Skip to content

Latest commit

 

History

History
17 lines (15 loc) · 2.1 KB

File metadata and controls

17 lines (15 loc) · 2.1 KB

ChangeLog

--- develop ---

  • dev: Measure CI coverage with xdebug instead of pcov so the plugin's own sources are instrumented (pcov auto-scopes to the Composer root and skipped cacti/plugins/, leaving the patch-coverage gate with nothing to measure)
  • dev: Enforce patch coverage of changed lines in CI and remove the inert COMPOSER_ROOT_VERSION env from the Pest step
  • security: Add a version-safe CSP nonce (plugin_wmi_csp_nonce()) to every inline <script> tag so pages stay compatible with Cacti's Content-Security-Policy nonce enforcement, while falling back cleanly on older Cacti releases that lack the CactiSecureHeaders class
  • issue: PHPStan level 8 typing pass - fixed an incorrect script_path/script_function in the exported WMI query resource XML, restrictive drp_action/menu-index guards in wmi_accounts.php and wmi_queries.php, several unguarded array offset accesses on DB fetch results, and html_start_box() argument-type mismatches
  • test: Expand Security/Unit/Integration Pest coverage for setup.php lifecycle, hook registration, and table/column provisioning
  • chore: Harmonize CI workflow, issue/PR templates, and PHP-compatibility test structure with the shared Cacti plugin baseline
  • feat: Add a PowerShell/CIM transport (PowerShellCim_Transport) for Windows collector hosts, with automatic transport selection based on the Cacti server OS
  • security: Escape WMI account, query, and tool output on render (html_escape/__esc) to close stored and reflected XSS
  • security: Bind the remaining interpolated SQL as prepared statements in functions.php, poller_wmi.php, and script/wmi-script.php
  • security: Remove wmi_accounts.php and wmi_tools.php from the Template Editor auth augment so credential management and the live query tool stay behind the WMI Management realm
  • security: Escape the wmic hostname and namespace before exec so a device-supplied address cannot inject a shell command (issue#5)
  • security: Quote the wmic delimiter so exec() no longer splits the command into a shell pipeline (issue#5)
  • security: Restrict decode() unserialize with allowed_classes to block PHP object injection (issue#5)