proposal-system/api/tests/ProposalSystem.Tests
Adam Moussa 9e579f84e2
fix(web,api): pin nanoid and sanitize auth logs (SEC-29) (#312)
* fix: bump nanoid to 3.3.16 and postcss to 8.5.26

Bump nanoid from 3.3.16 to 3.3.18 in web/
Bump postcss from 8.5.25 to 8.5.26 in web/

Closes [Dependabot 47] (https://github.com/Sea-Haven-Industries/proposal-system/security/dependabot/47)

* fix(api): sanitize request path in internal API key logs (SEC-29)

Strip CR/LF from Request.Path before logging invalid-key and disallowed-path warnings so CodeQL alerts 4 and 5 close without changing 401/403 behavior.

* fix(api): log user id instead of email on cognito role sync (SEC-29)

Keep AuthResponse.Email unchanged so CodeQL alert 1 closes without altering the callback payload.

* fix(api): use sanitized path on both internal key logs (SEC-29)

The 401 branch referenced an out-of-scope identifier and the 403 branch skipped SanitizeForLog. Cover newline-in-path logs and Cognito role-sync user-id logging with tests.
2026-08-20 12:38:29 -04:00
..
Common feat(api): Phase 6 — optimistic concurrency (SHOC contract) + atomic audit staging (#226) 2026-07-14 01:18:30 -04:00
Controllers fix(web,api): pin nanoid and sanitize auth logs (SEC-29) (#312) 2026-08-20 12:38:29 -04:00
Helpers fix(web,api): pin nanoid and sanitize auth logs (SEC-29) (#312) 2026-08-20 12:38:29 -04:00
Middleware fix(web,api): pin nanoid and sanitize auth logs (SEC-29) (#312) 2026-08-20 12:38:29 -04:00
Services feat(api): Phase 6 — optimistic concurrency (SHOC contract) + atomic audit staging (#226) 2026-07-14 01:18:30 -04:00
Validators feat: pricing library — curated priced items feed the RAG corpus (#127) 2026-06-18 12:49:47 -04:00
ProposalSystem.Tests.csproj chore(deps): bump xunit.runner.visualstudio from 3.1.5 to 4.0.0 (#308) 2026-08-17 23:10:09 +00:00