Skip to content

WA-SEC-018: Verify admin search query scope isolation — model_type param allowlist audit #1022

@kitcommerce

Description

@kitcommerce

Summary

After PR for #802 implements the constantize allowlist fix, this follow-up task verifies the full scope of the params[:model_type] path in AdminSearchQueryWrapper.

Objective

Confirm:

Acceptance Criteria

Verification Plan

  • Run the grep commands; confirm no new hits
  • Run Brakeman and confirm UnsafeReflection warnings are gone

Client Impact

None (verification + documentation only).

Depends On

#802 (must be merged first)

Metadata

Metadata

Assignees

No one assigned

    Labels

    blocked:needs-specMissing objective, acceptance criteria, or verification planstatus:blockedTask is blocked on something

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions