Skip to content

Conversation

@haralkvi
Copy link
Contributor

@haralkvi haralkvi commented Jun 6, 2025

💰 Funksjonell beskrivelse av endringen

Manifest is part of document bundle sent to the server.

A Portal.Job object might be newed up with a non-sensitive title, but this was lost in the mapping from Portal.Job to Manifest. This resulted in a bug which made it impossible for consumers of our dotnet client library to create portal jobs with non-sensitive tiles.

Non-sensitive titles are titles that may be added in addition to "regular" titles. Non-sensitive titles may be displayed in contexts where we cannot ensure that people viewing are authorized, such as in email notificaitons sent to signers.

🏆 Interessante highlights

Usikkerheter, avveininger og andre ting som kan være interessant å se på

🤷‍♀️ Anbefalt fremgangsmåte

Hvordan bør pull requesten angripes? Commit for commit? Hele smæla på en gang? Gjennomgang i fellesskap IRL?

👀 Eksempler og screenshots

Har du gjort en API-endring? Vis et request! Har du endret i GUI? Ta et screenshot!

⚙️ Avhengigheter

Er koden avhengig av en endring i for eksempel frontend eller API-klienten? Sleng inn en link til relevante pull requests her

🚔 Sikkerhet

Hvordan er de viktigste sikkerhetsaspektene ivaretatt? Her er det lov til å slette ting som ikke er relevante, men det er kjempeviktig at du har vurdert relevansen av alt!

  • Autentisering og autorisasjon
  • Datasanitering (XSS, SQL injection, …)
  • Trengs det risikovurdering?
  • Sikring av tilgang til data; tillater vi noen å aksessere data hos oss? Hvordan er i så fall det sikret?
  • Har vi innført nye tredjepartsrammeverk? Hvor trygge er vi på sikkerheten i disse?

Manifest is part of document bundle sent to the server.

A Portal.Job object might be newed up with a non-sensitive title, but
this was lost in the mapping from Portal.Job to Manifest. This resulted
in a bug which made it impossible for consumers of our dotnet client
library to create portal jobs with non-sensitive tiles.

Non-sensitive titles are titles that may be added in addition to
"regular" titles. Non-sensitive titles may be displayed in contexts
where we cannot ensure that people viewing are authorized, such as in
email notificaitons sent to signers.
@haralkvi
Copy link
Contributor Author

haralkvi commented Jun 6, 2025

This bug was already fixed with the release of version 10.0.1. 🙃

@haralkvi haralkvi closed this Jun 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant