Commit Graph
5 Commits
Author SHA1 Message Date
Do SikiandClaude Sonnet 5 4c54c639e5 fix(docker): authenticate the dev app's MongoDB URI (MITHOME-98)
docker-compose.dev.yml's mongodb service sets MONGO_INITDB_ROOT_USERNAME/
PASSWORD, which makes the official mongo image enable --auth — but the
app service's MONGODB_URI was unauthenticated
(mongodb://mongodb:27017/mozdit). Same bug class as MITHOME-32
(staging/production), but that ticket covers docker-compose.staging.yml
/docker-compose.prod.yml specifically, not this dev file — hence the
separate MITHOME-98.

Why /api/health never caught it: that route is a pure liveness check
and never touches MongoDB. Only an endpoint that actually performs a
DB operation exercises the bug.

Verified live (docker compose -f docker-compose.dev.yml up --build):
- Reproduced the failure first: inside the running app container, a
  plain `mongodb://mongodb:27017/mozdit` connection's findOne() throws
  "Command find requires authentication" — confirms the hypothesis
  that the app fails only on a real query, not at startup.
- With the fix in place: POST /api/contact returns 200 with a
  submissionId, and the document is actually present in
  contact_submissions (checked via mongosh) — a real, previously-
  broken write path now works end to end.
- npm test: 58/58 passed (unaffected, as expected for a
  docker-compose/doc-only change).

Also fixed the same stale unauthenticated example in DOCKER.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 10:39:29 +02:00
Do Siki c5d5198fbf fix(cms): implement v2 security and stability review findings
CI Pipeline with Test Management / 🧪 Run Tests & Generate Reports (push) Waiting to run
CI Pipeline with Test Management / 🐳 Docker Integration Tests (push) Blocked by required conditions
CI Pipeline with Test Management / 🏗️ Build Docker Image (push) Blocked by required conditions
CI Pipeline with Test Management / 📊 Generate Test Summary (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🧪 Run Tests & Generate Reports (push) Waiting to run
Test Reporting & Gherkin Analysis / 📊 Analyze Test Coverage (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🔄 Sync with Linear (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / ⚡ Performance Monitoring (push) Blocked by required conditions
Resolves:
- CSRF false positive checked (global POST protection)
- Publish mutex to prevent git lock / double deploy
- Basic Auth rate limit checked before credential evaluation
- Memory leak in rate limiter (added GC interval)
- XSS in Toast messages
- XSS in data-path attribute
- CI healthcheck port mismatch (3000 -> 8080)
- Added security headers (X-Frame-Options, X-Content-Type-Options)
2026-08-20 11:35:01 +02:00
Do Siki c02017e30f chore: change docker mapped ports to prevent conflicts with local development 2026-04-27 01:06:44 +02:00
Do Siki e413bab812 refactor: update testing architecture, improve CI/CD workflows, and standardize documentation across the project. 2026-04-26 20:20:53 +02:00
Do Siki b0df8dd182 feat: enhance README and TODO documentation, implement mobile menu functionality in Header component
- Updated README.md with project details, quick start instructions, and tech stack.
- Expanded TODO.md to reflect current project status and backlog items, including Linear ticket synchronization.
- Added mobile menu toggle functionality in Header component with corresponding tests for user interactions.
- Configured Next.js for Docker deployment and optimized build settings.
2025-09-05 17:28:52 +02:00