Skip to content

fix(security): T2 2026 permission and security fixes - #120

Open
Clupai8o0 wants to merge 1 commit into
thoth-tech:11.0.xfrom
ontrack-features-t2-2026:upstream-pr/security
Open

Clupai8o0 wants to merge 1 commit into
thoth-tech:11.0.xfrom
ontrack-features-t2-2026:upstream-pr/security

Conversation

@Clupai8o0

@Clupai8o0 Clupai8o0 commented Sep 27, 2026 •

Copy link
Copy Markdown

What this is

Fixes found while reviewing sign in, LTI, settings and the plagiarism check. Sign in is now rate limited, LTI enrolment tokens can only be used once by the person they were issued to, and callers who are not signed in only see public settings.

What is in it

  • config/initializers/rack_attack.rb limits sign in attempts by IP and by username.
  • authentication_api.rb and authentication_helpers.rb keep callback credentials out of URLs and logs, and renew refresh tokens before they expire.
  • federated_identity_helper.rb matches a login only on what the identity provider asserted.
  • lti_api.rb, lti_helper.rb and the new ConsumedLtiToken model with its migration bind each enrolment token to its user and make it single use. d2l_api.rb returns 404 when a unit has no D2L mapping.
  • settings_public_api.rb splits public branding from the settings that now need a signed in user. context_model_helpers.rb limits learning outcome lookups to units and task definitions.
  • sentry_tunnel_middleware.rb limits payload size, and unit_similarity_module.rb runs JPlag in a workspace named only by ids and survives a deleted task.
  • deployApi.Dockerfile and deployAppSvr.Dockerfile pin the base image and drop packages the API does not need.
  • Tests for authentication, refresh cookies, LTI, D2L, context lookups and similarity cleanup.

How this set of PRs works

This is one of 24 PRs from the Thoth Tech T2 2026 Features team (9 api, 14 web, 1 deploy), one per feature per repo. Each one carries that feature's files, taken from our team org's 11.0.x branch, and applied straight onto thoth-tech 11.0.x. Every file is in exactly one PR. Some files are shared between features, so a PR on its own may not build. The demo PR in each repo (api #127, web doubtfire-lms#544) is imported by earlier PRs too, so it has to go in with the rest, not be dropped. Merged in the order below, the set equals our org 11.0.x minus team docs, evidence files, org-only CI and dev setup files. No app code or tests are left out.

On 28 Sep 2026 the set was brought up to our org's latest merges (api ontrack-features-t2-2026#178, web ontrack-features-t2-2026/doubtfire-web#281 and ontrack-features-t2-2026/doubtfire-web#282, deploy ontrack-features-t2-2026/doubtfire-deploy#41). Most PRs got one more commit for that. Two web PRs are new, panels (thoth-tech/doubtfire-web#546) and celebrate (thoth-tech/doubtfire-web#547), for files that were in no PR before.

Merge order, api first, then web, then deploy. In web, panels goes before the pages that use it, and celebrate goes after a11y, whose confetti service it needs.

Built against

  • api: thoth-tech 11.0.x @ dc76a5a0e, taken from org 11.0.x @ a9589b302
  • web: thoth-tech 11.0.x @ 20d1f380c, taken from org 11.0.x @ 0b8a20344
  • deploy: thoth-tech 11.0.x @ 58905969e, taken from org 11.0.x @ 8e560f7e0

Testing

Checked on 28 Sep 2026 with all the branches merged together. This PR was not tested on its own, see above.

  • web: with all 14 web branches merged onto thoth-tech 11.0.x, npm run test:ci runs 2603 tests in 290 files, all passing, and npm run lint and ng build pass. The merged set's app code is the same as our org 11.0.x after fix(profile): save a changed summary email cadence ontrack-features-t2-2026/doubtfire-web#282, where CI passed test, lint (22) and build (22).
  • api: the full Minitest suite passes on the nine api PRs merged onto thoth-tech 11.0.x. 1799 tests, 20182 assertions, 0 failures, 0 errors, 0 skips. It ran through our CI on branch check/upstream-combined-28sep (run), and the database schema check and RuboCop pass there too. The set differs from our org 11.0.x only by the left-out docs, evidence, CI and dev setup files, none of them app code.
  • deploy: production/tests/validate_test.sh, verify_pwa_test.py, publish_release_test.py and nginx_upload_test.py pass. The production compose file loads with docker compose config against .env.production.example, and the development and .devcontainer ones load as they are.

Contributors

Samridh Limbu, Maple Fox

This was referenced Sep 27, 2026
Brings the T2 2026 security work from ontrack-features-t2-2026 11.0.x (reviewed and merged work) onto thoth-tech 11.0.x.

Co-authored-by: maplefoxgit <s223932052@deakin.edu.au>
Co-authored-by: Maple Fox <s223932052@deakin.edu.au>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants