diff --git a/CHANGELOG.md b/CHANGELOG.md index aef9932b9..b0ee0efac 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -101,7 +101,7 @@ All notable changes to this project will be documented in this file. - Fix: Preserve CHECKBOX attribute state when adding attributes (#4385) by @jekkos - Fix payment type becoming null when editing sales by @Ollama - Fix broken SQL injection fix - use havingLike() instead of having() with named params by @Ollama -- Fix mass assignment vulnerability in bulk edit (GHSA-49mq-h2g4-grr9) by @Ollama +- Fix mass assignment vulnerability in bulk edit by @Ollama - Sync language files (#3468) by @Ollama - Add workflow to auto-update issue templates with releases by @Ollama - Update SECURITY.md with published security advisories by @Ollama @@ -109,15 +109,15 @@ All notable changes to this project will be documented in this file. - Add filter persistence for table views via URL query string (#4400) by @jekkos - Fix filter persistence javascript issues (#4400) by @jekkos - Fix PHPUnit test configuration for database connectivity (#4430) by @jekkos -- Fix IDOR vulnerability in password change (GHSA-mcc2-8rp2-q6ch) (#4427) by @jekkos +- Fix IDOR vulnerability in password change (#4427) by @jekkos - Fix XSS vulnerability in tax invoice view (#4432) by @jekkos - Fix permission bypass in Sales.getManage() access control (#4428) by @jekkos - Update SECURITY.md with published security advisories (#4431) by @jekkos - Fix SQL injection in suggestions column configuration (#4421) by @jekkos - Fix PHPUnit environment variables not being set (#4434) by @jekkos - Fix DECIMAL attribute not respecting locale format (#4422) by @jekkos -- Fix stored XSS vulnerability in Attribute Definitions (GHSA-rvfg-ww4r-rwqf) (#4429) by @jekkos -- Fix: Host Header Injection vulnerability (GHSA-jchf-7hr6-h4f3) by @Ollama +- Fix stored XSS vulnerability in Attribute Definitions (#4429) by @jekkos +- Fix: Host Header Injection vulnerability by @Ollama - Fix stored XSS in gcaptcha_site_key on login page by @Ollama - Fix stored XSS via stock location name by @Ollama - Fix Token_lib::render() for PHP 8.4 compatibility by @Ollama @@ -149,7 +149,7 @@ All notable changes to this project will be documented in this file. - fix: Use file-based session until database is migrated by @Ollama - feat: Improve migration UX on login page by @Ollama - Disable opencode workflow + run docker build by @jekkos -- Fix negative price/quantity/discount validation (GHSA-wv3j-pp8r-7q43) (#4450) by @Nozomu Sasaki (Paul) +- Fix negative price/quantity/discount validation (#4450) by @Nozomu Sasaki (Paul) - fix(ci): replace / with _ in branch names for Docker tags by @Ollama - fix(security): prevent command injection in sendmail path configuration by @Ollama - fix(security): prevent SQL injection in tax controller sort columns by @Ollama @@ -254,7 +254,7 @@ All notable changes to this project will be documented in this file. - fix(validation): broaden sendmail path regex, expand i18n, strip advisory IDs by @objecttothis - fix(security): handle special characters in `.env` key values and improve insertion logic (#4656) by @objecttothis - fix(locale): validate language_code against known locales to block path traversal (#4704) by @jekkos -- Fix GHSA-frx7-c5vv-m3mr: recompute cashup total server-side and force owner identity (#4706) by @jekkos +- Fix: recompute cashup total server-side and force owner identity (#4706) by @jekkos - feat(security): add THROTTLE_KEY env-var fallback for throttle.key (#4707) by @jekkos - fix(i18n): translate remaining English labels in Swiss German Items.php (#4701) by @Rayan Abdul Cader - fix(ci): stop stamping app version onto master and branch Docker tags (#4709) by @jekkos diff --git a/app/Config/App.php b/app/Config/App.php index 69fabf65d..de204b036 100644 --- a/app/Config/App.php +++ b/app/Config/App.php @@ -307,7 +307,7 @@ class App extends BaseConfig /** * Validates and returns a trusted hostname. * - * Security: Prevents Host Header Injection attacks (GHSA-jchf-7hr6-h4f3) + * Security: Prevents Host Header Injection attacks * by validating the HTTP_HOST against a whitelist of allowed hostnames. * * In production: Fails fast if allowedHostnames is not configured. diff --git a/app/Models/Item.php b/app/Models/Item.php index 1268839a3..f8cd99175 100644 --- a/app/Models/Item.php +++ b/app/Models/Item.php @@ -529,7 +529,7 @@ class Item extends Model */ public function updateMultiple(array $itemData, string $itemIds): bool { - // Query Builder bypasses $allowedFields, so the whitelist is enforced here (GHSA-49mq-h2g4-grr9) + // Query Builder bypasses $allowedFields, so the whitelist is enforced here $itemData = array_intersect_key($itemData, array_flip(self::ALLOWED_BULK_EDIT_FIELDS)); if (empty($itemData)) { diff --git a/tests/Controllers/HomeTest.php b/tests/Controllers/HomeTest.php index d8821c37a..d10c8c650 100644 --- a/tests/Controllers/HomeTest.php +++ b/tests/Controllers/HomeTest.php @@ -303,7 +303,7 @@ class HomeTest extends CIUnitTestCase /** * Test non-admin cannot view admin password change form - * BOLA vulnerability fix: GHSA-q58g-gg7v-f9rf + * BOLA vulnerability fix. * * @return void */ @@ -319,7 +319,7 @@ class HomeTest extends CIUnitTestCase /** * Test non-admin cannot change admin password - * BOLA vulnerability fix: GHSA-q58g-gg7v-f9rf + * BOLA vulnerability fix. * * @return void */ @@ -448,7 +448,7 @@ class HomeTest extends CIUnitTestCase /** * Test non-admin cannot view another non-admin's password form - * IDOR vulnerability fix: GHSA-mcc2-8rp2-q6ch + * IDOR vulnerability fix. * * @return void */ @@ -470,7 +470,7 @@ class HomeTest extends CIUnitTestCase /** * Test non-admin cannot change another non-admin's password - * IDOR vulnerability fix: GHSA-mcc2-8rp2-q6ch + * IDOR vulnerability fix. * * @return void */ @@ -503,7 +503,7 @@ class HomeTest extends CIUnitTestCase } /** - * Regression test for GHSA-9gr6-4mm4-4wrq: Home::__construct() previously + * Regression test: Home::__construct() previously * read the raw (single-decoded) URI segment to decide whether to skip * Secure_Controller's module-grant check for 'logout'. A route whose * double-decoded method name resolves to 'logout' must still be treated diff --git a/tests/Controllers/ItemKitsControllerTest.php b/tests/Controllers/ItemKitsControllerTest.php index 566516c40..cfdfca983 100644 --- a/tests/Controllers/ItemKitsControllerTest.php +++ b/tests/Controllers/ItemKitsControllerTest.php @@ -111,7 +111,7 @@ class ItemKitsControllerTest extends CIUnitTestCase $itemKitId = $this->createItemKit(); $this->loginAsAdmin(); - // URL-encoded three times (GHSA-3vpv-jqr3-7256 PoC). + // URL-encoded three times. // The framework's router decodes this twice before routing; the controller used to apply // a third urldecode(), turning the remaining %3C.../%3E into a live tag. // With that urldecode() removed, the value must stay percent-encoded text and never diff --git a/tests/Controllers/ItemsControllerTest.php b/tests/Controllers/ItemsControllerTest.php index 895f87868..1f73c73e5 100644 --- a/tests/Controllers/ItemsControllerTest.php +++ b/tests/Controllers/ItemsControllerTest.php @@ -103,7 +103,7 @@ class ItemsControllerTest extends CIUnitTestCase } /** - * Regression test for GHSA-92cx-fc8x-7wmm: `tax_names[]` containing `<`/`>` + * Regression test: `tax_names[]` containing `<`/`>` * (the stored-XSS vector) must be rejected by postSave. */ public function testPostSaveRejectsMaliciousTaxName(): void @@ -190,7 +190,7 @@ class ItemsControllerTest extends CIUnitTestCase } /** - * Regression test for GHSA-cm7j-957q-8pgg: an attribute definition whose + * Regression test: an attribute definition whose * `definition_name` contains HTML must be entity-escaped when rendered in the * items attributes dropdown, not emitted as a live (executable) tag. */ diff --git a/tests/Controllers/LoginTest.php b/tests/Controllers/LoginTest.php index 8378f98e5..8d75c3134 100644 --- a/tests/Controllers/LoginTest.php +++ b/tests/Controllers/LoginTest.php @@ -9,7 +9,7 @@ use CodeIgniter\Test\FeatureTestTrait; /** * Test suite for the Login controller, including the CI Throttler - * mitigation for brute-force/credential-stuffing (GHSA-hm9c-xchj-xgcp). + * mitigation for brute-force/credential-stuffing. */ class LoginTest extends CIUnitTestCase { diff --git a/tests/Controllers/ReportsControllerTest.php b/tests/Controllers/ReportsControllerTest.php index 7960f508d..c2f59979c 100644 --- a/tests/Controllers/ReportsControllerTest.php +++ b/tests/Controllers/ReportsControllerTest.php @@ -10,7 +10,7 @@ use App\Models\Employee; use Config\OSPOS; /** - * Regression tests for GHSA-9gr6-4mm4-4wrq + * Regression tests for the reports permission bypass * * Reports::__construct() previously derived the report method name from * $request->getUri()->getSegment(2), which CodeIgniter decodes once, while diff --git a/tests/Controllers/SalesControllerTest.php b/tests/Controllers/SalesControllerTest.php index d0b5dec6e..08e643c1a 100644 --- a/tests/Controllers/SalesControllerTest.php +++ b/tests/Controllers/SalesControllerTest.php @@ -14,7 +14,7 @@ use Tests\Support\EmployeeFixtureTrait; use Tests\Support\SaleFixtureTrait; /** - * Regression tests for GHSA-3xf6-8fmq-44wg. + * Regression tests for the Sales per-endpoint access-control bypass. * * A cashier holding only the base "sales" grant (no "reports_sales") must * not be able to reach the per-sale endpoints that getManage() gates diff --git a/tests/Models/CustomerRewardPointsTest.php b/tests/Models/CustomerRewardPointsTest.php index 7671a1d8d..7e89a29d4 100644 --- a/tests/Models/CustomerRewardPointsTest.php +++ b/tests/Models/CustomerRewardPointsTest.php @@ -9,7 +9,7 @@ use Config\Database; use Tests\Support\ConcurrentDbRaceTrait; /** - * Regression tests for GHSA-995p-52qw-5hh2: adjustRewardPoints() must apply + * Regression tests: adjustRewardPoints() must apply * its balance check and its write in a single atomic UPDATE, so that two * concurrent reward-point spends against the same customer can never both * read the same stale balance and double-spend it. diff --git a/tests/Models/GiftcardTest.php b/tests/Models/GiftcardTest.php index e57b88cd9..d097cd673 100644 --- a/tests/Models/GiftcardTest.php +++ b/tests/Models/GiftcardTest.php @@ -9,7 +9,7 @@ use Config\Database; use Tests\Support\ConcurrentDbRaceTrait; /** - * Regression tests for GHSA-995p-52qw-5hh2: decrementGiftcardValue() must + * Regression tests: decrementGiftcardValue() must * apply its balance check and its write in a single atomic UPDATE, so that * two concurrent decrements against the same gift card can never both read * the same stale balance and double-spend it. diff --git a/tests/Models/ItemBulkUpdateTest.php b/tests/Models/ItemBulkUpdateTest.php index a48e2d547..4e1cdcb5a 100644 --- a/tests/Models/ItemBulkUpdateTest.php +++ b/tests/Models/ItemBulkUpdateTest.php @@ -7,7 +7,7 @@ use CodeIgniter\Test\CIUnitTestCase; use CodeIgniter\Test\DatabaseTestTrait; /** - * Regression coverage for GHSA-49mq-h2g4-grr9 (mass assignment in bulk edit). + * Regression coverage for mass assignment in bulk edit. * * Item::update_multiple() writes through the Query Builder, which bypasses the * model's $allowedFields, so these assertions go straight to the items table. diff --git a/tests/Models/ItemQuantityTest.php b/tests/Models/ItemQuantityTest.php index b564fb097..8ca38a267 100644 --- a/tests/Models/ItemQuantityTest.php +++ b/tests/Models/ItemQuantityTest.php @@ -10,7 +10,7 @@ use Tests\Support\ConcurrentDbRaceTrait; use Tests\Support\ItemFixtureTrait; /** - * Regression tests for GHSA-995p-52qw-5hh2: changeQuantity() must apply + * Regression tests: changeQuantity() must apply * its write in a single atomic upsert, so that two concurrent sales of the * same item/location can never both read the same stale quantity and * oversell stock. Unlike the gift card and reward point spends, there is diff --git a/tests/Models/ReceivingTest.php b/tests/Models/ReceivingTest.php index 106d9e3a3..318727b09 100644 --- a/tests/Models/ReceivingTest.php +++ b/tests/Models/ReceivingTest.php @@ -9,7 +9,7 @@ use Tests\Support\EmployeeFixtureTrait; use Tests\Support\ItemFixtureTrait; /** - * Regression tests for GHSA-995p-52qw-5hh2: Receiving::delete_value() must + * Regression tests: Receiving::delete_value() must * correctly reverse the stock quantity change it applied via * Item_quantity::changeQuantity(), using the same atomic upsert as the * sale-checkout and sale-cancel paths. diff --git a/tests/Models/SaleTest.php b/tests/Models/SaleTest.php index 4dffad438..aff3b79c5 100644 --- a/tests/Models/SaleTest.php +++ b/tests/Models/SaleTest.php @@ -10,7 +10,7 @@ use Tests\Support\EmployeeFixtureTrait; use Tests\Support\ItemFixtureTrait; /** - * Regression tests for GHSA-995p-52qw-5hh2: Sale::save_value() must reject + * Regression tests: Sale::save_value() must reject * (and roll back) a payment that would overdraw a gift card or a customer's * reward points, instead of silently applying a stale/negative balance. */