Jeppe B
|
a5b674286a
|
Merge pull request #205 from copenhagentruckwash/fix-order-update-vulnerability-for-invoice-collection
Validate invoice collection ownership when updating orders
|
2026-06-01 22:54:31 +02:00 |
|
copilot-swe-agent[bot]
|
18bf7aa013
|
Resolve merge conflict: combine invoice collection ownership validation with auto-reassign guard
|
2026-06-01 20:53:42 +00:00 |
|
Jeppe B
|
bf8262b64f
|
Validate invoice collection ownership when updating orders
|
2026-06-01 22:51:09 +02:00 |
|
Jeppe B
|
fdb073f17f
|
Merge pull request #204 from copenhagentruckwash/fix-unauthenticated-sync-usage-endpoint
Enforce permission on XLVask sync-usage route
|
2026-06-01 22:50:42 +02:00 |
|
Jeppe B
|
20fcd4ac16
|
Protect XLVask sync-usage route with permission check
|
2026-06-01 22:50:33 +02:00 |
|
Jeppe B
|
0f7d76d96d
|
Merge pull request #203 from copenhagentruckwash/fix-unauthenticated-limble-endpoints
Enforce Limble route permissions and secure Limble HTTP requests
|
2026-06-01 22:50:10 +02:00 |
|
Jeppe B
|
324f2c856f
|
Fix Limble auth and secure request handling
|
2026-06-01 22:50:00 +02:00 |
|
Jeppe B
|
84f203939c
|
Merge pull request #202 from copenhagentruckwash/fix-unauthenticated-limble-webhook-vulnerability
Prevent credential leak in Limble request error path
|
2026-06-01 22:49:38 +02:00 |
|
Jeppe B
|
368501a8ce
|
Fix Limble request error path credential leak
|
2026-06-01 22:49:29 +02:00 |
|
Jeppe B
|
d9a36e4050
|
Merge pull request #201 from copenhagentruckwash/fix-idor-vulnerability-in-attachment-endpoints
Ensure attachment belongs to task before download/delete (fix IDOR)
|
2026-06-01 22:48:14 +02:00 |
|
Jeppe B
|
a5019efbda
|
Fix task attachment IDOR in self-serve endpoints
|
2026-06-01 22:48:04 +02:00 |
|
Jeppe B
|
b16a07fdbb
|
Merge pull request #200 from copenhagentruckwash/fix-subuser-permission-vulnerability
Harden subuser permission customer context resolution
|
2026-06-01 22:46:50 +02:00 |
|
Jeppe B
|
ca02fd3436
|
Harden subuser permission customer context resolution
|
2026-06-01 22:46:40 +02:00 |
|
Jeppe B
|
65283b8ad7
|
Merge pull request #196 from copenhagentruckwash/fix-sql-injection-in-recommended-order-lookup
Escape plate input to prevent SQL injection in recommended-order lookup
|
2026-06-01 22:45:46 +02:00 |
|
Jeppe B
|
ad53041bfd
|
Merge pull request #197 from copenhagentruckwash/fix-department-lanes-access-vulnerability
Enforce department scoping in department lanes routes
|
2026-06-01 22:45:34 +02:00 |
|
Jeppe B
|
b11b38a95b
|
Merge pull request #198 from copenhagentruckwash/fix-lane-ownership-validation-for-commands
Enforce department scoping for self-serve lane command route
|
2026-06-01 22:45:23 +02:00 |
|
Jeppe B
|
ba9c4d3b9f
|
Merge pull request #199 from copenhagentruckwash/fix-missing-department-access-checks
Require department-level access for /departments/self-serve/enabled endpoints
|
2026-06-01 22:45:11 +02:00 |
|
copilot-swe-agent[bot]
|
ded497b3d8
|
Merge remote-tracking branch 'origin/master' into fix-missing-department-access-checks
# Conflicts:
# services/nginx/app/routes/departmentsRoute.php
|
2026-06-01 20:43:01 +00:00 |
|
copilot-swe-agent[bot]
|
2fd3ce4877
|
Merge remote-tracking branch 'origin/master' into fix-department-lanes-access-vulnerability
# Conflicts:
# services/nginx/app/routes/departmentLanesRoute.php
|
2026-06-01 20:42:43 +00:00 |
|
copilot-swe-agent[bot]
|
64fc70a0a8
|
Merge remote-tracking branch 'origin/master' into fix-lane-ownership-validation-for-commands
# Conflicts:
# services/nginx/app/routes/moduleSelfServeRoute.php
|
2026-06-01 20:41:57 +00:00 |
|
Jeppe B
|
42acf26ee1
|
Merge pull request #193 from copenhagentruckwash/fix-subuser-tokens-allowing-user-impersonation
Prevent subuser session token escalation into user auth
|
2026-06-01 22:41:35 +02:00 |
|
Jeppe B
|
fe6eae862f
|
Merge pull request #194 from copenhagentruckwash/fix-missing-department-authorization-for-payment-intents
Require department access on Stripe payment-intent routes
|
2026-06-01 22:41:24 +02:00 |
|
copilot-swe-agent[bot]
|
eedde6c6d7
|
Merge origin/master and resolve orders_o conflict
|
2026-06-01 20:41:18 +00:00 |
|
copilot-swe-agent[bot]
|
2782afde2e
|
Merge master into branch and re-apply department access checks on Stripe payment-intent routes
|
2026-06-01 20:40:30 +00:00 |
|
Jeppe B
|
484529660b
|
Enforce department access on self-serve status routes
|
2026-06-01 22:39:52 +02:00 |
|
copilot-swe-agent[bot]
|
fbe700a4db
|
Merge remote-tracking branch 'origin/master' into fix-subuser-tokens-allowing-user-impersonation
# Conflicts:
# services/nginx/app/classes/authentication.php
|
2026-06-01 20:39:16 +00:00 |
|
Jeppe B
|
6225c4b072
|
Enforce department access for self-serve lane commands
|
2026-06-01 22:39:14 +02:00 |
|
Jeppe B
|
300a37fce3
|
Enforce department access in department lanes routes
|
2026-06-01 22:38:53 +02:00 |
|
Jeppe B
|
c43618351e
|
Escape plate in recommended order SQL lookup
|
2026-06-01 22:37:55 +02:00 |
|
Jeppe B
|
b3225c8d8b
|
Merge pull request #195 from copenhagentruckwash/fix-sql-injection-in-filter-handling
Fix SQL injection in array-based pagination filters
|
2026-06-01 22:37:38 +02:00 |
|
Jeppe B
|
0f96247bf3
|
Fix SQL injection in array pagination filters
|
2026-06-01 22:37:28 +02:00 |
|
Jeppe B
|
4703e07951
|
Enforce department access on Stripe payment intent order routes
|
2026-06-01 22:36:49 +02:00 |
|
Jeppe B
|
7ddda9ab03
|
Merge pull request #190 from copenhagentruckwash/fix-2fa-token-validation-bypass
Enforce auth token types to prevent 2FA bypass
|
2026-06-01 22:36:18 +02:00 |
|
copilot-swe-agent[bot]
|
4e9575cd87
|
Merge master and resolve conflict: use rawToken in get_user() exception-handled lookup
|
2026-06-01 20:35:51 +00:00 |
|
Jeppe B
|
ef82a95feb
|
Merge pull request #186 from copenhagentruckwash/propose-fix-for-edge-broker-vulnerability
Harden edge broker defaults and restrict compose exposure
|
2026-06-01 22:35:45 +02:00 |
|
Jeppe B
|
fd4ec3dda2
|
Fix subuser token confusion in user auth flow
|
2026-06-01 22:35:24 +02:00 |
|
Jeppe B
|
1616bd431a
|
Merge pull request #192 from copenhagentruckwash/fix-subuser-permission-evaluation-vulnerability
Use resolved customer context in subuser permission checks
|
2026-06-01 22:34:56 +02:00 |
|
copilot-swe-agent[bot]
|
334a7a4401
|
Merge origin/master into propose-fix-for-edge-broker-vulnerability, resolving conflicts
|
2026-06-01 20:34:47 +00:00 |
|
Jeppe B
|
22dd9f9c07
|
Fix subuser permission checks to use resolved customer context
|
2026-06-01 22:34:45 +02:00 |
|
Jeppe B
|
5684da1bc7
|
Merge pull request #191 from copenhagentruckwash/fix-sql-injection-in-gate/relay-creation
Escape JSON-encoded values in add_object to prevent SQL injection
|
2026-06-01 22:34:00 +02:00 |
|
Jeppe B
|
69cd039322
|
Escape JSON values in add_object inserts
|
2026-06-01 22:33:49 +02:00 |
|
Jeppe B
|
0dc7f813a8
|
Merge pull request #188 from copenhagentruckwash/propose-fix-for-relay-control-bypass-vulnerability
Fix self-serve relay sync to enforce lane safety guards
|
2026-06-01 22:33:11 +02:00 |
|
copilot-swe-agent[bot]
|
a828e9bc25
|
Merge origin/master into propose-fix-for-edge-broker-vulnerability, resolving all conflicts
|
2026-06-01 20:27:11 +00:00 |
|
copilot-swe-agent[bot]
|
8d2e71aaf3
|
Merge origin/master and resolve self-serve relay sync conflicts
|
2026-06-01 20:23:09 +00:00 |
|
Jeppe B
|
721e2670dd
|
Reject 2FA verification tokens for API authentication
|
2026-06-01 22:22:42 +02:00 |
|
Jeppe B
|
b03500d2d1
|
Merge pull request #189 from copenhagentruckwash/fix-subuser-token-authorization-vulnerability
Validate subuser grants before resolving subuser customer context
|
2026-06-01 22:21:58 +02:00 |
|
Jeppe B
|
ed9ebc2ac8
|
Validate subuser grants before resolving customer user
|
2026-06-01 22:21:44 +02:00 |
|
Jeppe B
|
64beb38bae
|
Fix self-serve relay sync to enforce lane safety guards
|
2026-06-01 22:19:34 +02:00 |
|
Jeppe B
|
e13bbae01f
|
Merge pull request #184 from copenhagentruckwash/fix-edge-broker-default-shared-secret-issue
Harden edge broker shared secret defaults
|
2026-06-01 22:17:57 +02:00 |
|
Jeppe B
|
5ba0f5f9ba
|
Merge pull request #183 from copenhagentruckwash/fix-credential-exposure-in-.env.old
Remove leaked `.env.old` with credentials and add to `.gitignore`
|
2026-06-01 22:17:30 +02:00 |
|