Skip to content

Port 2.1 validation & permission-enforcement improvements to master - #497

Merged
navneetkumar-pim-webkul merged 1 commit into
unopim:masterfrom
dripar-webkul:chore/port-2.1-validation-acl-hardening-to-master
Jun 12, 2026
Merged

navneetkumar-pim-webkul merged 1 commit into
unopim:masterfrom
dripar-webkul:chore/port-2.1-validation-acl-hardening-to-master

Conversation

@dripar-webkul

Copy link
Copy Markdown
Collaborator

Description

Brings the input-validation and permission-enforcement improvements already on 2.1
over to master, so the main line stays consistent. Each change mirrors its 2.1 PR.

Included changes

  • Rich-text (TinyMCE) uploads — restricted to an approved image set and stored under
    randomised filenames via FileStorer.
  • Configurable-product API endpoints — every route now requires the correct access
    scope; the scope middleware fails closed for unmapped write requests.
  • Magic AI platform actions — update and set-default now require the
    platform-edit permission.
  • Product grid sorting — the sort direction is restricted to a safe allowlist
    (asc/desc) on both the database and Elasticsearch paths.
  • Attribute swatch image uploads — validated against an image allowlist and stored
    through FileStorer with a randomised filename.
  • Channel options on the family Completeness screen — output is now escaped.
  • Magic AI prompt / system-prompt & AI Agent generate — these actions now require
    the matching permission.

Adds the corresponding regression tests for each.

How To Test This?

  • Run the new Feature tests under packages/Webkul/Admin/tests/Feature/** (use a root
    APP_URL). Non-image/mismatched uploads are rejected; restricted users get 403;
    malformed sort input is coerced to a safe value; swatch SVGs are stored sanitized.

Documentation

  • My pull request requires an update on the documentation repository.

Branch Selection

  • Target Branch: master

Pint

  • All Pint checks pass.

Tailwind Reordering

  • N/A — no Tailwind class changes.

Tests

  • Pint ✅ · Translations 256/256 ✅
  • New regression tests pass on master. (The AdminApi token-based tests need master's
    oauth_clients schema aligned with the installed Passport version — a separate
    test-infra item, unrelated to these changes.)

@navneetkumar-pim-webkul
navneetkumar-pim-webkul merged commit 52220b7 into unopim:master Jun 12, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants