prime-reportstream icon indicating copy to clipboard operation
prime-reportstream copied to clipboard

Engagement/jessica/15073 louisiana validation

Open JessicaWNava opened this issue 1 year ago • 2 comments

This PR removes AOEs for LA and adds allowing RSVs into their condition fiters

Test Steps:

  1. Make sure that an RSV message can get through to LA.
  2. Make sure a LA message does not contain AOEs

Changes

  • Removed AOEs
  • Add ability to receive RSV messages

Checklist

Testing

  • [ ] Tested locally?
  • [ ] Ran ./prime test or ./gradlew testSmoke against local Docker ReportStream container?
  • [ ] (For Changes to /frontend-react/...) Ran npm run lint:write?
  • [ ] Added tests?

Process

  • [ ] Are there licensing issues with any new dependencies introduced?
  • [ ] Includes a summary of what a code reviewer should test/verify?
  • [ ] Updated the release notes?
  • [ ] Database changes are submitted as a separate PR?
  • [ ] DevOps team has been notified if PR requires ops support?

Linked Issues

  • Fixes #issue

To Be Done

Create GitHub issues to track the work remaining, if any

  • #issue

Specific Security-related subjects a reviewer should pay specific attention to

  • Does this PR introduce new endpoints?
    • new endpoint A
    • new endpoint B
  • Does this PR include changes in authentication and/or authorization of existing endpoints?
  • Does this change introduce new dependencies that need vetting?
  • Does this change require changes to our infrastructure?
  • Does logging contain sensitive data?
  • Does this PR include or remove any sensitive information itself?

If you answered 'yes' to any of the questions above, conduct a detailed Review that addresses at least:

  • What are the potential security threats and mitigations? Please list the STRIDE threats and how they are mitigated
    • Spoofing (faking authenticity)
      • Threat T, which could be achieved by A, is mitigated by M
    • Tampering (influence or sabotage the integrity of information, data, or system)
    • Repudiation (the ability to dispute the origin or originator of an action)
    • Information disclosure (data made available to entities who should not have it)
    • Denial of service (make a resource unavailable)
    • Elevation of Privilege (reduce restrictions that apply or gain privileges one should not have)
  • Have you ensured logging does not contain sensitive data?
  • Have you received any additional approvals needed for this change?

JessicaWNava avatar Aug 20 '24 19:08 JessicaWNava

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails

Scanned Manifest Files

github-actions[bot] avatar Aug 20 '24 19:08 github-actions[bot]

Test Results

1 209 tests  ±0   1 205 :white_check_mark: ±0   6m 22s :stopwatch: +7s   158 suites ±0       4 :zzz: ±0    158 files   ±0       0 :x: ±0 

Results for commit 826125ff. ± Comparison against base commit 344b7e2f.

github-actions[bot] avatar Aug 20 '24 22:08 github-actions[bot]

Integration Test Results

 63 files  ±0   63 suites  ±0   29m 33s :stopwatch: +35s 436 tests ±0  427 :white_check_mark: ±0  9 :zzz: ±0  0 :x: ±0  439 runs  ±0  430 :white_check_mark: ±0  9 :zzz: ±0  0 :x: ±0 

Results for commit 826125ff. ± Comparison against base commit 344b7e2f.

github-actions[bot] avatar Aug 20 '24 22:08 github-actions[bot]