Skip to content

Release: security hardening, P0 platform parity (SUM-PLAT-01–05), and core fixes - #110

Merged
ATRIwOX merged 17 commits into
mainfrom
dev
Sep 29, 2026
Merged

ATRIwOX merged 17 commits into
mainfrom
dev

Conversation

@ATRIwOX

@ATRIwOX ATRIwOX commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Summary

Promotes dev to main for the Sumeru kernel: a broad security hardening pass, P0 platform parity (SUM-PLAT-01 through SUM-PLAT-05), engineering standards (test layout, lint/Makefile, render shell), and core/parser/module fixes merged via PR #100.

Pre-alpha — see README caution: not for production workloads; upgrade and smoke-test on staging first.

Security (SUM-SEC)

  • Session lifecycle: inactive-user revoke, logout POST + session destroy, credential-change session revoke
  • CSRF on login, logout, report print; production csrf_secret requirement
  • __Host- session cookies, centralized cookie helpers, Secure policy
  • AuditedBypass / elevated context; CI bypass lint; smuggled bypass rejected on user CRUD/RPC
  • Fail-closed field ACL read redaction and company allow checks
  • Sensitive field registry; totp_secret redaction/deny writes; log scrubbing
  • RPC: JSON Content-Type, restricted Upsert; API key lifecycle hardening
  • Attachments: MIME allowlist, authenticated download, datas redaction
  • Safe Content-Disposition on exports; mail/chatter company scoping; addon ACL CSV audit tests

P0 platform parity

ID Delivered
SUM-PLAT-01 XML-aware view inherit matching and ordered apply
SUM-PLAT-02 Document reports: arch, HTML templates, preview, PDF attachments
SUM-PLAT-03 Audited / time-boxed orm.WithElevated
SUM-PLAT-04 Default company isolation on company-scoped models
SUM-PLAT-05 Portal shell and signed share links

Engineering & shell (incl. PR #95 “platform” hygiene)

  • All Go tests under sumeru/test/; testexports.go pattern documented
  • Consolidated Makefile / lint gates (security bypass, SQL safety, test layout)
  • Render shell: deduped menus, enriched SWC bootstrap; dropped thin apps detail URL wrapper
  • View/module XML boolean attributes restricted to true/false
  • CONTRIBUTING updates; simplified PR template checklist

Core fixes (PR #100 and related)

  • Bootstrap admin password seeding without unsafe direct writes
  • Parser: CDATA unwrap, HTML field bodies, & in field maps, eval 0/1 as numbers
  • Module sync: avoid double-syncing actions; sys.sequence by code; activity/report types by natural key
  • ORM: url / body_html column pinning for acronym fields
  • Assets: menu icon symbols; contacts menu web_icon

Merged PRs (high level)

Out of scope (follow-up)

platform is 27 commits ahead of dev (SUM-PLAT-07–12, debug/command palette, settings hub, field/model ACL matrices, collection-bar UX, etc.). This dev → main PR does not include that work unless platform is merged into dev first.


Upgrade / deploy notes

  • Run cd sumeru && make on the release tag/commit before tagging.
  • Upgrade installed modules (especially base, mail, security CSV changes) on each database after deploy.
  • Set csrf_secret and review cookie/HTTPS settings in production.
  • Rebuild SWC bundles as documented in README (bundles are not committed).

Test plan

  • CI green on dev (make / GitHub Actions)
  • Login → logout (POST); session cookie cleared; return-path cookie behavior
  • Inactive user cannot keep an old session
  • RPC rejects bad Content-Type; exports use safe download filenames
  • Portal share link flow (SUM-PLAT-05) on a test record
  • View inherit on a module that uses <xpath> extensions
  • Report preview/PDF on a sample document report
  • Multi-company: user restricted to allowed companies (SUM-PLAT-04)
  • Fresh DB bootstrap + module update without action double-sync errors

ATRIwOX and others added 17 commits September 29, 2026 15:10
Pass user and company ids into form, list, and header button modifier eval;
validate required fields from resolveFieldModifiers on save. Document list
column and empty action context limits in CONTRIBUTING.
Add document parsing with t-name templates, safe expressions, merged static
and dynamic class attrs, t-set over remaining siblings, and scope destructuring
in named templates. Fix self-closing tags and add composition runtime tests.
Load security/sys.field.access.csv on module sync, validate model and field
names, and warn on orphan rows after sync. Document CSV format and list export
in MODULE_STANDARD.
Add GET/POST /web/settings/field-acl for system admins, batch upsert of
sys.field.access deny rules, menu and URL action, flash messages, and hub CSS.
Point menu_general_settings at action_settings.hub (/web/settings) and stop
syncing the legacy window action; keep a minimal res.config.settings model/view for CRM inherit only.
Add category cards with dedupe and hub template/CSS; exclude hub nav from center cards.
Consolidate settings nav rules, map URL actions to direct paths, force /web/settings for
menu_general_settings, and hide Personal/Account security from the settings sidebar.
…oute

Remove password flow from the hub; restore /web/settings/account; align shell page data and tests.
Send menu_general_settings + res.config.settings workspace hits to /web/settings.
Move field-access URL actions into security_actions, add model ACL hub
action, and link form views to the matrix pages.
Expose field/model ACL routes and map matrix menu XML ids to hub URLs
for correct sidebar links and active highlight.
Add shared ACL matrix helpers, effective-rights labels, and a settings
hub field-acl page with model/group filters and safe CSV download.
Persist sys.access rows from the settings hub, register routes, and flash
feedback after save.
Document matrix conventions in MODULE_STANDARD and expose test hooks for
matrix row naming and CSV disposition safety.
Platform P1: record store, commands, debug, modifiers, Sum composition, settings hub & security matrices (SUM-PLAT-07–12, 26)
@ATRIwOX
ATRIwOX merged commit 6147526 into main Sep 29, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants