Conversation
| policyRequirements = validate(policies, conditionalPolicies, fallbackPolicies, fullObject, | ||
| propName, getPropertyValue(fullObject, propName), failedPolicyRequirements); |
maximthomas
left a comment
There was a problem hiding this comment.
praise: The clean-up stays behaviour-neutral, and its one behavioural edit closes a gap.
policy.js:882now guardsrequest.resourcePathwith the same=== null || === undefinedtest as the lookup atpolicy.js:854, so no action reachesresource.propertieswithresourceunset.- The locals removed from
router-authz.js(returnVal,requestedRoles,params) are all function-local, so the scope the eval'dcustomAuthzexpressions see is unchanged.
issue (non-blocking): The new comment says getResource() never yields null, but it does.
openidm-zip/src/main/resources/bin/defaults/script/policy.js:881, :518, :857-861
getResource() falls through to return null; at :518 whenever no configured resource matches, e.g. a validateObject action on a path absent from policy.json. The empty entry comes from processRequest's own fallback at :857-861, and that fallback is what makes the removed resource === null branch dead. Behaviour at the head is correct, but the comment points the next maintainer at the wrong function: dropping :857-861 on its word turns that request's result: true into a TypeError on resource.properties. The js/unneeded-defensive-code row of the PR description repeats the framing.
// resource is never null here: an unconfigured resource was replaced by an empty entry above
if (request.resourcePath === null || request.resourcePath === undefined) {
throw "No resource specified";
}…Script - Drop locals that are declared but never read across the admin/common/ end-user UI and the bundled scripts, including two dead helper functions - Add the missing semicolons where automatic semicolon insertion was relied on - policy.js: remove the unreachable "resource === null" branch and treat an undefined resourcePath like a null one Resolves CodeQL alerts #761-#767, #788-#854, #860, #864, #867, #868, #872-#879, #908, #922, #923.
getResource() does return null for an unconfigured path; it is the empty-entry fallback in processRequest that makes the removed resource === null branch dead.
ff5912b to
cc87532
Compare
|
Fixed. The comment now says the guarantee comes from the fallback above, not from |
Summary
Fourth note-level CodeQL batch: the JavaScript findings —
js/unused-local-variable(93),js/automatic-semicolon-insertion(7),js/unneeded-defensive-code(1). 87 fixed across 42 files, 14 dismissed as false positives.This PR deliberately also touches files that #204 and #209 change (
policy.js,router-authz.js,autoPurgeAuditRecon.js,postOperation-roles.js,temporalConstraints.js,defaultMapping.js,UserQueryFilterEditor.js); the overlaps are neighbouring line removals and will be resolved at merge time, whichever lands second. The overlap with #210 (FormGenerationUtils.js,RelationshipWidget.js) is already resolved: the branch is rebased ontomasterwith #210 in it.js/unused-local-variablevar x,= []/= {}/= this, side-effect-free DOM lookups,$.Deferred(),AbstractModel.extend(...), an unusedrequire('roles/effectiveRoles'); two dead helpers (getUserByIdingetavailableuserstoassign.js,joiningettasksview.js); the unusedallUsedClasses/usableForQueriesClassesblock inAuditEventHandlersView. Where avarlist was shortened, the following object/array literal was re-indented (eslintindent). TheexcludeMappings→excludeMappingtypo inautoPurgeAuditRecon.jsis the same fix as in #209.js/automatic-semicolon-insertion;added inreconResults.js,resetPassword.js,router-authz.js,policy.js×2,autoPurgeAuditRecon.js,defaultMapping.js.js/unneeded-defensive-codepolicy.js:resourceis nevernullat this point —processRequestreplaces an unmatchedgetResource()result with an empty entry before the action branch — so theif (resource === null) … else …around the validation was dead; the body is unwrapped. Small correctness gain: anundefinedresourcePathnow fails with "No resource specified" like anullone instead of aTypeError.Dismissed as false positives (14): the 13
router-authz.js"unused function" alerts (ownDataOnly,isOneOfMyWorkflows,reauthIfProtectedAttributeChange, …) — they are referenced by name from thecustomAuthzexpressions inconf/script/access.js, whichpassesAccessConfig()evaluates witheval(); andpolicy.jsaddPolicy, the documented API that custom policy scripts call, again througheval()insideadditionalPolicyLoader.load().Not addressed here: CodeQL #930 (
js/useless-assignment-to-local,policyRequirementsinpolicy.js) is the existing #895 re-reported under a new number because unwrapping theifre-indented that line. It stays with #895/#896, which #209 defers until #204 lands.Test plan
.jsparse-checked with Node and linted with the module's eslint configopenidm-ui-common,openidm-ui-admin,openidm-ui-enduser: eslint clean, QUnit green, BUILD SUCCESSmvn -pl openidm-zip -am package—ScriptRunnerTestgreen over all JS test modules (incl.policyFilterTest,effectiveRolesTest,temporalConstraintsTest,conditionalRolesTest)