Commit Graph
1483 Commits
Author SHA1 Message Date
Jeppe B a5b674286a Merge pull request #205 from copenhagentruckwash/fix-order-update-vulnerability-for-invoice-collection
Validate invoice collection ownership when updating orders
2026-06-01 22:54:31 +02:00
copilot-swe-agent[bot] 18bf7aa013 Resolve merge conflict: combine invoice collection ownership validation with auto-reassign guard 2026-06-01 20:53:42 +00:00
Jeppe B bf8262b64f Validate invoice collection ownership when updating orders 2026-06-01 22:51:09 +02:00
Jeppe B fdb073f17f Merge pull request #204 from copenhagentruckwash/fix-unauthenticated-sync-usage-endpoint
Enforce permission on XLVask sync-usage route
2026-06-01 22:50:42 +02:00
Jeppe B 20fcd4ac16 Protect XLVask sync-usage route with permission check 2026-06-01 22:50:33 +02:00
Jeppe B 0f7d76d96d Merge pull request #203 from copenhagentruckwash/fix-unauthenticated-limble-endpoints
Enforce Limble route permissions and secure Limble HTTP requests
2026-06-01 22:50:10 +02:00
Jeppe B 324f2c856f Fix Limble auth and secure request handling 2026-06-01 22:50:00 +02:00
Jeppe B 84f203939c Merge pull request #202 from copenhagentruckwash/fix-unauthenticated-limble-webhook-vulnerability
Prevent credential leak in Limble request error path
2026-06-01 22:49:38 +02:00
Jeppe B 368501a8ce Fix Limble request error path credential leak 2026-06-01 22:49:29 +02:00
Jeppe B d9a36e4050 Merge pull request #201 from copenhagentruckwash/fix-idor-vulnerability-in-attachment-endpoints
Ensure attachment belongs to task before download/delete (fix IDOR)
2026-06-01 22:48:14 +02:00
Jeppe B a5019efbda Fix task attachment IDOR in self-serve endpoints 2026-06-01 22:48:04 +02:00
Jeppe B b16a07fdbb Merge pull request #200 from copenhagentruckwash/fix-subuser-permission-vulnerability
Harden subuser permission customer context resolution
2026-06-01 22:46:50 +02:00
Jeppe B ca02fd3436 Harden subuser permission customer context resolution 2026-06-01 22:46:40 +02:00
Jeppe B 65283b8ad7 Merge pull request #196 from copenhagentruckwash/fix-sql-injection-in-recommended-order-lookup
Escape plate input to prevent SQL injection in recommended-order lookup
2026-06-01 22:45:46 +02:00
Jeppe B ad53041bfd Merge pull request #197 from copenhagentruckwash/fix-department-lanes-access-vulnerability
Enforce department scoping in department lanes routes
2026-06-01 22:45:34 +02:00
Jeppe B b11b38a95b Merge pull request #198 from copenhagentruckwash/fix-lane-ownership-validation-for-commands
Enforce department scoping for self-serve lane command route
2026-06-01 22:45:23 +02:00
Jeppe B ba9c4d3b9f Merge pull request #199 from copenhagentruckwash/fix-missing-department-access-checks
Require department-level access for /departments/self-serve/enabled endpoints
2026-06-01 22:45:11 +02:00
copilot-swe-agent[bot] ded497b3d8 Merge remote-tracking branch 'origin/master' into fix-missing-department-access-checks
# Conflicts:
#	services/nginx/app/routes/departmentsRoute.php
2026-06-01 20:43:01 +00:00
copilot-swe-agent[bot] 2fd3ce4877 Merge remote-tracking branch 'origin/master' into fix-department-lanes-access-vulnerability
# Conflicts:
#	services/nginx/app/routes/departmentLanesRoute.php
2026-06-01 20:42:43 +00:00
copilot-swe-agent[bot] 64fc70a0a8 Merge remote-tracking branch 'origin/master' into fix-lane-ownership-validation-for-commands
# Conflicts:
#	services/nginx/app/routes/moduleSelfServeRoute.php
2026-06-01 20:41:57 +00:00
Jeppe B 42acf26ee1 Merge pull request #193 from copenhagentruckwash/fix-subuser-tokens-allowing-user-impersonation
Prevent subuser session token escalation into user auth
2026-06-01 22:41:35 +02:00
Jeppe B fe6eae862f Merge pull request #194 from copenhagentruckwash/fix-missing-department-authorization-for-payment-intents
Require department access on Stripe payment-intent routes
2026-06-01 22:41:24 +02:00
copilot-swe-agent[bot] eedde6c6d7 Merge origin/master and resolve orders_o conflict 2026-06-01 20:41:18 +00:00
