Skip to content

fix: batch of small fixes from the simple-directory audit - #161

Merged
BatLeDev merged 16 commits into
masterfrom
fix-small-fixes
Oct 1, 2026
Merged

BatLeDev merged 16 commits into
masterfrom
fix-small-fixes

Conversation

@BatLeDev

@BatLeDev BatLeDev commented Oct 1, 2026

Copy link
Copy Markdown
Member

Small fixes found while auditing Simple Directory, one commit each.

API

  • members CSV export is reserved to admins (of the organization, or of the single department exported); the UI button is hidden for others and exports the department on a department page
  • AVATARS_USERS / AVATARS_ORGS = false now refuse uploads (403), deletion stays open so existing avatars can be moderated
  • multi-roles member patch: changing a membership to a role the member already holds merges both (it answered 204 and kept the duplicate); moving a membership to another department no longer deletes the user's memberships holding another role, in every organization
  • contact form mail: Simple Directory names the sender ("émis par ", as a mailto link) and keeps the line breaks of a plain text message
  • default mail logo bundled and served by GET /api/mails/logo.png?v=<hash> (immutable cache) instead of an old rawgit url; no divider under a mail without caption, more even margins

UI

  • organization settings locked for members who are not admins (avatar, 2FA roles, save button)
  • partner removal warning now says the permissions are withdrawn; pending partners show the default organization avatar; accepting a partnership is only offered for organizations the user administers at their root
  • admin color on every superadmin-only action, admin dialog titles wrap, service account avatar widget hidden when user avatars are disabled, department separated from the organization name in the users lists

Chore: unused emailCaption message dropped, outdated links (repository urls, release badge, samlify and vite docs), dead nyc report script.

Heads-up:

  • the multi-roles patch fix in api/src/storages/mongo.ts is the change to review hardest: before it, moving a member to another department in multi-roles mode silently deleted their other-role memberships
  • release together with fix(contact): let simple-directory name the sender of a contact message portals#136, which drops the "émis par" the portal used to add, otherwise the contact mail names the sender twice
  • behavior changes for API clients: the CSV export and avatar uploads (when disabled) now answer 403

BatLeDev and others added 16 commits October 1, 2026 13:19
…rawn

data-fair and processings remove the permissions granted to an organization
that is no longer in the partners list of the identity webhook, so the old
warning (permissions not modified, do it yourself) was wrong.
…mins

The organization avatar widget and the 2FA roles selector stayed editable and
the save button was shown to a simple member, while the other fields were
disabled and the API refuses the change.
Impersonation from the members list, service account creation and edition
and the direct partner addition used primary or warning, unlike the same
actions in /admin/users.
…tner

A partner whose invitation is not accepted yet has no id, the avatar circle
stayed empty; an unknown id serves the default organization image.
…isters at its root

A department admin membership looked selectable and ended in a raw 403, and a
member of several departments saw the organization listed once per membership.
Simple Directory now writes the sender in its fixed intro ("... émis par
<address>") instead of relying on the caller to add it, and the plain text
sent by its own contact form keeps its paragraphs and line breaks (it was
rendered on a single line). The html sent by the portal contact form is kept
as is, after the intro.
Any member could download the names and emails of every member. The export
now requires the admin role of the organization, or of the department it is
filtered on; the department page exports its own members only.
…gins

The divider only announces the caption; the contact form mail has none and
showed a lone line with a large empty block under the message. In the generic
templates the message has 16px above and 32px under it, and the divider 32px
on both sides.
…y and vite docs)

The repository moved to the data-fair organization, the Travis and Coveralls
badges were frozen: the README now shows the release workflow (quality checks
and build), and the unused nyc report script is dropped since no coverage is
measured. The samlify and vite documentation links landed on a generic page.
… for good

When neither the site nor the config define a logo, mails pointed to the
v0.12.3 asset of the old koumoul-dev repository through rawgit, a CDN shut
down since 2019 (it only works through a redirect to jsdelivr). The same logo
is now bundled and served by GET /api/mails/logo.png, with a content hash in
the url and an immutable cache header.
… open

AVATARS_USERS / AVATARS_ORGS only hid the upload widgets since they were
added: the API still accepted any upload. Deletion stays allowed so an
instance can switch uploads off and still moderate the existing avatars.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…eps other memberships

Changing a membership to a role the member already holds answered 204 and
left both memberships: the patched one is now dropped. Moving a membership to
another department in multi-roles mode deleted every membership of the user
holding another role, in every organization (the filter returned false for
them): only a membership with the same role conflicts now.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… users lists

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added the fix label Oct 1, 2026
@BatLeDev
BatLeDev merged commit 8553af2 into master Oct 1, 2026
4 checks passed
@BatLeDev
BatLeDev deleted the fix-small-fixes branch October 1, 2026 12:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant