Skip to content
This repository has been archived by the owner on Feb 20, 2024. It is now read-only.

fix for multirequest problem for locator and finder #192

Merged
merged 37 commits into from
Mar 27, 2023

Conversation

jungwire
Copy link
Contributor

Should fix the problem of disappearing queries when adding more queries

@jungwire jungwire requested a review from konradlang March 27, 2023 10:33
RadovanTomik and others added 28 commits March 27, 2023 15:27
* added attempt to "login" without prompt if fails redirect to login page

* bugfix only overwrite redirect is no error is in QueryString

Co-authored-by: Emilian Jungwirth <emilian.jung+github@gmail.com>
* updated documentation
* feat: GitHub packages

* fix: maven settings

* fix: pom version

* fix: docker registries

* feat: deploy workflow

* feat: deploy workflow on dispatch
* fix: jackson media to 2.35

* fix: commons-configuration to 1.10

* fix: trivy scan
…t queryID to allow acting on behalf of Biobank; (#179)

for details see RT #7426: AW: [ext] AW: Negotiator requests
* Throttling the requests by waiting for x seconds in the range [0,3] before requesting the next batch.

* changed text for step away reasons  - #163 (#163)

* Change the wording for texts according to suggestions - #162 - (#162)

* feat: dynamic step away view

* feat: dynamic step away view

---------

Co-authored-by: Radovan Tomášik <tomasik@mail.muni.cz>
Co-authored-by: Konrad Lang <110096044+konradlang@users.noreply.github.com>
* feat: removed auth check

* feat: removed auth check
* fix: tests mocks
* feat: favicon and tag title

* feat: favicon and tag title for admin
* chore: new favicon
RadovanTomik and others added 6 commits March 27, 2023 15:27
* hotfix: maven settings
* getQuery by ID for owner directly from DB

* redirect to researcher query detail page if not an owner

* only use query_paarm_for redirect

* fix: dockerhub credentials

* removed old commented code

* added check for query_param

---------

Co-authored-by: Emilian Jungwirth <emilian.jung+github@gmail.com>
* feat: swagger json

* fix: git properties

* chore: workflow java version 11

* feat: swagger-ui
@gitguardian
Copy link

gitguardian bot commented Mar 27, 2023

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id Secret Commit Filename
5350997 Generic High Entropy Secret 247d39b src/main/resources/sql/dummyData.sql View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Our GitHub checks need improvements? Share your feedbacks!

String query_param=req.getQueryString().split("&")[0];
if(query_param.matches("^queryId=\\d+")){
HttpServletResponse resp = (HttpServletResponse) response;
resp.sendRedirect(req.getContextPath() + "/researcher/detail.xhtml?"+query_param);

Check warning

Code scanning / CodeQL

URL redirection from remote source

Untrusted URL redirection depends on a [user-provided value](1).
@konradlang konradlang changed the title should fix the problem with multirequest for locator and finder fix for multirequest problem for locator and finder Mar 27, 2023
@konradlang konradlang merged commit 249ea4b into master Mar 27, 2023
@konradlang konradlang deleted the hotfix/multi-query-requests branch April 20, 2023 07:51
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants