• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / integrity / 34299371885
91%

Build:
DEFAULT BRANCH: main
Ran 09 Sep 2026 01:34AM UTC
Jobs 1
Files 16
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

09 Sep 2026 01:29AM UTC coverage: 90.588% (-0.04%) from 90.628%
34299371885

push

github

web-flow
fix: redact personal data in audit params, revive the 400 diagnostic, scope expansions (#73)

Three findings from the security review, all in the same authorisation and
logging path.

F6. AuditLogger::sanitizeParams() redacted credentials but knew nothing about
personal_email or mobile_number — the two fields Scrutiny exists to obscure.
The resource controllers pass hand-picked parameters, which is right, but
logFailedRequest() passes $request->get_params() wholesale, so a 401, 403 or
429 on /members/create or /members/{id}/update wrote a real member's address
and number in the clear into wp_integrity_audit_log.request_params, where
they sat for the whole 90-day retention window. A rate-limited integration
is the everyday way to reach that, not an attack. email, mobile, telephone,
landline and phone join the list, matched as substrings so personal_email
and email_address are covered too.

F5. The rest_pre_dispatch validation diagnostic could never fire. That
filter runs in dispatch() before match_request_to_handler() calls
set_attributes(), so the request has no route args yet, has_valid_params()
walks an empty list and returns true; the block only ever ran for a
malformed JSON body. It now hooks rest_request_before_callbacks, which fires
after attributes are set and after core has run the validation — and is
handed the resulting WP_Error, so the error is read rather than recomputed.

Relocating it was the obvious fix and the dangerous one: the original logged
get_params() with no redaction, so a working diagnostic would have started
writing member contact details straight into the log file. Everything now
goes through AuditLogger::redact(), which is why F6 is in the same commit.

Moved out of integrity.php into ValidationDiagnostic and registered through
the container. As a top-level closure it would have had to reach for
Plugin::getContainer() at request time, which throws when Integrity has not
booted; registering it where RestController is registe... (continued)

2743 of 3028 relevant lines covered (90.59%)

4.53 hits per line

Coverage Regressions

Lines Coverage ∆ File
37
48.42
0.07% integrity/integrity/src/Plugin.php
22
93.88
0.28% integrity/integrity/src/Api/RestController.php
20
89.78
0.59% integrity/integrity/src/Auth/AuditLogger.php
Jobs
ID Job ID Ran Files Coverage
1 34299371885.1 09 Sep 2026 01:34AM UTC 16
90.59
GitHub Action Run
Source Files on build 34299371885
  • Tree
  • List 16
  • Changed 3
  • Source Changed 0
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34299371885
  • 642b5cfd on github
  • Prev Build on main (#34297109663)
  • Next Build on main (#35540047197)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc