Release Blocker ? Pending

User tests: Successful: Unsuccessful:

avatar wilsonge
wilsonge
25 Oct 2022

Summary of Changes

Fixes improperly applied fix from the security repo (thanks @richard67 for finding this when doing #39075 and securely raising this when he realised)

Unfortunately the fix from @joomla/security wasn't correctly applied to this repo when combining the 3 parts of the fix. Luckily the important parts were fixed and it's been agreed to fix 'the fix' in the public domain.

This moves the protected keys to the more secure version in the main plugin class, therefore fixing the PHPCS failure too.

Testing Instructions

Ensure drone checks now pass, ensure the debug plugin continues to work and only display the correct results in the previous requests log and also displays no secrets in the request data logs

Link to documentations

Please select:

  • Documentation link for docs.joomla.org:

  • No documentation changes for docs.joomla.org needed

  • Pull Request link for manual.joomla.org:

  • No documentation changes for manual.joomla.org needed

avatar wilsonge wilsonge - open - 25 Oct 2022
avatar wilsonge wilsonge - change - 25 Oct 2022
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 25 Oct 2022
Category Front End Plugins
avatar wilsonge wilsonge - change - 25 Oct 2022
The description was changed
avatar wilsonge wilsonge - edited - 25 Oct 2022
avatar richard67
richard67 - comment - 26 Oct 2022

@wilsonge Any idea why api tests are failing in drone? Maybe the global namespace is wrong?

avatar roland-d
roland-d - comment - 26 Oct 2022

@richard67 from what i can see that namespace should not be a problem. Restarted drone to see if it errors out in the same place.

avatar richard67
richard67 - comment - 26 Oct 2022

Restarted drone to see if it errors out in the same place.

@roland-d It does. It's failing at the login after installation. The screenshot in the artifacts doesn't show any error.

avatar bembelimen bembelimen - change - 26 Oct 2022
Labels Added: Release Blocker ?
avatar bembelimen bembelimen - change - 26 Oct 2022
Status Pending Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2022-10-26 17:36:06
Closed_By bembelimen
avatar bembelimen bembelimen - close - 26 Oct 2022
avatar bembelimen bembelimen - merge - 26 Oct 2022
avatar bembelimen
bembelimen - comment - 26 Oct 2022

Thx

Add a Comment

Login with GitHub to post a comment