-
Notifications
You must be signed in to change notification settings - Fork 55
Revert "fix: update safeCommands whitelist for notification service" #1407
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
This reverts commit 526e65d.
Reviewer's guide (collapsed on small PRs)Reviewer's GuideReverts a previous change to the notification service safeCommands whitelist configuration, restoring the prior JSON config for org.deepin.dde.shell.notification. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey - I've left some high level feedback:
- Since this is reverting a change to the safeCommands whitelist, please double-check that the reverted configuration remains consistent with other related service configs to avoid divergent security behavior across panels.
- It would be helpful to capture in the commit message or PR description why the original whitelist update is being reverted (e.g., regression, compatibility issue, or policy change) so future readers understand the rationale for this rollback.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- Since this is reverting a change to the safeCommands whitelist, please double-check that the reverted configuration remains consistent with other related service configs to avoid divergent security behavior across panels.
- It would be helpful to capture in the commit message or PR description why the original whitelist update is being reverted (e.g., regression, compatibility issue, or policy change) so future readers understand the rationale for this rollback.Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
deepin pr auto review这份代码审查针对 审查概要本次修改从 详细审查意见1. 代码逻辑与安全性
2. 代码质量与规范
3. 代码性能
总结与建议结论:该变更是一个良好的安全加固措施,移除了存在潜在滥用风险的高级系统工具。 改进建议:
|
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: BLumia, xionglinlin, yixinshark The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/forcemerge |
|
This pr force merged! (status: blocked) |
This reverts commit 526e65d.
Summary by Sourcery
Bug Fixes: