https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=41921 Brendan Lawlor <blawlor@clamsnet.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|Signed Off |Failed QA --- Comment #113 from Brendan Lawlor <blawlor@clamsnet.org> --- This is a really cool new feature and the test plan works as described. I used Claude Code Opus 5.5 to help test and confirmed a few blockers through manual human testing. 1. The new jobs page is vulnerable to cross-site scripting because it passes the raw url parameter to the template and into the javascript To replicate: As superlibrarian open a link like http://localhost:8081/cgi-bin/koha/reports/jobs.pl?new_job_id=document.title... Confirm the title of the page has been changed to 1337 View source, search for new_job_id and confirm the parameter was injected into the script Fix in jobs.pl by only accepting an integer: my $new_job_id = $input->param('new_job_id'); $template->param( new_job_id => $new_job_id ) if defined $new_job_id && $new_job_id =~ /^\d+$/; 2. svc/convert_report still requires the old execute_reports permission To replicate: Create a report with outdated SQL but don’t run it yet SELECT biblionumber, ExtractValue(marcxml, '//datafield[@tag="245"]/subfield[@code="a"]') AS title FROM biblioitems With a user that does not have the top level reports permission but has execute_reports_foreground and execute_reports_background Go to the list of reports Click on the Update SQL button Confirm the modal shows a login form with Error: You do not have permission to access this page. Fix in svc/convert_report by allowing either of the new permissions: flagsrequired => { reports => [ 'execute_reports_foreground', 'execute_reports_background' ] 3. Stored results skip the report library limits To replicate: Enable LimitReportsByLibrary Create a report named CPL Only, with Library limitation Centerville select * from items where homebranch = ‘CPL’ Run it once so that there are saved results Login as a user from another home library with one of execute_reports_background or execute_reports_foreground They can view the report jobs page and click on the View results button they can then see the results of a report that they are not allowed to run. Jobs should be hidden for reports that they can’t run. They also should get a permission error if they try to change the id to a report they can’t run in a url like /reports/guided_reports.pl?op=view_stored_results&id=<not_my_report_id> guided_reports.pl doesn't respect Libray limitations when op=view_stored results, but it should. -- You are receiving this mail because: You are watching all bug changes.