58 Commits
Author SHA1 Message Date
Ruslan KonviserandClaude Fable 5 84032fd11c fix(security): close the residual gaps in the remaining advisories + the LOCAL-provider attachment bug
A re-verification of every draft and published advisory against develop found 9 fully closed and 8
with residuals. This closes the code-fixable ones. Three patterns cover almost all of them:

1. `{ id, ...body }` — the body wins. A path id spread BEFORE the body is overridden by a body `id`,
   and save()/create() with an existing PK is an UPDATE of that row: every authorization check ran
   against the path id while the write hit the body id. On PUT /user/:id that is account takeover
   (a PROFILE_EDIT employee posts {"id":"<SUPER_ADMIN>","hash":"..."}). The id is now pinned LAST in
   all 25 controllers/handlers with that shape, UserService.updateProfile pins entity.id = id, and
   TenantAwareCrudService.create/save/createMany/saveMany refuse an entity whose id already names a
   row of ANOTHER tenant (or a tenant-less row) — the update-through-create endpoints had no other
   ownership check. (GHSA-x4mv-fhwj-g3rp, GHSA-gwpq-mmw7-vx85)

2. A client-supplied value decides an authorization branch. The register handler gated "only a
   SUPER_ADMIN may register a SUPER_ADMIN" on input.user.role.name, and POST /user had no gate at
   all. Both now resolve EVERY role identifier (the flat roleId and the role relation — the relation
   wins on persist) from the database in the caller's tenant and fail closed on an id that does not
   resolve. (GHSA-hjcg-633x-qq74, GHSA-x4mv-fhwj-g3rp)

3. Only the root row is tenant-scoped. SharedEntity turned caller-supplied shareRules.relations
   straight into TypeORM relations on a @Public() token route, so a share of an OWNED Organization
   could pivot featureOrganizations -> feature -> featureOrganizations -> tenant -> organizations ->
   employees -> user into every tenant. Relations are now validated against entity metadata (each hop
   must exist AND target a tenant-scoped entity), depth-bounded, joined rows are scope-filtered,
   tenant-less roots are refused, and create/update bodies are whitelisted. (GHSA-cx2q-xmh2-pc38,
   GHSA-gpg5-qwjc-8hqh)

Also:
- /invite/accept mass-assignment: AuthService.register strips id/hash/emailVerifiedAt/emailToken/
  code/codeExpireAt/refreshToken from input.user, honours createdByUserId only for the authenticated
  caller, pins user.tenantId to the trusted tenant; invite accept pins the invited email.
  (GHSA-929w-5p4w-cxjp)
- TimeOffStatusHandler used raw repositories with no tenant scope (an admin of tenant A could
  approve/deny tenant B's requests); equipment-sharing deleted the request_approval row unscoped, and
  its status change went through an update() that deletes and re-inserts — a { status }-only body
  replaced the record with a stub. (GHSA-gwpq-mmw7-vx85)
- Hubstaff /refresh-token no longer returns the refresh token. (GHSA-3rqg-gpm9-gx84)
- Upload filters on the endpoints that had none: POST /import (archive allowlist), POST
  /ai-chat/attachments and the 5 registry upload routes (script-capable-extension denylist).
  (GHSA-p334-cm7f-php5)
- docker-compose defaults NODE_ENV to production so the insecure-secret guard actually fires (compose
  `environment:` overrode .env.compose and the image ENV); render blueprints generate their secrets
  instead of shipping secretKey/refreshSecretKey/gauzy, and the CORP policy is overridable
  (CORP_POLICY) because API and webapp live on two different *.onrender.com sites.
  (GHSA-chm8-2ggf-pgjq)

And a functional bug found on the way: POST /ai-chat/attachments was broken on the default LOCAL file
provider. It used Nest's @UploadedFile(), which hands over multer's diskStorage object — no `key` (only
core's @UploadedFileStorage() maps it through provider.mapUploadedFile, where LOCAL derives key from
path) — so the service threw 400 AFTER the bytes were written, leaving an orphan. It now uses the core
decorator, never puts a browser-renderable extension on the stored object name, and deletes the stored
object when the upload is rejected (service) or when sniffFile rejects it (docs chat-capture).

PUT /product-types/:id was likewise a silent 400 for every caller (a DTO instance was passed to
EntityManager.save, which resolves metadata from the constructor); it now saves with an explicit
entity target under the verified id.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-19 18:24:20 +02:00
samuel mbabhazi 292e6eaa6d [feat] Integrate PostHog plugin (#8911)
* feat(plugin-posthog): initial setup of PostHog plugin

* feat(posthog): add interfaces for PostHog module configuration

* feat(posthog): add constant for injection token

* feat(posthog): implement PosthogService with track, identify and shutdown methods

* feat(posthog): implement core module with support for sync and async config

* feat(posthog): create main module with forRoot and forRootAsync

* chore(posthog):install latest posthog-node

* feat(posthog): update PostHog interfaces to match official client options

* feat(posthog): enhance PostHog service with feature flag support and alignment with official client

* feat(posthog): update PostHog interfaces to match official client options

* feat(middleware): add PosthogRequestMiddleware for capturing request context

* feat(middleware): enhance PosthogTraceMiddleware with performance metrics

* feat(interceptor): implement PosthogErrorInterceptor for error tracking

* feat(plugin): create base PosthogPlugin structure

* feat(interceptor): implement PosthogCustomInterceptor

* feat(config):Add config posthog

* add plugin

* feat(posthog): Refactor service logic && update config

* Remove unnecessary changes

* feat(posthog):Refactor and reorganize the plugin codebase for better structure and maintainability

* fix: deepscan

* feadback integration

* suggestion integration

* remove unecessary changes
2025-04-20 09:52:22 +02:00
JycreynandRuslan Konviser 6e58abf16e Chore: Docker Compose improvements (#8827)
* FIx for "demo" var that was not usin .env.compose

* Adding data forlder to ever-gauzy/.deploy/redis/data

because compose could not mount biond point.

"Error response from daemon: Bind mount failed: 
'ever-gauzy/.deploy/redis/data' does not exists

* Update docker-compose.yml

---------

Co-authored-by: Ruslan Konviser <evereq@gmail.com>
2025-03-02 13:38:35 +01:00
Ruslan Konviser 5aa5f7faa1 chore: fix minio 2025-03-01 17:33:55 +01:00
Ruslan Konviser 17eb11959d chore: update to PostgreSQL v17 and OpenSearch instead of ES 2025-03-01 16:56:40 +01:00
Ruslan Konviser f610fb9ac3 chore: improvements to docker compose 2024-04-18 18:33:36 +02:00
Ruslan Konviser 32f5799db3 fix: docker compose builds 2024-04-18 10:26:23 +02:00
Ruslan Konviser 2ecb746e35 chore: update Mikro-ORM packages and more OTEL related fixes 2024-03-07 22:29:10 +01:00
Ruslan Konviser a599a6dcdb feat: adding more OTEL providers 2024-03-06 17:36:13 +01:00
Ruslan Konviser f3318cff12 chore: add SENTRY_PROFILE_SAMPLE_RATE 2023-12-22 21:42:41 +01:00
Ruslan Konviser 4b7d728c34 feat: more Sentry related improvements 2023-12-22 00:36:58 +01:00
Ruslan Konviser 7c886425b3 fix: running migrations and docker compose builds 2023-12-13 11:36:13 +01:00
Ruslan Konviser 2a5bba49af feat: more for SigNoz 2023-11-29 13:08:07 +01:00
Ruslan Konviser 90a2e80e7d feat: more improvements to OTEL / SigNoz integration 2023-11-29 10:56:35 +01:00
Ruslan Konviser d211d17481 feat: #7136 integration of SigNoz 2023-11-28 22:51:59 +01:00
Ruslan Konviser 213dbf5687 chore: env vars / logos 2023-11-27 12:40:08 +01:00
RAHUL RATHORE 095241f286 chore: move env variables 2023-11-21 16:00:57 +05:30
RAHUL RATHORE 0cd3c416ce fix: #7151 github call URL removed 2023-11-21 13:14:44 +05:30
Ruslan Konviser 03258ab66e chore: #6997 - make sure we use correct volume name and latest image for JITSU
Note: I don't think it solve anything because we still see ERROR in logs for JITSU: [ERROR]: ❌ Airbyte integration is disabled: volume with name: jitsu_workspace hasn't been mounted to the current docker container. The volume is required for Airbyte integration. Please add -v jitsu_workspace:/home/eventnative/data/airbyte to your Jitsu container run
2023-10-14 20:57:29 +02:00
Ruslan Konviser 77e5b47d77 chore: more env vars for GitHub integration 2023-10-14 13:47:20 +02:00
Ruslan Konviser f95f240b59 chore: move env vars 2023-10-08 08:08:33 +02:00
Nelson Bwogora edbd2e965e Jitsu integration to capture events (#6891)
* Did jitsu intergration for
capturing events data, currently work in
progress

* PR fixes - adopt new Jitsu env vars naming , refactor app.module to
 follow conventions , NB not final commit

* correct Jitsu app module provides definition

* refactor jitsu service handle when no configs are
 found , include new events interface type

* added jitsu events types and enums

* work on adding user identity to jitsu events

* add user id and mail identity to analytics click

* clean . env file remove console logs in jitsu
service

* clean env files

* Jitsu Configuration remove unnecessary string

* Finished up adding more jitsu analytics
methods and cleanups

* rename variable function adpatExternalUrl
to getExternalUrl
2023-09-29 21:13:12 +02:00
Ruslan Konviser 2a4363cce5 fix: more for Sentry 2023-07-22 19:58:39 +02:00
Ruslan Konviser af210ae3e1 chore: add Jitsu and required deps in Docker Compose 2023-06-16 20:50:42 +02:00
Ruslan Konviser 7ed85c0c94 feat: #6345 improvements in Docker Compose files for better compatibility 2023-06-08 12:04:07 +02:00
Ruslan Konviser 89c5cf1334 feat: more improvements for docker compose and introduce Cube 2023-03-28 16:21:27 +02:00
Ruslan Konviser c4ede4bd00 chore: docker compose improvements 2023-01-14 22:31:15 +01:00
Ruslan Konviser 001b91169b chore: add Redis, ElasticSearch and Minio 2023-01-12 22:04:51 +01:00
Ruslan Konviser 796b2f1cab fix: #4151 - docker-compose compatibility fixing 2022-02-12 17:58:13 +02:00
Ruslan Konviser 18ece46a75 fix: we need CLIENT_BASE_URL for our APIs for email templates at least 2022-01-16 10:39:49 +02:00
Ruslan Konviser 07da6dc62f fix: hosts / ports env vars usages 2021-10-13 14:42:40 +03:00
Ruslan Konviser cc6d4348e5 fix: some fixes for Docker Compose runs 2021-07-17 20:39:49 +03:00
Ruslan Konviser f147a46a81 fix: some fixes for better handing of entrypoints / dockers 2021-03-28 17:19:52 +03:00
Ruslan Konviser 0203f8722e fix: multiple fixes in regards to env vars naming / usage 2021-03-13 15:31:24 +02:00
Ruslan Konviser 51931a12b0 feat: we don't need 2 nginx anymore for docker compose :) 2021-01-20 16:31:49 +02:00
Ruslan Konviser 093cf4fc4c fix: some docker compose related fixes 2021-01-20 15:59:54 +02:00
Ruslan Konviser 5d165a4b9d feat: integration with Chatwoot widget (optionally) 2021-01-19 19:24:06 +02:00
Ruslan Konviser 8698419de8 feat: some more improvements related to docker builds 2021-01-19 01:23:56 +02:00
Ruslan Konviser 2ca1deb511 feat: refactor and improve Docker / Compose 2021-01-16 21:37:20 +02:00
Ruslan Konviser 7d10e60695 feat: optimize Dockers 2021-01-15 21:02:47 +02:00
Ruslan Konviser 0a61add26a fix: make sure docker containers can run without compose too 2021-01-13 02:21:45 +02:00
IsmayilMirzali 05afb6748a fix: resolve issues with api failing to run 2020-08-20 21:04:23 +03:00
Ruslan Konviser 2b110ad2f3 Update docker-compose.yml 2020-07-05 19:41:29 +03:00
IsmayilMirzali 5d4f3d248a Docker-compose changes 2020-07-05 16:39:01 +03:00
Ruslan Konviser bcf7097da6 fix: docker-compose file fix 2020-07-03 23:41:36 +03:00
Muiz Nadeem bf0957d63a Merge branch 'develop' into feat/#398-tenants-links 2020-07-01 14:30:30 +05:30
Salathiel Genese 494db2ea9d feat: allow API_BASE_URL to be configurable 2020-06-29 06:29:40 +04:00
Salathiel Genese 22a4e9fe11 feat: get env vars as configurable, with fallback values 2020-06-29 06:25:57 +04:00
Salathiel Genese b2c0bba39e feat: enable docker-compose to pass all sort of env vars from .env to the container 2020-06-29 06:11:20 +04:00
Salathiel Genese fec0035a81 fix: remove WAIT_HOSTS as the docker image handles it 2020-06-29 06:06:19 +04:00