harsh mahajan
a3f6cf4645
fix: restrict CSRF guard to same-origin only, drop same-site
2026-04-28 13:00:18 +05:30
harsh mahajan
9a175c5098
test: add E2E tests for impersonateUserId query param and CSRF guards
2026-04-28 12:56:17 +05:30
harsh mahajan
5465be6301
fix: make CSRF guard fail-closed by requiring explicit same-origin Sec-Fetch-Site
2026-04-28 12:27:57 +05:30
harsh mahajan
46a457bfa3
fix: block impersonateUserId query param on cross-site requests to prevent CSRF
2026-04-28 12:10:51 +05:30
harsh mahajan
4c989f99c3
fix: cast impersonateUserId query param to string to prevent array injection
2026-04-28 12:05:02 +05:30
harsh mahajan
8f1d73a6cb
chore: clarify intentional header-only restriction for email/phone impersonation
2026-04-28 12:02:00 +05:30
harsh mahajan
01b5fa8ecb
fix: restrict impersonation query param fallback to userId only
...
Remove query param fallback for impersonateEmail and impersonatePhone
to avoid PII exposure in server logs, browser history, and Referer
headers. Only impersonateUserId (an opaque internal ID) is safe to
pass via URL query param.
2026-04-28 11:58:25 +05:30
harsh mahajan
d73b7a70d8
feat: add query param fallback for impersonation headers
...
Allow impersonation to be specified via URL query params
(?impersonateUserId, ?impersonateEmail, ?impersonatePhone) as a
fallback to the existing headers, enabling Console to embed
impersonation in direct file/image URLs where headers cannot be set.
2026-04-28 11:44:39 +05:30
Damodar Lohani
cefd063c55
Merge pull request #12165 from appwrite/fix/CLO-4280-getheader-string-coerce
...
fix: coerce non-string header values in Request::getHeader
2026-04-28 10:43:40 +05:45
Damodar Lohani
c924cbcc59
Merge pull request #12166 from appwrite/fix/CLO-4279-favicon-empty-body
...
fix: guard DOMDocument::loadHTML against empty body in favicon endpoint
2026-04-28 10:32:32 +05:45
Damodar Lohani and greptile-apps[bot]
81321e82d1
Update src/Appwrite/Platform/Modules/Avatars/Http/Favicon/Get.php
...
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-04-28 10:05:01 +05:45
Damodar Lohani
30a511692b
test: add unit coverage for Request::getHeader non-string coercion
...
Refs CLO-4280
2026-04-28 04:15:00 +00:00
Damodar Lohani
9637409831
fix: coerce non-string header values in Request::getHeader
...
Closes CLO-4280
2026-04-28 03:54:35 +00:00
Damodar Lohani
c4f6b11706
fix: guard DOMDocument::loadHTML against empty body in favicon endpoint
...
Closes CLO-4279
2026-04-28 03:54:34 +00:00
ArnabChatterjee20k
1b8123bf62
Merge pull request #11992 from appwrite/realtime-logs
...
added missing include for exporter in the realtime
2026-04-24 16:45:28 +05:30
ArnabChatterjee20k
1ca75c73df
Merge branch '1.9.x' into realtime-logs
2026-04-24 16:35:25 +05:30
ArnabChatterjee20k
0633662695
removed dispatch experiment
2026-04-24 16:22:57 +05:30
ArnabChatterjee20k
89819db775
added exporter
2026-04-24 16:12:42 +05:30
Matej Bačo
29b700d1ec
Merge pull request #11981 from appwrite/feat-public-list-endpoints
...
Feat: Project public list endpoints
2026-04-24 10:08:23 +02:00
Matej Bačo
e3231393b9
Fix anayser
2026-04-23 16:06:45 +02:00
Matej Bačo
5beeca5a99
Placeholder test
2026-04-23 15:57:09 +02:00
Matej Bačo
4de3009f67
Fix analyser
2026-04-23 15:36:16 +02:00
Matej Bačo
4b3963512c
Linter fix
2026-04-23 15:28:20 +02:00
Matej Bačo
8c634a95e4
Fix failing tests
2026-04-23 15:28:10 +02:00
Matej Bačo
7a3c001452
Re-add project removal tests
2026-04-23 15:22:40 +02:00
Matej Bačo
a48fd13ced
Add getPolicy + tests + move wrongly placed project tests
2026-04-23 15:19:49 +02:00
Matej Bačo
9c6ed9565e
Remove tests of removed endpoints
2026-04-23 14:07:58 +02:00
Matej Bačo
bdbc5b92df
Fix after code review
2026-04-23 13:47:31 +02:00
Matej Bačo
c246fb0f83
Project deletion tests
2026-04-23 13:41:11 +02:00
Matej Bačo
a0a3849b16
Remove unsupported bulk endpoints
2026-04-23 13:37:32 +02:00
Matej Bačo
b99139661e
Migrate delete project endpoint
2026-04-23 13:37:19 +02:00
Matej Bačo
6d86b8fd0d
Removal of project JWTs
2026-04-23 13:25:21 +02:00
Matej Bačo
cef7a5197f
List policies API
2026-04-23 13:24:39 +02:00
Matej Bačo
c1dfeae323
Add queries to email tempaltes list
2026-04-23 13:06:05 +02:00
Matej Bačo
51fa0770a6
Add queries to mock numbers list
2026-04-23 12:43:45 +02:00
Matej Bačo
d46403507c
Merge pull request #11979 from appwrite/fix-membership-privacy
...
Fix: membership privacy bug on production
2026-04-23 10:47:54 +02:00
Matej Bačo
83724ce96f
Console membership privacy test coverage
2026-04-23 10:37:35 +02:00
Matej Bačo
34930e6d67
Merge branch '1.9.x' into fix-membership-privacy
2026-04-23 10:18:32 +02:00
Matej Bačo
096f8041fd
Merge pull request #11970 from appwrite/feat-mocks-public-api
...
Feat: Public mock phone APIs
2026-04-23 10:18:14 +02:00
Matej Bačo
9dad7cef9e
Merge branch '1.9.x' into feat-mocks-public-api
2026-04-23 10:17:32 +02:00
Matej Bačo
9e23867f0a
Merge pull request #11976 from appwrite/feat-auth-methods-api
...
Feat: Auth methods public API
2026-04-23 10:14:34 +02:00
Matej Bačo and greptile-apps[bot]
48353faa9b
Apply suggestions from code review
...
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-04-23 10:13:01 +02:00
Matej Bačo
c36b8fbabf
Fix membershiip privacy bug on production
2026-04-23 10:07:32 +02:00
Luke B. Silver
5a5cb1e74e
Merge pull request #11977 from appwrite/perf/v20-investigation
...
perf: memoize request filter chain and V20 schema lookups
2026-04-23 07:38:03 +01:00
Chirag Aggarwal
a8e6b1b683
Merge pull request #11963 from appwrite/chore/http-benchmark-comparison
2026-04-23 09:48:37 +05:30
Matej Bačo
b0939b92c3
Fix failing account tests
2026-04-22 17:02:22 +02:00
Chirag Aggarwal
3d66078fe9
Increase benchmark iterations
2026-04-22 19:46:27 +05:30
Chirag Aggarwal
9a6a597710
Address benchmark hardening review
2026-04-22 19:38:48 +05:30
Chirag Aggarwal
c15e8d0126
Harden benchmark failure guard
2026-04-22 19:30:01 +05:30
Chirag Aggarwal
7b25d778d4
Trim benchmark scenarios
2026-04-22 19:21:51 +05:30