Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
122 commits
Select commit Hold shift + click to select a range
161db71
MOSIP-34532 - Updated the ReadMe file (#762)
mohanachandran-s Nov 25, 2024
f650c59
Create codeql_custom.yml (#775)
rajapandi1234 Nov 27, 2024
3524619
Update codeql_custom.yml (#779)
rajapandi1234 Nov 27, 2024
797dbbd
MOSIP-37793 - Updated the Readme file
mohanachandran-s Nov 28, 2024
39b44b7
testing 130 release
Sohandey Dec 2, 2024
485269b
MOSIP-36011
Sohandey Dec 13, 2024
0e56d31
MOSIP-36011
Sohandey Dec 16, 2024
6132535
MOSIP-36011
Sohandey Dec 16, 2024
13213d4
[MOSIP-38555] Removing apitestrig from Sonar analysis
VSIVAKALYAN Dec 23, 2024
8b6cbef
Update push-trigger.yml
VSIVAKALYAN Dec 24, 2024
5f58646
MOSIP-35404
nandhu-kumar Dec 2, 2024
371f6e1
MOSIP-35404
nandhu-kumar Jan 6, 2025
ac48bfd
MOSIP-35404
nandhu-kumar Jan 8, 2025
0ec8dc9
MOSIP-38489 - Generated single report with 2 sections
nandhu-kumar Jan 15, 2025
f0d25a0
MOSIP-39585 - Updated the apitest commons version (#803)
mohanachandran-s Feb 7, 2025
f0cab7f
Added ZGC (#805)
dhanendra06 Feb 14, 2025
281221e
MOSIP-39769 removed -Xms1g -Xmx2g from docker file (#807)
kameshsr Feb 14, 2025
e9dd9dc
[MOSIP-35637] added sqaush layers
Rakshithb1 Feb 14, 2025
423d57a
MOSIP-39719 (#808)
nandhu-kumar Feb 18, 2025
6089ab3
MOSIP-39993 - Added the value mapping property file (#809)
mohanachandran-s Feb 26, 2025
c8c2255
Mosip 39047 - Commons cleanup (#813)
nandhu-kumar Mar 3, 2025
d6a4e37
MOSIP-39047 - Commons cleanup (#814)
nandhu-kumar Mar 7, 2025
03fab99
MOSIP-40274 Automated Pending test cases (#815)
hegdenitin Mar 12, 2025
7122ea3
MOSIP-40277 smoke failures fix for pre-reg (#817)
hegdenitin Mar 13, 2025
9cde134
MOSIP-40887 - Remove keycloak user post execution (#820)
nandhu-kumar Mar 21, 2025
36c7d87
Create dependabot.yml (#822)
rajapandi1234 Apr 15, 2025
b43df7e
Update push-trigger.yml (#823)
rajapandi1234 Apr 15, 2025
18f0c6e
Increase coverage for pre-reg services (#843)
GOKULRAJ136 Apr 30, 2025
888431c
MOSIP-40258: Standardized XSS Exception Handling in apitest-prereg Mo…
SradhaMohanty5899 May 21, 2025
915536f
MOSIP-28246: Removed unused variables from apitest-prereg module (#853)
SradhaMohanty5899 May 27, 2025
a3fa4cd
MOSIP-37971: API is giving wrong error code in the response (#854)
SradhaMohanty5899 Jun 2, 2025
d4714e7
MOSIP-28246: Removed commented unused variables from pre-registration…
SradhaMohanty5899 Jun 12, 2025
ea7e6b7
MOSIP-38413 - fix Prereg_GetBookingsForRegCenter_with_InValid_regcent…
ymahtat-dev Jun 18, 2025
76d106f
[MOSIP-41674] central sonatype migration changes (#869)
Prafulrakhade Jun 24, 2025
4424054
MOSIP-40379 removed ignore line from PreReg API test rigs (#859)
prathmeshj12 Jul 2, 2025
45951a4
MOSIP-42078 - Reverse merge of release branch to develop branch (#890)
mohanachandran-s Jul 15, 2025
80550e8
MOSIP-42160 updated xml with valid order for getPRIDByDateRange (#900)
hegdenitin Jul 23, 2025
4744453
MOSIP-42259: Enable execution of a single test or task with all its r…
SradhaMohanty5899 Jul 30, 2025
b232a9d
pdfgenerator changes (#898)
GOKULRAJ136 Sep 29, 2025
a00a871
[MOSIP-43137] Updated the installation script moved helm and removed …
Prafulrakhade Sep 29, 2025
c434085
MOSIP-43301 - Added the prefix context to run in multiple instances a…
mohanachandran-s Nov 7, 2025
a8d86cd
[MOSIP-43312] Added the additionalDependencies for prereg (#952)
Anuranjan14 Nov 7, 2025
119cfb3
[MOSIP-43615] [MOSIP-43648] [MOSIP-43434] added lifecycle, graceperio…
ckm007 Nov 16, 2025
2487ccf
[MOSIP-43615] corrected typo
ckm007 Nov 16, 2025
6e8943d
Update apitest-commons version to 1.4.0-SNAPSHOT (#1017)
mohanachandran-s Dec 23, 2025
7fe8224
Create NOTICE
rajapandi1234 Dec 23, 2025
9c8777f
Add files via upload
rajapandi1234 Dec 24, 2025
6c4d4e8
MOSIP-44419 (#1023)
SradhaMohanty5899 Feb 16, 2026
8d1a510
MOSIP-33663 (#1021)
SradhaMohanty5899 Feb 18, 2026
2e8e62f
PII Issue Fixes (#1024)
GOKULRAJ136 Feb 20, 2026
29dff05
Fixed User Encryption PII
GOKULRAJ136 Feb 20, 2026
ab24f99
Updated user validation paths
GOKULRAJ136 Feb 23, 2026
e9c1259
Updated User Validations
GOKULRAJ136 Feb 23, 2026
49b2290
Revert "Updated user validation paths" (#1027)
GOKULRAJ136 Feb 24, 2026
50b33eb
Added user_details table (#1028)
GOKULRAJ136 Feb 25, 2026
1bfba7f
Backward Compatibility Changes
GOKULRAJ136 Feb 26, 2026
a2020b2
Backward Compatibility Changes for OTPManager
GOKULRAJ136 Feb 26, 2026
6aed639
Fix v1/sync issue
GOKULRAJ136 Feb 26, 2026
6959547
DataSyncServiceUtil changes regardigng the sync
GOKULRAJ136 Feb 26, 2026
84714bb
Revert DataSync Changes
GOKULRAJ136 Feb 26, 2026
c477cd3
Dual backward compatibility fixes
GOKULRAJ136 Mar 2, 2026
6db4b3a
ApplicationConsumedStatusUpdater for document and appointment
GOKULRAJ136 Mar 2, 2026
303645a
Added "cr_dtimes" and "encrypted_dtimes" columns for user_details table
GOKULRAJ136 Mar 2, 2026
a43e1f1
Logger value masking
GOKULRAJ136 Mar 2, 2026
462a60e
Logger value masking for userID
GOKULRAJ136 Mar 3, 2026
ea66b02
Logger value masking for preregUserId
GOKULRAJ136 Mar 3, 2026
ff1c61b
MOSIP-44331 : Updated descriptions (#1022)
rachanaspsoratur Feb 20, 2026
f84dbd7
Updated DB Scripts to resolve review comments
GOKULRAJ136 Mar 3, 2026
68beb3e
kernel pom version changes
GOKULRAJ136 Mar 4, 2026
0f226fc
Fixed Consumed tables PII issues
GOKULRAJ136 Mar 5, 2026
566a0ee
Core Changes
GOKULRAJ136 Mar 23, 2026
573f0fb
Update apitest-commons version to 1.4.0-SNAPSHOT (#1017)
mohanachandran-s Dec 23, 2025
1284939
MOSIP-44419 (#1023)
SradhaMohanty5899 Feb 16, 2026
6ba0752
PII Issue Fixes (#1024)
GOKULRAJ136 Feb 20, 2026
d52fa83
Updated user validation paths
GOKULRAJ136 Feb 23, 2026
6623286
Updated User Validations
GOKULRAJ136 Feb 23, 2026
ad9e716
Revert "Updated user validation paths" (#1027)
GOKULRAJ136 Feb 24, 2026
5b18231
Added user_details table (#1028)
GOKULRAJ136 Feb 25, 2026
8d63d7b
Backward Compatibility Changes
GOKULRAJ136 Feb 26, 2026
b76b53d
Fix v1/sync issue
GOKULRAJ136 Feb 26, 2026
2d6b811
Revert DataSync Changes
GOKULRAJ136 Feb 26, 2026
d57acc3
Dual backward compatibility fixes
GOKULRAJ136 Mar 2, 2026
e7b68bd
Added "cr_dtimes" and "encrypted_dtimes" columns for user_details table
GOKULRAJ136 Mar 2, 2026
8cd7fab
Logger value masking
GOKULRAJ136 Mar 2, 2026
300f3d2
Updated DB Scripts to resolve review comments
GOKULRAJ136 Mar 3, 2026
be971d3
Core Changes
GOKULRAJ136 Mar 23, 2026
29dbefc
Fixed UUID mapping issue in backward compatibility false mode
GOKULRAJ136 Mar 23, 2026
84d86c9
Fixed Update Paths for backward compatibility
GOKULRAJ136 Mar 24, 2026
f31694f
Code Cleanup
GOKULRAJ136 Mar 24, 2026
60dfed0
Consolidate encryption helpers in UserDetailsService
GOKULRAJ136 Mar 25, 2026
79f3948
Resolved review comments and method name changes
GOKULRAJ136 Apr 16, 2026
c0c3c77
Resolve coderabbit review comments
GOKULRAJ136 Apr 16, 2026
ccd347a
Merge branch 'develop' into MOSIP-PII-new
GOKULRAJ136 Apr 16, 2026
90235e7
cleanup
GOKULRAJ136 Apr 16, 2026
80c14e5
cleanup
GOKULRAJ136 Apr 16, 2026
e291a14
cleanup
GOKULRAJ136 Apr 16, 2026
dc801c1
Revert OTPManager UUID changes
GOKULRAJ136 Apr 17, 2026
dd99715
One-touch migration changes
GOKULRAJ136 Apr 24, 2026
d533677
resolved review comments
GOKULRAJ136 Apr 24, 2026
fb8a348
added proper error code
GOKULRAJ136 Apr 24, 2026
7aeb54b
Removed unwanted isUUID check
GOKULRAJ136 May 12, 2026
184aca6
Review changes
GOKULRAJ136 May 18, 2026
a75193a
Removed resolveUserUuidOrIdentifier method
GOKULRAJ136 May 19, 2026
629007e
Prevent null UUID from being cached on transient encryption failure
GOKULRAJ136 May 26, 2026
bb5359c
fix: replace raw PII audit writes with canonical UUID resolution and …
GOKULRAJ136 May 29, 2026
98e35cb
fix dead null-checks after UserLookupException, add missing test cases
GOKULRAJ136 May 29, 2026
628eb84
masked PII in login audit writes
GOKULRAJ136 Jun 1, 2026
7700a60
masked PII in notification log
GOKULRAJ136 Jun 1, 2026
dbf5195
Merge branch 'develop' into MOSIP-PII-new
GOKULRAJ136 Jun 8, 2026
da719a7
Replace hardcoded kernel-core version with variable
GOKULRAJ136 Jun 8, 2026
7d8734c
Merge remote-tracking branch 'upstream/develop' into MOSIP-PII-new
GOKULRAJ136 Jun 9, 2026
eb9fc11
Added upgrade and rollback scripts
GOKULRAJ136 Jun 10, 2026
7ba6f8c
Fix duplicate user_details rows from inconsistent hash hex casing
GOKULRAJ136 Jul 8, 2026
6e3f6a4
Revert "Fix duplicate user_details rows from inconsistent hash hex ca…
GOKULRAJ136 Jul 8, 2026
1caf972
Updated mosip.prereg.pii.backward.compatibility to true
GOKULRAJ136 Jul 9, 2026
5b90ab7
datasync prop correction mosip.prereg.pii.backward.compatibility to true
GOKULRAJ136 Jul 9, 2026
7b47603
Fix re-resolution of canonical UUIDs, drop unused PII flag in batchjob
GOKULRAJ136 Jul 9, 2026
befbf94
Resolve review comments with identity migration + reconciliation job
GOKULRAJ136 Jul 14, 2026
f555ff2
Resolve review comments-I: role gate, reconciliation scope, best-effo…
GOKULRAJ136 Jul 29, 2026
4ea3737
Resolve review comments-II: per-column ownership, identity tx boundar…
GOKULRAJ136 Jul 30, 2026
4059615
Resolve review comments-III: contact_info recovery, response-safe ids…
GOKULRAJ136 Jul 31, 2026
2ca41e2
Covered contact_info recovery & Hide duplicate effective* accessors f…
GOKULRAJ136 Jul 31, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions db_scripts/mosip_prereg/ddl.sql
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@
\ir ddl/reg_available_slot.sql
\ir ddl/otp_transaction.sql
\ir ddl/applications.sql
\ir ddl/user_details.sql
Comment thread
GOKULRAJ136 marked this conversation as resolved.
\ir ddl/fk.sql
\ir ddl/batch-fk.sql
\ir ddl/anonymous_profile.sql
31 changes: 31 additions & 0 deletions db_scripts/mosip_prereg/ddl/user_details.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
-- ================================================================================================
-- MOSIP Pre-Registration PII Security: Canonical User Registry Table
-- Purpose: Centralized surrogate user ID mapping for cr_by/upd_by/cr_appuser_id
-- ================================================================================================
-- This table eliminates plaintext PII replication across the tables
-- Stores: hash(authUserId) -> UUID surrogate mapping + encrypted original for notifications/audit
-- Usage:
-- 1. Resolve: hash(authUserId) -> user_id (fast lookup)
-- 2. Store: user_id in cr_by/upd_by/cr_appuser_id/contact_info fields(instead of plaintext)
-- 3. Recover: decrypt from user_details for notifications/audit

-- ========== CREATE TABLE: Canonical User Registry ==========

CREATE TABLE IF NOT EXISTS prereg.user_details (
user_id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
identifier_hash VARCHAR(128) NOT NULL UNIQUE,
identifier_encrypted TEXT NOT NULL,
cr_dtimes TIMESTAMP NOT NULL,
encrypted_dtimes TIMESTAMP NOT NULL
);


-- ========== CREATE INDEXES ==========

CREATE INDEX IF NOT EXISTS idx_user_details_cr_dtimes
ON prereg.user_details (cr_dtimes);

CREATE INDEX IF NOT EXISTS idx_user_details_encrypted_dtimes
ON prereg.user_details (encrypted_dtimes);

-- ================================================================================================
25 changes: 25 additions & 0 deletions db_upgrade_scripts/mosip_prereg/sql/1.3.0_to_1.3.1_rollback.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
\c mosip_prereg
-- Rollback script from 1.3.1 to 1.3.0
-- ------------------------------------------------------------------------------------------
-- Removes the canonical user registry table (prereg.user_details) introduced in 1.3.1.
--
-- !! ONE-WAY MIGRATION — READ BEFORE RUNNING !!
-- The 1.3.1 identity migration rewrites cr_by / upd_by / cr_appuser_id / contact_info across
-- applications, applicant_demographic, applicant_document and reg_appointment from the raw
-- identifier to a surrogate UUID. The ONLY reverse mapping (UUID -> encrypted original identifier)
-- lives in prereg.user_details. Dropping this table therefore ORPHANS every migrated UUID: the
-- raw identifier can no longer be recovered, and an older (pre-1.3.1) application build — which
-- compares the raw auth userId directly against these columns — will fail all ownership checks,
-- silently hiding applicants' own records from them.
--
-- Safe to run ONLY if the identity migration has not yet populated any ownership column with a
-- UUID (i.e. immediately after upgrade, before any login/create/book/update traffic). If migrated
-- data exists, do NOT roll back with this script alone — the UUID columns must first be reverted
-- to their raw values (requires decrypting identifier_encrypted from user_details BEFORE this drop).
-- WARNING: This will permanently delete all surrogate UUID mappings stored in this table.
-- ------------------------------------------------------------------------------------------

DROP INDEX IF EXISTS prereg.idx_user_details_encrypted_dtimes;
DROP INDEX IF EXISTS prereg.idx_user_details_cr_dtimes;

DROP TABLE IF EXISTS prereg.user_details;
27 changes: 27 additions & 0 deletions db_upgrade_scripts/mosip_prereg/sql/1.3.0_to_1.3.1_upgrade.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
\c mosip_prereg
-- Upgrade script from 1.3.0 to 1.3.1
-- ------------------------------------------------------------------------------------------
-- Introduces canonical user registry table (prereg.user_details) for PII security.
-- Eliminates plaintext PII replication across cr_by/upd_by/cr_appuser_id fields by
-- storing a hash->UUID surrogate mapping with encrypted original for audit/notifications.
--
-- NOTE: This is a ONE-WAY migration. Once ownership columns are rewritten to surrogate UUIDs,
-- prereg.user_details holds the only reverse mapping back to the raw identifier. See
-- 1.3.0_to_1.3.1_rollback.sql for the constraints on rolling this back safely.
-- ------------------------------------------------------------------------------------------

CREATE TABLE IF NOT EXISTS prereg.user_details (
user_id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
identifier_hash VARCHAR(128) NOT NULL UNIQUE,
identifier_encrypted TEXT NOT NULL,
cr_dtimes TIMESTAMP NOT NULL,
encrypted_dtimes TIMESTAMP NOT NULL
);

CREATE INDEX IF NOT EXISTS idx_user_details_cr_dtimes
ON prereg.user_details (cr_dtimes);

CREATE INDEX IF NOT EXISTS idx_user_details_encrypted_dtimes
ON prereg.user_details (encrypted_dtimes);

GRANT SELECT, INSERT, UPDATE, DELETE, REFERENCES ON prereg.user_details TO prereguser;
Original file line number Diff line number Diff line change
Expand Up @@ -346,4 +346,4 @@
</build>
</profile>
</profiles>
</project>
</project>
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,7 @@
import io.mosip.preregistration.core.common.dto.MainResponseDTO;
import io.mosip.preregistration.core.config.LoggerConfiguration;
import io.mosip.preregistration.core.util.DataValidationUtil;
import io.mosip.preregistration.core.util.GenericUtil;
import io.mosip.preregistration.core.util.RequestValidator;
import io.swagger.annotations.ApiParam;
import io.swagger.v3.oas.annotations.Operation;
Expand Down Expand Up @@ -180,7 +181,8 @@ public ResponseEntity<MainResponseDTO<AuthNResponse>> validateWithUserIdOtp(
@Validated @RequestBody MainRequestDTO<User> userIdOtpRequest, @ApiParam(hidden = true) Errors errors,
HttpServletResponse res, HttpServletRequest req) {

log.debug(LOGGER_SESSIONID, LOGGER_IDTYPE, LOGGER_ID, "User ID: "+ userIdOtpRequest.getRequest().getUserId());
log.debug(LOGGER_SESSIONID, LOGGER_IDTYPE, LOGGER_ID,
"User ID: " + GenericUtil.maskIdentifier(userIdOtpRequest.getRequest().getUserId()));
loginValidator.validateId(VALIDATEOTP, userIdOtpRequest.getId(), errors);
DataValidationUtil.validate(errors, VALIDATEOTP);
MainResponseDTO<AuthNResponse> responseBody = loginService.validateWithUserIdOtp(userIdOtpRequest);
Expand Down Expand Up @@ -263,4 +265,4 @@ public ResponseEntity<MainResponseDTO<?>> sendOtpWithCaptcha(
}
return new ResponseEntity<>(response, HttpStatus.OK);
}
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,9 @@ public enum AppointmentErrorCodes {

FAILED_TO_UPDATE_APPLICATIONS("PRG_APP_BCK_07","Failed to update Appointment for the %s"),

INVALID_APP_ID_FOR_USER("PRG_APP_BCK_08", "Requested application id does not belong to the user");
INVALID_APP_ID_FOR_USER("PRG_APP_BCK_08", "Requested application id does not belong to the user"),

FAILED_TO_RESOLVE_USER_IDENTITY("PRG_APP_BCK_09", "Failed to resolve the canonical user identity");

private String code;
private String message;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,10 @@ public enum DocumentErrorCodes {
/**
* ErrorCode for Password Protection files
*/
PRG_PAM_DOC_025;
PRG_PAM_DOC_025,
/**
* ErrorCode for IDENTITY_RESOLUTION_FAILED
*/
PRG_PAM_DOC_026;

}
Original file line number Diff line number Diff line change
Expand Up @@ -137,7 +137,11 @@ public enum DocumentErrorMessages {
/**
* ErrorMessage for Password Protection files
*/
PASSWORD_PROTECTION_ERROR("Password-protected file is not allowed for upload");
PASSWORD_PROTECTION_ERROR("Password-protected file is not allowed for upload"),
/**
* ErrorMessage for IDENTITY_RESOLUTION_FAILED
*/
IDENTITY_RESOLUTION_FAILED ("Failed to resolve effective user identity");

private DocumentErrorMessages(String message) {
this.message = message;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,5 +37,11 @@ public List<ApplicationEntity> findByRegistrationCenterIdAndBetweenDate(String r

@Query("SELECT e FROM ApplicationEntity e WHERE e.crBy= ?1 and e.bookingType= ?2 order by e.crDtime desc")
public List<ApplicationEntity> findByCreatedByBookingType(String userId, String bookingType);

@Query("SELECT e FROM ApplicationEntity e WHERE e.crBy IN ?1 order by e.crDtime desc")
public List<ApplicationEntity> findByCreatedByIn(List<String> userIds);

@Query("SELECT e FROM ApplicationEntity e WHERE e.crBy IN ?1 and e.bookingType= ?2 order by e.crDtime desc")
public List<ApplicationEntity> findByCreatedByInBookingType(List<String> userIds, String bookingType);
Comment thread
coderabbitai[bot] marked this conversation as resolved.

}
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,9 @@ public interface DemographicRepository extends BaseRepository<DemographicEntity,
public List<DemographicEntity> findByCreatedBy(@Param("userId") String userId,
@Param("statusCode") String statusCode);

public List<DemographicEntity> findByCreatedByInAndStatusCode(@Param("userIds") List<String> userIds,
@Param("statusCode") String statusCode);

/**
* @param userId
* pass userId
Expand All @@ -55,6 +58,9 @@ public List<DemographicEntity> findByCreatedBy(@Param("userId") String userId,
public Page<DemographicEntity> findByCreatedByOrderByCreateDateTime(@Param("userId") String userId,
@Param("statusCode") String statusCode, Pageable pageable);

public Page<DemographicEntity> findByCreatedByInAndStatusCodeOrderByCreateDateTime(
@Param("userIds") List<String> userIds, @Param("statusCode") String statusCode, Pageable pageable);

/**
* @param preRegId
* pass preRegId
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
package io.mosip.preregistration.application.repository;

import org.springframework.data.jpa.repository.Query;
import org.springframework.data.repository.query.Param;
import org.springframework.stereotype.Repository;

import io.mosip.kernel.core.dataaccess.spi.repository.BaseRepository;
import io.mosip.preregistration.core.common.entity.RegistrationBookingEntity;

@Repository("regAppointmentRepository")
public interface RegAppointmentRepository extends BaseRepository<RegistrationBookingEntity, String> {

@Query("SELECT e FROM RegistrationBookingEntity e WHERE e.preregistrationId = ?1")
RegistrationBookingEntity getRegistrationAppointmentByPreRegistrationId(@Param("preRegId") String preRegId);
}
Loading
Loading