1fb984e352c4b8c5f554caec8e0548c3dffb129a
443
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
1fb984e352 |
Merge #22 chart click-to-filter into main
Lint / JS (eslint) (push) Successful in 19s
Lint / PHP requirements (version + extensions) (push) Successful in 56s
Lint / PHP (phpcs PSR-12) (push) Successful in 30s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 2m3s
Lint / Deploy (push) Successful in 19s
|
||
|
|
ce0ea66994 |
Charts: click a segment to filter the dashboard (#22)
Lint / PHP (phpcs PSR-12) (push) Successful in 31s
Lint / JS (eslint) (push) Successful in 21s
Lint / PHP requirements (version + extensions) (push) Successful in 1m7s
Lint / Notify on failure (push) Skipped
Lint / Deploy (push) Successful in 3s
Security / PHP Security (semgrep) (push) Successful in 2m0s
All three charts (priority donut, status donut, category bar) now navigate to the same URL filters the stat cards already use, with a pointer cursor on hover, a title hint, and "click to filter" in the tooltip. The status each click applies is explicit rather than left to the default. With no `status` param the controller falls back to the viewer's default_status_filters preference, which can be anything, so the list would not necessarily match what the chart counted. StatsModel builds by_priority and by_category with `status != 'Closed'` while by_status spans every status, so only the priority and category charts pin the open set; the status chart filters on the clicked status alone (which is how clicking "Closed" works at all). Verified two ways: - 17/17 in headless chromium, driving the real chart script from this view with the Chart constructor stubbed, asserting the exact query each click produces and that a click hitting no segment navigates nowhere. - Against the live database, every segment's count equals the number of tickets its filter returns — 12/12 across all three charts — so the list you land on matches the number you clicked. |
||
|
|
4fd2c7ce7d |
Merge #20 modal dismissal fix into main
Lint / PHP (phpcs PSR-12) (push) Successful in 18s
Lint / JS (eslint) (push) Successful in 9s
Lint / PHP requirements (version + extensions) (push) Successful in 39s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 1m32s
Lint / Deploy (push) Successful in 3s
|
||
|
|
2ff7345a73 |
Dismissing the required-comment modal no longer looks like a close (#20)
Lint / JS (eslint) (push) Successful in 15s
Lint / PHP requirements (version + extensions) (push) Successful in 41s
Security / PHP Security (semgrep) (push) Successful in 1m8s
Lint / PHP (phpcs PSR-12) (push) Successful in 18s
Lint / Notify on failure (push) Skipped
Lint / Deploy (push) Successful in 2s
A modal can be dismissed four ways: the ✕ button, Cancel, a backdrop click, or
Escape. base.js handles the last two globally (a document click handler and
registerKey('escape', closeAllModals)), so the status-change modal — which wired
only the two buttons — never learned it had been dismissed. The status dropdown
kept displaying the new status even though update_ticket.php was never called,
so the ticket looked closed with no comment until a reload showed it still open.
The same gap left every dynamically-inserted modal in the DOM when dismissed
that way, so the next open inserted a duplicate id that shadowed the live one.
- base.js closeModal now dispatches a bubbling lt:modalclose event (synced to
web_template as bbec859), and _statusCommentModal treats it as "no comment".
- ticket.js reverts the dropdown on any dismissal, guarded against the re-entry
its own lt.modal.close() would otherwise cause.
- dashboard.js gains openModalWithDismiss() so all seven dynamic modals plus the
generic prompt modal tear down however they are dismissed.
Verified in headless chromium against all four dismissal routes plus a
confirm-with-comment control: 22/22. Against the pre-fix files the same test
fails 6 assertions — backdrop and Escape leave the dropdown on "Closed *" with
an orphaned overlay — so it reproduces the reported behaviour exactly.
|
||
|
|
1de04d4908 |
Clear the markdown live preview after posting a comment
Setting the textarea's .value programmatically does not fire an 'input' event, so updatePreview() never ran and the preview kept showing the just-posted comment's rendered markdown underneath an empty composer. (This change was already present in the working tree at the start of the session; committing it on its own rather than folding it into an unrelated fix.) |
||
|
|
153f9a7cef |
Merge #23 light-mode ticket preview fix into main
Lint / PHP (phpcs PSR-12) (push) Successful in 1m9s
Lint / JS (eslint) (push) Successful in 9s
Lint / PHP requirements (version + extensions) (push) Successful in 21s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 2m54s
Lint / Deploy (push) Successful in 6s
|
||
|
|
0a7201d754 |
Light mode: ticket-ID hover preview follows the theme (#23)
Lint / PHP (phpcs PSR-12) (push) Successful in 17s
Lint / JS (eslint) (push) Successful in 9s
Lint / PHP requirements (version + extensions) (push) Successful in 22s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 1m15s
Lint / Deploy (push) Successful in 2s
.ticket-preview-popup used var(--lt-surface), which is not defined anywhere, so the background always fell through to the hardcoded #0a0e14. In light mode that left a near-black panel — and since the rule set no `color`, the inherited near-black body text was effectively invisible on it. The border was hardcoded neon green and the shadow a heavy rgba(0,0,0,0.5). Now uses --bg-card / --text-primary / --accent-green-border / --shadow-color, and .preview-id uses --accent-cyan instead of the undefined --lt-cyan. base.css gains the two tokens the light theme was missing (--accent-green-border and --shadow-color), synced from web_template 0d633bd. Verified with computed styles in headless chromium: light body-text contrast on the panel goes from invisible to 17.7:1, dark stays at 13.2:1, and the ID accent clears 3:1 in both themes. |
||
|
|
12ffd217bb |
Merge #19 light-mode status dropdown fix into main
Lint / PHP (phpcs PSR-12) (push) Successful in 29s
Lint / JS (eslint) (push) Successful in 17s
Lint / PHP requirements (version + extensions) (push) Successful in 40s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 1m14s
Lint / Deploy (push) Successful in 3s
|
||
|
|
a5b0655623 |
Light mode: status dropdown no longer renders dark (#19)
Lint / PHP (phpcs PSR-12) (push) Successful in 23s
Lint / JS (eslint) (push) Successful in 11s
Lint / PHP requirements (version + extensions) (push) Successful in 22s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 1m11s
Lint / Deploy (push) Successful in 2s
Two separate causes, both light-mode-only: 1. base.css `.lt-select` sets `color-scheme: dark` on the element itself, which outranks the `color-scheme: light` the light theme sets on <html>, so the native dropdown popup kept dark chrome. The option list is also hardcoded #0d1117/#c9d1d9 with no light override. Fixed with light overrides for both (synced from web_template, where the same fix landed as 378a8cd). 2. ticket.css coloured the status select with var(--lt-success), --lt-amber, --lt-cyan and --lt-danger — none of which are defined anywhere in the project, so all four always fell through to hardcoded neon fallbacks. Now uses the --accent-* tokens, which carry the same hues and are redefined for light mode. The selectors also lead with .lt-select: at two classes they lost to base.css's `html[data-theme="light"] .lt-select` (0,2,1) and every status was repainted near-black in light mode. Verified with computed styles in headless chromium — all four statuses in both themes (8/8), plus the popup colour-scheme and option colours. |
||
|
|
fa5f347c08 |
Merge #21 workflow enforcement for bulk operations into main
Lint / PHP (phpcs PSR-12) (push) Successful in 31s
Lint / JS (eslint) (push) Successful in 12s
Lint / PHP requirements (version + extensions) (push) Successful in 40s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 1m13s
Lint / Deploy (push) Successful in 3s
|
||
|
|
1d03800ab2 |
Widen bulk_operations.status so partial bulk results can be recorded (#21)
Lint / PHP (phpcs PSR-12) (push) Successful in 26s
Lint / JS (eslint) (push) Successful in 9s
Lint / PHP requirements (version + extensions) (push) Successful in 22s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 1m8s
Lint / Deploy (push) Successful in 3s
Found while verifying #21 against the live schema: the model writes 'completed_with_errors' (21 chars) when a bulk operation finishes with per-ticket failures, but bulk_operations.status was varchar(20), so the write failed with "Data too long for column 'status'". This was latent — bulk status changes previously forced every transition through, so failed was always 0. Now that they honour the Workflow Designer, a partially-skipped batch is a normal outcome and hits it. - migrations/001 widens the column to varchar(32) (idempotent). - The baseline is updated to match, for fresh installs. - The bookkeeping UPDATE is wrapped in a try/catch: it runs after the ticket changes are committed, so an instance deployed ahead of its migrations must not turn a completed operation into an error response. Verified against the live database with a disposable-ticket harness: comment-required rejection changes nothing, undefined transitions are refused per ticket with a reason, allowed transitions still work, mixed batches apply the valid half, and an already-Closed ticket is a no-op. |
||
|
|
9d982ab73f |
Bulk status/close: enforce Workflow Designer rules (#21)
Lint / PHP (phpcs PSR-12) (push) Successful in 23s
Lint / JS (eslint) (push) Successful in 9s
Lint / PHP requirements (version + extensions) (push) Successful in 30s
Lint / Notify on failure (push) Skipped
Security / PHP Security (semgrep) (push) Successful in 1m15s
Lint / Deploy (push) Successful in 2s
Bulk status changes previously bypassed the workflow entirely — the model carried an explicit "admin-only escape hatch" note — so bulk edit could drive tickets through transitions the designer forbids and skip comments the designer requires. BulkOperationsModel now applies the same rules as the single-ticket path: - Transitions absent from status_transitions are refused per ticket and reported with a reason, instead of being forced through. - requires_comment is checked up front across the whole selection, so a batch is rejected before any ticket is mutated rather than half-applied. - The reason is persisted as a comment on each ticket changed, matching what a single-ticket close records. - Tickets already in the target status are a no-op success, not a failure. requires_admin needs no extra check: api/bulk_operation.php already gates the endpoint on admin. Client: both bulk modals now collect a reason, the close path gets a real modal instead of a bare confirm, and per-ticket skip reasons surface in the result toast instead of a bare failure count. |
||
|
|
f57b472211 |
Merge pull request 'Bearer API extension: list/read/comment/close + key scopes' (#26) from development into main
Lint / PHP (phpcs PSR-12) (push) Successful in 25s
Lint / JS (eslint) (push) Successful in 7s
Lint / PHP requirements (version + extensions) (push) Successful in 18s
Security / PHP Security (semgrep) (push) Successful in 1m2s
Lint / Deploy (push) Successful in 3s
Lint / Notify on failure (push) Has been skipped
|
||
|
|
d81fdf4104 |
Docs: document the Bearer API (endpoints, scopes) in README + admin page
Lint / PHP (phpcs PSR-12) (push) Successful in 24s
Lint / JS (eslint) (push) Successful in 7s
Lint / PHP requirements (version + extensions) (push) Successful in 28s
Security / PHP Security (semgrep) (push) Successful in 1m23s
Lint / Deploy (push) Successful in 2s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (pull_request) Successful in 19s
Lint / JS (eslint) (pull_request) Successful in 6s
Lint / PHP requirements (version + extensions) (pull_request) Successful in 23s
Security / PHP Security (semgrep) (pull_request) Successful in 2m36s
Lint / Deploy (pull_request) Has been skipped
Lint / Notify on failure (pull_request) Has been skipped
- README: Bearer API table (list/read/comment/status), scope explanation, and the new endpoints in the API Endpoints table. - /admin/api-keys API Usage section: scopes note + copy-paste cURL examples for create, list/triage, read-one, comment, and close (uses APP_DOMAIN). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
d46f8ffd77 |
Add Bearer API: list/read tickets, post comments, change status
Lint / PHP (phpcs PSR-12) (push) Successful in 41s
Lint / JS (eslint) (push) Successful in 11s
Lint / PHP requirements (version + extensions) (push) Successful in 44s
Security / PHP Security (semgrep) (push) Successful in 2m47s
Lint / Deploy (push) Successful in 2s
Lint / Notify on failure (push) Has been skipped
Extends the Bearer-key API beyond create-only (all rate-limited, scope- enforced, per-key-label attribution): - GET /api/tickets_api.php: triage the queue (status/priority/host title match + pagination) or read one ticket + its comments. read scope. - POST /api/ticket_comment_api.php: post a comment as the key (user_name = key name, linked to the key owner). read_write scope. - POST /api/ticket_status_api.php: change/close status with workflow validation + requires_comment; posts the close reason in the same call, fires the Matrix status notification, invalidates stats. read_write scope. Reuses TicketModel/CommentModel/WorkflowModel/NotificationHelper; a read key cannot mutate. Reachability requires the reverse-proxy Authelia bypass (handled separately). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
5cf5aa9591 |
API keys: add read/read_write scopes + admin scope selector & pagination
Foundation for extending the Bearer API beyond create-only:
- api_keys gains a scope column (read | read_write); baseline schema updated
and the column applied to the live DB. Existing keys default to
read_write so the hwmon create key keeps working.
- ApiKeyModel: createKey() takes a validated scope; validateKey() always
surfaces scope (defaults read_write); getAllKeys() is paginated
({keys,total,page,perPage}, key_hash stripped).
- ApiKeyAuth: expose getKeyContext() (scope/key_name/created_by/api_key_id)
and requireScope() (403 on insufficient scope); existing return values
unchanged.
- create_ticket_api.php: require read_write scope (a read key can't create).
- Admin /admin/api-keys: scope selector on the create form, a scope column,
and pagination (revoked keys were stacking up).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
||
|
|
20e4352f24 |
Merge pull request 'Ship CSRF-drift + markdown fixes to production' (#25) from development into main
Lint / PHP (phpcs PSR-12) (push) Successful in 32s
Lint / JS (eslint) (push) Successful in 13s
Lint / PHP requirements (version + extensions) (push) Successful in 59s
Security / PHP Security (semgrep) (push) Successful in 1m12s
Lint / Deploy (push) Successful in 5s
Lint / Notify on failure (push) Has been skipped
|
||
|
|
d535557e5a |
Strip trailing whitespace failing phpcs (unblocks CI/deploy)
Lint / PHP (phpcs PSR-12) (push) Successful in 20s
Lint / JS (eslint) (push) Successful in 8s
Lint / PHP requirements (version + extensions) (push) Successful in 39s
Security / PHP Security (semgrep) (push) Successful in 1m8s
Lint / Deploy (push) Successful in 2s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (pull_request) Successful in 36s
Lint / JS (eslint) (pull_request) Successful in 7s
Lint / PHP requirements (version + extensions) (pull_request) Successful in 20s
Security / PHP Security (semgrep) (pull_request) Successful in 1m10s
Lint / Deploy (pull_request) Has been skipped
Lint / Notify on failure (pull_request) Has been skipped
CI has been red since the CSRF-drift changes landed a trailing space on the 'success' => false line in these two endpoints, which blocks the deploy job (and therefore beta/prod). No logic change. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
53d3670c7f |
Fix markdown comments breaking on reload (template whitespace parsed as code)
Lint / PHP (phpcs PSR-12) (push) Failing after 55s
Lint / JS (eslint) (push) Successful in 9s
Lint / PHP requirements (version + extensions) (push) Successful in 21s
Security / PHP Security (semgrep) (push) Successful in 1m2s
Lint / Deploy (push) Has been skipped
Lint / Notify on failure (push) Successful in 2s
Stored markdown comments rendered fine in the live preview (parses the raw textarea value) but broke after refresh: the server template emitted the comment text on an indented line, so the on-load renderer parsed element.textContent with ~20 spaces of leading indentation. Markdown treats 4+ leading spaces as a code block, so the first line (e.g. a heading or table row) was mis-parsed and blocks got wrapped in <p>, producing invalid HTML that broke the page layout. - markdown.js: trim the text before parseMarkdown in both on-load renderers so template indentation can't be parsed as a leading code block. - TicketView.php: emit the comment text inline (no surrounding whitespace) so the element's textContent is exactly the stored markdown. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
8f7c669b8f |
Fix markdown code block parser to support language tags and UI classes
Lint / PHP (phpcs PSR-12) (push) Failing after 18s
Lint / JS (eslint) (push) Successful in 7s
Lint / PHP requirements (version + extensions) (push) Successful in 19s
Security / PHP Security (semgrep) (push) Successful in 56s
Lint / Deploy (push) Has been skipped
Lint / Notify on failure (push) Successful in 2s
|
||
|
|
5dea47cd01 |
Fix double-parsing of markdown comments on page load
Lint / PHP (phpcs PSR-12) (push) Failing after 16s
Lint / JS (eslint) (push) Successful in 7s
Lint / PHP requirements (version + extensions) (push) Successful in 19s
Security / PHP Security (semgrep) (push) Successful in 1m1s
Lint / Deploy (push) Has been skipped
Lint / Notify on failure (push) Successful in 2s
|
||
|
|
7a537f46bc |
Fix CSRF token drift in add_comment and update_ticket endpoints
Lint / PHP (phpcs PSR-12) (push) Failing after 50s
Lint / JS (eslint) (push) Successful in 7s
Lint / PHP requirements (version + extensions) (push) Successful in 20s
Security / PHP Security (semgrep) (push) Successful in 1m0s
Lint / Deploy (push) Has been skipped
Lint / Notify on failure (push) Successful in 2s
|
||
|
|
55087bf2cb |
Merge pull request 'Fix bugs across data layer, API, frontend, ops (multi-agent review)' (#24) from development into main
Lint / PHP (phpcs PSR-12) (push) Successful in 33s
Lint / JS (eslint) (push) Successful in 10s
Lint / PHP requirements (version + extensions) (push) Successful in 25s
Security / PHP Security (semgrep) (push) Successful in 1m0s
Lint / Deploy (push) Successful in 3s
Lint / Notify on failure (push) Has been skipped
|
||
|
|
622cae8bbd |
Fix PHP 8.4 breakage: drop deprecated mysqli::ping(), harden dep handler
Lint / PHP (phpcs PSR-12) (push) Successful in 20s
Lint / JS (eslint) (push) Successful in 7s
Lint / PHP requirements (version + extensions) (push) Successful in 19s
Lint / PHP (phpcs PSR-12) (pull_request) Successful in 29s
Lint / JS (eslint) (pull_request) Successful in 14s
Lint / PHP requirements (version + extensions) (pull_request) Successful in 39s
Security / PHP Security (semgrep) (push) Successful in 1m15s
Security / PHP Security (semgrep) (pull_request) Successful in 1m23s
Lint / Deploy (push) Successful in 2s
Lint / Notify on failure (push) Has been skipped
Lint / Deploy (pull_request) Has been skipped
Lint / Notify on failure (pull_request) Has been skipped
The hosts were upgraded to PHP 8.4, where mysqli::ping() is deprecated
(auto-reconnect was removed in 8.2). Database::getConnection() called it on
every reused connection, and api/ticket_dependencies.php's custom error
handler treated the deprecation as a fatal 500 ('A server error occurred'),
breaking the ticket Dependencies tab.
- Database.php: remove the redundant ping()/reconnect check (connection is
request-scoped; no liveness check needed on PHP 8.2+).
- ticket_dependencies.php: only abort on genuine errors; log notices/
warnings/deprecations and continue, so a future deprecation can't 500 it.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
||
|
|
d6214a0339 |
Add schema baseline, fix cron/retention, restore cleanup, correct docs
Lint / PHP (phpcs PSR-12) (push) Successful in 26s
Lint / JS (eslint) (push) Successful in 12s
Lint / PHP requirements (version + extensions) (push) Successful in 21s
Security / PHP Security (semgrep) (push) Successful in 1m11s
Lint / Deploy (push) Successful in 2s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (pull_request) Successful in 47s
Lint / JS (eslint) (pull_request) Successful in 12s
Lint / PHP requirements (version + extensions) (pull_request) Successful in 59s
Security / PHP Security (semgrep) (pull_request) Successful in 1m6s
Lint / Deploy (pull_request) Has been skipped
Lint / Notify on failure (pull_request) Has been skipped
- migrations/000_baseline.sql: full schema baseline captured from prod (validated on a throwaway DB: 17 tables/17 FKs), so the schema is reproducible for fresh installs / disaster recovery - create_recurring_tickets cron: send the Matrix ticket-created notification and invalidate the stats cache like the other create paths - create_ticket_api.php + TicketController::create: invalidate the stats cache on create/escalate/reopen so dashboard counts aren't stale - scripts/cleanup_orphan_uploads.php: restored, made safe (24h mtime grace, 9-digit-dir only, skips avatars/symlinks, matches the unique filename column, --dry-run) - cron/cleanup_audit_log.php: enforce the configured audit-log retention (deleteOldLogs was implemented but never called) - README: correct CSRF-rotation, hwmon dedup (no 24h window), SLA (no P3), stats-cache callers, and the project structure/endpoint listing - .env.example: document TRUSTED_PROXIES fail-open risk and .env quoting Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
27a5db8c85 |
Fix views/controllers/router: command palette, create form, admin views
- Consolidate the duplicated command palette to a single overlay + init in the footer; fix New Ticket to route to /ticket/create (was a 404 /create); keep the CSP nonce and all commands - TicketController create(): trim title, require a non-empty description, and honor the posted status (validated against the canonical list) instead of silently discarding it - UserActivityView: 'Active Users' counts only users active in the selected range, not every registered user - layout_footer/DashboardView: local esc() now escapes quotes so values used in HTML attributes can't break out - TicketView: comments tab badge shows the true total, not just page one - layout_header: gate the 'View activity log' link behind the admin flag - index.php: validate /admin/user-activity date params; anchor the legacy /ticket.php route; align the audit action-type whitelist with the dropdown - ApiKeysView: correct the external API sample to /create_ticket_api.php Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
113b7f9d3f |
Fix frontend JS: CSRF resync, status-comment flow, markdown/XSS, kanban
- base.js lt.api: resync window.CSRF_TOKEN from response bodies before throwing on errors and attach err.data/err.status, so a desynced client auto-recovers without a reload - add lt.ticketStatus.submit: status changes that require a comment now prompt, post the comment, and retry update_ticket with it; wired into the ticket dropdown, dashboard quick-status, kanban drag-drop and the 1-4 keyboard shortcuts (bulk ops unchanged) — matches the new server requires_comment enforcement - base.js markdown.render: drop the unsafe marked/markdownit delegation; always use the built-in XSS-safe renderer - ticket.js: XHR upload sends the X-CSRF-Token header and resyncs the token; use lt.escHtml instead of a re-inlined escape chain; @-mention trigger requires a word boundary (no firing inside emails); idempotent, anchor-safe highlightMentions - base.js typeahead: discard out-of-order async results - markdown.js: balanced table tbody/thead; ticket-ref linkification runs after code extraction so #ids inside code aren't linked - dashboard.js kanban: don't swallow the click after a drag - keyboard-shortcuts.js: J/K skip hidden/skeleton rows; drop duplicate ? Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
d11cb989bf |
Fix API correctness: external API stub/collision, recurring dates, CSV, audit
- create_ticket_api.php: remove the wrong CREATE TABLE stub that broke a fresh DB; generate collision-safe ticket_ids so a genuine id collision isn't misreported as a duplicate and a hw alert dropped; stop leaking raw DB errors; correct a reopen comment that falsely claimed refreshed sensor data - manage_recurring.php: fix next-run so create/edit no longer skips the current period (monthly day-of-month this month, daily today if time not passed, correct ISO weekday, month-length clamp); only recompute on schedule changes to avoid double-fire - export_tickets.php, audit_log.php: neutralize CSV formula injection - revoke_api_key.php, generate_api_key.php: correct HTTP status codes and stop the catch clobbering specific 4xx codes - health.php: stop leaking PHP version / extension names / paths to unauthenticated callers - watch_ticket.php: define $data before use - manage_templates/recurring/custom_fields: add audit logging for CRUD; add recurring_ticket + custom_field to the audit entity whitelist Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
327c225ded |
Fix API security: dependency/visibility leaks, authz, CSRF, comment spoofing
- ticket_dependencies.php: pass current user id/groups/is_admin into the visibility-filtered DependencyModel methods; drop (int) casts that stripped leading zeros from varchar ticket_ids - update_ticket.php: authorize visibility changes (admin or creator only); enforce requires_comment transitions server-side (400 + requires_comment flag so the client can prompt-and-retry); return proper 401/400/403 - add_comment.php: take commenter name from the session not the client (anti-spoofing); validate parent_comment_id belongs to the ticket; reject empty comments; pass ticket visibility to notifications so non-public comment bodies aren't leaked - add_comment/update_comment/bulk_operation: validate CSRF for all state-changing methods, not just POST - bootstrap.php: return the current CSRF token on rejection and never rotate it on a rejected request, so a desynced client can auto-recover - correct auth->401 and validation->400 status codes across these endpoints Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
c5f7a01e1d |
Fix helpers/config: timezone, comment leak, silent misconfig, cache perms
- Database.php: pin MySQL session time_zone to the configured named zone (mysql.time_zone tables now loaded on the DB) with a fixed-offset fallback, so NOW()/TIMESTAMP and PHP agree regardless of the DB server's SYSTEM tz. Best-effort, never fatals the connection. - NotificationHelper: redact comment-body previews for internal/ confidential tickets in sendCommentNotification and notifyWatchers so they are not leaked to the shared Matrix notify list (new $visibility param; callers wired in the API batch). - config.php: die with a clear error if parse_ini_file fails instead of silently falling back to insecure defaults (empty DB pass / proxies). - CacheHelper: create cache dir 0700 and cache files 0600 so other local users cannot read or poison security-relevant cached data. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
882ab2662c |
Fix data-layer bugs: bind_param fatals, ticket_id bindings, cache poisoning
- CustomFieldModel: assign ?? fallbacks to variables before bind_param
(by-reference args cannot be ?? expressions; fatal on PHP 8.2, custom
fields were uncreatable/uneditable)
- RecurringTicketModel::create: fix swapped bind type for schedule_type
(enum bound as int coerced 'daily' to 0, breaking the cron)
- TicketModel/CommentModel: bind varchar ticket_id as string not int so
the unique index is usable and leading-zero IDs match; ticket_watchers
(int column) left as integer
- TicketModel::deleteTicket: delete from custom_field_values (real table)
not the nonexistent ticket_custom_fields
- TicketModel search: honor literal '0'; never emit AGAINST('*') on
all-special-char input (fall back to LIKE)
- TicketModel::updateTicket: disambiguate not-found vs no-op vs genuine
optimistic-lock conflict on zero affected rows
- WorkflowModel: do not cache transitions/statuses on DB failure (a
transient error no longer blocks all status changes for the TTL)
- DependencyModel: filter linked tickets by visibility (new optional user
context params) to stop confidential metadata leaking via dependencies
- BulkOperationsModel: validate status/priority/assignee before mutating
- AuditLogModel: gate getClientIP forwarded headers on trusted proxies;
add missing action/entity types so audit-log filters work
- WorkflowModel: add transitionRequiresComment() accessor for enforcement
- CommentModel: stop leaking raw DB errors to clients (log instead)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
||
|
|
f1e172caec |
Shorten hwmonDaemon auto-comments (drop embedded ASCII description)
Security / PHP Security (semgrep) (push) Successful in 2m12s
Lint / Deploy (push) Successful in 4s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (push) Successful in 1m4s
Lint / JS (eslint) (push) Successful in 14s
Lint / PHP requirements (version + extensions) (push) Successful in 37s
The priority-escalation and recurrence comments embedded the full ASCII
alert description in a code block, producing a wall-of-text comment every
time. Since the ticket DESCRIPTION is already refreshed with the current
sensor data on each update, the comment only needs to record the event:
- Escalation: short note with from/to priority labels + a brief reason
("more severe condition reported, needs faster attention; see description").
- Recurrence: short reopened note pointing at the refreshed description.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
deploy-2026.06.30-96
|
||
|
|
94ad84dae9 |
CI: pin actions/checkout to a commit SHA
Lint / Deploy (push) Successful in 4s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (push) Successful in 34s
Lint / JS (eslint) (push) Successful in 9s
Lint / PHP requirements (version + extensions) (push) Successful in 44s
Security / PHP Security (semgrep) (push) Successful in 2m48s
semgrep's github-actions-mutable-action-tag rule (now running, after the pip install was fixed) flags actions/checkout@v3 as a mutable tag that could be repointed upstream (supply-chain risk). Pin all four uses to the SHA the v3 tag currently resolves to (v3.6.0), preserving behavior. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>deploy-2026.06.30-92 |
||
|
|
99c840fce0 |
Fix logic bugs found in third multi-agent review
Security / PHP Security (semgrep) (push) Failing after 2m44s
Lint / Deploy (push) Successful in 8s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (push) Successful in 18s
Lint / JS (eslint) (push) Successful in 8s
Lint / PHP requirements (version + extensions) (push) Successful in 21s
Medium:
- create_ticket_api.php: environment tags were parsed with explode('][') which
left brackets on the first/last tag so the whitelist never matched, dropping
the env tag from the dedup hash — a [production] and [staging] issue with
otherwise-identical components could collide onto one ticket. Use a
bracket-aware regex.
- CommentModel::getThreadedCommentsPaged only fetched DIRECT children of root
comments, so when pagination is active, nested replies at depth 2-3 vanished
from the thread. Expand replies level-by-level (bounded to depth 3).
- StatsModel::getTicketsByAssignee ignored the visibility filter the rest of the
stats apply, so a non-admin's "by assignee" widget counted (leaked) confidential
tickets. Thread the same filter through.
- watch_ticket.php GET path returned watch state / watcher names / count for any
ticket with no access check (the POST path checks it) — added canUserAccessTicket.
- dashboard.js kanban: every card rendered as P4 because the [class*="lt-p"]
selector never matched the lt-badge-p1 class and the fallback didn't strip "P".
Extract the digit directly.
Low:
- audit_log.php CSV: "Log ID" column was always blank ($log['log_id'] vs the real
audit_id column). Use audit_id.
- check_duplicates.php: the graceful-degradation try/catch only covered the throw
path; guard the false-return (non-exception mysqli) path too.
- notifications.php: owner-who-is-also-@mentioned got two notifications for one
comment; drop the duplicate comment row when a mention covers the same comment.
- dashboard.js hover preview rendered "PP1" (doubled prefix); strip the leading P.
- markdown.js: code/inline-code restore used string replace, so $&, $$, $`, $' in
user code were treated as replacement patterns; use a function replacer. Also
removed an unused loop var.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
deploy-2026.06.30-88
|
||
|
|
9941fd2dfa |
Address remaining review items: Synapse caching, cycle detection, cache/ratelimit/kanban
Security / PHP Security (semgrep) (push) Successful in 1m45s
Lint / Deploy (push) Successful in 3s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (push) Successful in 21s
Lint / JS (eslint) (push) Successful in 9s
Lint / PHP requirements (version + extensions) (push) Successful in 26s
- SynapseHelper: memoize username->Matrix-ID lookups per-request (incl. negative
results) and add an overall time budget to resolveUsernames() plus a 2s connect
timeout, so notifying N watchers with a slow/unreachable Synapse can't stall the
request for N x 5s. (Chosen over async/queue per maintainer.)
- DependencyModel: fix cycle detection treating 'blocks' and 'blocked_by' as the
same edge direction. They are inverse relationships (single row each, no mirror
row), so the traversal now walks a unified precedence graph (blocks: ticket->
depends_on; blocked_by: depends_on->ticket) and wouldCreateCycle normalizes the
new edge's direction. Prevents both false-positive and missed cycles.
- CacheHelper: anchor prefix-delete to exact key boundaries (bare prefix or
prefix + '_' + md5) so delete('workflow') can't wipe a 'workflow_rules' cache.
- RateLimitMiddleware: hold an exclusive flock across the per-IP counter's
read-modify-write so concurrent requests can't both read N and write N+1
(undercounting past the limit). Fails open if the file can't be locked.
- dashboard.js: kanban status update now uses lt.api.post (per no-raw-fetch
convention) and reverts the card AND the optimistic column counts on failure
(the old raw-fetch catch left the card moved without reverting).
- BulkOperationsModel: document that bulk_status/bulk_close intentionally bypass
workflow transition validation (admin override, by design).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
deploy-2026.06.30-84
|
||
|
|
e0e92e326a |
Quick-win fixes from second review
Security / PHP Security (semgrep) (push) Successful in 1m27s
Lint / Deploy (push) Successful in 4s
Lint / Notify on failure (push) Has been skipped
Lint / PHP (phpcs PSR-12) (push) Successful in 20s
Lint / JS (eslint) (push) Successful in 9s
Lint / PHP requirements (version + extensions) (push) Successful in 38s
- create_ticket_api.php: validate status (against TICKET_STATUSES) and priority (numeric 1-5). A non-numeric priority previously cast to 0 and escalated the ticket below P1 on the dedup/update path. - manage_workflows.php: reject empty/invalid from_status/to_status on POST and PUT (must be valid ticket statuses) so the workflow table can't be populated with bogus transitions. - TicketModel::getAllTickets: COUNT(*) OVER() rides on returned rows, so a page past the last row returned total/pages = 0. Fall back to a direct COUNT when an over-range page yields no rows, keeping pager math correct. - DashboardView: stop double-escaping category/type/assigned active-filter labels (they were htmlspecialchars'd into the label and again at output, rendering R&D as R&D); output escaping is retained. - check_duplicates.php / NotificationHelper::notifyWatchers: wrap the DB lookups in try/catch so a failed prepare/query degrades gracefully (advisory dup-check returns none; best-effort watcher notify is skipped) instead of fataling the request. Works whether mysqli throws or returns false. (manage_* endpoints already have a top-level try/catch.) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>deploy-2026.06.30-80 |
||
|
|
4164f85051 |
Fix bugs found in second multi-agent review
Security / PHP Security (semgrep) (push) Successful in 1m14s
Lint / Deploy (push) Successful in 3s
Lint / PHP (phpcs PSR-12) (push) Successful in 19s
Lint / JS (eslint) (push) Successful in 8s
Lint / PHP requirements (version + extensions) (push) Successful in 24s
Lint / Notify on failure (push) Has been skipped
XSS / security:
- markdown.js: sanitize footnote labels to a safe slug before using them in
id/href attributes. Labels are captured before the HTML-escape pass, so a
label like x"><img onerror=...> broke out → stored XSS (the earlier quote-
escape fix didn't cover this path). Verified neutralized.
- RateLimitMiddleware: only trust X-Forwarded-For / X-Real-IP when REMOTE_ADDR
is a configured trusted proxy, and use the rightmost (proxy-appended) entry.
Previously any client could rotate XFF to escape the per-IP rate limit.
- .env.example: document TRUSTED_PROXIES so fresh deploys aren't fail-open on
the Authelia forward-auth spoofing protection.
Correctness:
- notifications.php: my previous assigned-to LIKE fix anchored only on '}', so
BULK assignments (logged {"assigned_to":N,"bulk_operation_id":..}) produced
no "assigned to you" notification — now matches both '}' and ',' delimiters.
- notifications.php: implement the documented @mention notifications (query
action_type='mention' rows for the current user); they were never delivered.
- NotificationHelper::notifyWatchers: guard unchecked prepare() so a missing
ticket_watchers table can't fatal the request after its DB write committed.
- AuditLogModel::getTicketTimeline: JSON_UNQUOTE the extracted ticket_id so
comment events actually match (string vs JSON-number comparison never did).
- AuditLogModel/audit_log.php: CSV export no longer silently truncates to the
1000-row UI cap; uses a dedicated higher export limit.
- DashboardView: quick-preview drawer read .ticket-link from the title cell
(which has none), so the title was always blank — use the cell text.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
deploy-2026.06.30-76
|
||
|
|
b2c19745eb |
Add trusted-proxy auth hardening + PHP requirements checks
Lint / PHP (phpcs PSR-12) (push) Successful in 20s
Lint / JS (eslint) (push) Successful in 11s
Lint / PHP requirements (version + extensions) (push) Successful in 52s
Security / PHP Security (semgrep) (push) Successful in 2m6s
Lint / Deploy (push) Successful in 13s
Lint / Notify on failure (push) Has been skipped
Trusted-proxy hardening (defense-in-depth for Authelia forward-auth): - AuthMiddleware now only honors Remote-* identity headers when REMOTE_ADDR is in a configured TRUSTED_PROXIES allowlist; otherwise it refuses with 403 and logs an 'untrusted_proxy' security event. Previously anything that could reach PHP directly could spoof Remote-User/Remote-Groups and log in as admin. - New config TRUSTED_PROXIES (comma-separated, from .env). Empty = enforcement off, so this is backward compatible until the allowlist is set on a host. Requirements checks (so a PHP upgrade dropping an extension can't silently break features like avatars again): - config/requirements.php: single source of truth for min PHP version and required extensions (ldap, mysqli, curl, mbstring, fileinfo, json). - scripts/check_requirements.php: CI script that fails the build if the environment doesn't satisfy them. - New 'requirements' CI job installs those extensions and runs the check; deploy now depends on it. - api/health.php: adds php_extensions + php_version checks so production monitoring surfaces the drift (returns 503 if a required extension is gone). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>deploy-2026.06.30-72 |
||
|
|
b3bc3ab159 |
Harden recurring cron, bulk delete, error handling; fix semgrep CI
Continued fixes from the multi-agent review: - recurring tickets cron: now that the parse error is fixed the job runs, exposing two latent bugs. (1) next_run_at was only advanced after the full success path, so any failure (e.g. a NULL created_by passed to the non-nullable assignTicket() $assignedBy -> TypeError) left it in the past and re-created a duplicate ticket every cron cycle. Added an atomic claimForRun() (conditional UPDATE gated on still-due) called BEFORE creation, which also prevents overlapping runs from double-creating. (2) The cron used a raw mysqli with no utf8mb4, corrupting non-ASCII content; it now uses Database::getConnection(). Also guard the assignment so created_by NULL falls back to the assignee. - bulk delete: attachment files were unlinked inside the DB transaction, so an atomic-mode rollback restored rows but the files were already gone. deleteTicket() can now defer file removal to the caller, and BulkOperationsModel deletes files only after a successful commit. - UserModel: back-tick the `groups` column (reserved word on MySQL 8.0.2+). - create_ticket_api.php: stop leaking raw DB/exception messages to callers; log server-side and return a generic error. (Also includes a pre-existing working-tree tweak that adds title to the manual-ticket dedupe hash.) - CI: semgrep install failed under PEP 668; add --break-system-packages. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>deploy-2026.06.30-68 |
||
|
|
2b8d593ab0 |
Fix issues found in multi-agent code review
Verified, high-confidence fixes from a project-wide review: - markdown.js: escape " and ' in the HTML-escape step. User-controlled image/link URLs and alt text were interpolated into "..." attributes without quote escaping, allowing attribute breakout and injected event handlers (stored XSS, only mitigated by CSP). Flagged independently by two reviewers. - cron/create_recurring_tickets.php & cron/cleanup_ratelimit.php: a mangled crontab example inside the docblock contained */ which closed the comment early, causing a fatal parse error — both cron jobs never ran. Rewrote the docblocks without a literal */. - update_ticket.php: validate visibility BEFORE the core DB write so an invalid payload can't leave the ticket updated while the request reports failure (which also skipped the audit delta and stats cache invalidation). - watch_ticket.php: GET watcher_count was capped at 6 (count of a LIMIT 6 list); use an unbounded COUNT(*) so it matches the POST path. - notifications.php: "assigned to me" LIKE pattern lacked a trailing delimiter, so user 12 also matched 120/123/etc.; anchor with }. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
600c46f673 |
Fix CSP-blocked command palette trigger (inline onclick -> addEventListener)
The ⌘K header button used an inline onclick handler, which the CSP (script-src-attr, nonce-based, no unsafe-inline) blocks, so clicking the button did nothing. Move the handler into the existing nonce'd script block and bind it via addEventListener on #lt-cmd-trigger. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
5808b93cdb |
Fix avatar negative-cache poisoning on transient LDAP errors
user_avatar.php wrote a ".none" sentinel whenever it failed to obtain avatar bytes, conflating "LDAP errored/timed out" with "user has no avatar". A brief lldap blip (restart, slow response past the 3s timeout, network hiccup) therefore cached a 404 for the full AVATAR_CACHE_TTL (1h default), leaving avatars broken long after lldap recovered. Track whether the LDAP query actually completed (`$ldapQueryOk`) and only write the negative-cache sentinel when lldap genuinely answered with no/ invalid avatar. On error/timeout, leave no sentinel so the lookup retries once lldap is healthy again. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
597e1b1eea |
fix: correct phpcs indentation on SLA banner conditional block
PHP inline conditionals inside HTML context must use 4-space indentation to satisfy PSR-12 Generic.WhiteSpace.ScopeIndent rule. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>deploy-2026.04.29-49 |
||
|
|
35a2b66038 |
refactor: migrate P1/P2 SLA banner to lt-sla-p1/lt-sla-p2 component
Replaces the lt-alert workaround with the new purpose-built SLA banner component now in base.css: - lt-sla-p1 (pulsing red) / lt-sla-p2 (static amber) wrapper classes - Structured subcomponents: lt-sla-icon, lt-sla-info, lt-sla-title, lt-sla-bar + lt-sla-fill (gradient fill), lt-sla-meta, lt-sla-dismiss - Dismiss now uses banner.hidden + sessionStorage key lt_sla_dismissed_<id> (aligns with web_template pattern; previous code used classList 'dismissed') - Elapsed/remaining/breach state driven by same tick() interval, now updating lt-sla-fill width instead of a separate lt-progress bar inside lt-alert-msg Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
b7aea8c683 |
sync: pull progress gradient fills and SLA banner from web_template v1.2
Progress bars now use linear-gradient fills for a more dramatic terminal readout appearance (matches web_template 39862fa): - Default (orange), --cyan, --green, --red variants all upgraded from flat accent colors to directional gradients with highlight endpoints SLA banner component (lt-sla-p1 / lt-sla-p2) added to base.css, replacing the lt-alert workaround previously used for P1/P2 SLA display: - lt-sla-p1: pulsing red banner (animation: lt-sla-pulse 2s) - lt-sla-p2: static amber banner - Subcomponents: icon, info, title, bar, fill, meta, dismiss - Both fills use gradients for visual consistency (P2 amber→#ffd740) - lt-sla-dismiss includes transition + :focus-visible ring Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>deploy-2026.04.29-41 |
||
|
|
d23bbc4b26 |
docs: fix CI/CD section and add security badge
- Add security.yml badge to header - Replace stale 'npm audit' description with actual semgrep config - Add deploy tagging and notify-failure rows that were missing - Fix ESLint config location note Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>deploy-2026.04.18-35 |
||
|
|
132098bee3 |
Exclude two more semgrep false-positive rules from security scan
- tainted-filename: filenames in upload_attachment.php and user_avatar.php are derived exclusively from (int)-cast integers; no user string reaches the filesystem path. Semgrep's taint engine tracks all use-sites of the variable, producing findings on every file_exists/readfile/unlink call. - tainted-callable: index.php audit-log query passes \$sql to prepare(); \$sql is assembled from hardcoded SQL fragments with ? placeholders and explicit (int) LIMIT/OFFSET casts. User values are bound via bind_param, never interpolated. Semgrep cannot see through the WHERE-builder logic. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>deploy-2026.04.16-31 |
||
|
|
3a4a13db7b |
Fix semgrep security findings to pass CI security scan
- index.php: replace SQL string interpolation with concatenation + explicit (int) casts for LIMIT/OFFSET; add nosemgrep for tainted-sql false positive (WHERE clause built from hardcoded fragments with bound params only) - api/upload_attachment.php: add realpath() path-traversal guard after mkdir - api/user_avatar.php: make (int) cast explicit at cache-path construction; add nosemgrep for tainted-filename false positive (integer-only input) - assets/js/ticket.js: add nosemgrep for insertAdjacentHTML — all dynamic content already escaped via lt.escHtml() before insertion - .gitea/workflows/security.yml: exclude echoed-request rule globally — all echo in API context is json_encode() output, not HTML; htmlentities() fix semgrep suggests would corrupt JSON responses Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>deploy-2026.04.16-27 |
||
|
|
6b2d8e4d03 |
Fix remaining spam issues and phpcs merge conflict marker
Spam fixes:
- Add ZFS pool category to hash with subtypes (pool_state, pool_usage,
pool_errors) so DEGRADED and usage-high on same pool get separate tickets
- Strip volatile percentages from LXC/ZFS usage titles ("usage high: 80.1%"
→ "usage high") and OSD counts from BlueStore slow-ops titles
("2 OSD(s) experiencing" → "OSD(s) experiencing") in hwmonDaemon.py
phpcs fix:
- Remove leftover merge conflict marker (<<<<<<< HEAD / >>>>>>>)
in create_ticket_api.php which caused phpcs to fail on bitshift
operator spacing
DB cleanup:
- Deleted 107 spam comments and 107 audit entries from tickets
357934698 (ZFS pool), 673679581 (BlueStore), 925498317 (LXC storage)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
deploy-2026.04.16-23
|
||
|
|
7fb60a365e |
Suppress title-only update comments to stop hourly comment spam
Comments on worsening condition now only fire on priority escalation. Title and description updates are silent — title changes (e.g. rising Power_On_Hours counters) were generating a comment on every hourly run. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |