fix: batch of small fixes from the simple-directory audit - #161
Merged
Merged
Conversation
…rawn data-fair and processings remove the permissions granted to an organization that is no longer in the partners list of the identity webhook, so the old warning (permissions not modified, do it yourself) was wrong.
…mins The organization avatar widget and the 2FA roles selector stayed editable and the save button was shown to a simple member, while the other fields were disabled and the API refuses the change.
Impersonation from the members list, service account creation and edition and the direct partner addition used primary or warning, unlike the same actions in /admin/users.
…tner A partner whose invitation is not accepted yet has no id, the avatar circle stayed empty; an unknown id serves the default organization image.
…isters at its root A department admin membership looked selectable and ended in a raw 403, and a member of several departments saw the organization listed once per membership.
Simple Directory now writes the sender in its fixed intro ("... émis par
<address>") instead of relying on the caller to add it, and the plain text
sent by its own contact form keeps its paragraphs and line breaks (it was
rendered on a single line). The html sent by the portal contact form is kept
as is, after the intro.
Any member could download the names and emails of every member. The export now requires the admin role of the organization, or of the department it is filtered on; the department page exports its own members only.
…gins The divider only announces the caption; the contact form mail has none and showed a lone line with a large empty block under the message. In the generic templates the message has 16px above and 32px under it, and the divider 32px on both sides.
…y and vite docs) The repository moved to the data-fair organization, the Travis and Coveralls badges were frozen: the README now shows the release workflow (quality checks and build), and the unused nyc report script is dropped since no coverage is measured. The samlify and vite documentation links landed on a generic page.
… for good When neither the site nor the config define a logo, mails pointed to the v0.12.3 asset of the old koumoul-dev repository through rawgit, a CDN shut down since 2019 (it only works through a redirect to jsdelivr). The same logo is now bundled and served by GET /api/mails/logo.png, with a content hash in the url and an immutable cache header.
… open AVATARS_USERS / AVATARS_ORGS only hid the upload widgets since they were added: the API still accepted any upload. Deletion stays allowed so an instance can switch uploads off and still moderate the existing avatars. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…eps other memberships Changing a membership to a role the member already holds answered 204 and left both memberships: the patched one is now dropped. Moving a membership to another department in multi-roles mode deleted every membership of the user holding another role, in every organization (the filter returned false for them): only a membership with the same role conflicts now. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… users lists Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Small fixes found while auditing Simple Directory, one commit each.
API
AVATARS_USERS/AVATARS_ORGS= false now refuse uploads (403), deletion stays open so existing avatars can be moderatedGET /api/mails/logo.png?v=<hash>(immutable cache) instead of an old rawgit url; no divider under a mail without caption, more even marginsUI
Chore: unused
emailCaptionmessage dropped, outdated links (repository urls, release badge, samlify and vite docs), deadnycreport script.Heads-up:
api/src/storages/mongo.tsis the change to review hardest: before it, moving a member to another department in multi-roles mode silently deleted their other-role memberships