Skip to content

fix(dashboard): reject unknown operator actions - #7427

Merged
houko merged 4 commits into
mainfrom
fix/dashboard-unknown-operator-action
Aug 17, 2026
Merged

houko merged 4 commits into
mainfrom
fix/dashboard-unknown-operator-action

Conversation

@houko

@houko houko commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • treat workflow operator action descriptors as untrusted runtime data
  • reject unknown string verbs and malformed provide_input objects before dereferencing them
  • skip only an unsupported action while preserving the remaining authorized action buttons
  • add focused regressions for unknown strings, malformed objects, and valid provide-input descriptors

Inventory finding: F-9855eab2ac16b385

Verification

  • corepack pnpm@10.33.0 --dir crates/librefang-api/dashboard exec vitest run src/components/OperatorActionBar.test.ts (3 passed)
  • corepack pnpm@10.33.0 --dir crates/librefang-api/dashboard test (102 files, 1078 tests passed)
  • corepack pnpm@10.33.0 --dir crates/librefang-api/dashboard typecheck
  • corepack pnpm@10.33.0 --dir crates/librefang-api/dashboard lint
  • corepack pnpm@10.33.0 --dir crates/librefang-api/dashboard build
  • git diff --check
  • pre-commit and pre-push hooks

Out of scope

  • validating operator action descriptors at the API boundary
  • adding UI copy for unsupported future action verbs
  • changing the workflow operator action schema

@github-actions github-actions Bot added the size/M 50-249 lines changed label Aug 15, 2026
@github-actions github-actions Bot added the no-rust-required This task does not require Rust knowledge label Aug 15, 2026
@houko
houko enabled auto-merge (squash) August 17, 2026 09:24
@houko
houko merged commit 9f67ff1 into main Aug 17, 2026
37 checks passed
@houko
houko deleted the fix/dashboard-unknown-operator-action branch August 17, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-rust-required This task does not require Rust knowledge size/M 50-249 lines changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant