Skip to content

[SE-3745]: Cherry picks 2020-12-03 XSS security fixes from upstream - #297

Merged
lgp171188 merged 1 commit into
opencraft-release/juniper.3from
raul/juniper-security-updates
Dec 9, 2020
Merged

[SE-3745]: Cherry picks 2020-12-03 XSS security fixes from upstream#297
lgp171188 merged 1 commit into
opencraft-release/juniper.3from
raul/juniper-security-updates

Conversation

@eLRuLL

@eLRuLL eLRuLL commented Dec 7, 2020

Copy link
Copy Markdown

This cherry-picks security updates and fixes from https://github.com/edx/edx-platform/pull/25786 which are the same shared as patch for the 2020-12-03 XSS security fixes.

Testing Instructions:

Reviewers

@lgp171188

Copy link
Copy Markdown

@eLRuLL, can you cherry-pick the single squashed commit containing the backported changes to the open-release/juniper.master branch with the -x option instead of cherry-picking multiple commits from the master? I will set up a sandbox to test this PR once you do that and then approve it.

@nizarmah

nizarmah commented Dec 8, 2020

Copy link
Copy Markdown

@eLRuLL here's the commit hash that you'll need to cherry-pick c03857b78d6204ed3b9a3093367348ebfaaf7d04
I would have done it, but I didn't want to rebase your branch without you approving first.

@s0b0lev

s0b0lev commented Dec 8, 2020

Copy link
Copy Markdown

@eLRuLL you mentioned me as a reviewer for this PR. I have followed the testing checklist - instance pr297 works as expected.

It looks like commits were squashed (as Nizar already mentioned).

I will leave this PR review to @lgp171188.

Let me know @lgp171188 if you wont have time to make a review:

I will set up a sandbox to test this PR once you do that and then approve it.

@eLRuLL
eLRuLL force-pushed the raul/juniper-security-updates branch from 2b633a5 to 5ed758d Compare December 8, 2020 12:52
@eLRuLL

eLRuLL commented Dec 8, 2020

Copy link
Copy Markdown
Author

@lgp171188 @nizarmah sorry about that I didn't check the releases, only saw the change on master and started getting the commits.

@lgp171188 this should be ready to test

ty @s0b0lev for the review btw

@lgp171188

Copy link
Copy Markdown

@eLRuLL, can you cherry-pick with the -x flag so that the commit message contains the hash of the source commit?

(cherry picked from commit c03857b)
@eLRuLL
eLRuLL force-pushed the raul/juniper-security-updates branch from 5ed758d to 8b6cff5 Compare December 8, 2020 16:22
@eLRuLL

eLRuLL commented Dec 8, 2020

Copy link
Copy Markdown
Author

oops, I forgot about that, @lgp171188 done

@lgp171188

Copy link
Copy Markdown

@eLRuLL, I have created a sandbox for testing this PR. Once it finishes provisioning, I will approve this PR and merge it.

@lgp171188
lgp171188 self-requested a review December 9, 2020 15:25

@lgp171188 lgp171188 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

  • I tested this and verified that this is a clean cherry-pick of the upstream fix and tested the changes on a sandbox and found no issues.
  • I read through the code NA
  • I checked for accessibility issues NA
  • Includes documentation NA

@lgp171188
lgp171188 merged commit df1786a into opencraft-release/juniper.3 Dec 9, 2020
@samuelallan72
samuelallan72 deleted the raul/juniper-security-updates branch December 14, 2020 04:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants