Skip to content

Hotfix/2.1.1 - #559

Merged
hhund merged 27 commits into
mainfrom
hotfix/2.1.1
Aug 4, 2026
Merged

Hotfix/2.1.1#559
hhund merged 27 commits into
mainfrom
hotfix/2.1.1

Conversation

@hhund

@hhund hhund commented Jul 29, 2026

Copy link
Copy Markdown
Member

closes #509
closes #529
closes #535
closes #547
closes #560
fixes GHSA-xfv4-vhh2-m2j8
fixes GHSA-xw2h-2xx5-j86q
fixes GHSA-448w-h27c-w53m

hhund and others added 12 commits July 29, 2026 12:10
* java, maven plugin, docker, docker-compose, github actions version
upgrades
* dev setup network and nginx config
* missing license header
Consumers of the TestAssertException should be able to perform
instanceof checks, thus the class needs to be public. Only functions in
the PluginTestExecutor need to instantiate TestAssertException.
- Set ID of SendTaskErrorBoundaryEventTestThrow send task for easier
debugging.
- Removed not needed execution listener from
SendTaskErrorBoundaryEventTestThrow send task, mandatory profile field
now set via constant.
- Added missing condition expression to the flow from the exclusive
gateway to the SendTaskErrorBoundaryEventTestThrow send task.
- Added default flows to the exclusive gateways of the v1 and v2 test
BPMNs to catch missing condition expression errors in the future.
RFC 6749 requires the client id and client secret to be url encoded
first when using HTTP Basic authentication scheme.

see https://datatracker.ietf.org/doc/html/rfc6749#section-2.3.1
@hhund hhund self-assigned this Jul 29, 2026
@hhund hhund modified the milestones: 211, 2.1.1 Jul 29, 2026
hhund added 14 commits July 31, 2026 00:43
Added defensive check to ensure old and new resource are not the same
when running update authorization rules.
Fixed new resource used twice instead of the new and old (dbResource) to
run update authorization rules.
Plain text limited to 250 MiB, crypt text limited to 250 MiB + 1024
Bytes. Additional 1024 Bytes for crypt text to accommodate the protocol
header.
Adds a GET method to the webservice client for retrieving a snapshot for
existing StructureDefinition resource:
.../StructureDefinition/id/$snapshot
Modified the search construction of conditional delete to run without
user filter, the same as conditional update. The delete authorization
rule checks resource access.

Using a user filter in the search may have suppressed a "Precondition
Failed" response status, for a unspecific delete criteria.
@hhund
hhund requested a review from schwzr August 4, 2026 07:37
@hhund
hhund marked this pull request as ready for review August 4, 2026 07:37
@hhund
hhund merged commit 3d55ab6 into main Aug 4, 2026
38 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

5 participants