copilot-swe-agent[bot]
|
3555904423
|
Merge origin/master and resolve invoice_period_flag_service conflict
|
2026-06-01 21:37:53 +00:00 |
|
Jeppe B
|
dcd57c7092
|
Merge pull request #221 from copenhagentruckwash/fix-system-search-associations-vulnerability
Prevent association expansion from bypassing own-only access
|
2026-06-01 23:31:00 +02:00 |
|
Jeppe B
|
bd7deaeded
|
Fix invoice period flag cache fallbacks
|
2026-06-01 23:29:05 +02:00 |
|
Jeppe B
|
07a3ef6418
|
Merge pull request #237 from copenhagentruckwash/fix-concurrent-access-vulnerability-in-start-command
Add per-lane START lock to prevent TOCTOU relay replay on wash start
|
2026-06-01 23:28:45 +02:00 |
|
Jeppe B
|
bffed6f5f3
|
Fix self-serve start relay race
|
2026-06-01 23:28:36 +02:00 |
|
Jeppe B
|
bfec31f94b
|
Merge pull request #236 from copenhagentruckwash/fix-task-attachment-link-vulnerability
Enforce lane department authorization for self-serve eligibility
|
2026-06-01 23:28:05 +02:00 |
|
Jeppe B
|
2123835aae
|
Fix self-serve eligibility lane authorization
|
2026-06-01 23:27:56 +02:00 |
|
Jeppe B
|
11f06e8f53
|
Merge pull request #235 from copenhagentruckwash/investigate-self-serve-path-projection-dos-vulnerability
Clamp self-serve path projection limits
|
2026-06-01 23:27:33 +02:00 |
|
Jeppe B
|
6712368323
|
Clamp self-serve path projection limits
|
2026-06-01 23:27:22 +02:00 |
|
Jeppe B
|
99fe659dbc
|
Merge pull request #234 from copenhagentruckwash/propose-fix-for-archived-department-vulnerability
Fix department archived filter smuggling
|
2026-06-01 23:27:06 +02:00 |
|
Jeppe B
|
357cfda46e
|
Fix department archived filter smuggling
|
2026-06-01 23:26:57 +02:00 |
|
Jeppe B
|
9c85135a07
|
Merge pull request #233 from copenhagentruckwash/fix-cross-tenant-vehicle-reference-leak
Restrict vehicle reference suggestions by department context
|
2026-06-01 23:26:36 +02:00 |
|
Jeppe B
|
a8a47104dd
|
Restrict vehicle reference suggestions by department context
|
2026-06-01 23:26:27 +02:00 |
|
Jeppe B
|
2c0907c486
|
Merge pull request #232 from copenhagentruckwash/fix-vulnerability-in-automatic-invoice-flags
Fix automatic invoice period flag suppression
|
2026-06-01 23:26:02 +02:00 |
|
Jeppe B
|
0ae28af309
|
Fix invoice period automatic flag cache misses
|
2026-06-01 23:25:54 +02:00 |
|
copilot-swe-agent[bot]
|
64d7e6f061
|
Merge master into fix-system-search-associations-vulnerability
|
2026-06-01 21:25:51 +00:00 |
|
Jeppe B
|
4f9a10402b
|
Merge pull request #231 from copenhagentruckwash/fix-exposure-of-private-git-commit-metadata
Redact GitHub commit metadata from public release runtime
|
2026-06-01 23:25:38 +02:00 |
|
Jeppe B
|
5e8ec85943
|
Redact release GitHub metadata from public runtime
|
2026-06-01 23:25:28 +02:00 |
|
Jeppe B
|
20d6056e40
|
Merge pull request #230 from copenhagentruckwash/fix-permission-bypass-for-invoice-flags
Guard invoice period flags by list permission
|
2026-06-01 23:25:02 +02:00 |
|
Jeppe B
|
5be6bc0198
|
Guard invoice period flags by list permission
|
2026-06-01 23:24:50 +02:00 |
|
Jeppe B
|
5282ee10ba
|
Merge pull request #229 from copenhagentruckwash/propose-fix-for-booking-po-vulnerability
Validate booking ownership before defaulting order PO (prevent cross-tenant leak)
|
2026-06-01 23:24:00 +02:00 |
|
Jeppe B
|
eab8394579
|
Fix booking PO default tenant validation
|
2026-06-01 23:23:49 +02:00 |
|
Jeppe B
|
b88c2742e8
|
Merge pull request #228 from copenhagentruckwash/fix-partial-release-tests-bypassing-promotion-gate
Require app-scoped release gates for bundle promotion
|
2026-06-01 23:23:34 +02:00 |
|
Jeppe B
|
4ea5eeb942
|
Require app-scoped release gates for bundle promotion
|
2026-06-01 23:23:23 +02:00 |
|
Jeppe B
|
7cb248a112
|
Merge pull request #226 from copenhagentruckwash/fix-ssrf-vulnerability-in-release-gate
Harden release gate diagnostics fetches
|
2026-06-01 23:17:01 +02:00 |
|
Jeppe B
|
dfa0441266
|
Harden release gate diagnostics fetches
|
2026-06-01 23:16:51 +02:00 |
|
Jeppe B
|
a0b1dcb3e3
|
Fix system search association expansion for own-only types
|
2026-06-01 23:13:50 +02:00 |
|
Jeppe B
|
38c4c32f07
|
Merge pull request #220 from copenhagentruckwash/fix-empty-edge-broker-secret-vulnerability
Fail closed when edge broker secret is missing
|
2026-06-01 23:13:13 +02:00 |
|
Jeppe B
|
b6beb9622b
|
Fail closed when edge broker secret is missing
|
2026-06-01 23:13:04 +02:00 |
|
Jeppe B
|
db80dad15f
|
Merge pull request #219 from copenhagentruckwash/propose-fix-for-unauthenticated-pdf-access
Fix unauthenticated PDF disclosure in file_server fallback
|
2026-06-01 23:12:00 +02:00 |
|
Jeppe B
|
cf370a8035
|
Fix unauthenticated pdf_store access in file server
|
2026-06-01 23:11:48 +02:00 |
|
Jeppe B
|
0778776f00
|
Merge pull request #218 from copenhagentruckwash/fix-machine-relay-helper-logic
Fix hard MACHINE relay targeting
|
2026-06-01 23:11:13 +02:00 |
|
Jeppe B
|
ee55c23cde
|
Fix hard machine relay targeting
|
2026-06-01 23:11:01 +02:00 |
|
Jeppe B
|
1f50c83f93
|
Merge pull request #217 from copenhagentruckwash/fix-unauthenticated-/files/-attachment-access
Require authentication for direct /files/ access
|
2026-06-01 23:09:47 +02:00 |
|
Jeppe B
|
85f7bd1fc9
|
Require auth for direct /files/ downloads
|
2026-06-01 23:09:37 +02:00 |
|
Jeppe B
|
8f53e80ede
|
Merge pull request #216 from copenhagentruckwash/fix-vulnerability-in-wash-certificate-access
Disable global .pdf shortcut to prevent unauthenticated certificate downloads
|
2026-06-01 23:09:03 +02:00 |
|
Jeppe B
|
2a1a730a8c
|
Fix unauthenticated direct PDF certificate serving
|
2026-06-01 23:08:53 +02:00 |
|
copilot-swe-agent[bot]
|
1065973b33
|
Merge master into fix-sql-injection-in-vehicle-plate-lookup
|
2026-06-01 21:07:49 +00:00 |
|
Jeppe B
|
1d05550cd3
|
Merge pull request #215 from copenhagentruckwash/fix-start-command-relay-activation-vulnerability
Fix self-serve START relay deferral bypass
|
2026-06-01 23:05:10 +02:00 |
|
Jeppe B
|
2cc12c23cd
|
Fix self-serve start relay deferral
|
2026-06-01 23:04:59 +02:00 |
|
Jeppe B
|
d1871f1420
|
Fix SQL injection in vehicle plate order history lookup
|
2026-06-01 23:03:18 +02:00 |
|
Jeppe B
|
08a1538ed6
|
Merge pull request #212 from copenhagentruckwash/propose-fix-for-sql-injection-vulnerability
Cast pickup_bool to int to prevent SQL injection in bookings sync
|
2026-06-01 23:02:38 +02:00 |
|
Jeppe B
|
f2fc4f6f18
|
Fix SQL injection risk in booking sync pickup_bool
|
2026-06-01 23:02:28 +02:00 |
|
Jeppe B
|
503fd50c61
|
Merge pull request #211 from copenhagentruckwash/fix-vulnerability-in-wash-certificate-pdf-handling
Restore deletion of local wash certificate PDFs after upload
|
2026-06-01 23:02:12 +02:00 |
|
Jeppe B
|
1d6df82c1c
|
Delete local wash certificate PDFs after upload
|
2026-06-01 23:02:01 +02:00 |
|
Jeppe B
|
3fda0f9912
|
Merge pull request #210 from copenhagentruckwash/fix-auth-bypass-in-booking-sync-endpoint
Remove hardcoded auth_key bypass from /admin/bookings/sync
|
2026-06-01 23:01:37 +02:00 |
|
Jeppe B
|
decc571307
|
Fix booking sync auth bypass
|
2026-06-01 23:01:28 +02:00 |
|
Jeppe B
|
ef237b5e87
|
Merge pull request #206 from copenhagentruckwash/fix-sql-injection-in-vehicle-plate-history
Fix SQL injection in vehicle plate order history lookup
|
2026-06-01 22:59:14 +02:00 |
|
Jeppe B
|
828c177a57
|
Merge pull request #207 from copenhagentruckwash/fix-order-item-update-idor-vulnerability
Enforce tenant ownership check for PUT /order/items to prevent IDOR
|
2026-06-01 22:59:03 +02:00 |
|
copilot-swe-agent[bot]
|
c79219eb00
|
Merge remote-tracking branch 'origin/master' into fix-order-item-update-idor-vulnerability
# Conflicts:
# services/nginx/app/routes/orderItemsRoute.php
|
2026-06-01 20:58:04 +00:00 |
|