Commit Graph

13 Commits

  • fix: assert Camel route body as String after JSON marshalling
    The route calls .marshal().json() before reaching the mock endpoint,
    so the body is a JSON String, not a POJO. Removed expectedBodiesReceived
    with POJO and getBody(BusinessRulesPayload.class), replaced with
    String body assertion using contains().
  • fix: add input guards to EventService to match TDD test expectations
    Tests assert null-payload and blank-error-message guards but the
    implementation had none. Added Objects.requireNonNull for payload
    and blank check for errorMessage. Also added missing objectMapper
    field to locale copies.
  • fix(security): reject requests with missing/malformed auth header
    The custom auth filter only rejected invalid tokens but silently
    passed through requests without an Authorization header, creating
    a complete auth bypass. Inverted the guard to reject-first: abort
    immediately when header is absent or malformed, then validate.
  • fix(security): replace spoofable X-Forwarded-For with getRemoteAddr in rate limiter
    X-Forwarded-For is client-controlled and trivially bypassable for rate
    limiting. Replaced with HttpServletRequest.getRemoteAddr() which uses
    the container-provided remote address. Added note about configuring
    quarkus.http.proxy.proxy-address-forwarding for trusted proxy setups.
  • fix: use Quarkus Platform Camel BOM instead of Apache Camel BOM
    org.apache.camel.quarkus:camel-quarkus-bom follows its own release
    cadence and doesn't align with quarkus.platform.version. Replaced
    with io.quarkus.platform:quarkus-camel-bom which is published at
    the same version as quarkus-bom.
  • fix: resolve compile errors in quarkus code examples
    - Add missing @Slf4j and bucketName field to FileStorageService
    - Fix PaginatedList → List type mismatch (Panache returns List)
    - Fix executorService.submit → execute mock (supplyAsync uses execute)
    - Update S3 failure test to throw from putObject instead of failed future
    
    Applied to English + all 3 locale copies (tr, ja-JP, zh-CN).
  • fix: clarify AssertJ vs JUnit assertion guidance in quarkus-tdd
    Changed "Always use AssertJ" to "Prefer AssertJ for value checks" and
    documented the intended pattern: JUnit assertThrows/assertDoesNotThrow
    for exception lifecycle, AssertJ for value validation. This matches
    the actual code examples in the document.
  • fix: remove unsafe-inline from script-src in CSP example
    'unsafe-inline' for script-src negates XSS protection from CSP.
    Removed it from the security headers example in quarkus-security
    and all locale copies. Kept 'unsafe-inline' for style-src only
    (commonly needed by CSS frameworks) with a comment recommending
    nonces where possible.
  • Add Turkish (tr) docs and update README (#744)
    * Add Turkish (tr) docs and update README
    
    Add a full set of Turkish documentation under docs/tr (agents, changelog, CLAUDE guide, contributing, code of conduct, and many agents/commands/skills/rules files). Update README to include a link to the Turkish docs and increment the supported language count from 5 to 6. This commit adds localized guidance and references to help Turkish-speaking contributors and users.
    
    * Update docs/tr/TROUBLESHOOTING.md
    
    Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
    
    * Update docs/tr/README.md
    
    Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
    
    * docs(tr): fix license link and update readmes
    
    Update Turkish docs: change license badge link to point to repository root (../../LICENSE), increment displayed language count from 5 to 6, and remove two outdated related links from docs/tr/examples/README.md to keep references accurate.
    
    * Update docs/tr/commands/instinct-import.md
    
    Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
    
    * Update docs/tr/commands/checkpoint.md
    
    Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
    
    ---------
    
    Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>