Repository navigation
Conversation
…lines Switch shared config to typescript-eslint recommendedTypeChecked with parserOptions.projectService; disableTypeChecked for plain JS config files. Baseline all @game-guild/eslint-config consumers (ui 66 files, infrastructure/client 118 files) via eslint --suppress-all; add lint:baseline regen scripts. Client tsconfig covers examples/ and build configs for the project service.
Add typescript-eslint recommendedTypeChecked (Codacy parity, no-unsafe-* rules) on top of eslint-config-next presets, with projectService and disableTypeChecked scopes for plain-JS and test files (outside tsconfig by design). Baseline: 255 -> 458 files, 363 -> 2993 entries. devDep typescript-eslint@^8.70.0 matches the instance eslint-config-next 16.3.6 resolves to; type-aware lint needs --max-old-space-size (12GB run). Evidence: .omo/evidence/task-4-codacy-quality-debt.md
…e LTI redirect URL
…, use SystemClock
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Rate-limit bypass, unsanitized logging, quadratic parsing, malformed doctest parsing, and stale-export concurrency issues remain.
Review effort: Balanced
Findings: 2
Open (7)
Normalize email before hashing to prevent rate-limit bypass · New Nested bracket parsing can cause quadratic rescanning · New Reject non-positive stale claim thresholds · New Prevent requeue when a newer in-progress claim exists · New Preserve correlation when redacting non-email identifiers · New Sanitize request path in permission-failure logs · New Missing colon validation before parsing line numbers · New
What changed in this PR
Hardens backend/frontend security findings, improves stale audit-export recovery, and enables type-aware linting.
Changes:
- Sanitizes sensitive logs, validates redirects/URLs, and hardens DOM/CSV/object handling.
- Adds stale scheduled-export recovery and tests.
- Strengthens TypeScript typing, lint baselines, and ReDoS-prone parsing.
| File | Description |
|---|---|
tools/emception/scripts/toolchain/provider.ts |
Validates GitHub API host. |
tools/emception/packages/core/src/ui/adapters.ts |
Blocks prototype-pollution keys. |
tools/emception/packages/core/src/testing/doctest/parse.ts |
Replaces regex parsers. |
pnpm-lock.yaml |
Updates resolved tooling dependencies. |
packages/ui/package.json |
Adds lint baseline script. |
packages/ui/eslint-suppressions.json |
Records existing lint debt. |
packages/tooling/eslint/src/index.js |
Enables type-aware linting. |
packages/infrastructure/wasm/dotnet/src/index.ts |
Types compiler global. |
packages/infrastructure/wasm/dotnet/index.html |
Removes unsafe HTML rendering. |
packages/infrastructure/client/tsconfig.json |
Expands checked source scope. |
packages/infrastructure/client/package.json |
Adds lint baseline script. |
packages/infrastructure/client/eslint-suppressions.json |
Records existing lint debt. |
packages/features/lexical-surface/src/index.ts |
Exports Vega theme types. |
packages/features/lexical-surface/src/features/vega-lite/lexical/vega-lite-component.tsx |
Repairs logical expression syntax. |
packages/features/lexical-surface/src/features/vega-lite/editor/vega-lite-export.tsx |
Types Vega theme configuration. |
packages/features/lexical-surface/src/features/mermaid/editor/mermaid-validator.ts |
Replaces arrow regex validation. |
packages/features/courses/src/components/learner/learner-activity-center.tsx |
Replaces trailing-slash regex. |
apps/web/src/components/feed/social-media-preview.tsx |
Restricts preview URL protocols. |
apps/web/src/components/block-content-editor/plugins/preview-components/preview-vega-lite.tsx |
Removes unsafe theme casts. |
apps/web/src/components/block-content-editor/plugins/preview-components/preview-text.tsx |
Types serialized text nodes. |
apps/web/src/components/block-content-editor/hooks/editor/executors/typescript-executor.ts |
Handles nested generic syntax. |
apps/web/src/components/block-content-editor/hooks/editor/executors/javascript-executor.ts |
Corrects console argument typing. |
apps/web/src/components/block-content-editor/extras/source-code/xml/xml-syntax-highlighter.tsx |
Bounds XML token regexes. |
apps/web/src/components/block-content-editor/extras/source-code/cpp/cpp-type-checker.tsx |
Types Monaco integration. |
apps/web/src/components/block-content-editor/extras/html/html-utils.ts |
Removes scripts via DOM parsing. |
apps/web/src/components/block-content-editor/extras/code-studio/monaco-file-system.ts |
Types completion provider. |
apps/web/src/app/[locale]/(dashboards)/workspace/learning/courses/[course]/listing/media/page.tsx |
Validates thumbnail protocols. |
apps/web/src/app/[locale]/(dashboards)/console/learning/courses/[course]/listing/media/page.tsx |
Validates thumbnail protocols. |
apps/web/scripts/learning-student-browser-e2e.mjs |
Uses cryptographic identifiers. |
apps/web/scripts/learning-professor-browser-e2e.mjs |
Uses cryptographic identifiers. |
apps/web/scripts/learning-checkout-browser-e2e.mjs |
Uses cryptographic identifiers. |
apps/web/scripts/learning-assets-browser-e2e.mjs |
Uses cryptographic identifiers. |
apps/web/scripts/community-admin-browser-e2e.mjs |
Uses cryptographic identifiers. |
apps/web/package.json |
Adds TypeScript ESLint dependency. |
apps/web/eslint.config.mjs |
Enables type-aware web linting. |
apps/api/tests/GameGuild.Audit.UnitTests/Services/ScheduledAuditExportServiceTests.cs |
Tests stale recovery invocation. |
apps/api/tests/GameGuild.Audit.UnitTests/Services/ScheduledAuditExportRepositoryTests.cs |
Tests stale claim persistence. |
apps/api/Source/Modules/GameGuild.TestingLab/Controllers/TestingLabPermissionController.cs |
Sanitizes permission logs. |
apps/api/Source/Modules/GameGuild.Social.Ratings/Services/RatingQueryService.cs |
Sanitizes rating logs. |
apps/api/Source/Modules/GameGuild.SharedKernel/Middlewares/IdempotencyMiddleware.cs |
Sanitizes replay logs. |
apps/api/Source/Modules/GameGuild.SharedKernel/Middlewares/ExceptionHandlingMiddleware.cs |
Sanitizes exception logs. |
apps/api/Source/Modules/GameGuild.Resources/Services/RedisDistributedRateLimiter.cs |
Sanitizes limiter keys. |
apps/api/Source/Modules/GameGuild.Resources/Services/DistributedCacheRateLimiter.cs |
Sanitizes cache limiter logs. |
apps/api/Source/Modules/GameGuild.Notifications/Services/NotificationDeliveryService.cs |
Redacts notification recipients. |
apps/api/Source/Modules/GameGuild.Notifications/Services/Email/Handlers/TenantInviteRequestedHandler.cs |
Masks invite emails. |
apps/api/Source/Modules/GameGuild.Notifications/Services/Email/EmailEventProcessor.cs |
Masks event recipients. |
apps/api/Source/Modules/GameGuild.Notifications/Services/Email/EmailDispatcherService.cs |
Masks dispatch recipients. |
apps/api/Source/Modules/GameGuild.Notifications/Services/Email/EmailDeliveryAdminService.cs |
Masks suppression emails. |
apps/api/Source/Modules/GameGuild.Notifications/Services/Email/DigestDispatcherService.cs |
Redacts digest recipients. |
apps/api/Source/Modules/GameGuild.Localization/Services/LocalizedErrorService.cs |
Sanitizes localization keys. |
apps/api/Source/Modules/GameGuild.Learning.Lti/Controllers/LtiController.cs |
Hardens deployment and redirects. |
apps/api/Source/Modules/GameGuild.Learning.Certificates/Services/CertificateService.cs |
Sanitizes certificate logs. |
apps/api/Source/Modules/GameGuild.Learning.Assessments.QuizAdapter/QuizProgramContentBoundary.cs |
Removes exception disclosure. |
apps/api/Source/Modules/GameGuild.Identity.Authorization/Services/ResourcePermissionService.cs |
Redacts invitation details. |
apps/api/Source/Modules/GameGuild.Identity.Authorization/Middleware/RequestContextLoggingMiddleware.cs |
Sanitizes request paths. |
apps/api/Source/Modules/GameGuild.Identity.Authorization/Middleware/PermissionCachingMiddleware.cs |
Sanitizes trace paths. |
apps/api/Source/Modules/GameGuild.Identity.Authorization/Middleware/ActorContextMiddleware.cs |
Redacts permission-failure context. |
apps/api/Source/Modules/GameGuild.Identity.Authorization/Middleware/AccessReviewMiddleware.cs |
Sanitizes trace paths. |
apps/api/Source/Modules/GameGuild.Identity.Authorization/Middleware/AbacPolicyMiddleware.cs |
Sanitizes trace paths. |
apps/api/Source/Modules/GameGuild.Identity.Authorization/Controllers/TenantPermissionsController.cs |
Redacts permission logs. |
apps/api/Source/Modules/GameGuild.Identity.Authorization/Controllers/ResourcePermissionsController.cs |
Redacts resource logs. |
apps/api/Source/Modules/GameGuild.Identity.Authorization/Commands/ResourcePermissionCommands.cs |
Masks invitation email. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/UserEnumerationProtectionService.cs |
Redacts email timing hash. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/ThreatDetectionService.cs |
Masks brute-force identifier. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/ServiceAccountService.cs |
Redacts service-account logs. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/PasswordHasher.cs |
Separates password score dataflow. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/OAuthAuthService.cs |
Masks OAuth emails. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/LocalAuthService.cs |
Masks local-auth emails. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/JwtTokenService.cs |
Redacts token metadata. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/EmailVerificationService.cs |
Redacts verification data. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/PermissionCachingMiddleware.cs |
Sanitizes trace paths. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Handlers/SendEmailVerificationCommandHandler.cs |
Masks unknown emails. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Handlers/LocalSignInHandler.cs |
Sanitizes IP logs. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Controllers/ServiceAccountTokenController.cs |
Restructures grant validation. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Controllers/RolesController.cs |
Sanitizes role logs. |
apps/api/Source/Modules/GameGuild.Identity.Authentication/Controllers/KeyRotationController.cs |
Sanitizes rotation logs. |
apps/api/Source/Modules/GameGuild.Features/Services/FeatureFlagEvaluationService.cs |
Sanitizes feature keys. |
apps/api/Source/Modules/GameGuild.Features/Services/CapabilityService.cs |
Sanitizes capability logs. |
apps/api/Source/Modules/GameGuild.Compliance.Audit/Services/ScheduledAuditExportService.cs |
Recovers claims and uses system clock. |
apps/api/Source/Modules/GameGuild.Compliance.Audit/Services/ScheduledAuditExportRepository.cs |
Persists stale-claim recovery. |
apps/api/Source/Modules/GameGuild.Compliance.Audit/Services/AuditExportWebhookNotifier.cs |
Sanitizes webhook logs. |
apps/api/Source/Modules/GameGuild.Compliance.Audit/Services/AuditActionTypeExportFormatter.cs |
Reuses hardened CSV escaping. |
apps/api/Source/Modules/GameGuild.Compliance.Audit/Extensions/AuditModule.cs |
Configures stale-claim threshold. |
apps/api/Source/Modules/GameGuild.Compliance.Audit/Controllers/AuditController.cs |
Sanitizes audit filters. |
apps/api/Source/Modules/GameGuild.Commerce.Payments/Services/StripeCustomerService.cs |
Masks payment emails. |
apps/api/Source/Modules/GameGuild.Commerce.Payments/Repositories/PaymentRepository.cs |
Sanitizes payment identifiers. |
apps/api/Source/Modules/GameGuild.Commerce.Billing/Controllers/BillingWebhooksController.cs |
Sanitizes webhook metadata. |
apps/api/Source/Modules/GameGuild.Assets/Security/SecureAssetDeliveryController.cs |
Sanitizes asset-security logs. |
apps/api/Source/Modules/GameGuild.Assets/Security/AssetRateLimitService.cs |
Sanitizes blocked IP logs. |
apps/api/Source/Modules/GameGuild.Assets/Controllers/AssetsController.cs |
Authorizes before validation. |
apps/api/Source/GameGuild.API/Database/PlatformIdentitySeeder.cs |
Masks seeded admin email. |
apps/api/Source/GameGuild.API/Database/DatabaseSeeder.cs |
Masks legacy admin email. |
apps/api/Source/GameGuild.API/Core/Middleware/RedisEndpointRateLimitingMiddleware.cs |
Sanitizes rate-limit logs. |
apps/api/Source/GameGuild.API/Core/Extensions/RateLimitingServiceCollectionExtensions.cs |
Sanitizes rejection logs. |
apps/api/Source/GameGuild.API/Core/Email/SesEmailSender.cs |
Masks SES recipients. |
apps/api/Source/GameGuild.API/Core/Email/EmailSender.cs |
Masks email recipients. |
apps/api/Source/GameGuild.API/Core/ApiVersioning/ApiVersionUsageMiddleware.cs |
Sanitizes API usage logs. |
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| { | ||
| var rateLimitKey = RateLimitKeyPrefix + $"{userId}:{email.ToLowerInvariant()}"; | ||
| // Deterministic hash keeps the per-(user, email) rate-limit window without caching the raw email. | ||
| var rateLimitKey = RateLimitKeyPrefix + $"{userId}:{LogRedaction.RedactSecret(email)}"; |
| do { | ||
| previous = output | ||
| output = previous.replace(/<[^<>]*>/g, "") | ||
| } while (output !== previous) |
| if (int.TryParse(section[AuditScheduledExportOptions.StaleClaimThresholdMinutesKey], out var staleMinutes)) | ||
| { | ||
| options.StaleClaimThreshold = TimeSpan.FromMinutes(staleMinutes); | ||
| } |
| foreach (var export in exports) | ||
| { | ||
| export.RecordFailure(nowUtc, "Stale claim recovered"); | ||
| export.UpdateNextRunTime(nowUtc); |
| logger.LogWarning( | ||
| "Brute force attack detected - Identifier: {Identifier}, Failed attempts: {FailedCount} in {TimeWindowMinutes} minutes", | ||
| identifier, failedCount, timeWindowMinutes); | ||
| LogRedaction.MaskEmail(identifier), failedCount, timeWindowMinutes); |
| LogRedaction.RedactId(ex.TenantId, "tid"), | ||
| context.TraceIdentifier, | ||
| context.Request.Path); | ||
| context.Request.Path.Value); |
| while (numberStart > 0 && isAsciiDigit(head.charAt(numberStart - 1))) { | ||
| numberStart -= 1; | ||
| } | ||
| if (numberStart === head.length || numberStart === 0) return null; |
Not up to standards ⛔🔴 Issues
|
| Category | Results |
|---|---|
| Compatibility | 8 medium 10 high |
| BestPractice | 6 medium 1 minor |
| Documentation | 4 minor |
| ErrorProne | 1 medium 3 high |
| Performance | 4 medium |
| Comprehensibility | 6 minor |
| Security | 17 critical |
| CodeStyle | 40 minor |
🟢 Metrics 1614 complexity · 32 duplication
Metric Results Complexity 1614 Duplication 32
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
There was a problem hiding this comment.
CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.
| catch (Exception ex) | ||
| { | ||
| logger.LogWarning(ex, "Failed to queue tenant invite notification for {Email}", notification.InviteeEmail); | ||
| logger.LogWarning(ex, "Failed to queue tenant invite notification for {Email}", LogRedaction.MaskEmail(notification.InviteeEmail)); |
| logger.LogInformation( | ||
| "Processed {EventType} delivery event. Recipient: {RecipientEmail}, SuppressionReason: {Reason}, DeadLettered: {DeadLettered}", | ||
| deliveryEvent.EventType, normalized, reason, deadLettered); | ||
| deliveryEvent.EventType, LogRedaction.MaskEmail(normalized), reason, deadLettered); |
| // Record successful registration | ||
| await authAttemptService.RecordSuccessfulAttemptAsync(request.Email, userId, ipAddress ?? "unknown", userAgent, stopwatch.Elapsed, "Registration").ConfigureAwait(false); | ||
| logger.LogInformation("User {Email} successfully signed up", request.Email); | ||
| logger.LogInformation("User {Email} successfully signed up", LogRedaction.MaskEmail(request.Email)); |
| var userId = newUser.Id; | ||
|
|
||
| logger.LogInformation("Created new user with ID: {UserId} and Email: {Email}", userId, newUser.Email); | ||
| logger.LogInformation("Created new user with ID: {UserId} and Email: {Email}", userId, LogRedaction.MaskEmail(newUser.Email)); |
| { | ||
| await enumerationProtection.AddTimingProtectionDelayAsync(true, SystemClock.UtcNow).ConfigureAwait(false); | ||
| logger.LogWarning("Sign-up attempt with existing email: {Email}", request.Email); | ||
| logger.LogWarning("Sign-up attempt with existing email: {Email}", LogRedaction.MaskEmail(request.Email)); |
| { | ||
| failureReason = "InvalidCredentials"; | ||
| logger.LogWarning("User not found: {Email}", request.Email); | ||
| logger.LogWarning("User not found: {Email}", LogRedaction.MaskEmail(request.Email)); |
| { | ||
| failureReason = "InvalidCredentials"; | ||
| logger.LogWarning("Invalid password for user {Email}", request.Email); | ||
| logger.LogWarning("Invalid password for user {Email}", LogRedaction.MaskEmail(request.Email)); |
| if (user is null) | ||
| { | ||
| logger.LogWarning("Verification email requested for unknown email {Email}", notification.Email); | ||
| logger.LogWarning("Verification email requested for unknown email {Email}", LogRedaction.MaskEmail(notification.Email)); |
| throw new InvalidOperationException("Authentication notification was not durably queued."); | ||
|
|
||
| logger.LogInformation("Verification email queued for {Email}", notification.Email); | ||
| logger.LogInformation("Verification email queued for {Email}", LogRedaction.MaskEmail(notification.Email)); |
| { | ||
| logger.LogError(ex, "Error queueing verification email to {Email}", notification.Email); | ||
| logger.LogError("Error queueing verification email to {Email}: {ErrorType}", | ||
| LogRedaction.MaskEmail(notification.Email), ex.GetType().Name); |
| if (user is null) | ||
| { | ||
| logger.LogWarning("Magic-link email requested for unknown email {Email}", notification.Email); | ||
| logger.LogWarning("Magic-link email requested for unknown email {Email}", LogRedaction.MaskEmail(notification.Email)); |
| throw new InvalidOperationException("Authentication notification was not durably queued."); | ||
|
|
||
| logger.LogInformation("Magic-link email queued for {Email}", notification.Email); | ||
| logger.LogInformation("Magic-link email queued for {Email}", LogRedaction.MaskEmail(notification.Email)); |
| throw new InvalidOperationException("Authentication notification was not durably queued."); | ||
|
|
||
| logger.LogInformation("Password reset email queued for {Email}", notification.Email); | ||
| logger.LogInformation("Password reset email queued for {Email}", LogRedaction.MaskEmail(notification.Email)); |
| { | ||
| logger.LogError(ex, "Error queueing password reset email to {Email}", notification.Email); | ||
| logger.LogError("Error queueing password reset email to {Email}: {ErrorType}", | ||
| LogRedaction.MaskEmail(notification.Email), ex.GetType().Name); |
|
|
||
| logger.LogInformation("Welcome email queued for {Email} (ID: {UserId})", notification.Email, notification.UserId); | ||
| logger.LogInformation("Welcome email queued for {Email} (ID: {UserId})", | ||
| LogRedaction.MaskEmail(notification.Email), LogRedaction.RedactId(notification.UserId, "uid")); |
| { | ||
| logger.LogWarning(ex, "Welcome email queueing failed for user {Email} (ID: {UserId})", notification.Email, notification.UserId); | ||
| logger.LogWarning("Welcome email queueing failed for user {Email} (ID: {UserId}): {ErrorType}", | ||
| LogRedaction.MaskEmail(notification.Email), LogRedaction.RedactId(notification.UserId, "uid"), ex.GetType().Name); |
| notification.AuthMethod, | ||
| notification.IpAddress ?? "Unknown", | ||
| LogRedaction.RedactId(notification.UserId, "uid"), | ||
| LogRedaction.MaskEmail(notification.Email), |
adapters.ts setPath (CodeQL prototype-pollution follow-up): the final segment write now uses Object.defineProperty so a hostile inherited setter (e.g. a planted __proto__ poison pill) can never be invoked; blocklist + Object.hasOwn traversal unchanged. doctest parse matchFailureLine: a digit run is only a line number when a ':' immediately precedes it. 'fileX12: ERROR: ...' no longer misparses as file='file', line=12 — it matches with file='fileX12' and no line. Canonical 'src/main.ts:42: ERROR: ...' still parses file + line. Both covered by new regression tests in packages/core/tests.
…t, quiz boundary - AuditModule: reject non-positive StaleClaimThresholdMinutes via options validation - ScheduledAuditExportRepository: skip schedule requeue when a fresh in-progress claim exists - ActorContextMiddleware: sanitize request path in permission-failure log (CWE-117) - LtiController: extract fail-closed authorization redirect validation (https, absolute, no userinfo) - QuizProgramContentBoundary: derive guard from document shape, not caller-supplied content type
CodeQL 'Exposure of private information' cluster (PR #698) flagged every email-logging call site because LogRedaction.MaskEmail collapsed all addresses to a constant, and threat alerts could not correlate repeated identifiers. Replace the constant with deterministic, irreversible masks in the shared platform helper: - MaskEmail: first alnum char of local part + domain + public suffix (alice@example.com -> a***@e***.com); output built only from masked segments, control characters cannot pass through - MaskUsername: first char + length (alice -> a***(5)) - MaskIpAddress: keep octets 1+3 for network correlation (10.20.0.30 -> 10.x.0.x), short hash fallback for non-IPv4 - MaskIdentifier: shape-dispatching mask for security logs where the identifier may be an email, IP, or username ThreatDetectionService brute-force alerts now use MaskIdentifier so repeated attacker identifiers remain correlatable without exposure. Also harden EmailVerificationService token handling: - verification/reset/magic-link tokens are one-time secrets; cache keys are now SHA-256 digests instead of the raw token (clear-text storage findings; no DB persistence involved, so no migration required) - rate-limit bucket digest now normalizes the email (trim + lowercase) so User@x and user@x share one bucket, closing a resend-limit bypass via case variants PasswordHasher strength score inspected: never logged or persisted (IsValid/ValidationFailures are the only consumed fields), no change needed. Tests: LogRedaction determinism/irreversibility/dispatch coverage; mixed-case resend rate-limit bucket test; existing format assertions updated to the new deterministic masks.
…nt close) Companion quadratic-loop fix (stripGenericGroups) was superseded upstream: the TypeScript executor now uses real ts.transpileModule + QuickJS isolation (7cbf392), removing the hand-rolled generic-strip loop entirely.
…nistic masks ThreatDetectionLoggingSecurityTests asserted the old constant 'email:redacted' marker; the correlation-preserving MaskIdentifier output (p***@p***.invalid style) satisfies the same no-leak/no-control- char assertions while keeping brute-force alerts correlatable.
…lized rate-limit keys The redaction cherry-pick accidentally reverted 2a25629's TryConsume/IsConsumed single-use machinery (caught by EmailTokenSingleUseSecurityTests). Restore that version verbatim and re-apply the one surviving piece from our branch: email rate-limit bucket keys now hash Trim().ToLowerInvariant(email) so User@x and user@x share one two-minute resend bucket.
Gate status at 26006c9All workflow checks green except Codacy. CodeQL: 0 open alerts on this branch (all 100 open alerts sit on Remaining red: Codacy (290 new issues). Cannot enumerate from CI artifacts — Codacy API requires the org API token (personal token lands in personal workspace, per prior note). Action needed from someone with Verified locally at this head: web lint + typecheck exit 0 · lint-budget ratchet ok · shell-gate tests 70/71 under bash 5 (1 fail = pnpm absent in container, env-only) · generated client matches fresh Release API regeneration ( |
Fix wave complete: all review findings addressedSecurity fixes (this wave, verified by full test suites):
Superseded (intentionally dropped): our Verification: build 0W/0E · Authentication 2372/2372 · Authorization 1738/1738 · Assessments 477/477 · lint exit 0 · budgets green (web 2774/2777). Merged current develop (#699) — PR is conflict-free. |
Classify canonical localhost DNS spellings before the custom remote asset allowlist check in both web and client guards. Preserve public allowlists, protocol and credential rules, and internal service origin pinning. Add 76 regression cases; qualify 4605 owning tests, typechecks, client build, and uncapped local lint. Hosted scan confirmation remains pending.
# Conflicts: # apps/api/Source/Modules/GameGuild.Identity.Authentication/Entities/ApiKey.cs # apps/api/Source/Modules/GameGuild.Identity.Authentication/Handlers/SendEmailVerificationCommandHandler.cs # apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/EncryptionService.cs # apps/api/Source/Modules/GameGuild.Identity.Authorization/Controllers/AccessReviewsController.cs # apps/api/Source/Modules/GameGuild.Identity.Authorization/Services/DelegatedAdminService.cs # apps/api/Source/Modules/GameGuild.Identity.Authorization/Services/FocusedPermissionServices.cs # apps/api/Source/Modules/GameGuild.Learning.Assessments/Controllers/AssessmentsController.cs # apps/api/Source/Modules/GameGuild.Learning.Assessments/Controllers/GroupSetsController.cs # apps/api/Source/Modules/GameGuild.Learning.Assessments/Controllers/PeerReviewsController.cs # apps/api/Source/Modules/GameGuild.Learning.Assessments/Controllers/RubricsController.cs # apps/api/Source/Modules/GameGuild.Learning.Courses/Controllers/ProgramCrudController.cs # apps/api/Source/Modules/GameGuild.Learning.Courses/Services/ContentInteractionService.cs # apps/api/Source/Modules/GameGuild.Learning.Courses/Services/ProgramWriteService.cs # apps/api/Source/Modules/GameGuild.SharedKernel/Configuration/PresentationLayer/Authorization/AuthorizationCacheOptions.cs # apps/api/tests/GameGuild.Identity.Authentication.IntegrationTests/AuthenticationFlowsE2ETests.cs # apps/web/package.json # apps/web/scripts/build-learning.mjs # apps/web/src/components/ui/date-time-range-picker.test.tsx # packages/infrastructure/client/src/generated/.metadata.json # packages/infrastructure/client/src/generated/types.gen.ts # pnpm-lock.yaml # scripts/dev-learning.mjs


Current remediation checkpoint
Published head: eab098b (signature G; normal push). PR open and unmerged; integration conflicts with develop remain.
Published remote asset URL fixes
Scanner scope and remaining gates
Goal active, no agents. No new ignores, dismissals or fix certificates. All historical references below are preserved byte-for-byte.
Dismissal restoration after user correction
The user clarified that ignoring is not closing/fixing issues. All 94 previously scoped GitHub dismissals have now been reversed and verified individually. The original IDs, dismissal reasons and evidence are retained in the audit record. Restoration is a state repair and is not counted as a source fix.
37579124047, previous exact published head246eef6b0, reports 79 raw results: C# 77, JavaScript 2, Python 0, Actions 0. All 79 locations/messages match1b3980a6c; the capability authorization repair did not remove a raw CodeQL result. The earlier three JavaScript fixture results disappeared after the preserved 168-case fixture cleanup; production code was unchanged by that cleanup.246eef6b0: authenticated actor, tenant scope and administrator checks now protect controller, handlers and service; override/removal audit identity comes from the actor. Baseline: 53 failures/38 controls across 91 HTTP cases plus 74 service/handler failures. After: all 165 new cases pass; full selected gates total 5,203 passing executions, 0 failures/skips, full solution 0 warnings/errors. The 12 committed files exactly match tested source. The commit is now published by normal fast-forward after the previous exact-head PR Verify run completed successfully (all nine jobs). New-head CI/scanning and whole-repository certification remain pending.No scanner finding is treated as fixed merely because it was ignored/dismissed. The earlier dismissal descriptions below are historical and have been superseded by this restoration. No merge or deployment is asserted.
Verified runtime feature context follow-through
Status checked at 2026-10-07T04:52:02.882796+00:00. Work remains incomplete. An ignored or dismissed finding is not an implemented fix. No new ignore, dismissal, or manual alert-closure action was taken in this follow-through.
Four signed commits have now been published by normal fast-forward to
fix/ghas-codeql-waves:cdf46cf75: removes the historical Codacy path exclusions. Stored issue ignores, existing analyzer baselines and any default-branch configuration precedence remain separate; this does not prove restored Codacy coverage.6694cf5a2: explicitly declares source families in three redirect-security test fixtures. Test-only change; no production vulnerability is claimed fixed by that fixture cleanup.bd5f9bbaa: fixes three real creator-query defects and filters before pagination. Its sealed local evidence remains 5,057 passing gate executions, including 16 real PostgreSQL creator cases, with a warning-clean solution build.1b3980a6c: binds all four runtime feature-evaluation MVC actions to the authenticated actor context. Invalid/missing User identity returns 401; mismatched body/query user or tenant selectors return 403 before evaluation, including on SystemAdmin runtime requests. Matching current selectors, authenticated service identities and null global tenant context remain supported. Request permissions and plan values cannot replace the actor values; IP, user agent and request time come from the request/server, and bulk input is copied rather than mutated.The last commit changed five files. The same 48 native HTTP cases showed 40 source failures / 8 controls before the repair and 48 passes afterward. Full Features (797), Authentication (2,292), Authorization (1,737), and the retained API architecture/security/PostgreSQL selection plus new HTTP cases (212) then passed: 5,038 gate executions, zero failures or skips. The strict solution build had zero warnings/errors. HTTP evidence uses real JWT validation, ActorContextMiddleware, MVC, command handlers and tenant targeting; the resolver/persistence boundaries are controlled fixtures. This does not certify the complete host membership pipeline or all feature-flag behavior. Sealed proof:
feature-context-committed-proof.zip, SHA2560bb1fc15a43b72cd6eaa63547fb3d2e73277032cf3704ac8a96c85dda2854832.Current default GitHub scope: 156 unique open alerts, 2 pages exhausted; #810 is
open. Scoped IDs from the previous inventory remain retained; disappearance is not counted as a source fix. Last accepted Codacy snapshot remains 1,804 open findings on the former published head; no result for this new head has yet been certified. Original 33,335 ignored IDs remain retained and unrestored. Codacy organization Join is still waiting for the previously requested human authorization.Prior published
0fd22376aPR Verify completed successfully in all nine jobs. Its Emception run 37561820916 is now terminal failure at the real instructor/learner coding cycle: 24 assertions, 15 green, 8 red, 1 observation, zero known-red. The correct backend rejection wasContent-backed graded assessments cannot start through the generic submission endpoint.No persisted submission or successful instructor grading was established; downstream smoke/deploy/publication were skipped. Selected receipt:published-0fd-emception-terminal-proof.json, SHA256a26d9f1ab6162c5924c40ef106d1a4e04fbd23e797a6f1c81088a917b2011876.New exact-head runs are underway: PR Verify 37573199699, Emception 37573199693 and CodeQL 37573196786. These new runs are not yet certified. The cache context identity, internal SDK factories, plan-attribute freshness, the retained S125 historical comment block, and capability-write authorization review remain open work. The assessment integration needs its supported runtime path; the backend guard must remain intact. This PR remains open against
developand has not been merged.Earlier snapshots below are historical; their individual commit bindings apply
Original heading of the preceding snapshot: published
0fd22376a.Follow-through verified locally — creator queries
This PR is still incomplete. Ignored, dismissed, excluded and baseline entries are not source repairs. No scanner disposition was changed in this follow-through.
bd5f9bbaaaafd7489d7eae0bedbe600bb5060bc7restores the actual creator filter inProgramReadServicebefore sorting/pagination, validates legacy string creator IDs in the all-programs CQRS query, and replaces the always-empty creator-query placeholder with the real nullable GUID/deletion filter. Public signatures and existing publication/archive/sort filters are preserved.cdf46cf75/6694cf5a2are not published yet. The expensive current Emception run37561820916remains live; publication is queued for its terminal result. No force push, merge or restart performed. The retained Codacy S125 IDsbc8f81f203bad7281e842cedab11ab4/2c626b1cc3e420aa1f789e07cbc9c866are not certified externally closed.0fd22376a1e0119d286ec705c14a06066f8b114enow has a terminal successful PR Verify run 37561820911: all nine jobs, including Testing Lab critical flow and required gate. Artifact-backed groups: 60 affected-API TRX / 20779 passing executions; full-application HTTP 15; Economy 90 TRX / 22360 passing executions. These are exact-head passing gates, not scanner closure and not the unpublished creator repair.Earlier checkpoint (historical; latest follow-through above)
The remediation goal is not complete. Ignored issues, dismissed alerts, local ESLint baselines and disabled analyzer rules are not counted as corrected source. All original scopes and IDs remain retained in the audit.
0fd22376a1e0119d286ec705c14a06066f8b114e; no merge or force push.cdf46cf75310879a5344774b8eb47705b6e963cdremoves all five blanket.codacy.yamlexclusions and explicitly includes those scopes. The previous 45,057-ignore manifest is preserved as historical evidence, not implementation proof. Stored Codacy issue ignores have not been undone: the authenticated UI returnedResource not found; no configured Codacy API token or matching connector was found. The ignored-issue refresh exhausted 67 pages but returned 33,036 unique records with 299 duplicates and changing totals (33,335 / 33,197). It is not accepted as a complete snapshot; all 33,335 IDs from the previous complete inventory remain retained. The organization list exposes gameguild-gg with a Join action; its precise authorization is pending under the browser confirmation policy. Local baselines and disabled EditorConfig diagnostics also remain unverified debt.6694cf5a2ae4bd5a17acbafa5d0c0d9efb6379f6makes three constant redirect-fixture cases explicit. Current CodeQL alerts #898/#899/#900 are at substring-based selection among fixed test URLs, not production authorization of attacker-controlled URLs. Independent AST/case review preserves all 34 other top-level statements and the exact three tool/version/URL cases; production provider bytes are unchanged. All 168 script tests pass, zero failures/skips. The three alerts have not been administratively dismissed; publication/rescan remains pending.Content-backed graded assessments cannot start through the generic submission endpoint.Toolchain, curl security, package build/types/unit tests and release staging/package checks passed, but downstream browser/deployment steps were skipped. The runtime integration remains unresolved; no authorization guard has been weakened.The earlier sections below retain historical checkpoints, including their then-current publication and scanner states; this status supersedes those states.
Current verified follow-ups (local commits; publication pending)
Learning process execution follow-up (local; publication pending)
Signed commit
0fd22376a1e0119d286ec705c14a06066f8b114eremoves shell interpolation from the development/build process wrappers and the native Windows taskkill call. The three original Codacy IDs remain recorded:6b6c965c80f669d811107a483f7bb556,f6a462c4025645041552ce9ed91d299f,6956d6f5da7aed942b945f41d8da45ac. They are source-repaired locally, with publication/rescan still pending.The Windows reproduction executed a bounded owned echo marker and changed arguments containing spaces, percent expansion and carets before the repair. Actual Node child processes preserve those arguments afterward. The 26 new process/resolver cases and existing audit/DBML controls pass 90/90, without skips; native installed pnpm 10.34.6, Next build CLI help and taskkill against an owned child also pass. The source-function harness uses controlled environments; it does not certify full Docker/API/development startup.
Final repository policy passes, including all 71 shell-gate controls and 35 process/audit cases. Its deployment group has 14 passed and 3 Linux-only checks skipped on Windows; those checks remain unverified. Helper strict CheckJS, touched Web-script ESLint, Prettier and independent AST preservation checks pass. Actual
turbo prune @game-guild/web --dockerretains both build script and helper byte-identically, and the pruned build module imports successfully. No startup/build order or route selection change is made.Four signed local commits (Toolchain provider, certificate expectation, assessment upload, process execution) await normal publication when the existing Emception build completes. The live published-head run has reached the instructor/learner coding cycle. No new ignore/dismissal, merge or external closure certification.
Assessment upload follow-up (local; publication pending)
Signed commit
3ae8cb50942e04d481eaa53da298d8905aa76e4fvalidates the configured asset service origin and rejects redirects during private assessment-file uploads. Ten owned HTTP redirect cases (301/302/303/307/308, same and different origins) reproduced the bug before the repair and pass afterward. The 201-upload and 400-rejection controls preserve private parenting and SDK behavior. Three configuration/error-contract cases also pass. Authentication and SDK metadata are mocked in these HTTP cases; native fetch, multipart bodies and servers are real. This does not certify the separate graded-content runtime integration.Local full Web verification now passes 3159/3159, with zero failures/skips (including all 15 new upload cases); the targeted suite passes 90/90. Web strict types, touched source/test strict types, ESLint, Prettier and the unchanged suppression-budget ratchet pass. This commit, the Toolchain provider commit
cb68436518ead145d339aafa675c33c15c8a7a2cand certificate expectation commit01e5560f210e8d47b8b379feb0a7ba1a0df3ef9aawait publication while the existing Emception run finishes.Additional terminal evidence at the published
dcb0bf9498e4d7e76fb52d72e1ba9b5bd493d289head: API verify artifact has 60 TRX reports / 20779 passed executions, zero failed/not-executed; the separate full-application OpenAPI artifact has 15/15 passed. Counts can include separate suite/provider scopes. PR Verify as a whole remains failed, and its Testing Lab flow was skipped; these are not certified green. No new ignore/dismissal, merge or default-branch closure is recorded.The published PR head remains dcb0bf9. These two signed follow-ups are committed locally and queued while the existing expensive CI run finishes:
Current scanner evidence on the published head:
Hosted gates at the published head:
Persistent local proofs retain failing and passing runs, source/commit signatures and checked hashes: toolchain-provider-committed-proof.zip (a22d532b8def955b66d1cba1c2b002b3ef22d6625cebddec817a95d18815b7ad) and redirect-web-followthrough-committed-proof.zip (e93c1d74afc6eb7065bfb5834224f475a46713813cb6e17307985e39e5cd6608).
The previous implementation/checkpoint history is retained below.
Published verified corrections (dcb0bf9)
The PR head is dcb0bf9. This checkpoint publishes three signed commits. It does not certify default-branch closure.
HTTP verification for the redirect fix:
Remaining hosted gates and scope:
Local evidence receipts:
Earlier checkpoints retained verbatim
Verified local corrections awaiting publication (7f316c9)
Published PR head remains 3e8c3a0. Two signed local commits are prepared for publication after the current Emception run finishes:
Reanalysis retains unresolved scope (3e8c3a0)
Checked 2026-10-06, exact published commit 3e8c3a0.
Retained evidence: published-3e8-reanalysis-unresolved-scope-proof.zip, 19 files, SHA-256 d0521788047f4667b3ee779c69b0e0530610a409729bdef85bc114111f77e562. Includes complete SARIF, current/default alert state, original and current issue IDs, the Codacy check and the earlier transient observer network failure.
Published source fixes; external closure pending (3e8c3a0)
This checkpoint supersedes status summaries below. Ignored or dismissed findings are not counted as source fixes.
Goal ACTIVE, solo work. Publication completed; fresh scanner confirmation pending. No default-branch integration or all-issues implementation certificate.
Ignored findings remain unresolved; suppressions removed locally (2026-10-06)
This checkpoint supersedes status summaries below. Ignoring a finding does not count as a source fix or a default-branch closure.
Goal ACTIVE, solo work. Verified queued commits await normal publication and exact-head rescans. No new scanner dismissals or exclusions, no default integration, and no all-issues implementation certificate.
Verified source repairs; ignored findings remain in scope (2026-10-06)
This checkpoint supersedes historical status summaries below. Ignoring a finding does not close or fix it.
Goal ACTIVE, solo work. No alerts newly ignored, dismissed, suppressed or excluded. No PR merge/default publication performed.
Current open findings — status correction (2026-10-06)
This completion status supersedes earlier scanner-count summaries below; historical evidence is preserved.
Latest verified batch: af38e8b (2026-10-06)
Remediation remains ACTIVE. This PR is not a repository-wide or historical-issue implementation certificate.
Previous implementation and verification checkpoints
Security and quality remediation — active goal
Published PR head:
b4040c7885d216c503c91acdb7fffec1515b6207. Normal push tofix/ghas-codeql-waves; no GitHub merge or default-branch publication. The goal remains active and incomplete.Latest published corrections and actual controls
Fresh external state (2026-10-06 17:35 UTC)
Prior verified integration evidence and remaining work
At preceding application head d6a5369: complete Release API solution 0 warnings / 0 errors, 4,403 unique targeted API cases passed, full client 1,189 passed, both TypeScript checks passed, Web ESLint 1,814 files with 0 active errors/warnings. 2,868 suppressed Web messages remain debt. Fresh compiled Swagger regenerates identical client code; actual curl digest and generator consistency pass. These application checks are scoped to their tested source; newest hosted integration gates are still required.
All four preceding d6 CodeQL analyses succeeded with empty warning/error fields and zero official open PR-head alerts. Prior documented false-positive dispositions remain distinct from source fixes; new exact-head proof is pending. Coding assessment adapter and official grading revision publication remain a functional gap. Default-branch integration/rescan and Dependabot's sprintf version alert remain outstanding. No repository-wide certification is claimed.
Retained evidence SHA256: d6 integration ZIP
0775f1396d379e8e508fc3e5bebcd80874edb0717ff077f0a9e7f7b6d9aa4af2; 93bb fixture ZIPd808de79097c4156031fbcdef698c33b990fe929c4e756742991d2b03d44ac83; b404 SDK ZIPd7ee45a36f6fdab106e8160ac8d3fb0423c840d66001f5f054dd9f1d5f3fd7cf.Preceding checkpoints (historical tested commit scopes)
Security and quality remediation — active goal
Published PR head:
93bb229568792cb4f6c5ec0913c322e99f2d4ad1. Normal push tofix/ghas-codeql-waves; no GitHub merge or default-branch publication. Source fixes and scanner disposition remain separately evidenced.Latest verified source fixes
Verified integration evidence at preceding head d6a5369
Complete Release API solution build: 0 warnings / 0 errors. Latest targeted API suites: 4,403 unique passing cases, including the unchanged full Resources repeat 66/66. The earlier Resources renewal timeout and isolated repeat are retained as separate evidence.
