @@ class Item extends Model
*/
public function updateMultiple(array $itemData, string $itemIds): bool
{
// Query Builder bypasses $allowedFields, so the whitelist is enforced here (GHSA-49mq-h2g4-grr9)
// Query Builder bypasses $allowedFields, so the whitelist is enforced here
$itemData = array_intersect_key($itemData, array_flip(self::ALLOWED_BULK_EDIT_FIELDS));
if (empty($itemData)) {
+5 -5
View File
@@ -303,7 +303,7 @@ class HomeTest extends CIUnitTestCase
/**
* Test non-admin cannot view admin password change form
* BOLA vulnerability fix: GHSA-q58g-gg7v-f9rf
* BOLA vulnerability fix.
*
* @return void
*/
@@ -319,7 +319,7 @@ class HomeTest extends CIUnitTestCase
/**
* Test non-admin cannot change admin password
* BOLA vulnerability fix: GHSA-q58g-gg7v-f9rf
* BOLA vulnerability fix.
*
* @return void
*/
@@ -448,7 +448,7 @@ class HomeTest extends CIUnitTestCase
/**
* Test non-admin cannot view another non-admin's password form
* IDOR vulnerability fix: GHSA-mcc2-8rp2-q6ch
* IDOR vulnerability fix.
*
* @return void
*/
@@ -470,7 +470,7 @@ class HomeTest extends CIUnitTestCase
/**
* Test non-admin cannot change another non-admin's password
* IDOR vulnerability fix: GHSA-mcc2-8rp2-q6ch
* IDOR vulnerability fix.
*
* @return void
*/
@@ -503,7 +503,7 @@ class HomeTest extends CIUnitTestCase
}
/**
* Regression test for GHSA-9gr6-4mm4-4wrq: Home::__construct() previously
* Regression test: Home::__construct() previously
* read the raw (single-decoded) URI segment to decide whether to skip
* Secure_Controller's module-grant check for 'logout'. A route whose
* double-decoded method name resolves to 'logout' must still be treated
+1 -1
View File
@@ -111,7 +111,7 @@ class ItemKitsControllerTest extends CIUnitTestCase
$itemKitId = $this->createItemKit();
$this->loginAsAdmin();
// <svg onload=alert(document.domain)> URL-encoded three times (GHSA-3vpv-jqr3-7256 PoC).
// <svg onload=alert(document.domain)> URL-encoded three times.
// The framework's router decodes this twice before routing; the controller used to apply
// a third urldecode(), turning the remaining %3C.../%3E into a live <svg onload=...> tag.
// With that urldecode() removed, the value must stay percent-encoded text and never
+2 -2
View File
@@ -103,7 +103,7 @@ class ItemsControllerTest extends CIUnitTestCase
}
/**
* Regression test for GHSA-92cx-fc8x-7wmm: `tax_names[]` containing `<`/`>`
* Regression test: `tax_names[]` containing `<`/`>`
* (the stored-XSS vector) must be rejected by postSave.
*/
public function testPostSaveRejectsMaliciousTaxName(): void
@@ -190,7 +190,7 @@ class ItemsControllerTest extends CIUnitTestCase
}
/**
* Regression test for GHSA-cm7j-957q-8pgg: an attribute definition whose
* Regression test: an attribute definition whose
* `definition_name` contains HTML must be entity-escaped when rendered in the
* items attributes dropdown, not emitted as a live (executable) tag.
*/
+1 -1
View File
@@ -9,7 +9,7 @@ use CodeIgniter\Test\FeatureTestTrait;
/**
* Test suite for the Login controller, including the CI Throttler
* mitigation for brute-force/credential-stuffing (GHSA-hm9c-xchj-xgcp).
* mitigation for brute-force/credential-stuffing.
*/
class LoginTest extends CIUnitTestCase
{
+1 -1
View File
@@ -10,7 +10,7 @@ use App\Models\Employee;
use Config\OSPOS;
/**
* Regression tests for GHSA-9gr6-4mm4-4wrq
* Regression tests for the reports permission bypass
*
* Reports::__construct() previously derived the report method name from
* $request->getUri()->getSegment(2), which CodeIgniter decodes once, while
+1 -1
View File
@@ -14,7 +14,7 @@ use Tests\Support\EmployeeFixtureTrait;
use Tests\Support\SaleFixtureTrait;
/**
* Regression tests for GHSA-3xf6-8fmq-44wg.
* Regression tests for the Sales per-endpoint access-control bypass.
*
* A cashier holding only the base "sales" grant (no "reports_sales") must
* not be able to reach the per-sale endpoints that getManage() gates
+1 -1
View File
@@ -9,7 +9,7 @@ use Config\Database;
use Tests\Support\ConcurrentDbRaceTrait;
/**
* Regression tests for GHSA-995p-52qw-5hh2: adjustRewardPoints() must apply
* Regression tests: adjustRewardPoints() must apply
* its balance check and its write in a single atomic UPDATE, so that two
* concurrent reward-point spends against the same customer can never both
* read the same stale balance and double-spend it.
+1 -1
View File
@@ -9,7 +9,7 @@ use Config\Database;
use Tests\Support\ConcurrentDbRaceTrait;
/**
* Regression tests for GHSA-995p-52qw-5hh2: decrementGiftcardValue() must
* Regression tests: decrementGiftcardValue() must
* apply its balance check and its write in a single atomic UPDATE, so that
* two concurrent decrements against the same gift card can never both read
* the same stale balance and double-spend it.
+1 -1
View File
@@ -7,7 +7,7 @@ use CodeIgniter\Test\CIUnitTestCase;
use CodeIgniter\Test\DatabaseTestTrait;
/**
* Regression coverage for GHSA-49mq-h2g4-grr9 (mass assignment in bulk edit).
* Regression coverage for mass assignment in bulk edit.
*
* Item::update_multiple() writes through the Query Builder, which bypasses the
* model's $allowedFields, so these assertions go straight to the items table.
+1 -1
View File
@@ -10,7 +10,7 @@ use Tests\Support\ConcurrentDbRaceTrait;
use Tests\Support\ItemFixtureTrait;
/**
* Regression tests for GHSA-995p-52qw-5hh2: changeQuantity() must apply
* Regression tests: changeQuantity() must apply
* its write in a single atomic upsert, so that two concurrent sales of the
* same item/location can never both read the same stale quantity and
* oversell stock. Unlike the gift card and reward point spends, there is
+1 -1
View File
@@ -9,7 +9,7 @@ use Tests\Support\EmployeeFixtureTrait;
use Tests\Support\ItemFixtureTrait;
/**
* Regression tests for GHSA-995p-52qw-5hh2: Receiving::delete_value() must
* Regression tests: Receiving::delete_value() must
* correctly reverse the stock quantity change it applied via
* Item_quantity::changeQuantity(), using the same atomic upsert as the
* sale-checkout and sale-cancel paths.
+1 -1
View File
@@ -10,7 +10,7 @@ use Tests\Support\EmployeeFixtureTrait;
use Tests\Support\ItemFixtureTrait;
/**
* Regression tests for GHSA-995p-52qw-5hh2: Sale::save_value() must reject
* Regression tests: Sale::save_value() must reject
* (and roll back) a payment that would overdraw a gift card or a customer's
* reward points, instead of silently applying a stale/negative balance.
*/