-
Notifications
You must be signed in to change notification settings - Fork 4
[NAE-2241] Anonymous access refactor #316
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: release/7.0.0-rev10
Are you sure you want to change the base?
Changes from all commits
9cdebe0
41cc8fb
8babfe3
f0a63a8
ffb3b5e
44be3b6
3949d93
0305882
5176c8f
9affb70
38d6f66
1b87bfd
09b6ec6
afd8481
6db3f17
956e3d8
757d792
ee014da
9085d7f
2033c19
79c4990
c4c68c8
10b4a24
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
|
|
@@ -14,7 +14,94 @@ Full Changelog: [https://github.com/netgrif/components/commits/v6.5.0](https://g | |||||
| - [NAE-2019] Bugs after merge with 6.4.0 | ||||||
|
|
||||||
| ### Changed | ||||||
| - [NAE- 1940] Update to new Angular | ||||||
| - [NAE-1889] Process list is not refreshed after uploading process file | ||||||
| - [NAE-1885] Side panel creates a new case when pressing Enter on date field | ||||||
| - [NAE-1687] Factory class as providers | ||||||
| - [NAE-1911] Autosave on text area in cooperation with button | ||||||
| - [NAE-1497] Frontend actions | ||||||
| - [NAE-1915] TaskRef behaviour handling for multiple level | ||||||
| - [NAE-1904] Case ref as multichoice and enumeration | ||||||
| - [NAE-1908] NAE-1906 Improvements | ||||||
| - [NAE-1918] Tags on process resources | ||||||
| - [NAE-1921] User field value cannot be cleared | ||||||
| - [NAE-1914] revertToPreviousValue - change is always false | ||||||
| - [NAE-1925] Panel is not opening | ||||||
| - [NAE-1924] Neziadane volanie setData z FE | ||||||
| - [NAE-1923] DateTime doesn't have locale and rework validation to isoWeekday | ||||||
| - [NAE-1928] Refresh tabs on change | ||||||
| - [NAE-1926] Can't close Tab in Tab view | ||||||
| - [NAE-1929] Data field type list of strings | ||||||
| - [NAE-1933] UserList deleteAll button | ||||||
| - [NAE-1939] Problem with Tests | ||||||
| - [NAE-1936] Disable create case button using menu items | ||||||
| - [NAE-1935] Improved breadcrumbs from menu items | ||||||
| - [NAE-1876] Process URI v2 | ||||||
| - [NAE-1882] Filter folder process | ||||||
| - [NAE-1890] Data field component register | ||||||
| - [NAE-1901] Taskref rendering update | ||||||
| - [NAE-1900] New component design | ||||||
| - [NAE-1920] Injection token NAE_USER_ASSIGN_COMPONENT breaks delegate | ||||||
| - [NAE-1879] Language register | ||||||
| - [NAE-1905] Add bold on i18n text plainText field | ||||||
| - [NAE-1873] Seperator for number field | ||||||
| - [NAE-1922] Signature Pad Field | ||||||
| - [NAE-1949] Allowed Types for Filefield | ||||||
| - [NAE-1813] Field id as path variable in TaskController | ||||||
| - [NAE-1957] Allow filter to caseRef field and variants | ||||||
| - [NAE-1960] Enumeration Map does not propagate changes when selecting | ||||||
| - [NAE-1958] Make component properties changeable | ||||||
| - [NAE- 1940] Update to new Angular | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win Fix ticket ID typo.
✏️ Proposed fix-- [NAE- 1940] Update to new Angular
+- [NAE-1940] Update to new Angular 📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||
| - [NAE-1983] Public view file handling | ||||||
| - [NAE-1999] Broken pagination on paged case view | ||||||
| - [NAE-1949] Allowed Types for Filefield | ||||||
| - [NAE-2005] Field behavior change does not work correctly with multiple references using taskRef | ||||||
| - [NAE-2013] Autocomplete options are set to the first dropdown | ||||||
| - [NAE-2013] Autocomplete options are set to the first dropdown | ||||||
| - [NAE-2016] Global roles for menu items permissions | ||||||
| - [NAE-2018] User list input is not showing dialog | ||||||
| - [NAE-2020] Create case error when allowed net blocks are present | ||||||
| - [NAE-2021] Outputs for navigation components | ||||||
| - [NAE-2022] UI Design Fixes and Improvements | ||||||
| - [NAE-2034] Open first view | ||||||
| - [NAE-2038] Public View | ||||||
| - [NAE-2033] Welcome dashboard | ||||||
| - [NAE-2035] Implement Single-Task-View | ||||||
| - [NAE-2036] Task-List-View to open Case by link | ||||||
| - [NAE-2041] Implementing Ticket View | ||||||
| - [NAE-2040] Search in role management | ||||||
| - [NAE-2052] Integrate ticket view with menu items | ||||||
| - [NAE-2039] Search in workflow view | ||||||
| - [NAE-2063] Action API 6.5.0 | ||||||
| - [NAE-2115] Task search on Search Node #314 | ||||||
| - [NAE-2119] Fix menuItem | ||||||
| - [NAE-2125] Remove URI service usage from admin and menu items #318 | ||||||
| - [NAE-2116] Frontend remote configuration | ||||||
| - [NAE-2085] Refactor User | ||||||
| - [NAE-2122] Implement Structured and Efficient Pagination in gRPC | ||||||
| - [NAE-2146] Broken hidden menu on frontend | ||||||
| - [NAE-2085] Refactor User | ||||||
| - [NAE-2118] Implement OpenID Connector Auth for Admin node | ||||||
| - [NAE-2165] Broken task list pagination | ||||||
| - [NAE-2174] Vanishing menu after few clicks | ||||||
| - Refactor case ID usage to replace `stringId` with `id` | ||||||
| - [NAE-2188] Wrong remote configuration loading order | ||||||
| - [NAE-2197] Wrong elastic sort | ||||||
| - [NAE-2205] DefaultCaseRefListViewComponent - headers not displayed when processes exceed single view | ||||||
| - [NAE-2202] Post test fixes | ||||||
| - [NAE-2218] Misaligned header on case view when displayed below 1920px | ||||||
| - [NAE-2224] Title in optional text in case creation button as I18nString | ||||||
| - [NAE-2226] Cannot switch between menu items | ||||||
| - [NAE-2232] Frontend Actions Task events resolver | ||||||
| - [NAE-2233] Fix dashboard menu issue | ||||||
| - [NAE-2227] MenuItem default headers not working | ||||||
| - [NAE-2234] Fix dashboard menu | ||||||
| - [NAE-2217] Single Task View | ||||||
| - [NAE-2251] Map field options are not translated | ||||||
| - [NAE-2285] Group as a value of userlists | ||||||
| - [NAE-2354] Include assignee userRealmId in task response | ||||||
| - [NAE-2263] Copy/selection prevention is set to to entire application not just for side menu | ||||||
| - [NAE-2435] Enumeration field with no choices does not properly handle validation | ||||||
| - [NAE-2416] AbstractFileDefaultFieldComponent does not push upload event | ||||||
|
|
||||||
| ## [6.5.0](https://github.com/netgrif/components/releases/tag/v6.5.0) (2025-02-18) | ||||||
| ### Added | ||||||
|
|
||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -20,11 +20,21 @@ | |
| "sessionTimeoutEnabled": false, | ||
| "sessionTimeout": 900, | ||
| "jwtBearer": "X-Jwt-Token", | ||
| "apiToken": { | ||
| "enabled": true, | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🤖 get_repo_knowledge executed:
Length of output: 844 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- nae.json ---'
cat -n nae.json | sed -n '1,80p'
printf '%s\n' '--- relevant files ---'
rg -n --glob '!node_modules' --glob '!dist' 'loginWithApiToken|removeFromUrl|auth\.address|endpoints\.login|api.?token' .Repository: netgrif/components Length of output: 50375 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- nae.json ---'
cat -n nae.json | sed -n '1,60p'
printf '%s\n' '--- source matches ---'
rg -n --glob 'projects/**' --glob '!**/*.html' --glob '!**/docs/**' \
'loginWithApiToken|removeFromUrl|auth\.address|endpoints\.login|api.?token' \
projects | head -n 240Repository: netgrif/components Length of output: 9097 🏁 Script executed: #!/bin/bash
set -eu
cat -n nae.json | sed -n '1,60p'
printf '%s\n' '--- matching source files ---'
rg -l --glob 'projects/**' --glob '!**/*.html' --glob '!**/docs/**' \
'loginWithApiToken|removeFromUrl|auth\.address|endpoints\.login|api.?token' projectsRepository: netgrif/components Length of output: 4674 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- authentication guard ---'
cat -n projects/netgrif-components-core/src/lib/authentication/services/guard/authentication-guard.service.ts | sed -n '1,110p'
printf '%s\n' '--- proxy authentication ---'
cat -n projects/netgrif-components-core/src/lib/authentication/proxyAuthentication.service.ts | sed -n '1,90p'
printf '%s\n' '--- configuration URL handling ---'
cat -n projects/netgrif-components-core/src/lib/configuration/configuration.service.ts | sed -n '145,185p;250,280p'Repository: netgrif/components Length of output: 13095 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- references to nae.json and configuration loading ---'
rg -n --glob '!**/*.html' --glob '!**/docs/**' --glob '!dist/**' \
'nae\.json|nae-default|APPLICATION_CONFIG|configuration.*json' \
package.json angular.json workspace.json nx.json projects README.md docs 2>/dev/null | head -n 240
printf '%s\n' '--- root files ---'
git ls-files | rg '(^|/)(nae\.json|package\.json|angular\.json|workspace\.json|nx\.json|README\.md)$' | head -n 120Repository: netgrif/components Length of output: 10352 Sensitive Data Exposure Reachability: External Use HTTPS before enabling API-token login.
🤖 Prompt for AI Agents |
||
| "queryParameter": "token", | ||
| "realmQueryParameter": "realmId", | ||
| "removeFromUrl": true, | ||
| "allowedPaths": [ | ||
| "/tabbed-views", | ||
| "/tabbed-views/**" | ||
| ] | ||
| }, | ||
| "sso": { | ||
| "enable": false, | ||
| "clientId": "dev-cluster-worker", | ||
| "redirectUrl": "http://localhost:8081/realms/netgrif-cloud-testing/protocol/openid-connect/auth", | ||
| "refreshUrl": "http://localhost:8800/api/auth/login", | ||
| "refreshUrl": "http://localhost:8080/api/auth/login", | ||
| "scopes": ["openid","email","profile","roles"] | ||
| } | ||
| }, | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,6 +1,6 @@ | ||
| { | ||
| "name": "@netgrif/components-core", | ||
| "version": "7.0.0-rc.19", | ||
| "version": "7.0.2", | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🤖 get_repo_knowledge executed:
Length of output: 1394 🏁 Script executed: #!/bin/bash
printf '%s\n' '--- package manifests ---'
cat -n projects/netgrif-components-core/package.json
cat -n projects/netgrif-components/package.json
printf '%s\n' '--- workspace manifests ---'
for f in package.json angular.json; do
if [ -f "$f" ]; then cat -n "$f"; fi
done
printf '%s\n' '--- Angular version declarations ---'
rg -n '"`@angular/`|angularVersion|ngVersion|peerDependencies|dependencies|devDependencies' \
package.json projects/netgrif-components-core/package.json projects/netgrif-components/package.json \
angular.json 2>/dev/nullRepository: netgrif/components Length of output: 29330 🏁 Script executed: #!/bin/bash
cat -n projects/netgrif-components-core/package.json
cat -n projects/netgrif-components/package.json
cat -n package.jsonRepository: netgrif/components Length of output: 13848 🤖 get_repo_knowledge executed:
Length of output: 1394 🏁 Script executed: #!/bin/bash
set -e
printf '%s\n' '--- core manifest ---'
cat -n projects/netgrif-components-core/package.json
printf '%s\n' '--- components manifest ---'
cat -n projects/netgrif-components/package.json
printf '%s\n' '--- root manifest ---'
cat -n package.jsonRepository: netgrif/components Length of output: 13920 🌐 Web query:
💡 Result: The Citations:
🏁 Script executed: printf '%s\n' '--- files ---'
git ls-files '*package.json' | sort
printf '%s\n' '--- core ---'
sed -n '1,120p' projects/netgrif-components-core/package.json
printf '%s\n' '--- package ---'
sed -n '1,120p' projects/netgrif-components/package.json
printf '%s\n' '--- root ---'
sed -n '1,160p' package.jsonRepository: netgrif/components Length of output: 12086 Synchronize the Angular peer ranges before publishing 7.0.2. The workspace uses Angular 17.3.x, but both library manifests declare 📍 Affects 2 files
🤖 Prompt for AI Agents |
||
| "description": "Netgrif Application engine frontend core Angular library", | ||
| "homepage": "https://components.netgrif.com", | ||
| "license": "SEE LICENSE IN LICENSE", | ||
|
|
||
This file was deleted.
This file was deleted.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,12 +1,12 @@ | ||
| import {ConfigurationService} from '../configuration/configuration.service'; | ||
| import {NullAuthenticationService} from './services/methods/null-authentication/null-authentication.service'; | ||
| import {BasicAuthenticationService} from './services/methods/basic-authentication/basic-authentication.service'; | ||
| import {HttpClient} from '@angular/common/http'; | ||
| import {HttpClient, HttpHeaders} from '@angular/common/http'; | ||
| import {BasicWithRealmAuthenticationService} from "./services/methods/basic-authentication/basic-with-realm-authentication.service"; | ||
| import {filter, take} from "rxjs/operators"; | ||
| import {UserResource} from "../resources/interface/user-resource"; | ||
| import {Credentials} from "./models/credentials"; | ||
| import {Observable} from 'rxjs'; | ||
| import {Observable, throwError} from 'rxjs'; | ||
| import {Injectable} from "@angular/core"; | ||
| import {AuthenticationMethodService} from "./services/authentication-method.service"; | ||
|
|
||
|
|
@@ -46,6 +46,24 @@ | |
| return this._proxyAuthMethod.login(credentials); | ||
| } | ||
|
|
||
| loginWithApiToken(token: string, realmId?: string): Observable<UserResource> { | ||
| const auth = this._config.get().providers.auth; | ||
| const loginEndpoint = typeof auth.endpoints === 'object' ? auth.endpoints['login'] : undefined; | ||
| const url = auth.address + (loginEndpoint ?? ''); | ||
| if (!loginEndpoint) { | ||
| return throwError(new Error('Login URL is not defined in the config [nae.providers.auth.endpoints.login]')); | ||
|
Check warning on line 54 in projects/netgrif-components-core/src/lib/authentication/proxyAuthentication.service.ts
|
||
| } | ||
| if (!token?.trim()) { | ||
| return throwError(new Error('API token is empty')); | ||
|
Check warning on line 57 in projects/netgrif-components-core/src/lib/authentication/proxyAuthentication.service.ts
|
||
| } | ||
|
|
||
| let headers = new HttpHeaders().set('Authorization', `Bearer ${token.trim()}`); | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
# Inspect repository configuration for insecure authentication endpoints.
rg -n -C 3 '"address"\s*:\s*"http:|sessionBearer|apiToken' nae.json projectsRepository: netgrif/components Length of output: 16802 Sensitive Data Exposure Reachability: External Reject non-HTTPS authentication endpoints.
🤖 Prompt for AI Agents |
||
| if (realmId?.trim()) { | ||
| headers = headers.set('X-Realm-ID', realmId.trim()); | ||
| } | ||
| return this._http.get<UserResource>(url, {headers}); | ||
| } | ||
|
|
||
| logout(): Observable<object> { | ||
| return this._proxyAuthMethod.logout(); | ||
| } | ||
|
|
||
| Original file line number | Diff line number | Diff line change | ||
|---|---|---|---|---|
|
|
@@ -8,9 +8,7 @@ export * from './sign-up/public-api'; | |||
| /* MODULES */ | ||||
| export * from './authentication.module'; | ||||
|
|
||||
| /* SERVICES */ | ||||
| export * from './anonymous/anonymous.service'; | ||||
| export * from './services/anonymous-authentication-interceptor' | ||||
| // export * from './services/anonymous-authentication-interceptor' | ||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🧹 Nitpick | 🔵 Trivial Remove the commented export from the public API surface. Keeping commented exports in a public API file creates dead code and ambiguity. If this export is intentionally retired, delete it outright. 🧹 Suggested cleanup-// export * from './services/anonymous-authentication-interceptor'📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||
| export * from './services/authentication-interceptor' | ||||
| export * from './proxyAuthentication.service' | ||||
|
|
||||
|
|
||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Remove duplicate changelog entries.
The following entries appear twice in the 7.0.0 "Changed" section:
[NAE-1949]Allowed Types for Filefield — lines 48 and 56[NAE-2013]Autocomplete options are set to the first dropdown — lines 58 and 59[NAE-2085]Refactor User — lines 79 and 82Also applies to: 56-56, 58-59, 79-79, 82-82
🤖 Prompt for AI Agents