Repository navigation
Feature/google sso auth #350
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
+3,372
−2,330
Merged
Changes from 44 commits
Commits
Show all changes
52 commits
Select commit
Hold shift + click to select a range
ba9693e
feat: implement Google SSO routing and secure HttpOnly cookies
pk-cybersec 630eb0f
chore: bump CI/CD action versions to resolve Git 128 and Node depreca…
pk-cybersec af4c1bc
fix: enable CORS credentials for cookies and silence v7 linters
pk-cybersec 826a1eb
fix: add CodeQL build-mode none for python analysis
pk-cybersec ecccd69
fix: finalize backend CI/CD workflow and resolve type mismatches
pk-cybersec 29f61a1
fix: set CodeQL build-mode to none for Python analysis
pk-cybersec 4af51e0
fix: streamline backend security analysis to use Bandit exclusively
pk-cybersec aa611b4
fix(frontend): update api client to include credentials for secure co…
pk-cybersec d1c5a49
feat(api): implement prometheus instrumentator middleware and /metric…
pk-cybersec 47c1f01
fix: align frontend with HttpOnly cookie auth and repair stale tests
pk-cybersec ab7ffc5
fix(security): resolve Bandit B105 hardcoded-password finding in init…
pk-cybersec 06fb5c2
fix(security): resolve Bandit B110 try-except-pass finding in evidenc…
pk-cybersec 8377629
fix(mypy): add missing __init__.py to app/core to stop it shadowing s…
pk-cybersec 149cda9
fix(mypy): add type annotation for SCAN_MEM in evidence_ui app
pk-cybersec 3b146b0
ci: disable ts-standard linter (project uses oxlint, not eslint/stand…
pk-cybersec 0ad2341
style(frontend): apply prettier formatting to api client files
pk-cybersec 31b7784
ci: disable jscpd and ts-standard in legacy security workflow (same f…
pk-cybersec f7bd0c1
fix(security): stop printing admin password in clear text during db s…
pk-cybersec 85d721a
Merge remote-tracking branch 'origin/main' into feature/google-sso-auth
pk-cybersec 887e4d4
fix(backend-api): resolve duplicate Alembic migration heads from main…
pk-cybersec 84952a1
fix(backend-api): stop update_users_me/change_password opening a seco…
pk-cybersec 5300d68
test(backend-api): add pytest+httpx integration suite for auth endpoints
pk-cybersec 9e9d48a
test(backend-api): extend integration suite to scan and evidence endp…
pk-cybersec beeee95
ci(backend-api): run the pytest integration suite on every PR
pk-cybersec 51f3813
fix(backend-api): suppress Bandit false positives in the test suite
pk-cybersec 915b0c9
fix: resolve pre-existing mypy errors newly surfaced by real app imports
pk-cybersec a0b489a
fix: resolve remaining mypy no-redef and arg-type errors
pk-cybersec 9bcb227
fix: resolve mypy module-identity collision and alembic op false posi…
pk-cybersec 596b920
test(backend-api): add create_scan happy-path coverage
pk-cybersec a729d71
feat(engine): add E8-UAH-2.1 Office child-process blocking control
pk-cybersec 8d9096a
fix(ci): reformat metadata.json for Prettier; exclude JSCPD/TS_STANDA…
pk-cybersec b949f08
feat(engine): automate CIS 5.2.2.2, 5.2.2.9, 5.2.2.12 (MFA, managed d…
pk-cybersec 59c99c5
Merge branch 'main' into feature/google-sso-auth
s225645819 a13556c
Fix CI: use uv dependency group for dev deps, complete PR comment try…
s225645819 269d211
Fix remaining CI failures: duplicate migration head, pylint, missing …
s225645819 25fd214
Fix Pytest job missing database, restore /readiness endpoint lost in …
s225645819 9b6b325
Fix RBAC test failures: elevate test user to Auditor for scan create/…
s225645819 1a4e0e5
Merge branch 'main' into feature/google-sso-auth
s225645819 cce021b
Merge alembic heads k1l2m3n4o567 and l1m2n3o4p567
s225645819 8b4a8a6
Fix lint and mypy errors in alembic merge migration
s225645819 65626cd
Merge branch 'main' into feature/google-sso-auth
s225645819 c1f444e
Fix post-merge CI failures: regenerate uv.lock and format metadata.json
s225645819 751691d
Fix remaining post-merge CI failures
s225645819 4c1fb00
Add missing Postgres service to the coverage job
s225645819 667e13e
Merge branch 'main' into feature/google-sso-auth
s225645819 9757700
Fix CI checks broken by the main merge
s225645819 bad0c69
Fix CORS to use FRONTEND_URL instead of a hardcoded localhost origin
s225645819 d295119
Fix cross-tool false positives from regenerated security baselines
s225645819 0b5304a
Restrict /metrics to superusers
s225645819 9279506
fix(frontend): gate dashboard data loading on isAuthenticated, not token
s225645819 11a1185
fix(backend): clear OAuth state cookie on every Google callback failu…
s225645819 53cf10f
test(frontend): add regression coverage for dashboard auth gating
s225645819 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,13 @@ | ||
| [mypy] | ||
| # Files across backend-api/ and its tests import each other as "app.*" / | ||
| # "tests.*" (e.g. tests/conftest.py does `from app.main import app`), but | ||
| # backend-api/app has no __init__.py, so plain mypy can't decide whether a | ||
| # file like backend-api/app/main.py should be identified as module "main" | ||
| # or "app.main". When super-linter passes several changed files to mypy in | ||
| # one invocation, that ambiguity surfaces as: | ||
| # error: Source file found twice under different module names | ||
| # explicit_package_bases + mypy_path pins module identity relative to | ||
| # backend-api, so it is always resolved consistently as "app.main". | ||
| mypy_path = backend-api | ||
| explicit_package_bases = True | ||
| ignore_missing_imports = True |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
23 changes: 23 additions & 0 deletions
23
backend-api/alembic/versions/e5f6a7b8c9d0_merge_k1l2m3n4o567_and_l1m2n3o4p567_.py
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,23 @@ | ||
| """merge k1l2m3n4o567 and l1m2n3o4p567 heads | ||
|
|
||
| Revision ID: e5f6a7b8c9d0 | ||
| Revises: k1l2m3n4o567, l1m2n3o4p567 | ||
| Create Date: 2026-09-08 00:00:00.000000 | ||
|
|
||
| """ | ||
| from typing import Sequence, Union | ||
|
|
||
|
|
||
| # revision identifiers, used by Alembic. | ||
| revision: str = 'e5f6a7b8c9d0' | ||
| down_revision: Union[str, Sequence[str], None] = ('k1l2m3n4o567', 'l1m2n3o4p567') | ||
| branch_labels: Union[str, Sequence[str], None] = None | ||
| depends_on: Union[str, Sequence[str], None] = None | ||
|
|
||
|
|
||
| def upgrade() -> None: | ||
| """Upgrade schema. No-op merge revision; reconciles the two heads.""" | ||
|
|
||
|
|
||
| def downgrade() -> None: | ||
| """Downgrade schema. No-op merge revision; reconciles the two heads.""" |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.