Skip to content

fix(security): resolve PR #696 GHAS findings (CodeQL, Copilot, Codacy) - #698

Open
tolstenko wants to merge 142 commits into
developfrom
fix/ghas-codeql-waves
Open

tolstenko wants to merge 142 commits into
developfrom
fix/ghas-codeql-waves

Conversation

@tolstenko

@tolstenko tolstenko commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Current remediation checkpoint

Published head: eab098b (signature G; normal push). PR open and unmerged; integration conflicts with develop remain.

Published remote asset URL fixes

  • Mirrored Web/client guards reject private/mapped address literals and canonical localhost DNS spellings, including trailing root dots. The reproduced bypass requires a custom allowlist containing the parsed local host; no default-allowlist or network exploit certificate.
  • DNS spelling regression: before 24 failures per module; after 277 focused tests pass. Final owning suites: Web 3306 tests/434 files and client 1299 tests/95 files pass, zero failures/skips. Original tests preserved; 76 added cases.
  • Both typechecks, client ESM/CJS/DTS build and local lint pass. Four files: uncapped local ESLint 0 messages/0 suppressedMessages; 12 policy AST declarations unchanged. Client lint has an existing Next pages-directory configuration warning.
  • DNS production matrix: before 96 incorrect accepts/152 calls; after 152 vectors + 86016 generated calls, zero mismatches; 24 internal service controls unchanged. Earlier literal-address matrix: 1310900 calls, zero mismatches. DNS resolution/rebinding remains outside these literal/spelling proofs.

Scanner scope and remaining gates

  • Matching eab098b CodeQL run 37905633267 started; hosted results pending. Previous 3b075ba PR analysis: C# 84/52 rules; JS 0/87; actions 0/17; Python 0/43. PR analysis does not certify develop alerts fixed.
  • Codacy's documented repository metadata binds the prior completed analysis to 3b075ba, 2971 current findings. Hosted ESLint caps 50/tool/file; the full cloud profile remains unqualified. Org membership is authorized; no new token, pattern disabling or configuration reductions.
  • Retained all 49360 original IDs and 49431 total IDs. Completed prior inventory: 33335 ignored, 2971 current, 13125 absent; ignored/absent are unresolved classifications. Six UI unignore requests were verified by reload; no source repair is attributed to restoration.
  • #810 remains open. Exact reported 7e33752 and observed develop 4a917fe both log identifier in clear text; neither contains the PR's keyed MaskIdentifier helper. Integration and matching analysis remain necessary.
  • Seven API/WIP files preserved byte-for-byte; empty index after the signed four-file commit. API privacy/ImageSharp Release license gates, exact cloud ESLint profile, pnpm-process candidate, OpenAPI, historical GitGuardian access and existing V1 grading identity failure remain pending.

Goal active, no agents. No new ignores, dismissals or fix certificates. All historical references below are preserved byte-for-byte.

Dismissal restoration after user correction

The user clarified that ignoring is not closing/fixing issues. All 94 previously scoped GitHub dismissals have now been reversed and verified individually. The original IDs, dismissal reasons and evidence are retained in the audit record. Restoration is a state repair and is not counted as a source fix.

  • PR fix(security): resolve PR #696 GHAS findings (CodeQL, Copilot, Codacy) #698 scope: 79 open, 32 scanner-fixed, 0 dismissed. The 32 fixed states include historical absent results; this checkpoint does not claim 32 newly implemented repairs.
  • The completed CodeQL run 37579124047, previous exact published head 246eef6b0, reports 79 raw results: C# 77, JavaScript 2, Python 0, Actions 0. All 79 locations/messages match 1b3980a6c; the capability authorization repair did not remove a raw CodeQL result. The earlier three JavaScript fixture results disappeared after the preserved 168-case fixture cleanup; production code was unchanged by that cleanup.
  • Default-branch open inventory after restoration: 177 unique open alerts, preserving all previous 156 IDs. The 21 added open IDs are restored dismissals, not 21 new source regressions. #810 remains open. Default-branch scope is separate from PR scope.
  • Codacy stored ignores remain unresolved. Joining the Codacy organization requires the previously requested human authorization; no new membership/access grant has been made.
  • Capability administration is repaired, verified and published in signed commit 246eef6b0: authenticated actor, tenant scope and administrator checks now protect controller, handlers and service; override/removal audit identity comes from the actor. Baseline: 53 failures/38 controls across 91 HTTP cases plus 74 service/handler failures. After: all 165 new cases pass; full selected gates total 5,203 passing executions, 0 failures/skips, full solution 0 warnings/errors. The 12 committed files exactly match tested source. The commit is now published by normal fast-forward after the previous exact-head PR Verify run completed successfully (all nine jobs). New-head CI/scanning and whole-repository certification remain pending.

No scanner finding is treated as fixed merely because it was ignored/dismissed. The earlier dismissal descriptions below are historical and have been superseded by this restoration. No merge or deployment is asserted.

Verified runtime feature context follow-through

Status checked at 2026-10-07T04:52:02.882796+00:00. Work remains incomplete. An ignored or dismissed finding is not an implemented fix. No new ignore, dismissal, or manual alert-closure action was taken in this follow-through.

Four signed commits have now been published by normal fast-forward to fix/ghas-codeql-waves:

  • cdf46cf75: removes the historical Codacy path exclusions. Stored issue ignores, existing analyzer baselines and any default-branch configuration precedence remain separate; this does not prove restored Codacy coverage.
  • 6694cf5a2: explicitly declares source families in three redirect-security test fixtures. Test-only change; no production vulnerability is claimed fixed by that fixture cleanup.
  • bd5f9bbaa: fixes three real creator-query defects and filters before pagination. Its sealed local evidence remains 5,057 passing gate executions, including 16 real PostgreSQL creator cases, with a warning-clean solution build.
  • 1b3980a6c: binds all four runtime feature-evaluation MVC actions to the authenticated actor context. Invalid/missing User identity returns 401; mismatched body/query user or tenant selectors return 403 before evaluation, including on SystemAdmin runtime requests. Matching current selectors, authenticated service identities and null global tenant context remain supported. Request permissions and plan values cannot replace the actor values; IP, user agent and request time come from the request/server, and bulk input is copied rather than mutated.

The last commit changed five files. The same 48 native HTTP cases showed 40 source failures / 8 controls before the repair and 48 passes afterward. Full Features (797), Authentication (2,292), Authorization (1,737), and the retained API architecture/security/PostgreSQL selection plus new HTTP cases (212) then passed: 5,038 gate executions, zero failures or skips. The strict solution build had zero warnings/errors. HTTP evidence uses real JWT validation, ActorContextMiddleware, MVC, command handlers and tenant targeting; the resolver/persistence boundaries are controlled fixtures. This does not certify the complete host membership pipeline or all feature-flag behavior. Sealed proof: feature-context-committed-proof.zip, SHA256 0bb1fc15a43b72cd6eaa63547fb3d2e73277032cf3704ac8a96c85dda2854832.

Current default GitHub scope: 156 unique open alerts, 2 pages exhausted; #810 is open. Scoped IDs from the previous inventory remain retained; disappearance is not counted as a source fix. Last accepted Codacy snapshot remains 1,804 open findings on the former published head; no result for this new head has yet been certified. Original 33,335 ignored IDs remain retained and unrestored. Codacy organization Join is still waiting for the previously requested human authorization.

Prior published 0fd22376a PR Verify completed successfully in all nine jobs. Its Emception run 37561820916 is now terminal failure at the real instructor/learner coding cycle: 24 assertions, 15 green, 8 red, 1 observation, zero known-red. The correct backend rejection was Content-backed graded assessments cannot start through the generic submission endpoint. No persisted submission or successful instructor grading was established; downstream smoke/deploy/publication were skipped. Selected receipt: published-0fd-emception-terminal-proof.json, SHA256 a26d9f1ab6162c5924c40ef106d1a4e04fbd23e797a6f1c81088a917b2011876.

New exact-head runs are underway: PR Verify 37573199699, Emception 37573199693 and CodeQL 37573196786. These new runs are not yet certified. The cache context identity, internal SDK factories, plan-attribute freshness, the retained S125 historical comment block, and capability-write authorization review remain open work. The assessment integration needs its supported runtime path; the backend guard must remain intact. This PR remains open against develop and has not been merged.

Earlier snapshots below are historical; their individual commit bindings apply

Original heading of the preceding snapshot: published 0fd22376a.

Follow-through verified locally — creator queries

This PR is still incomplete. Ignored, dismissed, excluded and baseline entries are not source repairs. No scanner disposition was changed in this follow-through.

  • Signed local commit bd5f9bbaaaafd7489d7eae0bedbe600bb5060bc7 restores the actual creator filter in ProgramReadService before sorting/pagination, validates legacy string creator IDs in the all-programs CQRS query, and replaces the always-empty creator-query placeholder with the real nullable GUID/deletion filter. Public signatures and existing publication/archive/sort filters are preserved.
  • Original focused regression: 15 failed / 7 passed. Corrected focused fixture: 22 passed. Final complete gates: Courses 864, Authentication 2292, Authorization 1737, API security/architecture/native PostgreSQL 164; 5057 passing executions, zero failed/skipped. The API group includes 16 new real PostgreSQL cases using the production EF model. A test-data username collision was fixed and its initial failure evidence retained. The focused tenant-filter model and direct DB execution do not certify HTTP tenant middleware.
  • Required solution build completed with warnings treated as errors: 0 warnings, 0 errors. Whole production files were checked against the parent: exactly three reviewed changes. The signed commit and source/test receipts are sealed; Git's line-ending normalization is explicitly bound in the receipt.
  • This new source repair and the two earlier local coverage/fixture commits cdf46cf75 / 6694cf5a2 are not published yet. The expensive current Emception run 37561820916 remains live; publication is queued for its terminal result. No force push, merge or restart performed. The retained Codacy S125 IDs bc8f81f203bad7281e842cedab11ab4 / 2c626b1cc3e420aa1f789e07cbc9c866 are not certified externally closed.
  • Published 0fd22376a1e0119d286ec705c14a06066f8b114e now has a terminal successful PR Verify run 37561820911: all nine jobs, including Testing Lab critical flow and required gate. Artifact-backed groups: 60 affected-API TRX / 20779 passing executions; full-application HTTP 15; Economy 90 TRX / 22360 passing executions. These are exact-head passing gates, not scanner closure and not the unpublished creator repair.
  • Fresh complete default-open GitHub query: 156 unique open alerts, #810 remains open. Last complete Codacy branch inventory remains 1804 at 02:29 UTC; current published raw CodeQL remains 82. Retained ignored debt remains 33335 original IDs; the recent unstable ignored query was not accepted as complete. The Codacy Join request still has no human answer; no membership or unignore action was performed.

Earlier checkpoint (historical; latest follow-through above)

The remediation goal is not complete. Ignored issues, dismissed alerts, local ESLint baselines and disabled analyzer rules are not counted as corrected source. All original scopes and IDs remain retained in the audit.

  • Four signed follow-ups are now published: Toolchain URL/redirect validation, the certificate redirect expectation, private assessment-upload redirect rejection, and learning process execution without a shell. PR head is 0fd22376a1e0119d286ec705c14a06066f8b114e; no merge or force push.
  • Fresh default open-alert inventory still has 156 unique open alerts, including #810. The PR's 94 false-positive dismissals are separate dispositions and are not source fixes or default-branch closure proof.
  • Fresh public Codacy branch inventory has 1,804 unique issues, four pages exhausted with matching totals. The three shell-execution IDs are absent after the published source repair. Toolchain SSRF absence requires identity review because the number of SSRF findings remains 35. Public branch inventory does not independently certify analyzed commit or every engine's coverage. The current Codacy PR check still requires action.
  • Local signed cdf46cf75310879a5344774b8eb47705b6e963cd removes all five blanket .codacy.yaml exclusions and explicitly includes those scopes. The previous 45,057-ignore manifest is preserved as historical evidence, not implementation proof. Stored Codacy issue ignores have not been undone: the authenticated UI returned Resource not found; no configured Codacy API token or matching connector was found. The ignored-issue refresh exhausted 67 pages but returned 33,036 unique records with 299 duplicates and changing totals (33,335 / 33,197). It is not accepted as a complete snapshot; all 33,335 IDs from the previous complete inventory remain retained. The organization list exposes gameguild-gg with a Join action; its precise authorization is pending under the browser confirmation policy. Local baselines and disabled EditorConfig diagnostics also remain unverified debt.
  • Local signed 6694cf5a2ae4bd5a17acbafa5d0c0d9efb6379f6 makes three constant redirect-fixture cases explicit. Current CodeQL alerts #898/#899/#900 are at substring-based selection among fixed test URLs, not production authorization of attacker-controlled URLs. Independent AST/case review preserves all 34 other top-level statements and the exact three tool/version/URL cases; production provider bytes are unchanged. All 168 script tests pass, zero failures/skips. The three alerts have not been administratively dismissed; publication/rescan remains pending.
  • Previous dcb Emception run 37552617013 failed the real learner submission cycle with Content-backed graded assessments cannot start through the generic submission endpoint. Toolchain, curl security, package build/types/unit tests and release staging/package checks passed, but downstream browser/deployment steps were skipped. The runtime integration remains unresolved; no authorization guard has been weakened.
  • Complete current-head CodeQL 2.27.1 SARIF contains 82 raw results: 77 C#, 5 JavaScript/TypeScript, 0 Python, 0 Actions, with no analysis errors. Results remain retained independently of dismissed dispositions. Current Web verify passes; affected API tests, Economy and Toolchain validation are still running. No complete PR/runtime certification.
  • Current published-head PR Verify 37561820911 and Emception 37561820916 are running. Local coverage/fixture follow-ups await normal publication after this expensive run reaches a terminal result. No cancellation, new ignore/dismissal or external closure certification.

The earlier sections below retain historical checkpoints, including their then-current publication and scanner states; this status supersedes those states.


Current verified follow-ups (local commits; publication pending)

Learning process execution follow-up (local; publication pending)

Signed commit 0fd22376a1e0119d286ec705c14a06066f8b114e removes shell interpolation from the development/build process wrappers and the native Windows taskkill call. The three original Codacy IDs remain recorded: 6b6c965c80f669d811107a483f7bb556, f6a462c4025645041552ce9ed91d299f, 6956d6f5da7aed942b945f41d8da45ac. They are source-repaired locally, with publication/rescan still pending.

The Windows reproduction executed a bounded owned echo marker and changed arguments containing spaces, percent expansion and carets before the repair. Actual Node child processes preserve those arguments afterward. The 26 new process/resolver cases and existing audit/DBML controls pass 90/90, without skips; native installed pnpm 10.34.6, Next build CLI help and taskkill against an owned child also pass. The source-function harness uses controlled environments; it does not certify full Docker/API/development startup.

Final repository policy passes, including all 71 shell-gate controls and 35 process/audit cases. Its deployment group has 14 passed and 3 Linux-only checks skipped on Windows; those checks remain unverified. Helper strict CheckJS, touched Web-script ESLint, Prettier and independent AST preservation checks pass. Actual turbo prune @game-guild/web --docker retains both build script and helper byte-identically, and the pruned build module imports successfully. No startup/build order or route selection change is made.

Four signed local commits (Toolchain provider, certificate expectation, assessment upload, process execution) await normal publication when the existing Emception build completes. The live published-head run has reached the instructor/learner coding cycle. No new ignore/dismissal, merge or external closure certification.

Assessment upload follow-up (local; publication pending)

Signed commit 3ae8cb50942e04d481eaa53da298d8905aa76e4f validates the configured asset service origin and rejects redirects during private assessment-file uploads. Ten owned HTTP redirect cases (301/302/303/307/308, same and different origins) reproduced the bug before the repair and pass afterward. The 201-upload and 400-rejection controls preserve private parenting and SDK behavior. Three configuration/error-contract cases also pass. Authentication and SDK metadata are mocked in these HTTP cases; native fetch, multipart bodies and servers are real. This does not certify the separate graded-content runtime integration.

Local full Web verification now passes 3159/3159, with zero failures/skips (including all 15 new upload cases); the targeted suite passes 90/90. Web strict types, touched source/test strict types, ESLint, Prettier and the unchanged suppression-budget ratchet pass. This commit, the Toolchain provider commit cb68436518ead145d339aafa675c33c15c8a7a2c and certificate expectation commit 01e5560f210e8d47b8b379feb0a7ba1a0df3ef9a await publication while the existing Emception run finishes.

Additional terminal evidence at the published dcb0bf9498e4d7e76fb52d72e1ba9b5bd493d289 head: API verify artifact has 60 TRX reports / 20779 passed executions, zero failed/not-executed; the separate full-application OpenAPI artifact has 15/15 passed. Counts can include separate suite/provider scopes. PR Verify as a whole remains failed, and its Testing Lab flow was skipped; these are not certified green. No new ignore/dismissal, merge or default-branch closure is recorded.

The published PR head remains dcb0bf9. These two signed follow-ups are committed locally and queued while the existing expensive CI run finishes:

  • cb68436: fixes a genuine Toolchain-provider SSRF path from remote annotated-tag metadata. Before: 21 failures / 24 regression cases, including an actual request to an owned private HTTP server. After: 103 provider cases within 168 complete script cases pass. Each initial URL and manual redirect is constrained to approved HTTPS origins without URL credentials, with API-token isolation and bounded tag/redirect traversal. Three real upstream downloads preserve the exact locked archive hashes. Strict targeted type/format checks pass.
  • 01e5560: updates one certificate-fetch assertion to require redirect:error. Complete local Web follow-through: 3144/3144 pass, zero failures/pending/skips; production Web code, timeout values and renderer code are unchanged.

Current scanner evidence on the published head:

  • All four CodeQL languages completed without analysis errors, retaining 79 raw results: C# 77, JavaScript 2, Python 0, Actions 0. A dismissed state is not proof of an implemented fix. All raw IDs/source paths remain in the review queue.
  • Develop still has 156 open alerts, including #810. Default-branch closure is not certified by this PR state.
  • Public Codacy branch pagination delivers 1757 unique findings, exhausted and count-consistent. Its public inventory does not certify analyzed commit or full engine coverage. Five culture-normalization findings are absent after the verified source corrections. A GitHub-provider SSRF ID changed while the finding remains present; it is not counted resolved.
  • No ignore, suppression or dismissal action was used for these follow-ups.

Hosted gates at the published head:

  • CodeQL: complete/success.
  • PR Verify: Web failed on the old certificate expectation. Economy evidence confirms the same single certificate expectation failure (3143/3144 Web cases passed). Its 90 TRX reports recorded 22360 executions across separate scopes and zero failed executions; this is not a deduplicated unique-test count. The complete gate remains failed and still requires a new hosted result. API verify was still running at the last check.
  • Emception: still building/validating Toolchain receipts. The earlier coding-cycle/runtime-submission failure remains separately tracked and is not marked green.

Persistent local proofs retain failing and passing runs, source/commit signatures and checked hashes: toolchain-provider-committed-proof.zip (a22d532b8def955b66d1cba1c2b002b3ef22d6625cebddec817a95d18815b7ad) and redirect-web-followthrough-committed-proof.zip (e93c1d74afc6eb7065bfb5834224f475a46713813cb6e17307985e39e5cd6608).

The previous implementation/checkpoint history is retained below.


Published verified corrections (dcb0bf9)

The PR head is dcb0bf9. This checkpoint publishes three signed commits. It does not certify default-branch closure.

  • 7b0d200: redact successful authentication endpoint logging. Six real HTTP privacy cases failed before the fix and passed afterward, with request binding, response tokens and account persistence preserved. Local API gates: 4,152 passed.
  • 7f316c9: normalize five repository input expressions with invariant culture while preserving translated database lower() expressions. Actual PostgreSQL controls: 10 culture regressions failed before and all 25 cases passed after. Strict Release solution build: zero warnings/errors; 6,080 targeted API cases passed.
  • dcb0bf9: reject automatic redirects at 34 existing guarded fetch calls in 19 client/web source files. Whole-file AST checks confirm URL guards, headers, payloads, caching, abort behavior and other source logic are retained. No fetch sinks were relocated to conceal findings. Thirty-five original SSRF IDs remain tracked; this source batch covers calls associated with 32 of them.

HTTP verification for the redirect fix:

  • Actual loopback servers in production guard mode: ten client redirect cases and 25 web action/route cases failed before the change. Normal-response controls passed before.
  • Final 43 HTTP cases passed, including normal JSON, multipart, authentication, tenant forwarding, URL encoding and redirect boundaries.
  • Full client suite: 1,202 passed, zero failed/skipped. Existing asset provider suite: 14 passed, including enforced redirect policy on seven operations.
  • Client build, client/web type checks, full client source lint and touched web source/test lint passed. The complete web suite remains in progress and is not asserted green.
  • No suppressions, audit exclusions or alert dismissals were added.

Remaining hosted gates and scope:

  • Exact new-head CodeQL/Codacy outcomes remain pending. The last complete public Codacy scope was 1,762 IDs; earlier 3,358/1,672 scopes remain preserved. Absence of a finding is not silently treated as implementation proof.
  • Fresh authenticated default-branch inventory still has 156 open code-scanning alerts, including #810 on develop. No default integration or closure occurred.
  • Published 3e8c3a0 Emception run 37536490775 completed with failure after successful Toolchain receipts, unit/type and release package gates. Its real coding cycle has eight unmet checks among 24 reported assertions (zero known-red, one observation): content-backed assessment submission uses the generic endpoint rejected by the backend. Browser diagnostics are retained; no skip/dismissal was applied.
  • Dependencies and the retained dismissed/raw-alert review queue remain unresolved as described below. Ignored/dismissed alerts are not counted as code fixes.

Local evidence receipts:

  • redirect-boundary-committed-proof.zip: SHA256 e5cfc6900d13f3abdd68996cd3e0b57d1bc050c6d24cb7ac08b3813da7ad21bd (51 entries, complete web suite pending).
  • published-3e8-emception-terminal-proof.zip: SHA256 465134fa39981faf09ba9ba0b36597f8293ea1d1c0ba45a68c010998e5f8203e (11 entries, runtime logs excluded).
  • Previous privacy, culture and hosted TestingLab proofs remain retained with their exact receipts.
Earlier checkpoints retained verbatim

Verified local corrections awaiting publication (7f316c9)

Published PR head remains 3e8c3a0. Two signed local commits are prepared for publication after the current Emception run finishes:

  • 7b0d200 repairs two legacy authentication success logs to redact identifiers. Its separate proof retains six HTTP regressions and 4,152 passing local checks.
  • 7f316c9 normalizes two username and three asset lookup inputs with invariant casing, preserving PostgreSQL column translation and authorization/tenant/resource/cancellation guards. A new 25-case PostgreSQL fixture fails ten Turkish-culture cases before the change and passes all 25 afterward. The earlier fixture data failure remains recorded separately.
  • Final local gates: Users 714, Assets 1,164, Authentication 2,292, Authorization 1,737, API architecture/security/HTTP/PostgreSQL selection 148, Users integration 25. Total 6,080 passed, zero failed or skipped; full solution build has zero warnings or errors. The API selection contains all previous 123 selected cases plus 25 new regressions. These two local commits await publication and hosted reanalysis.
  • Published-head PR Verify 37536490880 completed successfully, including Testing Lab browser workflow; artifact 11450595324 retains six browser screenshots and successful runner evidence. Emception 37536490775 remains active.
  • The five retained S1449 IDs remain linked to the repair, pending verified external removal: 4851deec027fd44a37b0a0f435fec307, e0c1fe14fe7d248da466640a75f1a5bc, bd74fcd764b151f618e2aac54f570317, d3f1e727e3d4374ac959b968e7e979fd, 94bc1b977961fa90f63d465a363abb21.
  • Zero new dismissals. No default-branch closure or integration is claimed. Previous raw CodeQL, current/default alert, and all Codacy scopes remain retained in the reanalysis section below.

Reanalysis retains unresolved scope (3e8c3a0)

Checked 2026-10-06, exact published commit 3e8c3a0.

  • All four CodeQL analyses completed without analysis errors or warnings: C# 77 raw findings, JavaScript/TypeScript 2, Python 0, Actions 0. The same 79 raw alert IDs remain present. Their GitHub disposition is dismissed; zero raw finding reduction is certified by this rescan. They remain in the review queue, and none is counted as fixed because of dismissal.
  • Develop still has 156 open code-scanning alerts, including #810. PR-only source corrections do not close default-branch alerts before integration.
  • Public Codacy branch inventory has 1,762 unique findings, four exhausted pages. The ten IDs matching published source corrections are absent; 100 ESLint IDs appeared. All 1,672 prior IDs remain in a state ledger, alongside the original 3,358 scope. The exact-head Codacy check is action_required. Complete engine coverage is not independently certified, so absence alone does not certify full external closure.
  • The two dependency advisories remain visible without Trivy ignore entries; Dependabot #1430 remains open.
  • PR Verify: Web, repository policy, OpenAPI consistency and migration compatibility passed. API, Economy and Emception verification remain in progress. No required workflow was cancelled to force publication.
  • No ignore, dismissal, default-branch update or merge was performed in this round. Goal remains active.
  • A further local correction removes complete email identifiers from two legacy authentication success logs. Six actual HTTP regressions reproduce the leak on the unchanged published source; seven existing binding cases pass. Full after verification is running. This local work is not published or externally certified yet.

Retained evidence: published-3e8-reanalysis-unresolved-scope-proof.zip, 19 files, SHA-256 d0521788047f4667b3ee779c69b0e0530610a409729bdef85bc114111f77e562. Includes complete SARIF, current/default alert state, original and current issue IDs, the Codacy check and the earlier transient observer network failure.


Published source fixes; external closure pending (3e8c3a0)

This checkpoint supersedes status summaries below. Ignored or dismissed findings are not counted as source fixes.

  • Five verified commits published to fix/ghas-codeql-waves: #810 service regressions; four genuine API quality repairs; removal of both Trivy exceptions; Emception policy-test correction; six further API quality repairs. Remote branch and PR head were read back as 3e8c3a0. Develop remains 295ee21.
  • New six-source repair verification: whole-file allowed-change review, public signatures preserved, twelve regression cases. Corrected full solution build: zero warnings/errors, TreatWarningsAsErrors. Complete Authorization 1737, Authentication 2292, Blog 147, Recommendations 262, Billing 352, API 1058: 5848 passed, zero failed/skipped. API includes all 108 architecture/security cases. HTTP authentication focus 9/9. Isolated PostgreSQL server removed after completion.
  • Failure evidence retained: first API attempt deliberately interrupted after two new fixture failures; fixture corrected without weakening assertions; final complete API suite passed. Previous published Emception run failed at a stale inline-install policy assertion (64/65); compiler receipts, native/WASM curl security regressions and package type checks passed.
  • Emception policy repair: follows the shared audited installer and enforces frozen lockfile, ignored install scripts, narrow braces/sprintf-js rebuild list and patch/audit gates. Local scripts 65/65. Further package tests 355 passed / zero failed / one real-worker smoke skipped; public types passed. Full hosted release/browser result remains pending.
  • Dependency findings stay visible: both Trivy advisory exceptions removed; source patches preserved; 34/34 security tests passed. Unfiltered registry audit still has two advisories, exit 1. Dependabot #1430 is open for sprintf-js / GHSA-hp3w-g68c-fv3c. Local mitigation does not certify external closure.
  • Original scope retained: latest confirmed develop count 156 open alerts, including #810. All original 156 IDs and 3358 Codacy IDs remain in scope. Latest retained Codacy inventory 1672 has engine-coverage limitations. Previous head's 79 raw dismissed findings remain in the review queue; no new dispositions changed. Web's 2777 bulk suppressions plus 14 source directives remain unresolved debt.
  • Fresh exact-head CI running: PR Verify 37536490880, Emception 37536490775, CodeQL 37536486202. These are new analyses; no fresh scanner closure or full-implementation certificate is claimed yet.
  • Retained new proof: quality-6-committed-source-and-ci-proof.zip, 50 files, SHA-256 4ba3677961a68270e800283d155b82d40ab40ee8464bc83d508e27eaffe2f1c9. Includes committed source/test patch, reviewed input hashes, before/after and failed/aborted TRXs, both build logs, PostgreSQL cleanup provenance, exact older CI outcomes, Testing Lab runner/screenshots, original open alerts and dismissed review queue. Earlier committed-source, dependency and Emception proofs remain preserved.

Goal ACTIVE, solo work. Publication completed; fresh scanner confirmation pending. No default-branch integration or all-issues implementation certificate.


Ignored findings remain unresolved; suppressions removed locally (2026-10-06)

This checkpoint supersedes status summaries below. Ignoring a finding does not count as a source fix or a default-branch closure.

  • Latest confirmed develop inventory remains 156 open alerts, including #810. All original scoped IDs remain retained. Published af38 CodeQL's 79 raw previously dismissed findings remain in the review queue; none is counted as a certified source fix.
  • Local commit bfe96f0 removes both Trivy advisory exceptions. Existing installed patches are preserved; 34/34 security checks passed. The fresh unfiltered audit still reports two advisories (exit 1). No upstream/scanner closure is claimed.
  • Local commit d38df5f repairs the Emception CI policy test to follow the shared audited installer while retaining frozen-lockfile, ignored-install-scripts and the narrow two-package rebuild policy. Focused baseline failed; corrected script suite 65/65. Further package verification: 355 passed, zero failed, one real-worker smoke skipped; public type checks passed. The skip remains an explicit coverage limitation.
  • Exact af38 PR Verify completed successfully, including Testing Lab browser workflow, API, Web production build, OpenAPI, migrations and Economy. Emception failed at the stale script policy test (64/65); its compiler receipt build, native/WASM curl security regressions and package type checks succeeded. Release/export/browser stages after the failure remain uncertified; hosted retest is pending.
  • Six further source repairs in five API production files are under final local verification, uncommitted and unpublished. Corrected full solution build: zero warnings/errors with TreatWarningsAsErrors. Completed full Authorization 1737, Authentication 2292, Blog 147, Recommendations 262, Billing 352: 4790 passed, no skips/failures. Actual HTTP endpoint focus 9/9. The complete API suite is still running on an isolated PostgreSQL server. Its first attempt was deliberately interrupted after diagnosing two new fixture failures; failure/abort evidence is retained, and assertions were preserved in the fixture repair.
  • Original 3358 Codacy IDs remain retained; latest retained inventory is 1672 with engine-coverage limitations. Web's 2777 bulk suppressions plus 14 source directives remain unresolved debt.
  • Retained proof: removed-trivy-suppressions-unfiltered-audit-proof.zip SHA-256 c0c160509c4725c27afc44cf86b458b018e2f3e8a3e8bbbb6c1e29139083031a; emception-policy-delegation-fix-proof.zip ab7ddc3076760c8cba34385515557c21995d9c43df03fa95faa31eab16e740be; emception-package-followthrough-proof.zip b4a00cbce851a885c6f7a2258eaf598ab2f8db02e307c9ad327c89cc044bd473. Previous complete hosted/source proofs remain retained.

