Skip to content

RDKB-67104 : Safely handles missing/empty POST fields - #103

Merged
GoutamD2905 merged 2 commits into
developfrom
bug/RDKB-67104
Oct 5, 2026
Merged

GoutamD2905 merged 2 commits into
developfrom
bug/RDKB-67104

Conversation

@pavankumar464

Copy link
Copy Markdown
Contributor

Reason for change: Command Injection tests results in "500 Internal Server Error"
Test Procedure: Test for Save/Restore
Risks: Low
Priority: P1

Copilot AI lite review requested due to automatic review settings September 28, 2026 03:18
@pavankumar464
pavankumar464 requested review from a team as code owners September 28, 2026 03:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Apply equivalent missing/empty-field handling to the parallel PHP endpoint.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Improves XB3 save-configuration handling for missing or invalid POST fields.

Changes:

  • Adds safe failure defaults and required-field checks.
  • Restricts filenames to valid alphanumeric values.
File Summary
source/​Styles/​xb3/​jst/​actionHandler/​ajaxSet_at_downloading.jst Adds safer POST validation; corresponding PHP handling remains unresolved.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread source/Styles/xb3/jst/actionHandler/ajaxSet_at_downloading.jst
Copilot AI review requested due to automatic review settings September 29, 2026 15:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Reject non-string POST values and update the PHP handler to prevent remaining 500 errors.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)

Comment thread source/Styles/xb3/jst/actionHandler/ajaxSet_at_downloading.jst
@GoutamD2905
GoutamD2905 merged commit 924213b into develop Oct 5, 2026
11 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 5, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants