[bot] Merge 26.3 to 26.7 - #1171
Merged
github-actions[bot] merged 5 commits intoJul 27, 2026
Merged
Conversation
## Rationale BillingNotification.createChargeSummaryReport built its per-financial-analyst tables by concatenating editor-entered database values (investigator, project, debitedAccount, projectNumber, category) and their derived URLs directly into HTML with no escaping. That HTML is rendered verbatim into the LDK RunNotificationAction admin preview via HtmlString.unsafe and is also sent as the HTML email body, so a stored payload in any of those project/alias fields executed in the browser of any user who previewed the notification or received the email — a stored XSS with privilege-escalation potential toward admins. The adjacent Charge Summary category table already escaped its values with PageFlowUtil.filter; this loop was simply never given the same treatment. ## Related Pull Requests None. ## Changes - Wrap every editor-entered value (investigator, project, account, project number, category) in PageFlowUtil.filter before rendering it into the charge summary tables. - Filter the derived href URLs (project, account, and per-field-descriptor links), which embed those same tainted values.
…#1168) ## Rationale This PR fixes ehr_lookups tables whose user-facing key column was hidden and non-insertable in the UI (`clinpath_status`, `project_types`, `full_snomed`, `flag_values`). The generic fallback in `EHRLookupsUserSchema.createTable()` wrapped any hard table with a single non-rowid key field and a container column in a `ContainerScopedTable`, but for tables whose user-facing key is the true DB PK the wrapper is unnecessary — the PK constraint already enforces uniqueness — and its init demoted the key column while the insert path still required a value for it. ## Related Pull Requests None. ## Changes - Updated the fallback wrapping heuristic to compare the promoted key field against the real PK from JDBC metadata, so only tables where they differ get `ContainerScopedTable`; tables whose key is the true PK now get `CustomPermissionsTable`. - Tables with composite or missing real PKs are no longer container-scoped, since `ContainerScopedTable` only supports a single-column real PK.
cnathe
approved these changes
Jul 27, 2026
github-actions
Bot
merged commit Jul 27, 2026
5a81bc4
into
release26.7-SNAPSHOT
9 of 11 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Generated automatically.
Merging changes from: 307719c
Approve all matching PRs simultaneously.
Approval will trigger automatic merge.
Verify all PRs before approving: https://internal.labkey.com/Scrumtime/Backlog/harvest-gitOpenPullRequests.view?branch=26.7_fb_bot_merge_26.3