Goal ACTIVE, solo work. Verified queued commits await normal publication and exact-head rescans. No new scanner dismissals or exclusions, no default integration, and no all-issues implementation certificate.


Verified source repairs; ignored findings remain in scope (2026-10-06)

This checkpoint supersedes historical status summaries below. Ignoring a finding does not close or fix it.

  • Develop still has 156 open alerts, including #810, at 295ee21, confirmed through a fresh paginated API inventory. No integrated/default closure or all-issues certification is claimed.
  • Published af38 CodeQL still has 79 raw findings, all previously dismissed. Their 79 exact IDs, rules, source locations and original rationales remain in the review queue; none counts as a certified source fix. The wider PR-head history (94 dismissed / 14 fixed) is separate from current raw results. No new scanner dispositions changed in this follow-up.
  • Four genuine API quality repairs committed locally in ab1e22a: unread assignment removed with awaited persistence/concurrent recovery preserved; null pattern retains default/nullable struct behavior; two webhook count locals preserve owner lookup, fallback/clamping/status/delivery. Four struct cases and twelve webhook cases added. No production contract or authorization change.
  • Local verification: warning-clean full solution build with TreatWarningsAsErrors; Resources 697/697, Audit 460/460, Courses 842/842, Authentication 2292/2292, Authorization 1735/1735, API architecture/security 108/108: 6134 passed, zero failed/skipped. Before controls: quota 15/15, audit 16/16, courses 3/3. Some preexisting solution mappings emit TestingLab Debug outputs; not every solution DLL is claimed Release.
  • Publication/rescan pending: local bd3db6b contains eleven actual #810 service regressions; ab1e22a contains the four repairs. These queued commits are unpublished while the existing browser/Toolchain gates run, preserving their evidence. The four Codacy findings are not yet counted closed.
  • Exact published-head CI evidence: Repository policy, Web (including production build), API, OpenAPI consistency, Migration and Economy gates succeeded. Downloaded affected API artifact: 60 selected projects, 20709/20709; full-application OpenAPI HTTP artifact: 15/15, zero failed/skipped. Testing Lab browser workflow and Emception Toolchain receipt build remain running; no full browser/Emception release completion claimed.
  • Remaining debt: latest Codacy branch inventory remains 1672 unique findings with engine-coverage limitations; original 3358 IDs are retained. Web baseline 2777 bulk suppressions plus 14 source directives remains debt. GitGuardian historical/access failure remains unresolved.
  • Retained proof: quality-4-and-af38-hosted-proof.zip, 96 files, SHA-256 bb1083486ddf9776f4579c322931d6ce1041bf281c338567f80dc982992e0713. Includes reviewed patches, build/before/after logs and TRXs, all 61 downloaded hosted TRXs, exact-head CI snapshots, all 156 default-open records and all 79 raw dismissed findings.

Goal ACTIVE, solo work. No alerts newly ignored, dismissed, suppressed or excluded. No PR merge/default publication performed.


Current open findings — status correction (2026-10-06)

This completion status supersedes earlier scanner-count summaries below; historical evidence is preserved.

  • Default branch: develop is still 295ee21, with 156 open alerts, including #810. No default-branch closure or all-issues certification is claimed.
  • Actual CodeQL results at published af38e8b: all four analyses succeeded without errors/warnings, but they still produce 79 raw findings: 77 C#, 2 JavaScript. All 79 currently have previously dismissed dispositions. The complete PR-head alert history contains 94 dismissed records and 14 fixed records. A zero-open query is not zero raw findings, and a dismissal does not count as a source fix. No new alerts were ignored, suppressed, or dismissed in this follow-up.
  • All 156 original IDs retained: complete baseline/published SARIF comparison covers 71 changed files. 124 scoped IDs have no current same-file/rule result; 32 have current same-file/rule results under other IDs. This is reconciliation, not automatic implementation proof. Every original ID remains in scope until its own source/tests and integrated default scan support resolution.
  • #810 real code evidence: the old LogRedaction.MaskEmail exposed the domain and accepted line/control-character injection. The published helper emits constant markers only. Exact old/new source reproduction gives 6 failing cases before / 8 passing cases after, with null/empty/malformed controls preserved. Real ThreatDetectionService controls: 35/35; SharedKernel logging: 28/28. Fresh full Authentication 2292/2292, Authorization 1735/1735, API architecture/security 108/108, no skips/failures. Thresholds, repository inputs, SIEM event parameters, warning fields and original exceptions remain intact. Local test-only commit bd3db6b adds 11 regressions, with no production change; publication waits for the running heavy gates so their evidence is not canceled.
  • Hosted gates: published af38 Web verify (including production build), Repository policy, OpenAPI consistency, Migration and all four CodeQL language jobs succeeded. API, Economy, Emception and subsequent Testing Lab completion remain pending. Codacy is action_required; GitGuardian still fails on historical findings/access limitations.
  • Codacy: fresh branch inventory has 1672 unique findings, four exhausted/count-consistent pages. The original 3358 IDs and ignored baselines remain retained. Incomplete engine coverage and scan absence do not establish fixes.
  • Retained proof: af38-published-156-810-verification-proof.zip, 53 files, SHA-256 4f5f31d5be320c990e72b5cc114d52835356c843a6466d29d202404e04bd09fa. Includes full source/SARIF reconciliation, actual before/after controls, TRXs, publication evidence and prior lint resource failures. Goal remains ACTIVE.

Latest verified batch: af38e8b (2026-10-06)

Remediation remains ACTIVE. This PR is not a repository-wide or historical-issue implementation certificate.

  • Real execution isolation: legacy JavaScript programs/terminal expressions and legacy TypeScript programs now run inside the installed QuickJS WASM guest. Neither executor passes page Window, DOM, storage or fetch to student code. Primitive dialog bridges, guest imports/terminal state, cancellation and failure handling are preserved. TypeScript uses the installed compiler for syntax transpilation; this does not claim full semantic type checking.
  • Deployment: prepare/version the exact installed QuickJS WASM asset in Web predev/prebuild and Learning builds. Byte-exact gzip and WebAssembly.compile control passed. A Chrome client blocked the local harness; actual browser execution remains unverified.
  • Source verification: 56 execution controls passed with real installed WASM/compiler; Web and client typechecks passed; changed-source ESLint passed. Full Web analysis covered 1,818 files with zero active errors/warnings and 2,791 suppressed messages. Remove77 unused bulk suppressions using installed ESLint SuppressionsService on the completed full report: counts2854 ->2777, plus14 inline suppressions remain. Tighten Web budget2860 ->2777. No new suppression or rule disabling. Full CLI repeats for pruning failed on PowerShell/Node memory limits and were retained; replay of the installed suppression service verifies no unused counts. This is not a subsequent full CLI pass.
  • SDK consistency: preserve/merge concurrent948 work, regenerate from its actual CI OpenAPI artifact11432631884 (JSON SHA256 e2e7c6bbba7665a2d932027b692f689063bd2eb4e1ba440886e736891ae9eeff). Seven generated TypeScript files have identical AST after array spelling normalization. Generator diff, client typecheck and sequential1189 tests/93 files passed. The earlier six import-suite failures during generation are retained separately; no test was weakened.
  • LLVM integrity: exact CI archive96cf1ae6... independently downloaded; all175014 file/link entries compared and the immutable Git tree34cd378b6fba47d5bd42003cdaf9505179879004 reconstructed. Only the describe abbreviation in metadata differs (14 vs15 characters), with the same full commit/date/tag/distance. Add this exact reviewed variant; keep primary checksum, pinned version/URL/commit and rejection of unknown hashes. Committed review JSON;28 maintenance controls passed and doctor validates15 tools.
  • Policy: current frozen install/live installed security controls34, shell71, audit-validator9 and deployment14 pass/3 Windows-specific skips. API source unchanged by this batch.
  • Scanner state: fresh18:45 Codacy inventory1674 unique findings, four pages exhausted. Visible logs bind948c013 and hosted ESLint9.18.12 crashes in import/no-namespace, Shopify jest/no-all-mocks-methods and security-node/detect-unhandled-async-errors. Coverage remains incomplete. Original3358 IDs retained; absence is not certification. All four exact948 CodeQL analyses completed without errors/warnings (rawC#77/JS2/Python0/Actions0; no open head alerts), distinct from prior93 false-positive dispositions. Newaf38 analyses are running; no new dismissals.
  • GitGuardian: approved OAuth completed, but organization incident access still redirects to the personal workspace. Historical range findings remain; no new app installation/trial/permission expansion, dismissal or history rewrite.
  • Retained evidence: local unpublished source/proof checkpoint SHA2564da56d6b4fb3b9b8e56ceba8a9d2028d0609023aebc85aa55fc8b7b52509b7e9, plus full report/pruning and published receipts saved separately. Incoming948 OpenAPI/Economy drift and LLVM failures retained. Its unfinished Testing Lab run is not treated as passed.
Previous implementation and verification checkpoints

Security and quality remediation — active goal

Published PR head: b4040c7885d216c503c91acdb7fffec1515b6207. Normal push to fix/ghas-codeql-waves; no GitHub merge or default-branch publication. The goal remains active and incomplete.

Latest published corrections and actual controls

  • Newly published GHSA-6qxp-vccf-f47h made the preceding 93bb dependency gates fail closed before downstream tests. Upgrade affected transitive MCP SDK consumers from 1.30.0 to fixed 1.31.0 with a same-major scoped override. Preserve unrelated Babel lock entries.
  • Actual cached SDK 1.30.0 attempts a credential-bearing request against a different authorization-server issuer in a wholly stubbed network witness. Actual installed SDK 1.31.0 rejects the same mismatch before any request. No authored MCP OAuth provider or credential storage was found in application source; this does not certify unrelated third-party storage implementations.
  • Final local frozen install, approved patch rebuild and live installed-graph audit pass. All 34 installed security controls pass, zero skips. Complete repository policy passes: 71 shell controls, 9 audit-validator controls, deployment 14 passed / 3 skipped on Windows. The provisional run that correctly rejected a concurrent lockfile edit is retained separately.
  • Retain the preceding random 256-bit disposable PostgreSQL credentials, consistent readiness/connection/template use, GitHub Actions masking, and command/output redaction. All four owned fixtures require SCRAM host authentication. Actual PostgreSQL accepts the intended credential, rejects a different credential, and authenticates the migrated template. The earlier wrong-password acceptance witness and all failed attempts remain retained.
  • Replace the runner's password-like hex regex literal with a stronger relational assertion that the TCP probe uses the actual generated Docker credential. Actual runner controls 10/10 pass. No scanner suppression or weaker test assertion.

Fresh external state (2026-10-06 17:35 UTC)

  • Exact b404 repository policy SUCCESS. CodeQL Actions, Python and JavaScript workflows SUCCESS; C# still running. API, Web, OpenAPI, Migration, Economy and Emception gates are still in progress. Earlier canceled runs are not successful.
  • Codacy's fresh branch inventory: 1,674 unique IDs, four exhausted pages and consistent totals. Its b404 check is ACTION_REQUIRED. Branch inventory alone does not establish commit binding; visible completed-analysis logs remain to be reviewed. The preceding hosted ESLint crashes remain incomplete scanner coverage, not a passed analysis.
  • Keep all original 3,358 IDs in the ledger: preceding reconciliation 1,621 still reported, 1,737 absent requiring source/coverage proof, plus 53 new IDs. No ID is certified from absence alone. Exclusions, disabled rules and ignored baselines remain debt.
  • Exact b404 GitGuardian check still reports two historical occurrences: fixture incident 37905043 at acc58c9, and regex-literal incident 37929785 at 93bb229. Neither points to a new b404 occurrence. Current source is repaired; historical PR-range records do not close themselves. Explicitly authorized GitGuardian OAuth completed, but this account lands in its personal workspace and cannot access the organization's incidents. No new installation, trial, history rewrite or dismissal.

Prior verified integration evidence and remaining work

At preceding application head d6a5369: complete Release API solution 0 warnings / 0 errors, 4,403 unique targeted API cases passed, full client 1,189 passed, both TypeScript checks passed, Web ESLint 1,814 files with 0 active errors/warnings. 2,868 suppressed Web messages remain debt. Fresh compiled Swagger regenerates identical client code; actual curl digest and generator consistency pass. These application checks are scoped to their tested source; newest hosted integration gates are still required.

All four preceding d6 CodeQL analyses succeeded with empty warning/error fields and zero official open PR-head alerts. Prior documented false-positive dispositions remain distinct from source fixes; new exact-head proof is pending. Coding assessment adapter and official grading revision publication remain a functional gap. Default-branch integration/rescan and Dependabot's sprintf version alert remain outstanding. No repository-wide certification is claimed.

Retained evidence SHA256: d6 integration ZIP 0775f1396d379e8e508fc3e5bebcd80874edb0717ff077f0a9e7f7b6d9aa4af2; 93bb fixture ZIP d808de79097c4156031fbcdef698c33b990fe929c4e756742991d2b03d44ac83; b404 SDK ZIP d7ee45a36f6fdab106e8160ac8d3fb0423c840d66001f5f054dd9f1d5f3fd7cf.

Preceding checkpoints (historical tested commit scopes)

Security and quality remediation — active goal

Published PR head: 93bb229568792cb4f6c5ec0913c322e99f2d4ad1. Normal push to fix/ghas-codeql-waves; no GitHub merge or default-branch publication. Source fixes and scanner disposition remain separately evidenced.

Latest verified source fixes

  • Disposable PostgreSQL fixtures now generate a distinct 256-bit random password per container and use it consistently in readiness, test connections and the migrated template.
  • Real-server verification exposed loopback TCP accepting incorrect passwords under the image's original authentication defaults. All four gate-owned fixtures now initialize host authentication with SCRAM. Real PostgreSQL controls pass: correct password accepted, different password rejected, template database accessible with the intended credential. Owned proof containers removed.
  • Generated passwords are masked in GitHub Actions and redacted from command logging and streamed output, including split chunks and trailing text. Command failures still propagate. Complete shell policy: 71 passed / 0 failed.
  • Previous dependency/source remediation is now published: pin pnpm 10.34.6, sharp 0.35.5 and affected shell-quote consumers 1.11.0; ensure approved braces/sprintf patches are actually applied; audit installed bytes and versions. Installed-security controls 33 passed / 0 skipped.
  • Integrated develop and concurrent remote branch changes while preserving the reviewed fixes. Web lint budget tightened to 2860; actual baseline 2854 passes.

Verified integration evidence at preceding head d6a5369

Complete Release API solution build: 0 warnings / 0 errors. Latest targeted API suites: 4,403 unique passing cases, including the unchanged full Resources repeat 66/66. The earlier Resources renewal timeout and isolated repeat are retained as separate evidence.
Complete client: 1,189 passed. Both client/Web TypeScript checks pass. Full Web ESLint: 1,814 files, 0 active errors/warnings; 2,868 suppressed messages remain debt. Fresh compiled API Swagger regenerates identical client code; final generator consistency and actual curl overlay digest pass.
Repository policy passes locally; three Linux deployment controls were skipped on Windows and remain unverified here.

Live scanner evidence and remaining scope

  • Codacy branch inventory at 2026-10-06 16:56:50 UTC: 1,674 unique findings, four exhausted pages, consistent totals. Visible PR logs bind analysis to d6a5369. Hosted ESLint 9.18.12 crashed in @shopify/jest/no-all-mocks-methods and import/no-namespace; SonarC# and other engines completed. This is incomplete scanner coverage.
  • Original 3,358 IDs are retained: 1,621 still reported, 1,737 absent requiring source/coverage proof, plus 53 new IDs. None is certified solely from absence. Broad exclusions, disabled diagnostics and previously ignored baselines remain explicit debt.
  • All four CodeQL analyses at exact d6a53697a succeeded with empty error/warning fields: C# 77, JS 2, Python 0, Actions 0 raw results. Official PR-head open-alert API returned zero open alerts. Prior documented false-positive dispositions are distinct from implementation fixes. New 93bb22956 rescans remain required.
  • GitGuardian reported seven occurrences under one historical disposable-fixture password incident. Current code is repaired; its historical-commit incident still needs dashboard review. No history rewrite or dismissal merely to lower counts.
  • Before the latest push, d6 repository policy, Web verify, migration compatibility and OpenAPI consistency succeeded. API/Economy/Emception runs were still incomplete; their subsequent cancellation is not success. Fresh latest-head CI remains required.
  • Coding assessment adapter and official grading revision publication remain a functional gap. Keep backend grading safeguards intact.
  • Default-branch integration/rescan remains necessary. Dependabot's default-branch sprintf version alert is still open despite the exact local patch.

The goal remains active and incomplete. No repository-wide certification is claimed.

Earlier checkpoints and evidence (historical commit scopes)

Security and quality remediation — active goal

Published source head: 15115456828f2d72691d81afd324bce1d1afb6b7, verified against the Git remote and PR API. The goal remains incomplete. Eight incoming commits advanced the branch while local work was in progress; both local fixes were rebased onto them without conflicts. Evidence below is explicitly scoped to the commit tested.

Latest source fixes and local evidence

  • QuizAdapter: 88 control-statement blocks in seven files; strict token/AST/comment equivalence under three preprocessing configurations and idempotence. Assessments 401/401 pass, zero skipped.
  • Remaining C# brace batch: 2,690 blocks across 330 files, split into API and WASM commits. Independent comparison against Git finds zero token, syntax or comment mismatches under all three configurations; a second pass proposes zero edits. No public signatures or executable statements changed in these style commits.
  • Replace two catch/rethrow branches with explicit exclusions in the downstream filters. Preserve virus-scan cancellation tokens and stream position, fail-closed scan failures, unwrapped policy-validation errors and original-inner-exception parse errors. Regressions and complete Assets suite pass.
  • Fresh complete Release API solution build: zero warnings and errors, warnings treated as errors. Fresh Authentication 2,266/2,266, Authorization 1,735/1,735, Assessments 401/401 and Assets 1,164/1,164 pass with zero skips.
  • API verification before the brace batch: 1,050/1,050 pass on an owned PostgreSQL fixture; exact owned-container cleanup verified. An earlier ordinary-fixture run failed nine database/container cases; its raw TRX remains retained.
  • Fresh full API verification now passes 1,050/1,050, zero skipped, on an independent owned PostgreSQL fixture. Both owned fixture containers are confirmed removed. The preceding relocated-output attempt failed 26 cases / 1,024 passed, including Windows native-library path length and repository-root lookups; its raw TRX remains retained. Copying the exact fresh binaries into the normal test output, with SHA256 verification, first passed 28/28 controls and then the full suite. No source tests, assertions or filters were weakened.
  • Declare browser-platform metadata only on the two JSExport compiler methods. Managed build has zero warnings/errors; 14 controls verify real single-file and multiple-file compilation, error paths, output restoration and method metadata. This does not certify browser execution: browser build is currently unavailable because the local wasm-tools-net8 workload is absent.
  • Add five malicious-identifier vectors across all seven asset-provider fetch sites. Actual provider tests 14/14 and targeted ESLint pass. These characterize fixed same-origin relative paths; no Codacy disposition was changed.
  • Correct the public Testing Lab smoke selector to the rendered level-one heading Test. Play. Earn. The actual public-community/layout component suites pass 13/13 and Node syntax checks pass. Fresh hosted browser proof remains required.

Previous verified fixes retained

Browser Python raw-argv persistence and bare exception removal; complete migrated Economy fixtures for affected API verification; actual Learn → Courses menu smoke; coding-cycle alert and failure-artifact collection; native/WASM curl buffer-overread security regressions; Economy braces; Announcements solution mappings; JSON-LD XSS; provider/log privacy and LTI boundaries; Resources host aliases; LLVM archive integrity and dependency patches. None is replaced by scanner suppression.
Fresh installed dependency-patch controls pass 12/12; prior enforced two-CVE exception-policy controls pass 19/19. Hosted Trivy continues reporting patched package versions and remains unresolved.

Scanner evidence — earlier published head 887aee7

Actual Codacy commit detail binds completed analysis to 887aee7. The complete five-page branch inventory at 12:21:58 UTC contains 2,199 unique findings, with consistent totals. Compared with 1d93c39: 822 IDs removed (820 S121 brace findings, two S2737 catch/rethrow findings), two S2360 IDs added for existing optional query/cancellation parameters in ProjectsController, and 2,197 retained. Both complete ID sets and original ignored debt remain preserved. No Codacy dispositions or rules were changed.

This Codacy analysis reports two analyzer problems: SonarC# timed out after 3m24; ESLint image 9.18.12 still crashes in import/no-namespace and Shopify jest/no-all-mocks-methods. Other engines, including Opengrep and PMD, completed. The reduced issue count is not a certification of complete scanner coverage.

All four CodeQL languages completed successfully at the exact earlier head 887aee7: C# 1900590902, JavaScript/TypeScript 1900468555, Python 1900458922 and Actions 1900457931, with empty analysis error/warning fields. The official exact PR-head open-alert API returns zero open alerts. Raw analysis and open-alert records are retained. Cumulative documented false-positive resolutions remain 93; no new dismissals. Default develop previously retains 156 open alerts and still requires integration/rescan.

Per-finding review remains necessary for fixture literals, constant/optional-parameter contracts, same-origin fetches and patched-version reports.

Current scanner readback — 1511545

The four-page branch inventory at 13:06:28 UTC has 1,678 unique findings and consistent totals. The visible commit page confirms analysis of 1511545 completed in two minutes. SonarC# completed in 1m18; the hosted ESLint image 9.18.12 still crashes on import/no-namespace and Shopify jest/no-all-mocks-methods. The incoming .codacy.yaml excludes tests and generated/vendored paths and documents bulk ignored baselines; the incoming .editorconfig disables many diagnostics. These configuration/disposition reductions are not implementation certification. Retain original findings and reconcile source fixes separately from exclusions or suppressions.

Hosted CI and unresolved work

Current PR Verify 37467469689 is running for 1511545. Policy and classification succeeded; API, Web, OpenAPI and Economy checks remain in progress. The preceding 37461799948 was canceled by incoming branch updates. Policy, classification, OpenAPI consistency and Web verification succeeded. API verify failed during fixture creation after 14 selected projects passed 6,048/6,048 tests, zero skips/failures. createdb encountered PostgreSQL shutting down; 45 remaining selected suites did not execute. A real disposable-image control and a failing-then-passing runner regression establish a premature socket-readiness race. An authenticated-TCP readiness repair and pre-cleanup server diagnostics are tested locally (nine runner cases, seven selector tests, 68 shell gate tests), pending publication. The earlier Economy result was interrupted; Testing Lab critical flow was dependency-skipped after the API failure, not passed. Earlier Emception 37461799984 was canceled. The new Emception 37467469630 is pending behind the 1d93c39 toolchain build. No merge is authorized by these intermediate results.

Previous PR Verify 37447881501 is failed: API, Web, repository policy, OpenAPI client consistency and Testing Lab critical flow succeeded; Economy release failed on the old Testing Lab heading selector. Its affected-API artifact has 23 TRXs with 14,879/14,879 passing, zero failures/skips. Its Economy artifact has 90 TRXs with 22,237 passing test executions, zero failures/skips; some profile executions overlap. The subsequent public-browser failure is retained, not hidden. The selector correction above awaits fresh CI. Migration compatibility was skipped by changed-path scope.

Both older 6a69252 and 631bb05 Emception runs failed the real coding assessment Submit step after toolchain, packaging and actual public WASM tests succeeded: no submission or grade was created. The 631bb05 uploader found no files. The 1d93c39 run is now active with the published diagnostic-path and visible-alert repair; this collects evidence and does not establish a product fix.

Continue fresh CI/scanner verification, genuine source fixes, per-finding dispositions, the hosted ESLint analyzer failure, coding Submit repair and original-ID reconciliation. Default-branch integration/rescan is still required. No merge or repository-wide certification is claimed.

…lines

Switch shared config to typescript-eslint recommendedTypeChecked with
parserOptions.projectService; disableTypeChecked for plain JS config
files. Baseline all @game-guild/eslint-config consumers (ui 66 files,
infrastructure/client 118 files) via eslint --suppress-all; add
lint:baseline regen scripts. Client tsconfig covers examples/ and
build configs for the project service.
Add typescript-eslint recommendedTypeChecked (Codacy parity, no-unsafe-*
rules) on top of eslint-config-next presets, with projectService and
disableTypeChecked scopes for plain-JS and test files (outside tsconfig
by design). Baseline: 255 -> 458 files, 363 -> 2993 entries.

devDep typescript-eslint@^8.70.0 matches the instance eslint-config-next
16.3.6 resolves to; type-aware lint needs --max-old-space-size (12GB run).
Evidence: .omo/evidence/task-4-codacy-quality-debt.md
Copilot AI balanced review requested due to automatic review settings October 5, 2026 22:03
Comment thread tools/emception/packages/core/src/ui/adapters.ts Fixed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Rate-limit bypass, unsanitized logging, quadratic parsing, malformed doctest parsing, and stale-export concurrency issues remain.

Review effort: Balanced
Findings: 2 High severity · 5 Medium severity

Open (7)
What changed in this PR

Hardens backend/frontend security findings, improves stale audit-export recovery, and enables type-aware linting.

Changes:

  • Sanitizes sensitive logs, validates redirects/URLs, and hardens DOM/CSV/object handling.
  • Adds stale scheduled-export recovery and tests.
  • Strengthens TypeScript typing, lint baselines, and ReDoS-prone parsing.
File Description
tools/​emception/​scripts/​toolchain/​provider.ts Validates GitHub API host.
tools/​emception/​packages/​core/​src/​ui/​adapters.ts Blocks prototype-pollution keys.
tools/​emception/​packages/​core/​src/​testing/​doctest/​parse.ts Replaces regex parsers.
pnpm-lock.yaml Updates resolved tooling dependencies.
packages/​ui/​package.json Adds lint baseline script.
packages/​ui/​eslint-suppressions.json Records existing lint debt.
packages/​tooling/​eslint/​src/​index.js Enables type-aware linting.
packages/​infrastructure/​wasm/​dotnet/​src/​index.ts Types compiler global.
packages/​infrastructure/​wasm/​dotnet/​index.html Removes unsafe HTML rendering.
packages/​infrastructure/​client/​tsconfig.json Expands checked source scope.
packages/​infrastructure/​client/​package.json Adds lint baseline script.
packages/​infrastructure/​client/​eslint-suppressions.json Records existing lint debt.
packages/​features/​lexical-surface/​src/​index.ts Exports Vega theme types.
packages/​features/​lexical-surface/​src/​features/​vega-lite/​lexical/​vega-lite-component.tsx Repairs logical expression syntax.
packages/​features/​lexical-surface/​src/​features/​vega-lite/​editor/​vega-lite-export.tsx Types Vega theme configuration.
packages/​features/​lexical-surface/​src/​features/​mermaid/​editor/​mermaid-validator.ts Replaces arrow regex validation.
packages/​features/​courses/​src/​components/​learner/​learner-activity-center.tsx Replaces trailing-slash regex.
apps/​web/​src/​components/​feed/​social-media-preview.tsx Restricts preview URL protocols.
apps/​web/​src/​components/​block-content-editor/​plugins/​preview-components/​preview-vega-lite.tsx Removes unsafe theme casts.
apps/​web/​src/​components/​block-content-editor/​plugins/​preview-components/​preview-text.tsx Types serialized text nodes.
apps/​web/​src/​components/​block-content-editor/​hooks/​editor/​executors/​typescript-executor.ts Handles nested generic syntax.
apps/​web/​src/​components/​block-content-editor/​hooks/​editor/​executors/​javascript-executor.ts Corrects console argument typing.
apps/​web/​src/​components/​block-content-editor/​extras/​source-code/​xml/​xml-syntax-highlighter.tsx Bounds XML token regexes.
apps/​web/​src/​components/​block-content-editor/​extras/​source-code/​cpp/​cpp-type-checker.tsx Types Monaco integration.
apps/​web/​src/​components/​block-content-editor/​extras/​html/​html-utils.ts Removes scripts via DOM parsing.
apps/​web/​src/​components/​block-content-editor/​extras/​code-studio/​monaco-file-system.ts Types completion provider.
apps/​web/​src/​app/​[locale]/​(dashboards)/​workspace/​learning/​courses/​[course]/​listing/​media/​page.tsx Validates thumbnail protocols.
apps/​web/​src/​app/​[locale]/​(dashboards)/​console/​learning/​courses/​[course]/​listing/​media/​page.tsx Validates thumbnail protocols.
apps/​web/​scripts/​learning-student-browser-e2e.mjs Uses cryptographic identifiers.
apps/​web/​scripts/​learning-professor-browser-e2e.mjs Uses cryptographic identifiers.
apps/​web/​scripts/​learning-checkout-browser-e2e.mjs Uses cryptographic identifiers.
apps/​web/​scripts/​learning-assets-browser-e2e.mjs Uses cryptographic identifiers.
apps/​web/​scripts/​community-admin-browser-e2e.mjs Uses cryptographic identifiers.
apps/​web/​package.json Adds TypeScript ESLint dependency.
apps/​web/​eslint.config.mjs Enables type-aware web linting.
apps/​api/​tests/​GameGuild.Audit.UnitTests/​Services/​ScheduledAuditExportServiceTests.cs Tests stale recovery invocation.
apps/​api/​tests/​GameGuild.Audit.UnitTests/​Services/​ScheduledAuditExportRepositoryTests.cs Tests stale claim persistence.
apps/​api/​Source/​Modules/​GameGuild.TestingLab/​Controllers/​TestingLabPermissionController.cs Sanitizes permission logs.
apps/​api/​Source/​Modules/​GameGuild.Social.Ratings/​Services/​RatingQueryService.cs Sanitizes rating logs.
apps/​api/​Source/​Modules/​GameGuild.SharedKernel/​Middlewares/​IdempotencyMiddleware.cs Sanitizes replay logs.
apps/​api/​Source/​Modules/​GameGuild.SharedKernel/​Middlewares/​ExceptionHandlingMiddleware.cs Sanitizes exception logs.
apps/​api/​Source/​Modules/​GameGuild.Resources/​Services/​RedisDistributedRateLimiter.cs Sanitizes limiter keys.
apps/​api/​Source/​Modules/​GameGuild.Resources/​Services/​DistributedCacheRateLimiter.cs Sanitizes cache limiter logs.
apps/​api/​Source/​Modules/​GameGuild.Notifications/​Services/​NotificationDeliveryService.cs Redacts notification recipients.
apps/​api/​Source/​Modules/​GameGuild.Notifications/​Services/​Email/​Handlers/​TenantInviteRequestedHandler.cs Masks invite emails.
apps/​api/​Source/​Modules/​GameGuild.Notifications/​Services/​Email/​EmailEventProcessor.cs Masks event recipients.
apps/​api/​Source/​Modules/​GameGuild.Notifications/​Services/​Email/​EmailDispatcherService.cs Masks dispatch recipients.
apps/​api/​Source/​Modules/​GameGuild.Notifications/​Services/​Email/​EmailDeliveryAdminService.cs Masks suppression emails.
apps/​api/​Source/​Modules/​GameGuild.Notifications/​Services/​Email/​DigestDispatcherService.cs Redacts digest recipients.
apps/​api/​Source/​Modules/​GameGuild.Localization/​Services/​LocalizedErrorService.cs Sanitizes localization keys.
apps/​api/​Source/​Modules/​GameGuild.Learning.Lti/​Controllers/​LtiController.cs Hardens deployment and redirects.
apps/​api/​Source/​Modules/​GameGuild.Learning.Certificates/​Services/​CertificateService.cs Sanitizes certificate logs.
apps/​api/​Source/​Modules/​GameGuild.Learning.Assessments.QuizAdapter/​QuizProgramContentBoundary.cs Removes exception disclosure.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authorization/​Services/​ResourcePermissionService.cs Redacts invitation details.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authorization/​Middleware/​RequestContextLoggingMiddleware.cs Sanitizes request paths.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authorization/​Middleware/​PermissionCachingMiddleware.cs Sanitizes trace paths.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authorization/​Middleware/​ActorContextMiddleware.cs Redacts permission-failure context.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authorization/​Middleware/​AccessReviewMiddleware.cs Sanitizes trace paths.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authorization/​Middleware/​AbacPolicyMiddleware.cs Sanitizes trace paths.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authorization/​Controllers/​TenantPermissionsController.cs Redacts permission logs.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authorization/​Controllers/​ResourcePermissionsController.cs Redacts resource logs.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authorization/​Commands/​ResourcePermissionCommands.cs Masks invitation email.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Services/​UserEnumerationProtectionService.cs Redacts email timing hash.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Services/​ThreatDetectionService.cs Masks brute-force identifier.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Services/​ServiceAccountService.cs Redacts service-account logs.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Services/​PasswordHasher.cs Separates password score dataflow.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Services/​OAuthAuthService.cs Masks OAuth emails.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Services/​LocalAuthService.cs Masks local-auth emails.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Services/​JwtTokenService.cs Redacts token metadata.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Services/​EmailVerificationService.cs Redacts verification data.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​PermissionCachingMiddleware.cs Sanitizes trace paths.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Handlers/​SendEmailVerificationCommandHandler.cs Masks unknown emails.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Handlers/​LocalSignInHandler.cs Sanitizes IP logs.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Controllers/​ServiceAccountTokenController.cs Restructures grant validation.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Controllers/​RolesController.cs Sanitizes role logs.
apps/​api/​Source/​Modules/​GameGuild.Identity.Authentication/​Controllers/​KeyRotationController.cs Sanitizes rotation logs.
apps/​api/​Source/​Modules/​GameGuild.Features/​Services/​FeatureFlagEvaluationService.cs Sanitizes feature keys.
apps/​api/​Source/​Modules/​GameGuild.Features/​Services/​CapabilityService.cs Sanitizes capability logs.
apps/​api/​Source/​Modules/​GameGuild.Compliance.Audit/​Services/​ScheduledAuditExportService.cs Recovers claims and uses system clock.
apps/​api/​Source/​Modules/​GameGuild.Compliance.Audit/​Services/​ScheduledAuditExportRepository.cs Persists stale-claim recovery.
apps/​api/​Source/​Modules/​GameGuild.Compliance.Audit/​Services/​AuditExportWebhookNotifier.cs Sanitizes webhook logs.
apps/​api/​Source/​Modules/​GameGuild.Compliance.Audit/​Services/​AuditActionTypeExportFormatter.cs Reuses hardened CSV escaping.
apps/​api/​Source/​Modules/​GameGuild.Compliance.Audit/​Extensions/​AuditModule.cs Configures stale-claim threshold.
apps/​api/​Source/​Modules/​GameGuild.Compliance.Audit/​Controllers/​AuditController.cs Sanitizes audit filters.
apps/​api/​Source/​Modules/​GameGuild.Commerce.Payments/​Services/​StripeCustomerService.cs Masks payment emails.
apps/​api/​Source/​Modules/​GameGuild.Commerce.Payments/​Repositories/​PaymentRepository.cs Sanitizes payment identifiers.
apps/​api/​Source/​Modules/​GameGuild.Commerce.Billing/​Controllers/​BillingWebhooksController.cs Sanitizes webhook metadata.
apps/​api/​Source/​Modules/​GameGuild.Assets/​Security/​SecureAssetDeliveryController.cs Sanitizes asset-security logs.
apps/​api/​Source/​Modules/​GameGuild.Assets/​Security/​AssetRateLimitService.cs Sanitizes blocked IP logs.
apps/​api/​Source/​Modules/​GameGuild.Assets/​Controllers/​AssetsController.cs Authorizes before validation.
apps/​api/​Source/​GameGuild.API/​Database/​PlatformIdentitySeeder.cs Masks seeded admin email.
apps/​api/​Source/​GameGuild.API/​Database/​DatabaseSeeder.cs Masks legacy admin email.
apps/​api/​Source/​GameGuild.API/​Core/​Middleware/​RedisEndpointRateLimitingMiddleware.cs Sanitizes rate-limit logs.
apps/​api/​Source/​GameGuild.API/​Core/​Extensions/​RateLimitingServiceCollectionExtensions.cs Sanitizes rejection logs.
apps/​api/​Source/​GameGuild.API/​Core/​Email/​SesEmailSender.cs Masks SES recipients.
apps/​api/​Source/​GameGuild.API/​Core/​Email/​EmailSender.cs Masks email recipients.
apps/​api/​Source/​GameGuild.API/​Core/​ApiVersioning/​ApiVersionUsageMiddleware.cs Sanitizes API usage logs.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

{
var rateLimitKey = RateLimitKeyPrefix + $"{userId}:{email.ToLowerInvariant()}";
// Deterministic hash keeps the per-(user, email) rate-limit window without caching the raw email.
var rateLimitKey = RateLimitKeyPrefix + $"{userId}:{LogRedaction.RedactSecret(email)}";
Comment on lines +310 to +313
do {
previous = output
output = previous.replace(/<[^<>]*>/g, "")
} while (output !== previous)
Comment on lines +54 to +57
if (int.TryParse(section[AuditScheduledExportOptions.StaleClaimThresholdMinutesKey], out var staleMinutes))
{
options.StaleClaimThreshold = TimeSpan.FromMinutes(staleMinutes);
}
Comment on lines +156 to +159
foreach (var export in exports)
{
export.RecordFailure(nowUtc, "Stale claim recovered");
export.UpdateNextRunTime(nowUtc);
logger.LogWarning(
"Brute force attack detected - Identifier: {Identifier}, Failed attempts: {FailedCount} in {TimeWindowMinutes} minutes",
identifier, failedCount, timeWindowMinutes);
LogRedaction.MaskEmail(identifier), failedCount, timeWindowMinutes);
LogRedaction.RedactId(ex.TenantId, "tid"),
context.TraceIdentifier,
context.Request.Path);
context.Request.Path.Value);
while (numberStart > 0 && isAsciiDigit(head.charAt(numberStart - 1))) {
numberStart -= 1;
}
if (numberStart === head.length || numberStart === 0) return null;
@codacy-production

codacy-production Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Not up to standards ⛔

🔴 Issues 17 critical · 13 high · 19 medium · 51 minor

Alerts:
⚠ 100 issues (≤ 0 issues of at least minor severity)

Results:
100 new issues

Category Results
Compatibility 8 medium
10 high
BestPractice 6 medium
1 minor
Documentation 4 minor
ErrorProne 1 medium
3 high
Performance 4 medium
Comprehensibility 6 minor
Security 17 critical
CodeStyle 40 minor

View in Codacy

🟢 Metrics 1614 complexity · 32 duplication

Metric Results
Complexity 1614
Duplication 32

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@github-advanced-security github-advanced-security AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

catch (Exception ex)
{
logger.LogWarning(ex, "Failed to queue tenant invite notification for {Email}", notification.InviteeEmail);
logger.LogWarning(ex, "Failed to queue tenant invite notification for {Email}", LogRedaction.MaskEmail(notification.InviteeEmail));
logger.LogInformation(
"Processed {EventType} delivery event. Recipient: {RecipientEmail}, SuppressionReason: {Reason}, DeadLettered: {DeadLettered}",
deliveryEvent.EventType, normalized, reason, deadLettered);
deliveryEvent.EventType, LogRedaction.MaskEmail(normalized), reason, deadLettered);
// Record successful registration
await authAttemptService.RecordSuccessfulAttemptAsync(request.Email, userId, ipAddress ?? "unknown", userAgent, stopwatch.Elapsed, "Registration").ConfigureAwait(false);
logger.LogInformation("User {Email} successfully signed up", request.Email);
logger.LogInformation("User {Email} successfully signed up", LogRedaction.MaskEmail(request.Email));
var userId = newUser.Id;

logger.LogInformation("Created new user with ID: {UserId} and Email: {Email}", userId, newUser.Email);
logger.LogInformation("Created new user with ID: {UserId} and Email: {Email}", userId, LogRedaction.MaskEmail(newUser.Email));
{
await enumerationProtection.AddTimingProtectionDelayAsync(true, SystemClock.UtcNow).ConfigureAwait(false);
logger.LogWarning("Sign-up attempt with existing email: {Email}", request.Email);
logger.LogWarning("Sign-up attempt with existing email: {Email}", LogRedaction.MaskEmail(request.Email));
{
failureReason = "InvalidCredentials";
logger.LogWarning("User not found: {Email}", request.Email);
logger.LogWarning("User not found: {Email}", LogRedaction.MaskEmail(request.Email));
{
failureReason = "InvalidCredentials";
logger.LogWarning("Invalid password for user {Email}", request.Email);
logger.LogWarning("Invalid password for user {Email}", LogRedaction.MaskEmail(request.Email));
if (user is null)
{
logger.LogWarning("Verification email requested for unknown email {Email}", notification.Email);
logger.LogWarning("Verification email requested for unknown email {Email}", LogRedaction.MaskEmail(notification.Email));
throw new InvalidOperationException("Authentication notification was not durably queued.");

logger.LogInformation("Verification email queued for {Email}", notification.Email);
logger.LogInformation("Verification email queued for {Email}", LogRedaction.MaskEmail(notification.Email));
{
logger.LogError(ex, "Error queueing verification email to {Email}", notification.Email);
logger.LogError("Error queueing verification email to {Email}: {ErrorType}",
LogRedaction.MaskEmail(notification.Email), ex.GetType().Name);
if (user is null)
{
logger.LogWarning("Magic-link email requested for unknown email {Email}", notification.Email);
logger.LogWarning("Magic-link email requested for unknown email {Email}", LogRedaction.MaskEmail(notification.Email));
throw new InvalidOperationException("Authentication notification was not durably queued.");

logger.LogInformation("Magic-link email queued for {Email}", notification.Email);
logger.LogInformation("Magic-link email queued for {Email}", LogRedaction.MaskEmail(notification.Email));
throw new InvalidOperationException("Authentication notification was not durably queued.");

logger.LogInformation("Password reset email queued for {Email}", notification.Email);
logger.LogInformation("Password reset email queued for {Email}", LogRedaction.MaskEmail(notification.Email));
{
logger.LogError(ex, "Error queueing password reset email to {Email}", notification.Email);
logger.LogError("Error queueing password reset email to {Email}: {ErrorType}",
LogRedaction.MaskEmail(notification.Email), ex.GetType().Name);

logger.LogInformation("Welcome email queued for {Email} (ID: {UserId})", notification.Email, notification.UserId);
logger.LogInformation("Welcome email queued for {Email} (ID: {UserId})",
LogRedaction.MaskEmail(notification.Email), LogRedaction.RedactId(notification.UserId, "uid"));
{
logger.LogWarning(ex, "Welcome email queueing failed for user {Email} (ID: {UserId})", notification.Email, notification.UserId);
logger.LogWarning("Welcome email queueing failed for user {Email} (ID: {UserId}): {ErrorType}",
LogRedaction.MaskEmail(notification.Email), LogRedaction.RedactId(notification.UserId, "uid"), ex.GetType().Name);
notification.AuthMethod,
notification.IpAddress ?? "Unknown",
LogRedaction.RedactId(notification.UserId, "uid"),
LogRedaction.MaskEmail(notification.Email),
mathrmartins and others added 8 commits October 7, 2026 06:47
adapters.ts setPath (CodeQL prototype-pollution follow-up): the final
segment write now uses Object.defineProperty so a hostile inherited
setter (e.g. a planted __proto__ poison pill) can never be invoked;
blocklist + Object.hasOwn traversal unchanged.

doctest parse matchFailureLine: a digit run is only a line number when
a ':' immediately precedes it. 'fileX12: ERROR: ...' no longer misparses
as file='file', line=12 — it matches with file='fileX12' and no line.
Canonical 'src/main.ts:42: ERROR: ...' still parses file + line.

Both covered by new regression tests in packages/core/tests.
…t, quiz boundary

- AuditModule: reject non-positive StaleClaimThresholdMinutes via options validation
- ScheduledAuditExportRepository: skip schedule requeue when a fresh in-progress claim exists
- ActorContextMiddleware: sanitize request path in permission-failure log (CWE-117)
- LtiController: extract fail-closed authorization redirect validation (https, absolute, no userinfo)
- QuizProgramContentBoundary: derive guard from document shape, not caller-supplied content type
CodeQL 'Exposure of private information' cluster (PR #698) flagged every
email-logging call site because LogRedaction.MaskEmail collapsed all
addresses to a constant, and threat alerts could not correlate repeated
identifiers. Replace the constant with deterministic, irreversible masks
in the shared platform helper:

- MaskEmail: first alnum char of local part + domain + public suffix
  (alice@example.com -> a***@e***.com); output built only from masked
  segments, control characters cannot pass through
- MaskUsername: first char + length (alice -> a***(5))
- MaskIpAddress: keep octets 1+3 for network correlation
  (10.20.0.30 -> 10.x.0.x), short hash fallback for non-IPv4
- MaskIdentifier: shape-dispatching mask for security logs where the
  identifier may be an email, IP, or username

ThreatDetectionService brute-force alerts now use MaskIdentifier so
repeated attacker identifiers remain correlatable without exposure.

Also harden EmailVerificationService token handling:

- verification/reset/magic-link tokens are one-time secrets; cache keys
  are now SHA-256 digests instead of the raw token (clear-text storage
  findings; no DB persistence involved, so no migration required)
- rate-limit bucket digest now normalizes the email (trim + lowercase)
  so User@x and user@x share one bucket, closing a resend-limit bypass
  via case variants

PasswordHasher strength score inspected: never logged or persisted
(IsValid/ValidationFailures are the only consumed fields), no change
needed.

Tests: LogRedaction determinism/irreversibility/dispatch coverage;
mixed-case resend rate-limit bucket test; existing format assertions
updated to the new deterministic masks.
…nt close)

Companion quadratic-loop fix (stripGenericGroups) was superseded upstream:
the TypeScript executor now uses real ts.transpileModule + QuickJS isolation
(7cbf392), removing the hand-rolled generic-strip loop entirely.
…nistic masks

ThreatDetectionLoggingSecurityTests asserted the old constant
'email:redacted' marker; the correlation-preserving MaskIdentifier
output (p***@p***.invalid style) satisfies the same no-leak/no-control-
char assertions while keeping brute-force alerts correlatable.
…lized rate-limit keys

The redaction cherry-pick accidentally reverted 2a25629's
TryConsume/IsConsumed single-use machinery (caught by
EmailTokenSingleUseSecurityTests). Restore that version verbatim and
re-apply the one surviving piece from our branch: email rate-limit
bucket keys now hash Trim().ToLowerInvariant(email) so User@x and
user@x share one two-minute resend bucket.
@tolstenko

Copy link
Copy Markdown
Contributor Author

Gate status at 26006c9

All workflow checks green except Codacy. CodeQL: 0 open alerts on this branch (all 100 open alerts sit on develop pre-fix state — the PR check's 'new alerts' listing misattributes them via the merge-base comparison; clears when this merges and develop rescans at the fixed code).

Remaining red: Codacy (290 new issues). Cannot enumerate from CI artifacts — Codacy API requires the org API token (personal token lands in personal workspace, per prior note). Action needed from someone with gameguild-gg Codacy org access: pull the issue list for PR 698 and either fix or disposition via the established .omo/codacy/ triage process.

Verified locally at this head: web lint + typecheck exit 0 · lint-budget ratchet ok · shell-gate tests 70/71 under bash 5 (1 fail = pnpm absent in container, env-only) · generated client matches fresh Release API regeneration (verify-openapi-surface.sh capture).

@tolstenko

Copy link
Copy Markdown
Contributor Author

Fix wave complete: all review findings addressed

Security fixes (this wave, verified by full test suites):

  • Redaction redesign — LogRedaction now exposes deterministic, correlation-preserving masks (MaskEmail → p***@p***.invalid, MaskUsername → p***(26), MaskIpAddress → 10.x.0.x, dispatching MaskIdentifier). Closes the Copilot 🔴 ThreatDetectionService correlation finding + 37 CodeQL exposure findings at their root. Brute-force alerts stay correlatable without leaking PII.
  • Audit hardening — stale-claim threshold validation (rejects ≤0), requeue guard against overlapping executions, request-path log sanitization (LogRedaction.Sanitize), LTI redirect fail-closed builder (https + no embedded credentials), quiz boundary shape-derived (fails closed on ambiguous docs).
  • XML highlighter — --!> comment close per HTML spec, multiline CDATA state (CodeQL bad-regex ×4).
  • emception — setPath write via defineProperty (kills setter-based __proto__ vector, CodeQL prototype-pollution), doctest failure-line parser requires : before line number (fileX12: ERROR: no longer misparsed as file/line).
  • Email tokens — teammate's atomic TryConsume/digest machinery preserved + case-normalized rate-limit keys (User@x == user@x bucket; closes Copilot 🔴 resend-limit bypass).

Superseded (intentionally dropped): our stripGenericGroups quadratic-loop fix — the executor now uses real ts.transpileModule + QuickJS isolation (7cbf392), removing the hand-rolled generic-strip loop entirely.

Verification: build 0W/0E · Authentication 2372/2372 · Authorization 1738/1738 · Assessments 477/477 · lint exit 0 · budgets green (web 2774/2777). Merged current develop (#699) — PR is conflict-free.

mathrmartins and others added 19 commits October 7, 2026 14:16
Classify canonical localhost DNS spellings before the custom remote asset allowlist check in both web and client guards. Preserve public allowlists, protocol and credential rules, and internal service origin pinning. Add 76 regression cases; qualify 4605 owning tests, typechecks, client build, and uncapped local lint. Hosted scan confirmation remains pending.
# Conflicts:
#	apps/api/Source/Modules/GameGuild.Identity.Authentication/Entities/ApiKey.cs
#	apps/api/Source/Modules/GameGuild.Identity.Authentication/Handlers/SendEmailVerificationCommandHandler.cs
#	apps/api/Source/Modules/GameGuild.Identity.Authentication/Services/EncryptionService.cs
#	apps/api/Source/Modules/GameGuild.Identity.Authorization/Controllers/AccessReviewsController.cs
#	apps/api/Source/Modules/GameGuild.Identity.Authorization/Services/DelegatedAdminService.cs
#	apps/api/Source/Modules/GameGuild.Identity.Authorization/Services/FocusedPermissionServices.cs
#	apps/api/Source/Modules/GameGuild.Learning.Assessments/Controllers/AssessmentsController.cs
#	apps/api/Source/Modules/GameGuild.Learning.Assessments/Controllers/GroupSetsController.cs
#	apps/api/Source/Modules/GameGuild.Learning.Assessments/Controllers/PeerReviewsController.cs
#	apps/api/Source/Modules/GameGuild.Learning.Assessments/Controllers/RubricsController.cs
#	apps/api/Source/Modules/GameGuild.Learning.Courses/Controllers/ProgramCrudController.cs
#	apps/api/Source/Modules/GameGuild.Learning.Courses/Services/ContentInteractionService.cs
#	apps/api/Source/Modules/GameGuild.Learning.Courses/Services/ProgramWriteService.cs
#	apps/api/Source/Modules/GameGuild.SharedKernel/Configuration/PresentationLayer/Authorization/AuthorizationCacheOptions.cs
#	apps/api/tests/GameGuild.Identity.Authentication.IntegrationTests/AuthenticationFlowsE2ETests.cs
#	apps/web/package.json
#	apps/web/scripts/build-learning.mjs
#	apps/web/src/components/ui/date-time-range-picker.test.tsx
#	packages/infrastructure/client/src/generated/.metadata.json
#	packages/infrastructure/client/src/generated/types.gen.ts
#	pnpm-lock.yaml
#	scripts/dev-learning.mjs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants