| fix: high-severity bug fixes + backend security hardening Backend security (broken access control / IDOR): cross-org create checks for usergroups/courses/podcasts/boards, usergroup member validation, MagicBlocks authz + session ownership, RAG chat ownership, chapter mass-assignment relocation, reorder cross-org grafting, student self-grading + assignment due-date, org Explore field lockdown, collection same-org links, trail read-access, content_files default-deny. Backend security (injection/file/config): RAG arbitrary file read, import manifest traversal, upload_sqlite traversal, upload type-from-content, CSV formula injection (org+analytics exports), magic-link open redirect, email/CORS host pinning, CSRF fullmatch + dev fail-open, JWT purpose confusion, playground org resolution. Backend bugs: await on 2 broken AI endpoints, AI credit refunds on failure, cookie max_age fix, third_party_login guard, credit summary extra_limit, admin_seats purchased seats, trail step serialization, certificate completion count, upvote race, webhook log prune, join_org transaction. Frontend bugs: fetch-race guards, DOMPurify hook leak, stable useDebounce, useOnboarding persistence, OAuth login route, CourseProgress null-guards, AuthContext stale closure + token refresh, AIChatBot reducer payload, contributor id normalization. Verification: backend 2529 tests pass, app boots; frontend tsc clean. Tests updated to assert new behavior. | 3 个月前 |