-
Notifications
You must be signed in to change notification settings - Fork 255
PII issues fixes with backward compatibility [MOSIP-44379] #1030
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
122 commits
Select commit
Hold shift + click to select a range
161db71
MOSIP-34532 - Updated the ReadMe file (#762)
mohanachandran-s f650c59
Create codeql_custom.yml (#775)
rajapandi1234 3524619
Update codeql_custom.yml (#779)
rajapandi1234 797dbbd
MOSIP-37793 - Updated the Readme file
mohanachandran-s 39b44b7
testing 130 release
Sohandey 485269b
MOSIP-36011
Sohandey 0e56d31
MOSIP-36011
Sohandey 6132535
MOSIP-36011
Sohandey 13213d4
[MOSIP-38555] Removing apitestrig from Sonar analysis
VSIVAKALYAN 8b6cbef
Update push-trigger.yml
VSIVAKALYAN 5f58646
MOSIP-35404
nandhu-kumar 371f6e1
MOSIP-35404
nandhu-kumar ac48bfd
MOSIP-35404
nandhu-kumar 0ec8dc9
MOSIP-38489 - Generated single report with 2 sections
nandhu-kumar f0d25a0
MOSIP-39585 - Updated the apitest commons version (#803)
mohanachandran-s f0cab7f
Added ZGC (#805)
dhanendra06 281221e
MOSIP-39769 removed -Xms1g -Xmx2g from docker file (#807)
kameshsr e9dd9dc
[MOSIP-35637] added sqaush layers
Rakshithb1 423d57a
MOSIP-39719 (#808)
nandhu-kumar 6089ab3
MOSIP-39993 - Added the value mapping property file (#809)
mohanachandran-s c8c2255
Mosip 39047 - Commons cleanup (#813)
nandhu-kumar d6a4e37
MOSIP-39047 - Commons cleanup (#814)
nandhu-kumar 03fab99
MOSIP-40274 Automated Pending test cases (#815)
hegdenitin 7122ea3
MOSIP-40277 smoke failures fix for pre-reg (#817)
hegdenitin 9cde134
MOSIP-40887 - Remove keycloak user post execution (#820)
nandhu-kumar 36c7d87
Create dependabot.yml (#822)
rajapandi1234 b43df7e
Update push-trigger.yml (#823)
rajapandi1234 18f0c6e
Increase coverage for pre-reg services (#843)
GOKULRAJ136 888431c
MOSIP-40258: Standardized XSS Exception Handling in apitest-prereg Mo…
SradhaMohanty5899 915536f
MOSIP-28246: Removed unused variables from apitest-prereg module (#853)
SradhaMohanty5899 a3fa4cd
MOSIP-37971: API is giving wrong error code in the response (#854)
SradhaMohanty5899 d4714e7
MOSIP-28246: Removed commented unused variables from pre-registration…
SradhaMohanty5899 ea7e6b7
MOSIP-38413 - fix Prereg_GetBookingsForRegCenter_with_InValid_regcent…
ymahtat-dev 76d106f
[MOSIP-41674] central sonatype migration changes (#869)
Prafulrakhade 4424054
MOSIP-40379 removed ignore line from PreReg API test rigs (#859)
prathmeshj12 45951a4
MOSIP-42078 - Reverse merge of release branch to develop branch (#890)
mohanachandran-s 80550e8
MOSIP-42160 updated xml with valid order for getPRIDByDateRange (#900)
hegdenitin 4744453
MOSIP-42259: Enable execution of a single test or task with all its r…
SradhaMohanty5899 b232a9d
pdfgenerator changes (#898)
GOKULRAJ136 a00a871
[MOSIP-43137] Updated the installation script moved helm and removed …
Prafulrakhade c434085
MOSIP-43301 - Added the prefix context to run in multiple instances a…
mohanachandran-s a8d86cd
[MOSIP-43312] Added the additionalDependencies for prereg (#952)
Anuranjan14 119cfb3
[MOSIP-43615] [MOSIP-43648] [MOSIP-43434] added lifecycle, graceperio…
ckm007 2487ccf
[MOSIP-43615] corrected typo
ckm007 6e8943d
Update apitest-commons version to 1.4.0-SNAPSHOT (#1017)
mohanachandran-s 7fe8224
Create NOTICE
rajapandi1234 9c8777f
Add files via upload
rajapandi1234 6c4d4e8
MOSIP-44419 (#1023)
SradhaMohanty5899 8d1a510
MOSIP-33663 (#1021)
SradhaMohanty5899 2e8e62f
PII Issue Fixes (#1024)
GOKULRAJ136 29dff05
Fixed User Encryption PII
GOKULRAJ136 ab24f99
Updated user validation paths
GOKULRAJ136 e9c1259
Updated User Validations
GOKULRAJ136 49b2290
Revert "Updated user validation paths" (#1027)
GOKULRAJ136 50b33eb
Added user_details table (#1028)
GOKULRAJ136 1bfba7f
Backward Compatibility Changes
GOKULRAJ136 a2020b2
Backward Compatibility Changes for OTPManager
GOKULRAJ136 6aed639
Fix v1/sync issue
GOKULRAJ136 6959547
DataSyncServiceUtil changes regardigng the sync
GOKULRAJ136 84714bb
Revert DataSync Changes
GOKULRAJ136 c477cd3
Dual backward compatibility fixes
GOKULRAJ136 6db4b3a
ApplicationConsumedStatusUpdater for document and appointment
GOKULRAJ136 303645a
Added "cr_dtimes" and "encrypted_dtimes" columns for user_details table
GOKULRAJ136 a43e1f1
Logger value masking
GOKULRAJ136 462a60e
Logger value masking for userID
GOKULRAJ136 ea66b02
Logger value masking for preregUserId
GOKULRAJ136 ff1c61b
MOSIP-44331 : Updated descriptions (#1022)
rachanaspsoratur f84dbd7
Updated DB Scripts to resolve review comments
GOKULRAJ136 68beb3e
kernel pom version changes
GOKULRAJ136 0f226fc
Fixed Consumed tables PII issues
GOKULRAJ136 566a0ee
Core Changes
GOKULRAJ136 573f0fb
Update apitest-commons version to 1.4.0-SNAPSHOT (#1017)
mohanachandran-s 1284939
MOSIP-44419 (#1023)
SradhaMohanty5899 6ba0752
PII Issue Fixes (#1024)
GOKULRAJ136 d52fa83
Updated user validation paths
GOKULRAJ136 6623286
Updated User Validations
GOKULRAJ136 ad9e716
Revert "Updated user validation paths" (#1027)
GOKULRAJ136 5b18231
Added user_details table (#1028)
GOKULRAJ136 8d63d7b
Backward Compatibility Changes
GOKULRAJ136 b76b53d
Fix v1/sync issue
GOKULRAJ136 2d6b811
Revert DataSync Changes
GOKULRAJ136 d57acc3
Dual backward compatibility fixes
GOKULRAJ136 e7b68bd
Added "cr_dtimes" and "encrypted_dtimes" columns for user_details table
GOKULRAJ136 8cd7fab
Logger value masking
GOKULRAJ136 300f3d2
Updated DB Scripts to resolve review comments
GOKULRAJ136 be971d3
Core Changes
GOKULRAJ136 29dbefc
Fixed UUID mapping issue in backward compatibility false mode
GOKULRAJ136 84d86c9
Fixed Update Paths for backward compatibility
GOKULRAJ136 f31694f
Code Cleanup
GOKULRAJ136 60dfed0
Consolidate encryption helpers in UserDetailsService
GOKULRAJ136 79f3948
Resolved review comments and method name changes
GOKULRAJ136 c0c3c77
Resolve coderabbit review comments
GOKULRAJ136 ccd347a
Merge branch 'develop' into MOSIP-PII-new
GOKULRAJ136 90235e7
cleanup
GOKULRAJ136 80c14e5
cleanup
GOKULRAJ136 e291a14
cleanup
GOKULRAJ136 dc801c1
Revert OTPManager UUID changes
GOKULRAJ136 dd99715
One-touch migration changes
GOKULRAJ136 d533677
resolved review comments
GOKULRAJ136 fb8a348
added proper error code
GOKULRAJ136 7aeb54b
Removed unwanted isUUID check
GOKULRAJ136 184aca6
Review changes
GOKULRAJ136 a75193a
Removed resolveUserUuidOrIdentifier method
GOKULRAJ136 629007e
Prevent null UUID from being cached on transient encryption failure
GOKULRAJ136 bb5359c
fix: replace raw PII audit writes with canonical UUID resolution and …
GOKULRAJ136 98e35cb
fix dead null-checks after UserLookupException, add missing test cases
GOKULRAJ136 628eb84
masked PII in login audit writes
GOKULRAJ136 7700a60
masked PII in notification log
GOKULRAJ136 dbf5195
Merge branch 'develop' into MOSIP-PII-new
GOKULRAJ136 da719a7
Replace hardcoded kernel-core version with variable
GOKULRAJ136 7d8734c
Merge remote-tracking branch 'upstream/develop' into MOSIP-PII-new
GOKULRAJ136 eb9fc11
Added upgrade and rollback scripts
GOKULRAJ136 7ba6f8c
Fix duplicate user_details rows from inconsistent hash hex casing
GOKULRAJ136 6e3f6a4
Revert "Fix duplicate user_details rows from inconsistent hash hex ca…
GOKULRAJ136 1caf972
Updated mosip.prereg.pii.backward.compatibility to true
GOKULRAJ136 5b90ab7
datasync prop correction mosip.prereg.pii.backward.compatibility to true
GOKULRAJ136 7b47603
Fix re-resolution of canonical UUIDs, drop unused PII flag in batchjob
GOKULRAJ136 befbf94
Resolve review comments with identity migration + reconciliation job
GOKULRAJ136 f555ff2
Resolve review comments-I: role gate, reconciliation scope, best-effo…
GOKULRAJ136 4ea3737
Resolve review comments-II: per-column ownership, identity tx boundar…
GOKULRAJ136 4059615
Resolve review comments-III: contact_info recovery, response-safe ids…
GOKULRAJ136 2ca41e2
Covered contact_info recovery & Hide duplicate effective* accessors f…
GOKULRAJ136 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,31 @@ | ||
| -- ================================================================================================ | ||
| -- MOSIP Pre-Registration PII Security: Canonical User Registry Table | ||
| -- Purpose: Centralized surrogate user ID mapping for cr_by/upd_by/cr_appuser_id | ||
| -- ================================================================================================ | ||
| -- This table eliminates plaintext PII replication across the tables | ||
| -- Stores: hash(authUserId) -> UUID surrogate mapping + encrypted original for notifications/audit | ||
| -- Usage: | ||
| -- 1. Resolve: hash(authUserId) -> user_id (fast lookup) | ||
| -- 2. Store: user_id in cr_by/upd_by/cr_appuser_id/contact_info fields(instead of plaintext) | ||
| -- 3. Recover: decrypt from user_details for notifications/audit | ||
|
|
||
| -- ========== CREATE TABLE: Canonical User Registry ========== | ||
|
|
||
| CREATE TABLE IF NOT EXISTS prereg.user_details ( | ||
| user_id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||
| identifier_hash VARCHAR(128) NOT NULL UNIQUE, | ||
| identifier_encrypted TEXT NOT NULL, | ||
| cr_dtimes TIMESTAMP NOT NULL, | ||
| encrypted_dtimes TIMESTAMP NOT NULL | ||
| ); | ||
|
|
||
|
|
||
| -- ========== CREATE INDEXES ========== | ||
|
|
||
| CREATE INDEX IF NOT EXISTS idx_user_details_cr_dtimes | ||
| ON prereg.user_details (cr_dtimes); | ||
|
|
||
| CREATE INDEX IF NOT EXISTS idx_user_details_encrypted_dtimes | ||
| ON prereg.user_details (encrypted_dtimes); | ||
|
|
||
| -- ================================================================================================ |
25 changes: 25 additions & 0 deletions
25
db_upgrade_scripts/mosip_prereg/sql/1.3.0_to_1.3.1_rollback.sql
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,25 @@ | ||
| \c mosip_prereg | ||
| -- Rollback script from 1.3.1 to 1.3.0 | ||
| -- ------------------------------------------------------------------------------------------ | ||
| -- Removes the canonical user registry table (prereg.user_details) introduced in 1.3.1. | ||
| -- | ||
| -- !! ONE-WAY MIGRATION — READ BEFORE RUNNING !! | ||
| -- The 1.3.1 identity migration rewrites cr_by / upd_by / cr_appuser_id / contact_info across | ||
| -- applications, applicant_demographic, applicant_document and reg_appointment from the raw | ||
| -- identifier to a surrogate UUID. The ONLY reverse mapping (UUID -> encrypted original identifier) | ||
| -- lives in prereg.user_details. Dropping this table therefore ORPHANS every migrated UUID: the | ||
| -- raw identifier can no longer be recovered, and an older (pre-1.3.1) application build — which | ||
| -- compares the raw auth userId directly against these columns — will fail all ownership checks, | ||
| -- silently hiding applicants' own records from them. | ||
| -- | ||
| -- Safe to run ONLY if the identity migration has not yet populated any ownership column with a | ||
| -- UUID (i.e. immediately after upgrade, before any login/create/book/update traffic). If migrated | ||
| -- data exists, do NOT roll back with this script alone — the UUID columns must first be reverted | ||
| -- to their raw values (requires decrypting identifier_encrypted from user_details BEFORE this drop). | ||
| -- WARNING: This will permanently delete all surrogate UUID mappings stored in this table. | ||
| -- ------------------------------------------------------------------------------------------ | ||
|
|
||
| DROP INDEX IF EXISTS prereg.idx_user_details_encrypted_dtimes; | ||
| DROP INDEX IF EXISTS prereg.idx_user_details_cr_dtimes; | ||
|
|
||
| DROP TABLE IF EXISTS prereg.user_details; |
27 changes: 27 additions & 0 deletions
27
db_upgrade_scripts/mosip_prereg/sql/1.3.0_to_1.3.1_upgrade.sql
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,27 @@ | ||
| \c mosip_prereg | ||
| -- Upgrade script from 1.3.0 to 1.3.1 | ||
| -- ------------------------------------------------------------------------------------------ | ||
| -- Introduces canonical user registry table (prereg.user_details) for PII security. | ||
| -- Eliminates plaintext PII replication across cr_by/upd_by/cr_appuser_id fields by | ||
| -- storing a hash->UUID surrogate mapping with encrypted original for audit/notifications. | ||
| -- | ||
| -- NOTE: This is a ONE-WAY migration. Once ownership columns are rewritten to surrogate UUIDs, | ||
| -- prereg.user_details holds the only reverse mapping back to the raw identifier. See | ||
| -- 1.3.0_to_1.3.1_rollback.sql for the constraints on rolling this back safely. | ||
| -- ------------------------------------------------------------------------------------------ | ||
|
|
||
| CREATE TABLE IF NOT EXISTS prereg.user_details ( | ||
| user_id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||
| identifier_hash VARCHAR(128) NOT NULL UNIQUE, | ||
| identifier_encrypted TEXT NOT NULL, | ||
| cr_dtimes TIMESTAMP NOT NULL, | ||
| encrypted_dtimes TIMESTAMP NOT NULL | ||
| ); | ||
|
|
||
| CREATE INDEX IF NOT EXISTS idx_user_details_cr_dtimes | ||
| ON prereg.user_details (cr_dtimes); | ||
|
|
||
| CREATE INDEX IF NOT EXISTS idx_user_details_encrypted_dtimes | ||
| ON prereg.user_details (encrypted_dtimes); | ||
|
|
||
| GRANT SELECT, INSERT, UPDATE, DELETE, REFERENCES ON prereg.user_details TO prereguser; |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -346,4 +346,4 @@ | |
| </build> | ||
| </profile> | ||
| </profiles> | ||
| </project> | ||
| </project> | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
15 changes: 15 additions & 0 deletions
15
...c/main/java/io/mosip/preregistration/application/repository/RegAppointmentRepository.java
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,15 @@ | ||
| package io.mosip.preregistration.application.repository; | ||
|
|
||
| import org.springframework.data.jpa.repository.Query; | ||
| import org.springframework.data.repository.query.Param; | ||
| import org.springframework.stereotype.Repository; | ||
|
|
||
| import io.mosip.kernel.core.dataaccess.spi.repository.BaseRepository; | ||
| import io.mosip.preregistration.core.common.entity.RegistrationBookingEntity; | ||
|
|
||
| @Repository("regAppointmentRepository") | ||
| public interface RegAppointmentRepository extends BaseRepository<RegistrationBookingEntity, String> { | ||
|
|
||
| @Query("SELECT e FROM RegistrationBookingEntity e WHERE e.preregistrationId = ?1") | ||
| RegistrationBookingEntity getRegistrationAppointmentByPreRegistrationId(@Param("preRegId") String preRegId); | ||
| } |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.