Skip to content

Fix injection 10 - #666

Merged
RomainLvr merged 3 commits into
10.0/bugfixesfrom
fix_injection_10
Sep 10, 2026
Merged

Fix injection 10#666
RomainLvr merged 3 commits into
10.0/bugfixesfrom
fix_injection_10

Conversation

@stonebuzz

Copy link
Copy Markdown
Contributor

Checklist before requesting a review

Please delete options that are not relevant.

  • I have performed a self-review of my code.
  • I have added tests (when available) that prove my fix is effective or that my feature works.
  • I have updated the CHANGELOG with a short functional description of the fix or new feature.
  • This change requires a documentation update.

Description

Backport for #660

  • Model identifiers received by the preview and report popups are now validated as integers before being used.
  • Model names and entity names are now escaped in the injection model selector.
  • The mapping form now verifies that each submitted mapping belongs to the model being edited, and checks the update right on that model.
  • Rights on relation itemtypes are now evaluated like any other itemtype when deciding whether a model can be listed and used.

Screenshots (if appropriate):

stonebuzz and others added 3 commits September 10, 2026 08:17
Co-authored-by: Stanislas Kita <7335054+stonebuzz@users.noreply.github.com>
@stonebuzz
stonebuzz requested a review from RomainLvr September 10, 2026 06:27
@stonebuzz stonebuzz self-assigned this Sep 10, 2026
@RomainLvr
RomainLvr merged commit 2f007bb into 10.0/bugfixes Sep 10, 2026
3 checks passed
@RomainLvr
RomainLvr deleted the fix_injection_10 branch September 10, 2026 07:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants