Skip to content

Conversation

bbenaissa
Copy link
Collaborator

@bbenaissa bbenaissa commented Jul 17, 2025

Description

Description des modifications

Type de changement

Indiquer le ou les types de changements

  • Build
  • PKI
  • Ansiblerie
  • Nouveau Code
  • Correction
  • Refactorisation de code
  • Autre

Documentation

Indiquer la documentation mise à jour

  • Quels sont les nouvelles documentations ?
  • Quels sont les modifications existantes ?
  • Quels sont les documentations ou sections de documentations supprimés ?

Tests

Indiquer comment le code à été testé (manuel, environnement, TU, etc)

  • manuel
  • environnement
  • TU

Migration

Indiquer si les modifications apportées impliquent une migration sur l'existant et comment la faire

Checklist

Sélectionner les éléments de la checklist

  • Mon code suit le style de code de ce projet.
  • J'ai commenté mon code, en particulier dans les classes et les méthodes difficile à comprendre.
  • J'ai fait les changements correspondant dans la documentation RAML.
  • J'ai fait les changements correspondant dans la documentation Métier.
  • J'ai fait les changements correspondant dans la documentation Technique.
  • J'ai rajouté les tests unitaires vérifiant mes fonctionnalités.
  • J'ai rajouté les tests de non régression vérifiant mes fonctionnalités.
  • Les tests unitaires nouveaux et existants passent avec succès localement.
  • Toutes les dépendances ont été mergées en priorité

Contributeur

Indiquer qui a développé cette fonctionnalité

  • VAS (Vitam Accessible en Service)
  • CEA (Commissariat à l'énergie atomique et aux énergies alternatives)

@vitam-prg
Copy link
Collaborator

vitam-prg commented Jul 17, 2025

Logo
Checkmarx One – Scan Summary & Details097f350e-2b9b-48ce-8519-8cf014bf4d64

New Issues (131)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH Passwords And Secrets - Generic Password /vitamui_vars.yml: 212
detailsQuery to find passwords and secrets in infrastructure code.
ID: WGmOzSeLLOsjk6y2h2ZAvpjqHbQ%3D
MEDIUM Privacy_Violation /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 85
detailsMethod getTenantIdentifier at line 85 of /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java sends...
ID: LAEgnglZT%2BxLSfiJ0i66aaRzbJ4%3D
Attack Vector
MEDIUM Privacy_Violation /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 85
detailsMethod getTenantIdentifier at line 85 of /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java sends...
ID: c52fOLCdimAoiG3W55QG7B%2B2yDg%3D
Attack Vector
MEDIUM Privacy_Violation /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 175
detailsMethod getApplicationId at line 175 of /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java sends u...
ID: z8jT27nU0hQXpEOSpJbcB97WNF8%3D
Attack Vector
MEDIUM Privacy_Violation /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 175
detailsMethod getApplicationId at line 175 of /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java sends u...
ID: SX5hX2mGj0mOwKJwaoMqN3Eyod4%3D
Attack Vector
MEDIUM Privacy_Violation /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 85
detailsMethod getTenantIdentifier at line 85 of /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java sends...
ID: 2pnRz9WidT1eZ3eGUfr83tAFT9A%3D
Attack Vector
LOW Log_Forging /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 175
detailsMethod getApplicationId at line 175 of /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java gets us...
ID: D7lxGnK8tsnaTGPuzFcJGxeJiFg%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java: 180
detailsMethod reclassification at line 180 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java gets...
ID: WFQIRPOvkr4GNcgos%2FSIsLF%2FQlA%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitController.java: 194
detailsMethod startDeletionAction at line 194 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitControl...
ID: Gj5osR9%2BoizLQpW9Z4hPzF%2BJbWc%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitController.java: 194
detailsMethod startDeletionAction at line 194 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitControl...
ID: FrBUZpK3Ck%2Bff5WEcUzUbnC1d%2BU%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitController.java: 194
detailsMethod startDeletionAction at line 194 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitControl...
ID: QETzNoFh1Zm9LQCAR9xIMYuM7BM%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitController.java: 194
detailsMethod startDeletionAction at line 194 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitControl...
ID: n8pTiZIVzt1j0txXC%2F1uza4OYTQ%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitController.java: 194
detailsMethod startDeletionAction at line 194 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitControl...
ID: Hk7IcZW0oYi9Ma8pzu9wSDPA7iw%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitController.java: 194
detailsMethod startDeletionAction at line 194 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitControl...
ID: A2ZvcgbWqjHCok%2F6WQZ7oGCdlYU%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitController.java: 173
detailsMethod selectUnitWithInheritedRules at line 173 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUn...
ID: PidPbvFWY7FIhLvzocBj4Ixb%2F74%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitController.java: 194
detailsMethod startDeletionAction at line 194 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionArchiveUnitControl...
ID: FmcPw%2FHljtxFarH%2FRUuckMM1D6I%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java: 180
detailsMethod reclassification at line 180 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java gets...
ID: jBossygUqc1nPaqKRWzpgCA7laI%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java: 180
detailsMethod reclassification at line 180 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java gets...
ID: tfkZwHz457LG42oyAH5SQh684Aw%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java: 180
detailsMethod reclassification at line 180 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java gets...
ID: I%2BIRb8lN5VJ0DAnLLOk6RZwFjM4%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java: 180
detailsMethod reclassification at line 180 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java gets...
ID: Qe4f5LhNMoNYVSTRDXvz8USztBk%3D
Attack Vector
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java: 180
detailsMethod reclassification at line 180 of /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/TransactionController.java gets...
ID: 7FoXDH1oU5ELFex0CYT4a5TSjic%3D
Attack Vector
LOW Log_Forging /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 175
detailsMethod getApplicationId at line 175 of /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java gets us...
ID: EBl8wtzXZpHSXTeFgvu7hj3MFtc%3D
Attack Vector
LOW Log_Forging /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 175
detailsMethod getApplicationId at line 175 of /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java gets us...
ID: b6o66PibpB5A%2BqOTqi9j4rPzUOM%3D
Attack Vector
LOW Log_Forging /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 114
detailsMethod searchArchiveUnitsByCriteria at line 114 of /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/r...
ID: LB1oY%2Bxg5UyGhIWy0R85no1vxO4%3D
Attack Vector
LOW Log_Forging /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 206
detailsMethod startEliminationAction at line 206 of /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/Ar...
ID: %2FeGDZ9LfapJPjeIZIpDKgR0TCDM%3D
Attack Vector
LOW Log_Forging /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 247
detailsMethod selectUnitWithInheritedRules at line 247 of /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/r...
ID: pjC0b9py6WJoLhYIe%2F3s3BjBFi0%3D
Attack Vector
LOW Log_Forging /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 237
detailsMethod computedInheritedRules at line 237 of /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/Ar...
ID: 563h1qhmyAY7ggFoe1bnb4n0i6M%3D
Attack Vector
LOW Log_Forging /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 227
detailsMethod updateArchiveUnitsRules at line 227 of /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/A...
ID: QbTYjVoZXCj2YO%2Bt4qNtJwCynlg%3D
Attack Vector
LOW Log_Forging /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 216
detailsMethod startEliminationUnitTreeAction at line 216 of /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server...
ID: DLYgyDr1QU3cs2k0DLTCvQ8kpUA%3D
Attack Vector
LOW Log_Forging /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 257
detailsMethod reclassification at line 257 of /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/Archives...
ID: kl8u%2BgCu0b5DFJiZHgReQlnqj%2Bc%3D
Attack Vector
LOW Log_Forging /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/rest/ArchivesSearchController.java: 114
detailsMethod searchArchiveUnitsByCriteria at line 114 of /api/api-archive-search/archive-search/src/main/java/fr/gouv/vitamui/archives/search/server/r...
ID: XmMdH573AMrCWwM%2Bef7zaT6OUh4%3D
Attack Vector

More results are available on the CxOne platform

Fixed Issues (14)
Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH Passwords And Secrets - Generic Password /vitamui_vars.yml: 210
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 101
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 101
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 114
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 72
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 100
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 114
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 100
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 101
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 72
LOW Log_Forging /api/api-iam/iam-security/src/main/java/fr/gouv/vitamui/iam/security/service/SecurityService.java: 175
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 73
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 115
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/CollectArchiveUnitController.java: 101

@bbenaissa bbenaissa force-pushed the story_14882_update_nodes_facets_limit branch from 77bb45f to f8af7d9 Compare July 17, 2025 07:51
@bbenaissa bbenaissa force-pushed the story_14882_update_nodes_facets_limit branch from f8af7d9 to 7857742 Compare July 17, 2025 07:57

@Value("${tree-nodes-search-facets-size:1000}")
@NotNull
private Integer treeNodesSearchFacetsSiz;
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Typo, il manque le e à Size

# offline_services: # Disables online search engines in collect
# - agencies
# - archive-unit-profiles
# offline_services: # Disables online search engines in collect
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pourquoi ajouter de l'indentation ici ?


ontologies_file_path: {{ vitamui_folder_data }}/external_ontology_fields.json

tree-nodes-search-facets-size: {{ vitamui_struct.tree_nodes_search_facets_size}}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mettre un default sur les templates.

Copy link
Contributor

@ebernard ebernard left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Trop tard pour les US sur 9.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants