Conversation
…n-ticket] Implementa validación server-side de identidad y permisos en getUserLogs() para prevenir exposición de logs de otros usuarios (riesgo ALTO). Cambios: - Valida que Session.getActiveUser() === usuario si no es ADMIN - Requier permiso 'PERMISOS' para ver logs de terceros - Registra intento denegado en auditoría con logAction() - Caso especial 'ALL' automáticamente cubierto (requiere ADMIN) Verificación: - Grep exhaustivo: saveTrackingData no está expuesta al cliente - Grep exhaustivo: getUserLogs expuesta en app_permisos_js.html:59 - Matriz PERMISOS: solo Administrador tiene 'PERMISOS' Auditoría: se registra ACCESO_LOGS_DENEGADO con contexto completo. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
…n-ticket]
Agrupa cambios de Fase 0 y Fase 1 previamente sin commitear:
- config.js: Agregar ADMIN_SISTEMA, PAC_APROBAR a PERMISOS_POR_ROL
- permisos.js: Método validarPermiso(accionRequerida) con validación RBAC
- pac_api.js: pac_verificarRolAdmin() usa validarPermiso('PAC_APROBAR')
- pac_api.js: getPACData() con guard validarPermiso('EDITAR')
- Codigo.js: initializeSystem() con guard validarPermiso('ADMIN_SISTEMA')
- Codigo.js: logAction() captura Session.getActiveUser() server-side
Nota: estos cambios fueron implementados en sesiones anteriores pero
no fueron commiteados hasta ahora. Se consolidan en un único commit
para mantener trazabilidad clara antes de clasp push a producción.
Validación: grep confirma todas las funciones modificadas en HEAD.
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
…ket] Excluye archivos de Node.js, documentación, logs y carpetas de desarrollo para evitar errores de sintaxis al desplegar con 'clasp push'. Problema resuelto: scripts/lint-html-scripts.js causaba ParseError al ser pusheado a Google Apps Script. Ahora solo se sincronizan archivos .js, .html, .json del proyecto Apps Script. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
…-ticket]
Implementa validación server-side de permisos en 5 funciones críticas
de gestión de reportes y exportación PDF. Patrón: 2 try/catch separados
(permisos vs. lógica de negocio).
Cambios:
- saveReport(): validarPermiso('REPORTES') + whitelist de roles
- executeReport(): validarPermiso('REPORTES')
- deleteReport(): validarPermiso('ELIMINAR')
- generarFichaPredialPdfBackend(): validarPermiso('REPORTES')
- generarReporteAlertasPdfBackend(): validarPermiso('REPORTES')
Validación server-side con Session.getActiveUser(), logAction auditoría.
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
…Fase 3 [sin-ticket]
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cierre de Sesión - Auditoría RBAC Completada
Resumen
Cierre formal de sesión 2026-09-23 con auditoría RBAC en 18 funciones críticas completada exitosamente.
Cambios
Status
✅ 18/18 funciones protegidas
✅ Fases 0/1/2/3 completadas
✅ Despliegue en producción exitoso
✅ GitHub backup realizado
Refs: Commits 6d680de, 7178948, 1498982, cc208ce, 5a02fea
Co-Authored-By: Claude Haiku 4.5 noreply@anthropic.com