Skip to content

[bot] Fast-forward for 26.7.3 - #670

Merged
github-actions[bot] merged 2 commits into
release26.7from
26.7_ff_bot_26.7.3
Aug 4, 2026
Merged

[bot] Fast-forward for 26.7.3#670
github-actions[bot] merged 2 commits into
release26.7from
26.7_ff_bot_26.7.3

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

Generated automatically.
Approve all matching PRs simultaneously.
Approval will trigger automatic merge.
View all PRs: https://internal.labkey.com/Scrumtime/Backlog/harvest-gitOpenPullRequests.view?branch=26.7_ff_bot_26.7.3

vagisha and others added 2 commits July 28, 2026 09:29
- **Group-change validation.** The self-service group change
re-validates the resolved groups before changing any membership. Both
must be project groups in the same project, and the target must grant no
more than read access, with no write or administrative permission
anywhere in the project tree. Requests that don't meet these constraints
are refused with the generic NO_PERMISSIONS status (the specific reason
is logged server-side), and successful moves are audited.
- **Consistent signup responses.** The signup endpoints return the same
response whether or not an address already has an account, including
when email delivery fails. The owner of an existing address receives a
notice pointing to the password-reset flow, and the existing account is
never modified.
- **Auditing.** The administrative configuration actions now write an
audit event on success.
- **Error handling.** Mail-send errors are logged server-side, and
callers receive a generic message.
- **Test.** Added `SignUpGroupChangeSecurityTest`, covering the
group-change validation and its auditing.

Co-Authored-By: Claude <noreply@anthropic.com>
@github-actions
github-actions Bot merged commit 8797b6c into release26.7 Aug 4, 2026
14 checks passed
@github-actions
github-actions Bot deleted the 26.7_ff_bot_26.7.3 branch August 4, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants