Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Downgrade passport back to 0.5.3 #1037

Merged
merged 1 commit into from Jul 26, 2022
Merged

fix: Downgrade passport back to 0.5.3 #1037

merged 1 commit into from Jul 26, 2022

Conversation

DafyddLlyr
Copy link
Contributor

@DafyddLlyr DafyddLlyr commented Jul 26, 2022

Undoes changes made in this commit - 22dad6c

Issue described here - jaredhanson/passport#904

Initially I thought this was a conflict caused by cookie-session v2, which is maybe not the cause of the issue. I'll separately try to update that and test. Discussion here that triggered this belief...! jaredhanson/passport#907

We'll have to keep an eye on this one as there is a CVE associated with this package/version (I'll maybe add to Slack for now like Hasura until we sort out dependabot?). There is an override in the package.json which should keep up on the safe side here however so no immediate worries 👍

To test...

  • I can log in to pizza
  • I can log out of pizza
  • I can repeat the above many times

@github-actions
Copy link

github-actions bot commented Jul 26, 2022

Removed vultr server and associated DNS entries

@DafyddLlyr DafyddLlyr marked this pull request as ready for review July 26, 2022 15:54
@DafyddLlyr
Copy link
Contributor Author

So we can't test this on the Pizza as it auths against the staging API.

If we're happy can we merge this and test on staging?

@gunar gunar merged commit 2bc34e4 into main Jul 26, 2022
@gunar gunar deleted the dp/downgrade-passport branch July 26, 2022 16:47
gunar added a commit that referenced this pull request Jul 28, 2022
…mains

# By Jessica McInchak (11) and Dafydd Llŷr Pearson (10)
# Via GitHub
* origin/main: (21 commits)
  chore: Upgrade Editor dependencies (Part 1) (#1047)
  chore: upgrade metabase (#1050)
  fix: Drop sslPolicy for HTTP (#1051)
  chore(infra): Update HTTP/HTTPS listener SSL policy (#1049)
  chore: Enable Save and Return by default (#1048)
  fix: add single line address as separate CSV row (#1046)
  feat: Enable emailReplyToID (#1044)
  fix: Display ContentPage on Save and Return path (#1045)
  chore: upgrade scripts/seed-database dependencies (#1043)
  chore: upgrade e2e test dependencies (#1042)
  fix: adjust HASURA_GRAPHQL_CORS_DOMAIN in pulumi (#1041)
  fix: preserve breadcrumb order when reconciling changed content (#1034)
  fix: restrict a user from drawing a site boundary and uploading a location plan (#1040)
  feat: Apply basic rate limiting to API (#1038)
  fix: use HASURA_GRAPHQL_CORS_DOMAIN env variable to whitelist domains (#1039)
  fix: Downgrade passport back to 0.5.3 (#1037)
  chore: Update Hasura (#1035)
  build: Upgrade API dependencies (#1033)
  chore: remove Uniform feature flag (#1027)
  fix: Review page shows all DrawBoundary data (map and/or plan) and file gets correct BOPS tag (#1030)
  ...

# Conflicts:
#	editor.planx.uk/package.json
#	editor.planx.uk/pnpm-lock.yaml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants