github-advanced-security[bot] commented on code in PR #695: URL: https://github.com/apache/fineract-backoffice-ui/pull/695#discussion_r4174121229
########## scripts/snapshot-permission-codes.mjs: ########## @@ -0,0 +1,102 @@ +#!/usr/bin/env node +/* + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + +/** + * Refreshes `scripts/permission-codes.json` from a running Fineract. + * + * The catalogue grows between releases, and a stale snapshot is a false *pass* — a new code the + * application legitimately names would be reported as invented. It is never a false failure, + * since codes are not removed, which is why a snapshot is safe to check against in CI at all. + * + * bash scripts/e2e-stack.sh + * npm run permissions:snapshot + * + * Padded codes are written verbatim. Fineract ships five with a trailing space, and + * `READ_STANDINGINSTRUCTION` and `READ_ClientSummary` exist *only* in that form — trimming them + * on the way in is what broke the role permission editor (#693), so they are preserved here and + * `check-permission-codes.mjs` trims only when comparing. + */ + +import { writeFileSync } from 'node:fs'; +import { dirname, join } from 'node:path'; +import { fileURLToPath } from 'node:url'; + +const ROOT = join(dirname(fileURLToPath(import.meta.url)), '..'); +const OUT = join(ROOT, 'scripts/permission-codes.json'); + +const origin = process.env.FINERACT_BACKEND_ORIGIN ?? 'https://localhost:8443'; +const tenant = process.env.FINERACT_TENANT_ID ?? 'default'; +const username = process.env.FINERACT_USERNAME ?? 'mifos'; +const password = process.env.FINERACT_PASSWORD ?? 'password'; + +// The local stack serves a self-signed certificate, which is the whole reason this is a script +// rather than a curl in the README. +process.env.NODE_TLS_REJECT_UNAUTHORIZED = '0'; Review Comment: ## CodeQL / Disabling certificate validation Disabling certificate validation is strongly discouraged. [Show more details](https://github.com/apache/fineract-backoffice-ui/security/code-scanning/17) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
