Skip to content

fix(leases): project status lease row to lease columns so joined conn… - #12115

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
geek007git:fix/lease-status-connection-projection
Aug 30, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
geek007git:fix/lease-status-connection-projection

Conversation

@geek007git

Copy link
Copy Markdown
Contributor

…ection PII never escapes

getExclusiveConnectionLeaseStatus built the returned lease via lease(row) where lease() was rowToCamel() cast to ExclusiveConnectionLease, so the runtime object also carried the joined connectionEmail, connectionDisplayName, connectionName, connectionAuthType, and connectionProvider columns from the status query, bypassing the configuredConnectionName() privacy fencing introduced in #11910. No consumer leaks today because the session-leases route whitelists five lifecycle fields, but any future consumer serializing status.lease directly would type-check fine and expose the connection owner identity. lease() is now an explicit projection of the twelve declared lease columns, so joined rows can never smuggle extra values onto the object, while the status-level fenced displayName/provider fields are unchanged. Validated by node --import tsx/esm --test tests/unit/exclusive-lease-status-projection.test.ts (failing before, passing after) plus the existing exclusive-connection-leases and session-leases-route suites.

Summary

  • Describe the user-facing or operational change.

Related Issues

  • Closes #
  • Related to #

Validation

Choose the change type and focused loop from the
Contribution Golden Path. The full unit suite,
Vitest, the 60% coverage gate, and the production build all run in CI on this PR (#8329):

  • Change type: provider / routing / UI / i18n / CLI / DB / build-deploy / other
  • Focused tests and category gates from the golden path
  • npm run lint
  • Reconciled with the current active release base; focused checks rerun afterward
  • Production-code changes include a new or updated automated test in this PR
  • SonarQube is temporarily opt-in while the private project has no quota; it is not a PR gate.

Tests Added Or Updated

  • List every changed or added automated test file.
  • If no production code changed, state that here.

Coverage Notes

  • If this PR changes src/, open-sse/, electron/, or bin/, explain which tests cover the change.
  • If coverage moved down in any touched file, explain why and what follow-up task will recover it.

Reviewer Notes

  • Call out any risky areas, migrations, feature flags, or manual validation that reviewers should know about.

…ection PII never escapes

getExclusiveConnectionLeaseStatus built the returned lease via lease(row) where lease() was rowToCamel() cast to ExclusiveConnectionLease, so the runtime object also carried the joined connectionEmail, connectionDisplayName, connectionName, connectionAuthType, and connectionProvider columns from the status query, bypassing the configuredConnectionName() privacy fencing introduced in diegosouzapw#11910. No consumer leaks today because the session-leases route whitelists five lifecycle fields, but any future consumer serializing status.lease directly would type-check fine and expose the connection owner identity. lease() is now an explicit projection of the twelve declared lease columns, so joined rows can never smuggle extra values onto the object, while the status-level fenced displayName/provider fields are unchanged. Validated by node --import tsx/esm --test tests/unit/exclusive-lease-status-projection.test.ts (failing before, passing after) plus the existing exclusive-connection-leases and session-leases-route suites.
@diegosouzapw
diegosouzapw merged commit 3d15294 into diegosouzapw:release/v3.8.51 Aug 30, 2026
9 of 16 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…ection PII never escapes (diegosouzapw#12115)

Corrige vazamento de colunas de conexão (email/nome/etc.) através do cast em `getExclusiveConnectionLeaseStatus` — a projeção agora fica restrita às colunas de lease, evitando que um futuro consumidor sirva PII sem querer via o tipo `ExclusiveConnectionLease`. Documentado como Finding 8 do seu próprio bug-audit (diegosouzapw#12113). Teste próprio (103 linhas). Validado no worktree combinado. Obrigado!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants