Skip to content

FOUR-32474 [Octane] CRITICAL Data Leaks Between Requests "$landlordVa… - #8955

Merged
pmPaulis merged 1 commit into
feature/FOUR-32464from
feature/FOUR-32474
Aug 3, 2026
Merged

FOUR-32474 [Octane] CRITICAL Data Leaks Between Requests "$landlordVa…#8955
pmPaulis merged 1 commit into
feature/FOUR-32464from
feature/FOUR-32474

Conversation

@gproly

@gproly gproly commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

…lues"

Description:
Fix Octane data leak by storing landlord config in request-scoped Context

Replace SwitchTenant static $landlordValues with Laravel Context to prevent tenant config snapshots from persisting across Octane requests. Remove unused duplicate property from ProcessMakerServiceProvider.

Related tickets:
https://processmaker.atlassian.net/browse/FOUR-32474

…lues"

Description:
Fix Octane data leak by storing landlord config in request-scoped Context

Replace SwitchTenant static $landlordValues with Laravel Context to prevent
tenant config snapshots from persisting across Octane requests. Remove unused
duplicate property from ProcessMakerServiceProvider.

Related tickets:
https://processmaker.atlassian.net/browse/FOUR-32474
@gproly
gproly requested a review from rodriquelca July 31, 2026 14:57
@processmaker-sonarqube

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarQube

@pmPaulis
pmPaulis changed the base branch from feature/FOUR-30918 to feature/FOUR-32464 July 31, 2026 18:26
@gproly
gproly changed the base branch from feature/FOUR-32464 to feature/FOUR-30918 July 31, 2026 19:49
@pmPaulis
pmPaulis changed the base branch from feature/FOUR-30918 to feature/FOUR-32464 July 31, 2026 20:17
@pmPaulis
pmPaulis merged commit b40ef22 into feature/FOUR-32464 Aug 3, 2026
26 of 27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants