Skip to content

[bot] Merge 26.3 to 26.7 - #1171

Merged
github-actions[bot] merged 5 commits into
release26.7-SNAPSHOTfrom
26.7_fb_bot_merge_26.3
Jul 27, 2026
Merged

[bot] Merge 26.3 to 26.7#1171
github-actions[bot] merged 5 commits into
release26.7-SNAPSHOTfrom
26.7_fb_bot_merge_26.3

Conversation

@github-actions

Copy link
Copy Markdown

Generated automatically.
Merging changes from: 307719c
Approve all matching PRs simultaneously.
Approval will trigger automatic merge.
Verify all PRs before approving: https://internal.labkey.com/Scrumtime/Backlog/harvest-gitOpenPullRequests.view?branch=26.7_fb_bot_merge_26.3

labkey-martyp and others added 5 commits July 22, 2026 11:18
## Rationale

BillingNotification.createChargeSummaryReport built its
per-financial-analyst tables by concatenating editor-entered database
values (investigator, project, debitedAccount, projectNumber, category)
and their derived URLs directly into HTML with no escaping. That HTML is
rendered verbatim into the LDK RunNotificationAction admin preview via
HtmlString.unsafe and is also sent as the HTML email body, so a stored
payload in any of those project/alias fields executed in the browser of
any user who previewed the notification or received the email — a stored
XSS with privilege-escalation potential toward admins. The adjacent
Charge Summary category table already escaped its values with
PageFlowUtil.filter; this loop was simply never given the same
treatment.

## Related Pull Requests

None.

## Changes

- Wrap every editor-entered value (investigator, project, account,
project number, category) in PageFlowUtil.filter before rendering it
into the charge summary tables.
- Filter the derived href URLs (project, account, and
per-field-descriptor links), which embed those same tainted values.
…#1168)

## Rationale

This PR fixes ehr_lookups tables whose user-facing key column was hidden
and non-insertable in the UI (`clinpath_status`, `project_types`,
`full_snomed`, `flag_values`). The generic fallback in
`EHRLookupsUserSchema.createTable()` wrapped any hard table with a
single non-rowid key field and a container column in a
`ContainerScopedTable`, but for tables whose user-facing key is the true
DB PK the wrapper is unnecessary — the PK constraint already enforces
uniqueness — and its init demoted the key column while the insert path
still required a value for it.

## Related Pull Requests

None.

## Changes

- Updated the fallback wrapping heuristic to compare the promoted key
field against the real PK from JDBC metadata, so only tables where they
differ get `ContainerScopedTable`; tables whose key is the true PK now
get `CustomPermissionsTable`.
- Tables with composite or missing real PKs are no longer
container-scoped, since `ContainerScopedTable` only supports a
single-column real PK.
@github-actions
github-actions Bot merged commit 5a81bc4 into release26.7-SNAPSHOT Jul 27, 2026
9 of 11 checks passed
@github-actions
github-actions Bot deleted the 26.7_fb_bot_merge_26.3 branch July 27, 2026 14:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants