Skip to content

Story #16471: add boundaries - #4026

Merged
marob merged 2 commits into
developfrom
16471-boundaries
Sep 29, 2026
Merged

marob merged 2 commits into
developfrom
16471-boundaries

Conversation

@marob

@marob marob commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • Improvements

    • Editable pattern fields now use the same control in design-system examples and identity provider settings, with labels, options, and validation preserved.
    • Ingest and batch statuses, as well as download notifications, remain available across relevant screens with consistent shared components.
  • Bug Fixes

    • Updated collect screens and tests to use the correct project-specific settings and data references.

@marob marob added this to the IT 176 milestone Sep 24, 2026
@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: b540256a-caa9-4c7f-885c-3c3be9ee5c43

📥 Commits

Reviewing files that changed from the base of the PR and between d8b9772 and e52d2eb.

⛔ Files ignored due to path filters (1)
  • ui/ui-frontend/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (42)
  • ui/ui-frontend/eslint.config.mjs
  • ui/ui-frontend/package.json
  • ui/ui-frontend/projects/collect/src/app/collect/archive-search-collect/archive-preview/archive-unit-rules-details-tab/archive-unit-rules-details-tab.component.spec.ts
  • ui/ui-frontend/projects/collect/src/app/collect/archive-search-collect/archive-search-collect.component.spec.ts
  • ui/ui-frontend/projects/collect/src/app/collect/archive-search-collect/archive-search-collect.component.ts
  • ui/ui-frontend/projects/collect/src/app/collect/transactions/transaction-list/transaction-list.component.spec.ts
  • ui/ui-frontend/projects/collect/src/app/collect/transactions/transaction-list/transaction-list.component.ts
  • ui/ui-frontend/projects/design-system/src/app/components/molecules/inputs/old-input/design-system-old-inputs.component.html
  • ui/ui-frontend/projects/design-system/src/app/components/molecules/inputs/old-input/design-system-old-inputs.component.ts
  • ui/ui-frontend/projects/identity/src/app/customer/customer-preview/sso-tab/identity-provider-details/identity-provider-details.component.html
  • ui/ui-frontend/projects/identity/src/app/customer/customer-preview/sso-tab/identity-provider-details/identity-provider-details.component.spec.ts
  • ui/ui-frontend/projects/identity/src/app/group/group.component.spec.ts
  • ui/ui-frontend/projects/identity/src/app/group/group.component.ts
  • ui/ui-frontend/projects/identity/src/app/shared/editable-field/editable-field.module.ts
  • ui/ui-frontend/projects/identity/src/app/shared/editable-field/editable-patterns/editable-patterns.component.scss
  • ui/ui-frontend/projects/identity/src/app/user/user.component.ts
  • ui/ui-frontend/projects/ingest/src/app/ingest/ingest-list/ingest-list.component.ts
  • ui/ui-frontend/projects/ingest/src/app/ingest/ingest-preview/ingest-information-tab/ingest-information-tab.component.ts
  • ui/ui-frontend/projects/ingest/src/app/ingest/ingest-preview/ingest-preview.component.ts
  • ui/ui-frontend/projects/ingest/src/app/models/logbook-event.interface.ts
  • ui/ui-frontend/projects/referential/src/app/access-contract/access-contract-create/access-contract-create.component.ts
  • ui/ui-frontend/projects/referential/src/app/access-contract/access-contract.component.ts
  • ui/ui-frontend/projects/referential/src/app/accession-register/accession-register.module.ts
  • ui/ui-frontend/projects/referential/src/app/agency/agency-create/agency-create.module.ts
  • ui/ui-frontend/projects/referential/src/app/context/context-create/context-create.component.ts
  • ui/ui-frontend/projects/referential/src/app/context/context-edit/context-edit.module.ts
  • ui/ui-frontend/projects/referential/src/app/file-format/file-format-create/file-format-create.module.ts
  • ui/ui-frontend/projects/referential/src/app/ingest-contract/ingest-contract-create/ingest-contract-create.component.ts
  • ui/ui-frontend/projects/referential/src/app/ingest-contract/ingest-contract.component.spec.ts
  • ui/ui-frontend/projects/referential/src/app/ingest-contract/ingest-contract.component.ts
  • ui/ui-frontend/projects/referential/src/app/logbook-operation/logbook-operation-detail/logbook-operation-detail.component.ts
  • ui/ui-frontend/projects/referential/src/app/management-contract/components/create-persistent-identifier-policy-form/create-persistent-identifier-policy-form.module.ts
  • ui/ui-frontend/projects/referential/src/app/management-contract/components/update-persistent-identifier-policy-form/update-persistent-identifier-policy-form.module.ts
  • ui/ui-frontend/projects/referential/src/app/management-contract/management-contract-create/management-contract-create.component.ts
  • ui/ui-frontend/projects/referential/src/app/rule/rule-create/rule-create.module.ts
  • ui/ui-frontend/projects/referential/src/app/security-profile/security-profile-create/security-profile-create.component.ts
  • ui/ui-frontend/projects/vitamui-library/src/lib/components/editable-patterns/editable-patterns.component.html
  • ui/ui-frontend/projects/vitamui-library/src/lib/components/editable-patterns/editable-patterns.component.spec.ts
  • ui/ui-frontend/projects/vitamui-library/src/lib/components/editable-patterns/editable-patterns.component.ts
  • ui/ui-frontend/projects/vitamui-library/src/lib/models/ingest-status.enum.ts
  • ui/ui-frontend/projects/vitamui-library/src/lib/services/download-snack-bar.service.ts
  • ui/ui-frontend/projects/vitamui-library/src/public-api.ts
💤 Files with no reviewable changes (14)
  • ui/ui-frontend/projects/referential/src/app/ingest-contract/ingest-contract-create/ingest-contract-create.component.ts
  • ui/ui-frontend/projects/referential/src/app/management-contract/components/create-persistent-identifier-policy-form/create-persistent-identifier-policy-form.module.ts
  • ui/ui-frontend/projects/referential/src/app/access-contract/access-contract-create/access-contract-create.component.ts
  • ui/ui-frontend/projects/referential/src/app/context/context-create/context-create.component.ts
  • ui/ui-frontend/projects/referential/src/app/accession-register/accession-register.module.ts
  • ui/ui-frontend/projects/referential/src/app/file-format/file-format-create/file-format-create.module.ts
  • ui/ui-frontend/projects/referential/src/app/security-profile/security-profile-create/security-profile-create.component.ts
  • ui/ui-frontend/projects/identity/src/app/shared/editable-field/editable-patterns/editable-patterns.component.scss
  • ui/ui-frontend/projects/referential/src/app/management-contract/management-contract-create/management-contract-create.component.ts
  • ui/ui-frontend/projects/referential/src/app/agency/agency-create/agency-create.module.ts
  • ui/ui-frontend/projects/referential/src/app/context/context-edit/context-edit.module.ts
  • ui/ui-frontend/projects/referential/src/app/management-contract/components/update-persistent-identifier-policy-form/update-persistent-identifier-policy-form.module.ts
  • ui/ui-frontend/projects/referential/src/app/rule/rule-create/rule-create.module.ts
  • ui/ui-frontend/projects/vitamui-library/src/lib/components/editable-patterns/editable-patterns.component.html
🚧 Files skipped from review as they are similar to previous changes (1)
  • ui/ui-frontend/projects/referential/src/app/access-contract/access-contract.component.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The frontend adds lint rules for project import boundaries, exposes shared components and models through the library, and updates application imports. Several referential features also remove imports from identity modules.

Changes

Frontend library boundaries

Layer / File(s) Summary
Add shared library exports
ui/ui-frontend/projects/vitamui-library/src/lib/components/editable-patterns/*, ui/ui-frontend/projects/vitamui-library/src/lib/models/ingest-status.enum.ts, ui/ui-frontend/projects/vitamui-library/src/lib/services/download-snack-bar.service.ts, ui/ui-frontend/projects/vitamui-library/src/public-api.ts
EditablePatternsComponent becomes standalone, IngestStatus is added to the library, and the public API exports these items and shared collect models. The service imports its dependencies from local module paths.
Update application imports
ui/ui-frontend/projects/collect/..., ui/ui-frontend/projects/design-system/..., ui/ui-frontend/projects/identity/..., ui/ui-frontend/projects/ingest/..., ui/ui-frontend/projects/referential/...
Applications import shared components, services, and status models from vitamui-library. Editable-patterns consumers use the vitamui-editable-patterns selector. Collect specs use collect-local environment and model imports.
Remove referential imports from identity
ui/ui-frontend/projects/referential/...
Referential components and modules remove imports of identity SharedModule and GroupAttributionModule.
Configure import-boundary linting
ui/ui-frontend/eslint.config.mjs, ui/ui-frontend/package.json
ESLint defines app and library boundaries, configures TypeScript import resolution, and enforces allowed dependencies and public library entry points. The resolver and boundaries plugin are added as development dependencies.

Priority: ⬆️ High

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Refactor

Suggested reviewers: regzox

Merge Risk: ⚪ Minimal · up to e52d2

The frontend import changes are mergeable after normal checks; no actionable failure was established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to e52d2

The reviewed exports consolidate frontend components and models without showing a new privileged operation or broader backend access. The import restrictions are a build-time boundary, not an authorization control; their enforcement in delivery was not established.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The new public exports can be consumed across frontend applications, but the inspected exports do not themselves grant backend authority. Runtime entrypoint exposure was not established.

Trust Boundaries and Controls

  • inferred — The new lint policy constrains source-code dependency direction, not browser-user authority or server-side authorization. Its execution as a required delivery gate was not verified.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The pull request has no author-provided description. It does not include the required modification summary, change type, documentation, tests, migration, checklist, or contributor information. Add a complete description using the repository template. Document the boundary configuration, change type, documentation impact, tests performed, migration impact, checklist status, and contributor.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: adding project boundaries for Story #16471. It is concise and relevant.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@vitam-prg

vitam-prg commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Logo
Checkmarx One – Scan Summary & Details – ac95536c-a2d2-40a6-a507-e4e995832e73


New Issues (25 out of 25) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 CRITICAL CVE-2026-102422 Npm-shell-quote-1.9.0
detailsDescription: shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 CRITICAL CVE-2026-84939 Maven-org.freemarker:freemarker-2.3.34
detailsRecommended version: 2.3.35
Description: Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 HIGH CVE-2026-100656 Maven-io.netty:netty-codec-http-4.1.127.Final
detailsRecommended version: 4.1.137.Final-redhat-00001
Description: Netty contains an unbounded per-connection queue growth flaw in "HttpServerCodec". The codec tracks the HTTP method of each still-unanswered pipeli...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 HIGH CVE-2026-100656 Maven-io.netty:netty-codec-http-4.2.17.Final
detailsRecommended version: 4.2.18.Final
Description: Netty contains an unbounded per-connection queue growth flaw in "HttpServerCodec". The codec tracks the HTTP method of each still-unanswered pipeli...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
5 HIGH CVE-2026-100660 Maven-io.netty:netty-codec-http3-4.2.17.Final
detailsRecommended version: 4.2.18.Final
Description: Netty's HTTP/3 codec versions from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. "QpackEncoder" stores a queue...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
6 HIGH CVE-2026-100661 Maven-io.netty:netty-codec-http3-4.2.17.Final
detailsRecommended version: 4.2.18.Final
Description: Netty's HTTP/3 codec versions from 4.2.0.Final through 4.2.17.Final contain a Denial-of-Service (DoS) vulnerability in the QPACK prefixed-integer d...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
7 HIGH CVE-2026-100662 Maven-io.netty:netty-codec-http3-4.2.17.Final
detailsRecommended version: 4.2.18.Final
Description: Netty's HTTP/3 codec versions from 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
8 HIGH CVE-2026-100663 Maven-io.netty:netty-codec-http3-4.2.17.Final
detailsRecommended version: 4.2.18.Final
Description: Netty's HTTP/3 codec versions from 4.2.2.Final through 4.2.17.Final does not special-case "HTTP/1 CONNECT" authority-form request-targets when conv...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
9 HIGH CVE-2026-100664 Maven-io.netty:netty-codec-http3-4.2.17.Final
detailsRecommended version: 4.2.18.Final
Description: Netty's HTTP/3 codec versions from 4.2.2.Final through 4.2.17.Final builds the HTTP/3 ":authority" pseudo-header from the HTTP/1 Host header before...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
10 HIGH CVE-2026-102276 Npm-brace-expansion-5.0.9
detailsRecommended version: 5.0.10
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.19, 2.0.0 prior to 2.1.5, 3...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
11 HIGH CVE-2026-102276 Npm-brace-expansion-1.1.18
detailsRecommended version: 1.1.19
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.19, 2.0.0 prior to 2.1.5, 3...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
12 HIGH CVE-2026-102276 Npm-brace-expansion-2.1.4
detailsRecommended version: 2.1.5
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.19, 2.0.0 prior to 2.1.5, 3...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
13 HIGH CVE-2026-102278 Npm-brace-expansion-5.0.9
detailsRecommended version: 5.0.11
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.20, 2.0.0 prior to 2.1.6, 3...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
14 HIGH CVE-2026-102278 Npm-brace-expansion-1.1.18
detailsRecommended version: 1.1.20
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.20, 2.0.0 prior to 2.1.6, 3...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
15 HIGH CVE-2026-102278 Npm-brace-expansion-2.1.4
detailsRecommended version: 2.1.6
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. In versions prior to 1.1.20, 2.0.0 prior to 2.1.6, 3...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
16 HIGH Missing User Instruction /Dockerfile.template: 1
detailsAlways set a user in the runtime stage of your Dockerfile. Without it, the container defaults to root, even if earlier build stages define a user.
17 MEDIUM Add Instead of Copy /Dockerfile.template: 5
detailsUsing ADD to load external installation scripts could lead to an evil web server leveraging this and loading a malicious script.
18 MEDIUM CVE-2026-100655 Maven-io.netty:netty-codec-http-4.1.127.Final
detailsRecommended version: 4.1.137.Final-redhat-00001
Description: Netty versions through 4.1.137.Final and 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: "...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package
19 MEDIUM CVE-2026-100655 Maven-io.netty:netty-codec-http-4.2.17.Final
detailsRecommended version: 4.2.18.Final
Description: Netty versions through 4.1.137.Final and 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: "...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package
20 MEDIUM CVE-2026-100666 Maven-io.netty:netty-codec-http-4.1.127.Final
detailsDescription: Netty's HttpServerCodec in versions through 4.1.136.Final and 4.2.0.Final through 4.2.16.Final pairs each outbound response with an inbound request...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
21 MEDIUM CVE-2026-102277 Npm-brace-expansion-2.1.4
detailsRecommended version: 2.1.7
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expan...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
22 MEDIUM CVE-2026-102277 Npm-brace-expansion-5.0.9
detailsRecommended version: 5.0.12
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expan...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
23 MEDIUM CVE-2026-102277 Npm-brace-expansion-1.1.18
detailsRecommended version: 1.1.21
Description: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expan...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
24 LOW CVE-2026-77756 Maven-org.apache.tomcat.embed:tomcat-embed-core-11.0.24
detailsRecommended version: 11.0.26
Description: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-e...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
25 LOW Healthcheck Instruction Missing /Dockerfile.template: 1
detailsEnsure that HEALTHCHECK is being used. The HEALTHCHECK instruction tells Docker how to test a container to check that it is still working

Use @Checkmarx to take action directly from this PR:

  • Rescan the PR

Try it: @Checkmarx how can you help? · @Checkmarx rescan this PR

@marob
marob force-pushed the 16471-boundaries branch 2 times, most recently from 0497986 to d8b9772 Compare September 24, 2026 17:13
@marob
marob marked this pull request as ready for review September 24, 2026 17:16
@marob
marob enabled auto-merge September 24, 2026 17:16

@Regzox Regzox left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Il y a quelques commentaires sonar à régler qui ne semble pas remonter sur la conversation de la PR.

@marob

marob commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

@Regzox Je ne vois pas de retours Sonar

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
0.0% Coverage on New Code (required ≥ 80%)
17.0% Duplication on New Code (required ≤ 3%)

See analysis details on SonarQube Cloud

@marob
marob disabled auto-merge September 29, 2026 12:34
@marob
marob merged commit 646e0a9 into develop Sep 29, 2026
20 of 24 checks passed
@marob
marob deleted the 16471-boundaries branch September 29, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants