mirror of
https://github.com/penpot/penpot.git
synced 2026-10-03 09:16:15 +00:00
* 🐛 Migrate openUIApi schema to Zod v4 function syntax Zod 4 removed z.function().args(), which broke the plugins-runtime build with implicit-any errors on every openUIApi parameter and knock-on possibly-null errors on the modal in plugin-manager. Declare the inputs with z.function({ input: [...] }) so the parameter and return types infer again; behavior is unchanged. Add a regression spec covering delegation, optional args and rejection of invalid theme and title values. AI-assisted-by: muse-spark-1.3-contributor * 📚 Fix deprecated markdown-it-anchor permalink option in docs Migrate docs Eleventy config to the markdown-it-anchor v10 API. Replace the deprecated boolean permalink option with linkInsideHeader, keeping the same symbol and class. Bump markdown-it-anchor to v10 and related docs deps. AI-assisted-by: muse-spark-1.3-contributor * ⬆️ Update deps * ⬆️ Update base docker images * 📎 Fix mcp tests
27 lines
1008 B
Bash
27 lines
1008 B
Bash
#!/bin/bash
|
|
# LDAP injection test script — run against running Penpot backend
|
|
# Usage: bash backend/test/e2e/ldap-test-curl.sh
|
|
|
|
BASE="http://localhost:3450/api/main/methods/login-with-ldap"
|
|
H1='Content-Type: application/json'
|
|
H2='Accept: application/json'
|
|
|
|
#echo "=== 1. Normal login (fry/fry) ==="
|
|
#curl -s -X POST "$BASE" -H "$H1" -H "$H2" \
|
|
# -d '{"email":"fry@planetexpress.com","password":"fry"}' | python3 -m json.tool
|
|
|
|
#echo ""
|
|
#echo "=== 2. Wildcard injection (*@planetexpress.com + amy) ==="
|
|
#curl -s -X POST "$BASE" -H "$H1" -H "$H2" \
|
|
# -d '{"email":"*@planetexpress.com","password":"amy"}' | python3 -m json.tool
|
|
|
|
echo ""
|
|
echo "=== 3. Identity swap (hubert@ + professor password) ==="
|
|
curl -s -X POST "$BASE" -H "$H1" -H "$H2" \
|
|
-d '{"email":"hubert@planetexpress.com","password":"professor"}' | python3 -m json.tool
|
|
|
|
#echo ""
|
|
#echo "=== 4. Wrong password ==="
|
|
#curl -s -X POST "$BASE" -H "$H1" -H "$H2" \
|
|
# -d '{"email":"fry@planetexpress.com","password":"wrong"}' | python3 -m json.tool
|