This repository was archived by the owner on Aug 7, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
All issues
Issues
is:issue state:open
is:issue state:open
Search results
[CRITICAL] 118 unit tests failing in @unerp/api due to missing RLS wrappers and tenantId in Prisma calls
backendNestJS APINestJS APIbugSomething isn't workingSomething isn't workingdatabasePrisma / PostgreSQL schema or migrationsPrisma / PostgreSQL schema or migrationsStatus: Open.#132 In kannan19302/ERPSys;[CRITICAL] 2,405 live API endpoints across 16 modules are generated stubs returning fake data — silent data loss on create/update
architectureArchitecture / foundation governanceArchitecture / foundation governancebackendNestJS APINestJS APIblockedBlocked on another issue or external dependencyBlocked on another issue or external dependencybugSomething isn't workingSomething isn't workingStatus: Open.#131 In kannan19302/ERPSys;[security][api-platform] API key rotation/regeneration is stubbed — writes predictable 'rotated-<ts>' placeholder, never issues a key
backendNestJS APINestJS APIbugSomething isn't workingSomething isn't workingStatus: Open.#130 In kannan19302/ERPSys;[security][crypto] CRITICAL: Hardcoded fallback encryption key 'fallback-secret-key-12345' in HR + Documents; AES-CBC unauthenticated; rotation destroys data
backendNestJS APINestJS APIblockedBlocked on another issue or external dependencyBlocked on another issue or external dependencybugSomething isn't workingSomething isn't workingStatus: Open.#129 In kannan19302/ERPSys;[security][notifications] CRITICAL: WebSocket join:channel has no authorization — cross-tenant message interception and spoofing
backendNestJS APINestJS APIblockedBlocked on another issue or external dependencyBlocked on another issue or external dependencybugSomething isn't workingSomething isn't workingStatus: Open.#128 In kannan19302/ERPSys;[security][marketing-site] Public admin login has no brute-force protection; no security headers; bcryptjs not Argon2id; 0 tests
bugSomething isn't workingSomething isn't workingfrontendNext.js web appNext.js web appStatus: Open.#127 In kannan19302/ERPSys;[security][verticals] CRITICAL: All 4 vertical services store regulated data (PHI/FERPA) with ZERO RLS and ZERO tests
architectureArchitecture / foundation governanceArchitecture / foundation governanceblockedBlocked on another issue or external dependencyBlocked on another issue or external dependencybugSomething isn't workingSomething isn't workingdatabasePrisma / PostgreSQL schema or migrationsPrisma / PostgreSQL schema or migrationsStatus: Open.#126 In kannan19302/ERPSys;[security][infra] CSP allows unsafe-inline+unsafe-eval (no XSS protection); API and web containers run as root, unpinned bases
architectureArchitecture / foundation governanceArchitecture / foundation governancebackendNestJS APINestJS APIStatus: Open.#125 In kannan19302/ERPSys;[security][deps] 41 vulnerabilities (1 critical, 22 high) — incl. Next.js SSRF ×2, xlsx prototype pollution, multer DoS; CI is red on this
dependenciesPull requests that update a dependency filePull requests that update a dependency fileStatus: Open.#124 In kannan19302/ERPSys;[security][storage] All 10 file-upload endpoints have no size limit, type filter, or AV scanning — single-request OOM DoS
backendNestJS APINestJS APIbugSomething isn't workingSomething isn't workingStatus: Open.#123 In kannan19302/ERPSys;[EPIC] Production-Readiness Audit 2026-07-31 — 17 findings (3 critical, 8 high) with sequencing
triageNeeds maintainer triageNeeds maintainer triageStatus: Open.#122 In kannan19302/ERPSys;[backend] Silent failures: RBAC guard swallows malformed role JSON; export processor returns placeholder URL
backendNestJS APINestJS APIbugSomething isn't workingSomething isn't workingStatus: Open.#121 In kannan19302/ERPSys;