-
Notifications
You must be signed in to change notification settings - Fork 242
CS-37 [Improvement] - render records on trust portal settings in app for vercel #1663
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
🔒 Comp AI - Security Review🔴 Risk Level: HIGHNo OSV/NPM CVEs detected. Scan shows code-level auth/injection issues: IDOR via X-Organization-Id, unsanitized domain inputs used in URLs/queries, and unsafe use of request-derived values in DB/commands. 📦 Dependency Vulnerabilities✅ No known vulnerabilities detected in dependencies. 🛡️ Code Security AnalysisView 7 file(s) with issues🟡 apps/api/src/main.ts (MEDIUM Risk)
Recommendations:
🟡 apps/api/src/trust-portal/dto/domain-status.dto.ts (MEDIUM Risk)
Recommendations:
🟡 apps/api/src/trust-portal/trust-portal.controller.ts (MEDIUM Risk)
Recommendations:
🟡 apps/api/src/trust-portal/trust-portal.service.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/settings/trust-portal/components/TrustPortalDomain.tsx (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/hooks/use-domain.ts (MEDIUM Risk)
Recommendations:
🔴 packages/docs/openapi.json (HIGH Risk)
Recommendations:
💡 RecommendationsView 3 recommendation(s)
Powered by Comp AI - AI that handles compliance for you. Reviewed Oct 16, 2025 |
…ow-domain-status
🔒 Comp AI - Security Review🟡 Risk Level: MEDIUMNo OSV CVEs found. Code changes show raw domain input used as localStorage key, raw error objects being logged/displayed, and no server-side authorization/ownership check for domain status. 📦 Dependency Vulnerabilities✅ No known vulnerabilities detected in dependencies. 🛡️ Code Security AnalysisView 2 file(s) with issues🟡 apps/app/src/app/(app)/[orgId]/settings/trust-portal/actions/domain-status.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/settings/trust-portal/components/TrustPortalDomain.tsx (MEDIUM Risk)
Recommendations:
💡 RecommendationsView 3 recommendation(s)
Powered by Comp AI - AI that handles compliance for you. Reviewed Oct 15, 2025 |
|
🎉 This PR is included in version 1.56.1 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |

This is an automated pull request to merge chas/show-domain-status into dev.
It was created by the [Auto Pull Request] action.