Skip to content

FOUR-32473: [Octane] CRITICAL Data Leaks Between Requests "$redirectionParams" - #8956

Merged
pmPaulis merged 2 commits into
feature/FOUR-32464from
feature/FOUR-32473
Jul 31, 2026
Merged

FOUR-32473: [Octane] CRITICAL Data Leaks Between Requests "$redirectionParams"#8956
pmPaulis merged 2 commits into
feature/FOUR-32464from
feature/FOUR-32473

Conversation

@rodriquelca

Copy link
Copy Markdown
Contributor

Issue & Reproduction Steps

[Octane] CRITICAL Data Leaks Between Requests "$redirectionParams"

Solution

  • HandleRedirectListener has three static properties ($processRequest, $redirectionMethod, $redirectionParams) that store redirect data during a request.

How to Test

Run the unit tests

cd /Users/rodrigoquelca/Herd/processmaker
php vendor/bin/phpunit tests/unit/ProcessMaker/Listeners/HandleRedirectListenerTest.php

Related Tickets & Packages

  • Link to any related FOUR tickets, PRDs, or packages

Code Review Checklist

  • I have pulled this code locally and tested it on my instance, along with any associated packages.
  • This code adheres to ProcessMaker Coding Guidelines.
  • This code includes a unit test or an E2E test that tests its functionality, or is covered by an existing test.
  • This solution fixes the bug reported in the original ticket.
  • This solution does not alter the expected output of a component in a way that would break existing Processes.
  • This solution does not implement any breaking changes that would invalidate documentation or cause existing Processes to fail.
  • This solution has been tested with enterprise packages that rely on its functionality and does not introduce bugs in those packages.
  • This code does not duplicate functionality that already exists in the framework or in ProcessMaker.
  • This ticket conforms to the PRD associated with this part of ProcessMaker.

@gitguardian

gitguardian Bot commented Jul 31, 2026

Copy link
Copy Markdown

️✅ There are no secrets present in this pull request anymore.

If these secrets were true positive and are still valid, we highly recommend you to revoke them.
While these secrets were previously flagged, we no longer have a reference to the
specific commits where they were detected. Once a secret has been leaked into a git
repository, you should consider it compromised, even if it was deleted immediately.
Find here more information about risks.


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@processmaker-sonarqube

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarQube

@pmPaulis
pmPaulis changed the base branch from feature/FOUR-30918 to feature/FOUR-32464 July 31, 2026 18:25
@pmPaulis
pmPaulis merged commit e628337 into feature/FOUR-32464 Jul 31, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants