Continued fixes from the multi-agent review: - recurring tickets cron: now that the parse error is fixed the job runs, exposing two latent bugs. (1) next_run_at was only advanced after the full success path, so any failure (e.g. a NULL created_by passed to the non-nullable assignTicket() $assignedBy -> TypeError) left it in the past and re-created a duplicate ticket every cron cycle. Added an atomic claimForRun() (conditional UPDATE gated on still-due) called BEFORE creation, which also prevents overlapping runs from double-creating. (2) The cron used a raw mysqli with no utf8mb4, corrupting non-ASCII content; it now uses Database::getConnection(). Also guard the assignment so created_by NULL falls back to the assignee. - bulk delete: attachment files were unlinked inside the DB transaction, so an atomic-mode rollback restored rows but the files were already gone. deleteTicket() can now defer file removal to the caller, and BulkOperationsModel deletes files only after a successful commit. - UserModel: back-tick the `groups` column (reserved word on MySQL 8.0.2+). - create_ticket_api.php: stop leaking raw DB/exception messages to callers; log server-side and return a generic error. (Also includes a pre-existing working-tree tweak that adds title to the manual-ticket dedupe hash.) - CI: semgrep install failed under PEP 668; add --break-system-packages. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
33 lines
958 B
YAML
33 lines
958 B
YAML
name: Security
|
|
|
|
on:
|
|
push:
|
|
branches: ["**"]
|
|
pull_request:
|
|
branches: ["**"]
|
|
schedule:
|
|
- cron: '0 6 * * 1'
|
|
|
|
jobs:
|
|
semgrep:
|
|
name: PHP Security (semgrep)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v3
|
|
|
|
- name: Install semgrep
|
|
run: |
|
|
apt-get update -qq
|
|
apt-get install -y -qq python3 python3-pip
|
|
# Debian's Python is externally managed (PEP 668); the runner is
|
|
# ephemeral so installing system-wide is fine here.
|
|
pip3 install --break-system-packages semgrep
|
|
|
|
- name: Run semgrep
|
|
run: |
|
|
semgrep --config=p/php --config=p/owasp-top-ten --error \
|
|
--exclude-rule=php.lang.security.injection.echoed-request.echoed-request \
|
|
--exclude-rule=php.lang.security.injection.tainted-filename.tainted-filename \
|
|
--exclude-rule=php.lang.security.injection.tainted-callable.tainted-callable \
|
|
.
|