Complete client: 1,189 passed. Both client/Web TypeScript checks pass. Full Web ESLint: 1,814 files, 0 active errors/warnings; 2,868 suppressed messages remain debt. Fresh compiled API Swagger regenerates identical client code; final generator consistency and actual curl overlay digest pass.
Repository policy passes locally; three Linux deployment controls were skipped on Windows and remain unverified here.
Live scanner evidence and remaining scope
d6a5369. Hosted ESLint 9.18.12 crashed in@shopify/jest/no-all-mocks-methodsandimport/no-namespace; SonarC# and other engines completed. This is incomplete scanner coverage.d6a53697asucceeded with empty error/warning fields: C# 77, JS 2, Python 0, Actions 0 raw results. Official PR-head open-alert API returned zero open alerts. Prior documented false-positive dispositions are distinct from implementation fixes. New93bb22956rescans remain required.The goal remains active and incomplete. No repository-wide certification is claimed.
Earlier checkpoints and evidence (historical commit scopes)
Security and quality remediation — active goal
Published source head:
15115456828f2d72691d81afd324bce1d1afb6b7, verified against the Git remote and PR API. The goal remains incomplete. Eight incoming commits advanced the branch while local work was in progress; both local fixes were rebased onto them without conflicts. Evidence below is explicitly scoped to the commit tested.Latest source fixes and local evidence
Previous verified fixes retained
Browser Python raw-argv persistence and bare exception removal; complete migrated Economy fixtures for affected API verification; actual Learn → Courses menu smoke; coding-cycle alert and failure-artifact collection; native/WASM curl buffer-overread security regressions; Economy braces; Announcements solution mappings; JSON-LD XSS; provider/log privacy and LTI boundaries; Resources host aliases; LLVM archive integrity and dependency patches. None is replaced by scanner suppression.
Fresh installed dependency-patch controls pass 12/12; prior enforced two-CVE exception-policy controls pass 19/19. Hosted Trivy continues reporting patched package versions and remains unresolved.
Scanner evidence — earlier published head 887aee7
Actual Codacy commit detail binds completed analysis to 887aee7. The complete five-page branch inventory at 12:21:58 UTC contains 2,199 unique findings, with consistent totals. Compared with 1d93c39: 822 IDs removed (820 S121 brace findings, two S2737 catch/rethrow findings), two S2360 IDs added for existing optional query/cancellation parameters in ProjectsController, and 2,197 retained. Both complete ID sets and original ignored debt remain preserved. No Codacy dispositions or rules were changed.
This Codacy analysis reports two analyzer problems: SonarC# timed out after 3m24; ESLint image 9.18.12 still crashes in import/no-namespace and Shopify jest/no-all-mocks-methods. Other engines, including Opengrep and PMD, completed. The reduced issue count is not a certification of complete scanner coverage.
All four CodeQL languages completed successfully at the exact earlier head 887aee7: C# 1900590902, JavaScript/TypeScript 1900468555, Python 1900458922 and Actions 1900457931, with empty analysis error/warning fields. The official exact PR-head open-alert API returns zero open alerts. Raw analysis and open-alert records are retained. Cumulative documented false-positive resolutions remain 93; no new dismissals. Default develop previously retains 156 open alerts and still requires integration/rescan.
Per-finding review remains necessary for fixture literals, constant/optional-parameter contracts, same-origin fetches and patched-version reports.
Current scanner readback — 1511545
The four-page branch inventory at 13:06:28 UTC has 1,678 unique findings and consistent totals. The visible commit page confirms analysis of 1511545 completed in two minutes. SonarC# completed in 1m18; the hosted ESLint image 9.18.12 still crashes on import/no-namespace and Shopify jest/no-all-mocks-methods. The incoming
.codacy.yamlexcludes tests and generated/vendored paths and documents bulk ignored baselines; the incoming.editorconfigdisables many diagnostics. These configuration/disposition reductions are not implementation certification. Retain original findings and reconcile source fixes separately from exclusions or suppressions.Hosted CI and unresolved work
Current PR Verify 37467469689 is running for 1511545. Policy and classification succeeded; API, Web, OpenAPI and Economy checks remain in progress. The preceding 37461799948 was canceled by incoming branch updates. Policy, classification, OpenAPI consistency and Web verification succeeded. API verify failed during fixture creation after 14 selected projects passed 6,048/6,048 tests, zero skips/failures.
createdbencountered PostgreSQL shutting down; 45 remaining selected suites did not execute. A real disposable-image control and a failing-then-passing runner regression establish a premature socket-readiness race. An authenticated-TCP readiness repair and pre-cleanup server diagnostics are tested locally (nine runner cases, seven selector tests, 68 shell gate tests), pending publication. The earlier Economy result was interrupted; Testing Lab critical flow was dependency-skipped after the API failure, not passed. Earlier Emception 37461799984 was canceled. The new Emception 37467469630 is pending behind the 1d93c39 toolchain build. No merge is authorized by these intermediate results.Previous PR Verify 37447881501 is failed: API, Web, repository policy, OpenAPI client consistency and Testing Lab critical flow succeeded; Economy release failed on the old Testing Lab heading selector. Its affected-API artifact has 23 TRXs with 14,879/14,879 passing, zero failures/skips. Its Economy artifact has 90 TRXs with 22,237 passing test executions, zero failures/skips; some profile executions overlap. The subsequent public-browser failure is retained, not hidden. The selector correction above awaits fresh CI. Migration compatibility was skipped by changed-path scope.
Both older 6a69252 and 631bb05 Emception runs failed the real coding assessment Submit step after toolchain, packaging and actual public WASM tests succeeded: no submission or grade was created. The 631bb05 uploader found no files. The 1d93c39 run is now active with the published diagnostic-path and visible-alert repair; this collects evidence and does not establish a product fix.
Continue fresh CI/scanner verification, genuine source fixes, per-finding dispositions, the hosted ESLint analyzer failure, coding Submit repair and original-ID reconciliation. Default-branch integration/rescan is still required. No merge or repository-wide certification is claimed.