Skip to content

Remove the redundant table-wide file cleanup from the manage-files view - #15836

Open
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:remove-unscoped-file-cleanup
Open

Remove the redundant table-wide file cleanup from the manage-files view#15836
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:remove-unscoped-file-cleanup

Conversation

@svader0

@svader0 svader0 commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Removes an inline cleanup step from the manage-files view. After every successful save the view scanned the whole FileUpload table and deleted any row that was not attached to an object.

That scan is no longer needed. Cleanup of files whose parent object is deleted has been handled by the delete signals added in #13028, and the backlog was cleared by migration 0242_file_upload_cleanup at the same time.

Adds a regression test that a file outside the object being edited is left alone.

No functional change for correctly-permissioned users.

Cleanup of files whose parent object is deleted has been handled by the
delete signals added in DefectDojo#13028, so the table-wide scan this view ran after
every save is redundant.
@dryrunsecurity

Copy link
Copy Markdown

DryRun Security

This pull request contains a critical finding where the sensitive file 'dojo/views.py' was modified by an unauthorized author, 'svader0'.

🔴 Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/views.py (drs_9ec2a3f5)
Vulnerability Configured Sensitive Codepath Modified by Non-Allowed Author
Description File 'dojo/views.py' matches configured sensitive codepath pattern 'dojo/views.py' and was modified by 'svader0' (commit 376aeca) who is not in the allowed authors list.

We've notified @mtesauro.


Comment to provide feedback on these findings.

Report false positive: @dryrunsecurity fp [FINDING ID] [FEEDBACK]
Report low-impact: @dryrunsecurity nit [FINDING ID] [FEEDBACK]

Example: @dryrunsecurity fp drs_90eda195 This code is not user-facing

All finding details can be found in the DryRun Security Dashboard.

@svader0 svader0 added this to the 3.3.0 milestone Aug 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant