https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=41921

Brendan Lawlor <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|Signed Off                  |Failed QA

--- Comment #113 from Brendan Lawlor <[email protected]> ---
This is a really cool new feature and the test plan works as described.

I used Claude Code Opus 5.5 to help test and confirmed a few blockers through
manual human testing.

1. The new jobs page is vulnerable to cross-site scripting because it passes
the raw url parameter to the template and into the javascript
To replicate:
As superlibrarian open a link like
http://localhost:8081/cgi-bin/koha/reports/jobs.pl?new_job_id=document.title=1337
Confirm the title of the page has been changed to 1337
View source, search for new_job_id and confirm the parameter was injected into
the script

Fix in jobs.pl by only accepting an integer:
my $new_job_id = $input->param('new_job_id');
$template->param( new_job_id => $new_job_id )
    if defined $new_job_id && $new_job_id =~ /^\d+$/;

2. svc/convert_report still requires the old execute_reports permission
To replicate:
Create a report with outdated SQL but don’t run it yet
SELECT biblionumber,
       ExtractValue(marcxml, '//datafield[@tag="245"]/subfield[@code="a"]') AS
title
FROM biblioitems
With a user that does not have the top level reports permission but has
execute_reports_foreground and execute_reports_background
Go to the list of reports 
Click on the Update SQL button
Confirm the modal shows a login form with Error: You do not have permission to
access this page.

Fix in svc/convert_report by allowing either of the new permissions:
flagsrequired => { reports => [ 'execute_reports_foreground',
'execute_reports_background' ]

3. Stored results skip the report library limits
To replicate:  
Enable LimitReportsByLibrary
Create a report named CPL Only, with Library limitation Centerville
select * from items where homebranch = ‘CPL’ 
Run it once so that there are saved results
Login as a user from another home library with one of
execute_reports_background or execute_reports_foreground 
They can view the report jobs page and click on the View results button
they can then see the results of a report that they are not allowed to run.
Jobs should be hidden for reports that they can’t run. They also should get a
permission error if they try to change the id to a report they can’t run in a
url like
/reports/guided_reports.pl?op=view_stored_results&id=<not_my_report_id>

guided_reports.pl doesn't respect Libray limitations when op=view_stored
results, but it should.

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to