Repository navigation
VITE LOGIN INBOX: Migrating Login and Inbox paths to Vite - #8916
Conversation
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 34069781 | Triggered | Generic Password | bc1d2d6 | resources/views/vite/auth/login.blade.php | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secret safely. Learn here the best practices.
- Revoke and rotate this secret.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
|
@henryjonathanquispe a few suggestions
|
58441fd to
327120d
Compare
|
@nolanpro the PR has been updated! |
b33d3b1 to
4af7386
Compare
VITE_INBOX: update AGENTS.md VITE_INBOX: remove webpack-login, change to vite VITE_INBOX: update task controller, remove unnecesary files changed VITE_INBOX: remove unnecesary files changed by extension, reduce the PR VITE_INBOX: remove tasks js files from webpack VITE_INBOX: remove tasks js files from webpack VITE_INBOX: update testCase VITE_INBOX: update rutes password/* because the last changes in login
4af7386 to
e2aed60
Compare
998c120 to
29fc119
Compare
|
QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net |
VITE_INBOX: update npm run dev VITE_INBOX: update npm run dev VITE_INBOX: update npm run dev VITE_INBOX: update broadcast pusher in ci build
29fc119 to
cac46ac
Compare
|
QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net |
|
QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net |
|
QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net |
|
QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net |
PR SummaryMedium Risk Overview Laravel integration: View data: Mix remains for the bulk of assets; production runs both Reviewed by Cursor Bugbot for commit 91b5ca2. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 4 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.
| icons: {}, | ||
| }, | ||
| }; | ||
|
|
There was a problem hiding this comment.
Login wipes ProcessMaker packages
High Severity
login.js assigns a new window.ProcessMaker with packages: [] after the Blade inline has already set ProcessMaker.packages. Vite emits type="module" scripts, which run after parsing, so the module overwrites the package list used by login addons and global scripts.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.
| @vite(['resources/js/processes/screen-builder/typeForm.js']) | ||
| @elseif ($type === 'DISPLAY') | ||
| @vite(['resources/js/processes/screen-builder/typeDisplay.js']) | ||
| @endif |
There was a problem hiding this comment.
Screen type scripts load twice
Medium Severity
Screen builder and request preview now @vite typeForm.js or typeDisplay.js while ScreenBuilderStarting still adds the Mix copies via $manager->getScripts(). The same type bundle runs twice and can register controls and listeners twice.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.
| @vite(['resources/js/vite/tasks/loaderTasks.js']) | ||
| @foreach($manager->getScripts() as $script) | ||
| <script src="{{$script}}"></script> | ||
| <script defer src="{{$script}}"></script> |
There was a problem hiding this comment.
Inbox Mix scripts lack webpack runtime
Medium Severity
Inbox still injects Mix typeForm.js and typeDisplay.js from $manager->getScripts(). layoutnextvite does not load mix('js/manifest.js') or other webpack runtime, so those chunks throw and package ScreenBuilder hooks on inbox can fail.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.
| return view('requests.preview', compact('request', 'screen', 'manager', 'data')); | ||
| $type = strtoupper($screen->type ?? 'FORM'); | ||
|
|
||
| return view('requests.preview', compact('request', 'screen', 'manager', 'data', 'type')); |
There was a problem hiding this comment.
Preview type disagrees with event
Medium Severity
screenPreview still starts ScreenBuilder with $request->summary_screen->type, but the new $type used by @vite comes from $screen->type. When those differ, Mix package scripts register one screen type and Vite loads the other type chunk.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.







Related Tickets & Packages
#Instructions to install
To update the routes:
php artisan config:clear#MInimal changes
PACKAGE-DATA-SOURCES
https://github.com/ProcessMaker/package-data-sources/pull/492
PACKAGE-VARIABLE-FINDER
https://github.com/ProcessMaker/package-variable-finder/pull/70
Code Review Checklist
ci:deploy
ci:package-data-sources:VITE_INBOX
ci:package-variable-finder:VITE_INBOX