copilot-swe-agent[bot] 2782afde2e Merge master into branch and re-apply department access checks on Stripe payment-intent routes 2026-06-01 20:40:30 +00:00
Jeppe B 484529660b Enforce department access on self-serve status routes 2026-06-01 22:39:52 +02:00
copilot-swe-agent[bot] fbe700a4db Merge remote-tracking branch 'origin/master' into fix-subuser-tokens-allowing-user-impersonation
# Conflicts:
#	services/nginx/app/classes/authentication.php
2026-06-01 20:39:16 +00:00
Jeppe B 6225c4b072 Enforce department access for self-serve lane commands 2026-06-01 22:39:14 +02:00
Jeppe B 300a37fce3 Enforce department access in department lanes routes 2026-06-01 22:38:53 +02:00
Jeppe B c43618351e Escape plate in recommended order SQL lookup 2026-06-01 22:37:55 +02:00
Jeppe B b3225c8d8b Merge pull request #195 from copenhagentruckwash/fix-sql-injection-in-filter-handling
Fix SQL injection in array-based pagination filters
2026-06-01 22:37:38 +02:00
Jeppe B 0f96247bf3 Fix SQL injection in array pagination filters 2026-06-01 22:37:28 +02:00
Jeppe B 4703e07951 Enforce department access on Stripe payment intent order routes 2026-06-01 22:36:49 +02:00
Jeppe B 7ddda9ab03 Merge pull request #190 from copenhagentruckwash/fix-2fa-token-validation-bypass
Enforce auth token types to prevent 2FA bypass
2026-06-01 22:36:18 +02:00
copilot-swe-agent[bot] 4e9575cd87 Merge master and resolve conflict: use rawToken in get_user() exception-handled lookup 2026-06-01 20:35:51 +00:00
Jeppe B ef82a95feb Merge pull request #186 from copenhagentruckwash/propose-fix-for-edge-broker-vulnerability
Harden edge broker defaults and restrict compose exposure
2026-06-01 22:35:45 +02:00
Jeppe B fd4ec3dda2 Fix subuser token confusion in user auth flow 2026-06-01 22:35:24 +02:00
Jeppe B 1616bd431a Merge pull request #192 from copenhagentruckwash/fix-subuser-permission-evaluation-vulnerability
Use resolved customer context in subuser permission checks
2026-06-01 22:34:56 +02:00
copilot-swe-agent[bot] 334a7a4401 Merge origin/master into propose-fix-for-edge-broker-vulnerability, resolving conflicts 2026-06-01 20:34:47 +00:00
Jeppe B 22dd9f9c07 Fix subuser permission checks to use resolved customer context 2026-06-01 22:34:45 +02:00
Jeppe B 5684da1bc7 Merge pull request #191 from copenhagentruckwash/fix-sql-injection-in-gate/relay-creation
Escape JSON-encoded values in add_object to prevent SQL injection
2026-06-01 22:34:00 +02:00
Jeppe B 69cd039322 Escape JSON values in add_object inserts 2026-06-01 22:33:49 +02:00
Jeppe B 0dc7f813a8 Merge pull request #188 from copenhagentruckwash/propose-fix-for-relay-control-bypass-vulnerability
Fix self-serve relay sync to enforce lane safety guards
2026-06-01 22:33:11 +02:00
copilot-swe-agent[bot] a828e9bc25 Merge origin/master into propose-fix-for-edge-broker-vulnerability, resolving all conflicts 2026-06-01 20:27:11 +00:00
copilot-swe-agent[bot] 8d2e71aaf3 Merge origin/master and resolve self-serve relay sync conflicts 2026-06-01 20:23:09 +00:00
Jeppe B 721e2670dd Reject 2FA verification tokens for API authentication 2026-06-01 22:22:42 +02:00
Jeppe B b03500d2d1 Merge pull request #189 from copenhagentruckwash/fix-subuser-token-authorization-vulnerability
Validate subuser grants before resolving subuser customer context
2026-06-01 22:21:58 +02:00
Jeppe B ed9ebc2ac8 Validate subuser grants before resolving customer user 2026-06-01 22:21:44 +02:00
Jeppe B 64beb38bae Fix self-serve relay sync to enforce lane safety guards 2026-06-01 22:19:34 +02:00
Jeppe B e13bbae01f Merge pull request #184 from copenhagentruckwash/fix-edge-broker-default-shared-secret-issue
Harden edge broker shared secret defaults
2026-06-01 22:17:57 +02:00
Jeppe B 5ba0f5f9ba Merge pull request #183 from copenhagentruckwash/fix-credential-exposure-in-.env.old
Remove leaked `.env.old` with credentials and add to `.gitignore`
2026-06-01 22:17:30 +02:00