Merged
Conversation
ArtursKadikis
approved these changes
Jan 5, 2026
5ec7f05 to
9da0bab
Compare
Contributor
There was a problem hiding this comment.
Pull request overview
This pull request adds application ID validation to database operations to prevent unauthorized cross-app data access. The changes ensure that when users perform CRUD operations on event groups and event categories, the queries are scoped to the specific app_id, preventing users from accessing or modifying data belonging to other applications.
Key changes include:
- Adding app_id filters to update, delete, and bulk operations in event groups management
- Adding app_id filter to event category edit operations
- Complete removal of the old-ui-compatibility plugin
Reviewed changes
Copilot reviewed 6 out of 14 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| api/parts/mgmt/event_groups.js | Added app_id validation to updateOne, bulkWrite, update (multi), and remove operations to ensure users can only modify event groups belonging to their application |
| plugins/data-manager/api/api.js | Added app_id filter to category edit operation's updateOne filter to prevent cross-app category modifications |
| plugins/old-ui-compatibility/* | Complete removal of the old-ui-compatibility plugin including all associated files (package files, frontend code, API endpoints, and third-party libraries) |
Files not reviewed (1)
- plugins/old-ui-compatibility/package-lock.json: Language not supported
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.