Skip to content

fix(security): T2 2026 permission and security fixes - #535

Open
Clupai8o0 wants to merge 2 commits into
thoth-tech:11.0.xfrom
ontrack-features-t2-2026:upstream-pr/security
Open

Clupai8o0 wants to merge 2 commits into
thoth-tech:11.0.xfrom
ontrack-features-t2-2026:upstream-pr/security

Conversation

@Clupai8o0

@Clupai8o0 Clupai8o0 commented Sep 27, 2026 •

Copy link
Copy Markdown

What this is

Security fixes on the web side, mostly around sign in. Callback credentials are scrubbed from the URL and from error reports, a user returns to the protected page they asked for after signing in, and the images are hardened.

What is in it

  • src/app/security/auth-callback.ts handles the sign in callback and removes credentials from the URL.
  • src/app/security/auth-return-url.service.ts restores the page the user wanted, and refuses routes that should not be returned to.
  • sign-in.component.ts uses both, and keeps setup and LTI flows first.
  • authentication.service.ts loads the protected settings only after sign in, ignores responses from an earlier session, and clears saved comment drafts on sign out.
  • The LTI pages no longer carry the LTI token in the URL, and no longer open a hardcoded localhost address.
  • src/main.ts scrubs credentials before anything reaches Sentry and turns off tracing, replay and Sentry logs.
  • Dockerfile, deploy.Dockerfile, docker-compose.yml and .env.example harden the images, and scripts/verify-deployment-config.js checks the production config.
  • Specs for the callback, the return URL service and the sign in component.
  • One more commit, "feat(theme): page redesign for the security files", brings the page redesign to 5 of this PR's files (1 of them specs). It comes from feat(theme): reland dark mode and the page redesign on 11.0.x ontrack-features-t2-2026/doubtfire-web#280, merged into our org 11.0.x on 27 Sep 2026. The rest of the redesign is feat(theme): page redesign and dark mode for every page #545.

How this set of PRs works

This is one of 24 PRs from the Thoth Tech T2 2026 Features team (9 api, 14 web, 1 deploy), one per feature per repo. Each one carries that feature's files, taken from our team org's 11.0.x branch, and applied straight onto thoth-tech 11.0.x. Every file is in exactly one PR. Some files are shared between features, so a PR on its own may not build. The demo PR in each repo (api #127, web #544) is imported by earlier PRs too, so it has to go in with the rest, not be dropped. Merged in the order below, the set equals our org 11.0.x minus team docs, evidence files, org-only CI and dev setup files. No app code or tests are left out.

On 28 Sep 2026 the set was brought up to our org's latest merges (api ontrack-features-t2-2026/doubtfire-api#178, web ontrack-features-t2-2026#281 and ontrack-features-t2-2026#282, deploy ontrack-features-t2-2026/doubtfire-deploy#41). Most PRs got one more commit for that. Two web PRs are new, panels (#546) and celebrate (#547), for files that were in no PR before.

Merge order, api first, then web, then deploy. In web, panels goes before the pages that use it, and celebrate goes after a11y, whose confetti service it needs.

Built against

  • api: thoth-tech 11.0.x @ dc76a5a0e, taken from org 11.0.x @ a9589b302
  • web: thoth-tech 11.0.x @ 20d1f380c, taken from org 11.0.x @ 0b8a20344
  • deploy: thoth-tech 11.0.x @ 58905969e, taken from org 11.0.x @ 8e560f7e0

Testing

Checked on 28 Sep 2026 with all the branches merged together. This PR was not tested on its own, see above.

  • web: with all 14 web branches merged onto thoth-tech 11.0.x, npm run test:ci runs 2603 tests in 290 files, all passing, and npm run lint and ng build pass. The merged set's app code is the same as our org 11.0.x after fix(profile): save a changed summary email cadence ontrack-features-t2-2026/doubtfire-web#282, where CI passed test, lint (22) and build (22).
  • api: the full Minitest suite passes on the nine api PRs merged onto thoth-tech 11.0.x. 1799 tests, 20182 assertions, 0 failures, 0 errors, 0 skips. It ran through our CI on branch check/upstream-combined-28sep (run), and the database schema check and RuboCop pass there too. The set differs from our org 11.0.x only by the left-out docs, evidence, CI and dev setup files, none of them app code.
  • deploy: production/tests/validate_test.sh, verify_pwa_test.py, publish_release_test.py and nginx_upload_test.py pass. The production compose file loads with docker compose config against .env.production.example, and the development and .devcontainer ones load as they are.

Contributors

Samridh Limbu, Maple Fox, Niethin

Brings the T2 2026 security work from ontrack-features-t2-2026 11.0.x (reviewed and merged work) onto thoth-tech 11.0.x.

Co-authored-by: maplefoxgit <s223932052@deakin.edu.au>
Co-authored-by: Maple Fox <s223932052@deakin.edu.au>
Co-authored-by: Niethin <niethinrueshil@gmail.com>
Brings the dark mode page redesign (#280, which relands
#192)
to the files this PR already carries, so every file stays in exactly one PR.

Co-authored-by: Maple Fox <s223932052@deakin.edu.au>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants