Skip to content

[bot] Merge 26.8 to develop - #671

Merged
github-actions[bot] merged 4 commits into
developfrom
fb_bot_merge_26.8
Aug 5, 2026
Merged

[bot] Merge 26.8 to develop#671
github-actions[bot] merged 4 commits into
developfrom
fb_bot_merge_26.8

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown

Generated automatically.
Merging changes from: 2e82448
Approve all matching PRs simultaneously.
Approval will trigger automatic merge.
Verify all PRs before approving: https://internal.labkey.com/Scrumtime/Backlog/harvest-gitOpenPullRequests.view?branch=fb_bot_merge_26.8

vagisha and others added 4 commits July 28, 2026 09:29
- **Group-change validation.** The self-service group change
re-validates the resolved groups before changing any membership. Both
must be project groups in the same project, and the target must grant no
more than read access, with no write or administrative permission
anywhere in the project tree. Requests that don't meet these constraints
are refused with the generic NO_PERMISSIONS status (the specific reason
is logged server-side), and successful moves are audited.
- **Consistent signup responses.** The signup endpoints return the same
response whether or not an address already has an account, including
when email delivery fails. The owner of an existing address receives a
notice pointing to the password-reset flow, and the existing account is
never modified.
- **Auditing.** The administrative configuration actions now write an
audit event on success.
- **Error handling.** Mail-send errors are logged server-side, and
callers receive a generic message.
- **Test.** Added `SignUpGroupChangeSecurityTest`, covering the
group-change validation and its auditing.

Co-Authored-By: Claude <noreply@anthropic.com>
@github-actions
github-actions Bot merged commit 69cea03 into develop Aug 5, 2026
6 of 7 checks passed
@github-actions
github-actions Bot deleted the fb_bot_merge_26.8 branch August 5, 2026 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants