Skip to content

Advertisement helper improvements - #2156

Open
Oaphi wants to merge 1 commit into
developfrom
0valt/settings-fixes
Open

Advertisement helper improvements#2156
Oaphi wants to merge 1 commit into
developfrom
0valt/settings-fixes

Conversation

@Oaphi

@Oaphi Oaphi commented Sep 6, 2026

Copy link
Copy Markdown
Member
  • Prevent malicious icon_path from executing system commands - See Security/Open cop for details;
  • Only allow safe URIs (HTTP, HTTP(S), or relative) for icon_path;

@codecov

codecov Bot commented Sep 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.35%. Comparing base (612ac9b) to head (af933d1).
⚠️ Report is 4 commits behind head on develop.

Additional details and impacted files
Components Coverage Δ
controllers 77.02% <ø> (ø)
helpers 85.47% <100.00%> (ø)
jobs 79.93% <ø> (ø)
models 93.48% <ø> (ø)
tasks 61.11% <ø> (ø)
scripts ∅ <ø> (∅)

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@Oaphi

Oaphi commented Sep 6, 2026

Copy link
Copy Markdown
Member Author

Blocked by: #2154 (I'd like to use the URI helper)

@Oaphi Oaphi added the status: blocked This is being worked on but is blocked by something else label Sep 6, 2026
@Oaphi Oaphi changed the title Prevent malicious icon_path from executing system commands Advertisement helper improvements Sep 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: blocked This is being worked on but is blocked by something else

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant