[DSD-4199] - #329
[DSD-4199]#329JanardhanBS-SyncByte wants to merge 195 commits into
Conversation
#325) * [DSD-4267] removed mock-sdk-jpeg-extractor functionality from mosip-mock-services repo Signed-off-by: techno-467 <prafulrakhade02@gmail.com> * [DSD-4267] removed mock-sdk-jpeg-extractor functionality from mosip-mock-services repo Signed-off-by: techno-467 <prafulrakhade02@gmail.com> * [DSD-4267] removed mock-sdk-jpeg-extractor functionality from mosip-mock-services repo Signed-off-by: techno-467 <prafulrakhade02@gmail.com> --------- Signed-off-by: techno-467 <prafulrakhade02@gmail.com>
…e floating point numbers Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
[MOSIP-31258] The attributes requestedScore and qualityScore should be floating point numbers
…e floating point numbers with return type String Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: Sowmya Ujjappa Banakar <sowmya.61022006@ltimindtree.com>
MOSIP-31498 code fix
Signed-off-by: JanardhanBS-SyncByte <72377118+JanardhanBS-SyncByte@users.noreply.github.com>
Signed-off-by: JanardhanBS-SyncByte <72377118+JanardhanBS-SyncByte@users.noreply.github.com>
Signed-off-by: JanardhanBS-SyncByte <72377118+JanardhanBS-SyncByte@users.noreply.github.com>
Signed-off-by: JanardhanBS-SyncByte <72377118+JanardhanBS-SyncByte@users.noreply.github.com>
Signed-off-by: JanardhanBS-SyncByte <72377118+JanardhanBS-SyncByte@users.noreply.github.com>
Signed-off-by: JanardhanBS-SyncByte <72377118+JanardhanBS-SyncByte@users.noreply.github.com>
Signed-off-by: JanardhanBS-SyncByte <72377118+JanardhanBS-SyncByte@users.noreply.github.com>
Signed-off-by: JanardhanBS-SyncByte <72377118+JanardhanBS-SyncByte@users.noreply.github.com>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
…iometricsdk.version Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
Signed-off-by: JanardhanBS-SyncByte <janardhan@syncbyte.in>
* Added Test cases for sonar coverage. Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Added test class for sonar coverage. Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * written test cases for Mock-MDS Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * code coverage-MockMDS Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * resolved some security issues and add test cases for some classes. GitHub Description while commiting: Signed-off-by: Chetan <chetankumar.h.239@gmail.com> Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Changes in import statements and necessary access modifiers added. Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Restored deleted application.properties file. Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Restored application.properties after accidental deletion Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Added test cases. Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Revert "Restored application.properties after accidental deletion" Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * reverting back application file Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Fix DCO signature format Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Re-add application.properties after accidental deletion Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * modified file Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * remodified Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * unnecessary files deleted. Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * "Added test cases" Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * "Added test cases" Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * changes done Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * text files put as they are. Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Remove .idea folders Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * mock-mv test cases added Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Update .gitignore Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com> Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * naming convention followed. (#1) Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Recover lost changes * naming convention followed. Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Fix Surefire plugin to resolve fork error in mock-abis Signed-off-by: Chetan <chetankumar.h.239@gmail.com> --------- Signed-off-by: Chetan <chetankumar.h.239@gmail.com> * Recover lost changes (#3) * naming convention followed. Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com> * Fix Surefire plugin to resolve fork error in mock-abis Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com> --------- Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com> Signed-off-by: Chetan <chetankumar.h.239@gmail.com> --------- Signed-off-by: Chetan <chetankumar.h.239@gmail.com> Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>
Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com>
* Update pom.xml Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com> * Update pom.xml Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com> --------- Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com>
* Update pom.xml Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com> * Update pom.xml Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com> --------- Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com>
* reverting all jacoco changes Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com> * Update pom.xml Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com> --------- Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com>
Signed-off-by: Dhanendra Sahu <dhanendra@Dhanendras-MacBook-Pro.local> Co-authored-by: Dhanendra Sahu <dhanendra@Dhanendras-MacBook-Pro.local>
* [MOSIP-41674] central sonatype migration changes Signed-off-by: techno-467 <prafulrakhade02@gmail.com> * [MOSIP-41674] central sonatype migration changes Signed-off-by: techno-467 <prafulrakhade02@gmail.com> * [MOSIP-41674] central sonatype migration changes Signed-off-by: techno-467 <prafulrakhade02@gmail.com> * [MOSIP-41674] central sonatype migration changes Signed-off-by: techno-467 <prafulrakhade02@gmail.com> * [MOSIP-41674] central sonatype migration changes Signed-off-by: techno-467 <prafulrakhade02@gmail.com> --------- Signed-off-by: techno-467 <prafulrakhade02@gmail.com> Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com>
Testing sonar single-module and multi-module changes. Signed-off-by: Mahesh-Binayak <76687012+Mahesh-Binayak@users.noreply.github.com>
* [MOSIP-42148]Update push-trigger.yml removing duplicate word mosip from project name, Signed-off-by: Mahesh-Binayak <76687012+Mahesh-Binayak@users.noreply.github.com> * Update push-trigger.yml --------- Signed-off-by: Mahesh-Binayak <76687012+Mahesh-Binayak@users.noreply.github.com>
* Updated for develop branch Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com> * mock abis test case updated Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com> --------- Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>
* [MOSIP-43434] [MOSIP-43615] [MOSIP-43648] added changes Signed-off-by: Chandra Keshav Mishra <chandrakeshavmishra@gmail.com> * [MOSIP-43615] corrected os-shell change Signed-off-by: Chandra Keshav Mishra <chandrakeshavmishra@gmail.com> --------- Signed-off-by: Chandra Keshav Mishra <chandrakeshavmishra@gmail.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
* MOSIP-37256: update the readme file - develop Signed-off-by: nagendra0721 <nagendra0718@gmail.com> * MOSIP-37256: update readme file for develop Signed-off-by: nagendra0721 <nagendra0718@gmail.com> * MOSIP-37256: update readme file for develop Signed-off-by: nagendra0721 <nagendra0718@gmail.com> * MOSIP-37256: update readme file for develop Signed-off-by: nagendra0721 <nagendra0718@gmail.com> --------- Signed-off-by: nagendra0721 <nagendra0718@gmail.com>
Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com>
Create NOTICE
| uses: mosip/kattu/.github/workflows/chart-lint-publish.yml@master | ||
| with: | ||
| CHARTS_DIR: ./helm | ||
| CHARTS_URL: https://mosip.github.io/mosip-helm | ||
| REPOSITORY: mosip-helm | ||
| BRANCH: gh-pages | ||
| INCLUDE_ALL_CHARTS: "${{ inputs.INCLUDE_ALL_CHARTS || 'NO' }}" | ||
| IGNORE_CHARTS: "${{ inputs.IGNORE_CHARTS || '\"\"' }}" | ||
| CHART_PUBLISH: "${{ inputs.CHART_PUBLISH || 'YES' }}" | ||
| LINTING_CHART_SCHEMA_YAML_URL: "https://raw.githubusercontent.com/mosip/kattu/master/.github/helm-lint-configs/chart-schema.yaml" | ||
| LINTING_LINTCONF_YAML_URL: "https://raw.githubusercontent.com/mosip/kattu/master/.github/helm-lint-configs/lintconf.yaml" | ||
| LINTING_CHART_TESTING_CONFIG_YAML_URL: "https://raw.githubusercontent.com/mosip/kattu/master/.github/helm-lint-configs/chart-testing-config.yaml" | ||
| LINTING_HEALTH_CHECK_SCHEMA_YAML_URL: "https://raw.githubusercontent.com/mosip/kattu/master/.github/helm-lint-configs/health-check-schema.yaml" | ||
| DEPENDENCIES: "mosip,https://mosip.github.io/mosip-helm;" | ||
| secrets: | ||
| TOKEN: ${{ secrets.ACTION_PAT }} | ||
| SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK }} |
Check warning
Code scanning / CodeQL
Workflow does not contain permissions Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 9 months ago
Generally, the fix is to explicitly define a permissions block that scopes the GITHUB_TOKEN to the minimum needed. This can be done at the workflow root (applies to all jobs without their own permissions) or per job. Since this workflow has a single job that calls a reusable workflow which likely needs to read repository contents and possibly write to gh-pages and read workflow metadata, we should set only those permissions that are clearly required.
Without modifying the functionality, we should:
- Add a root‑level
permissionsblock after theon:section (lines 3–42). - Grant
contents: writeto allow publishing Helm charts (push togh-pages), andid-token: writeonly if needed for OIDC (we will omit it since there is no indication it’s used). - Optionally grant
actions: readif the reusable workflow needs to query workflow runs; since we do not see such usage here, we’ll keep it minimal.
Concretely, in .github/workflows/chart-lint-publish.yml, insert:
permissions:
contents: writebetween the on: block (ending at line 42) and the jobs: block (line 44). This limits GITHUB_TOKEN to repository contents write access only, which is the minimum obviously required for linting/publishing charts.
| @@ -41,6 +41,9 @@ | ||
| paths: | ||
| - 'helm/**' | ||
|
|
||
| permissions: | ||
| contents: write | ||
|
|
||
| jobs: | ||
| chart-lint-publish: | ||
| uses: mosip/kattu/.github/workflows/chart-lint-publish.yml@master |
Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com>
Signed-off-by: rajapandi1234 <138785181+rajapandi1234@users.noreply.github.com>
Add files via upload
Signed-off-by: Ivanmeneges <ivan.anil016@gmail.com>
…#494) * Merge all changes from upstream mosip/mosip-mock-services v1.3.1-rc.1 Incorporates all 83 commits from the v1.3.1-rc.1 release tag into develop, including: - [DSD-10347] Packet processing performance tuning - [MOSIP-44844] Logger level change from info to debug for performance - Github issue-479: Fixed security hotspot - Github issues 474, 476, 481: Helm chart and SSL fixes - [MOSIP-43434][MOSIP-43615][MOSIP-43648] Various platform changes - [MOSIP-43625] Updated pom and dateutils - [MOSIP-42464][MOSIP-41674] Central sonatype migration - Updated pom versions to 1.3.1-rc.1 release - Added test coverage: new JUnit 5 test classes across MockMDS, mock-abis, mock-sdk - Mocked extractor template in mock-sdk Signed-off-by: kameshsr <kameshsr1338@gmail.com> * #1830 Correct version Signed-off-by: kameshsr <kameshsr1338@gmail.com> * #1830 added agents.md Signed-off-by: kameshsr <kameshsr1338@gmail.com> --------- Signed-off-by: kameshsr <kameshsr1338@gmail.com>
Signed-off-by: kameshsr <kameshsr1338@gmail.com>
Signed-off-by: kameshsr <kameshsr1338@gmail.com>
#1830 Changed to use latest version of dependent repo
Signed-off-by: GurukiranP <talk2gurukiran@gmail.com>
[issue-403] Updated the central-publishing-maven versions.
Add use-pr-linker workflow to auto-link PRs to issues
* MOSIP-45570: Return 404 when deleting a missing mock-abis expectation Single expectation delete previously always returned HTTP 200 even when the id was absent from the in-memory cache, which made failed deletes look successful. Propagate the cache delete result and return 404 when no expectation is removed. Signed-off-by: Jayesh Kharode <jayesh.kharode@technoforte.co.in> Co-authored-by: Cursor <cursoragent@cursor.com> * MOSIP-45570: Keep single-expectation delete fix minimal Drop README/path/trim/extra-test noise and rely on existing ExpectationCache.delete boolean. Signed-off-by: Jayesh Kharode <jayesh.kharode@technoforte.co.in> Co-authored-by: Cursor <cursoragent@cursor.com> --------- Signed-off-by: Jayesh Kharode <jayesh.kharode@technoforte.co.in> Co-authored-by: Jayesh Kharode <jayesh.kharode@technoforte.co.in> Co-authored-by: Cursor <cursoragent@cursor.com>
| try { | ||
| proxyAbisConfigService.deleteExpectation(id); | ||
| if (!proxyAbisConfigService.deleteExpectation(id)) { | ||
| return new ResponseEntity<>("Expectation not found: " + id, HttpStatus.NOT_FOUND); |
Check failure
Code scanning / CodeQL
Cross-site scripting High
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 1 day ago
To fix this, avoid including raw id in response messages sent back to clients. The best minimal-change fix is to return static messages that preserve behavior (status codes and success/failure semantics) while removing reflected user input.
In mock-abis/src/main/java/io/mosip/proxy/abis/controller/ProxyAbisConfigController.java, update the deleteExpectation method:
- Replace line returning
"Expectation not found: " + idwith a constant"Expectation not found". - Replace line returning
"Successfully deleted expectation " + idwith a constant"Successfully deleted expectation".
No new imports, helper methods, or dependencies are required.
| @@ -122,9 +122,9 @@ | ||
|
|
||
| try { | ||
| if (!proxyAbisConfigService.deleteExpectation(id)) { | ||
| return new ResponseEntity<>("Expectation not found: " + id, HttpStatus.NOT_FOUND); | ||
| return new ResponseEntity<>("Expectation not found", HttpStatus.NOT_FOUND); | ||
| } | ||
| return new ResponseEntity<>("Successfully deleted expectation " + id, HttpStatus.OK); | ||
| return new ResponseEntity<>("Successfully deleted expectation", HttpStatus.OK); | ||
| } catch (Exception exp) { | ||
| logger.error("Exception while deleting expectation: ", exp); | ||
| throw new AbisException(AbisErrorCode.DELETE_EXPECTATION_EXCEPTION.getErrorCode(), |
No description provided.