<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/OpenBmc/bmcweb.git/include, branch master</title>
<subtitle>A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/'/>
<updated>2026-09-19T14:52:07+00:00</updated>
<entry>
<title>include,http: Extract getUserInfo/onRequestRecv</title>
<updated>2026-09-19T14:52:07+00:00</updated>
<author>
<name>Yuvakumar Selvamani</name>
<email>yuvakumars@ami.com</email>
</author>
<published>2026-09-01T10:12:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=e5fdb213cfc5e43cbf3e7d327a78ce771362edaf'/>
<id>urn:sha1:e5fdb213cfc5e43cbf3e7d327a78ce771362edaf</id>
<content type='text'>
Move long lambdas in getUserInfo() and onRequestRecv() into named
functions, afterGetUserInfo() and afterCompleteRequest(), per the &lt;10
line lambda rule in docs/COMMON_ERRORS.md. No functional change.

Tested:
- Tested on AST2600 SoC.
- getUserInfo/afterGetUserInfo: sent an authenticated Basic-auth Redfish
  GET and confirmed a 200 response with no "Failed to populate user
  information" error in journalctl, proving populateUserInfo() succeeded
  via the extracted callback.
- onRequestRecv/afterCompleteRequest: RSV's client uses HTTP/1.1, so it
  does not exercise this HTTP/2-only code path. Instead, used
  "curl --http2" and confirmed ALPN negotiated h2 and the request
  completed as HTTP/2 200. journalctl -u bmcweb confirmed both
  "onRequestRecv streamId:1" and the extracted callback's
  "res.completeRequestHandler called" fired for that stream.
- Redfish Service Validator: 5830 Pass / 353 Warn / 0 Fail.

Change-Id: I0e6365c682f6acc8d39510ad5f1fe239d747154f
Signed-off-by: Yuvakumar Selvamani &lt;yuvakumars@ami.com&gt;
</content>
</entry>
<entry>
<title>Detect HTML content type with existing parser</title>
<updated>2026-07-16T17:21:50+00:00</updated>
<author>
<name>Joel Pullokaran Jesin</name>
<email>joelpj@ami.com</email>
</author>
<published>2026-07-13T13:34:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=d7744feb85a79ebb9069a5a0c2afa6f56c6f9f4a'/>
<id>urn:sha1:d7744feb85a79ebb9069a5a0c2afa6f56c6f9f4a</id>
<content type='text'>
Use http_helpers::getContentType() when deciding whether to add
HTML-only security headers.

Previously this logic checked the raw Content-Type header with a
text/html prefix match. That worked for the values we emit today,
but it open-coded Content-Type handling in this path instead of using
the existing parser.

Switch this logic to getContentType() so it stays consistent with
the rest of the code and correctly handles valid variations such as
case-insensitive HTML MIME types.

Add unit coverage for getContentType() to verify HTML MIME types
with charset parameters and case-insensitive input.

Tested: unit tests passed.

Change-Id: I1cff40453ab4851cc7b24615a20fb6abcfba864b
Signed-off-by: Joel Pullokaran Jesin &lt;joelpj@ami.com&gt;
</content>
</entry>
<entry>
<title>Fix bug in asio resolver</title>
<updated>2026-07-15T18:27:05+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-05-29T17:11:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=a72a21df2401924757519bd56ac1f729a87489e2'/>
<id>urn:sha1:a72a21df2401924757519bd56ac1f729a87489e2</id>
<content type='text'>
This regressed when the bypass was added.  Fix the code for
resolver=asio to properly construct the results object using the built
in asio type instead of std::vector.

Tested: Code compiles with resolver=asio again.

Change-Id: I3d9ddc38b88a392cf82fc81bd5609f3360837393
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Allow setting Mozilla modern</title>
<updated>2026-07-02T18:30:22+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-05-26T20:28:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=917fbad478cf5db4a79944d59a4927207adf49d1'/>
<id>urn:sha1:917fbad478cf5db4a79944d59a4927207adf49d1</id>
<content type='text'>
Mozilla publishes recommendations for TLS cipher suites to support.  For
many years bmcweb selected "intermediate" because of compatibility with
clients that didn't yet support TLS1.3.

This commit adds the ability to use the Mozilla modern recommendations,
and disable TLS1.2 support through a new meson option, tls-profile.

Tested:

Loaded on qemu, and verified with testssl.sh[1] that parameters were
applied.

[1] https://github.com/testssl/testssl.sh

Change-Id: I38e915b3943b5dbe5fb31e54eb3ebda9bbaeb811
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Flag long lambdas</title>
<updated>2026-07-01T17:10:08+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-06-22T16:53:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=8176ae6778015743b77e8744c046bc50edf13cc4'/>
<id>urn:sha1:8176ae6778015743b77e8744c046bc50edf13cc4</id>
<content type='text'>
Long lambdas have been documented as an anti-pattern for some time.[1]
Despite this being generally understood, bmcweb has a long ways to go
cleaning these up, and routinely code is submitted in violation of this
anti-pattern.

Invent an ast-grep rule that can identify when new examples of this
anti-pattern are added, and ignore the existing 200+ examples that are
in the codebase already using ast-grep ignore.  These flags will give us
something to search for as we clean this up, and will help to prevent
new instances from being added unintentionally.

[1] https://github.com/openbmc/docs/blob/master/anti-patterns.md#very-long-lambda-callbacks

Tested: Comment only change.  ast-grep passes.  Manually removing an
ast-grep ignore flag shows as a failure in ast-grep scan

Change-Id: I77d634a393884969f184d2c39c02cc08288d5a29
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>sdbusplus: use shorter type aliases</title>
<updated>2026-06-19T11:42:03+00:00</updated>
<author>
<name>Patrick Williams</name>
<email>patrick@stwcx.xyz</email>
</author>
<published>2026-06-19T11:42:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=a887d6d977f0c058f999dc2a7f479420623e12e4'/>
<id>urn:sha1:a887d6d977f0c058f999dc2a7f479420623e12e4</id>
<content type='text'>
The sdbusplus headers provide shortened aliases for many types.
Switch to using them to provide better code clarity and shorter
lines.  Possible replacements are for:
  * exception_t
  * manager_t
  * match
  * match_rules
  * message_t
  * object_t
  * slot_t

Change-Id: Iaf2a83fb67d57a6fafb664d27b349add17a96bcd
Signed-off-by: Patrick Williams &lt;patrick@stwcx.xyz&gt;
</content>
</entry>
<entry>
<title>Generate 64 bit serial numbers</title>
<updated>2026-06-12T16:01:54+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>ed@tanous.net</email>
</author>
<published>2026-05-26T21:29:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=e5cd5009b23255637dd7f11701a65d8c8fa09b88'/>
<id>urn:sha1:e5cd5009b23255637dd7f11701a65d8c8fa09b88</id>
<content type='text'>
Even though the certificate is self signed, we should pass as many
certificate tests as possible.  testssl.sh prints
```
 Serial 4B32D4F0   NOT ok: length should be &gt;= 64 bits entropy (is: 4 bytes)
```

On our default certificate.  This is relatively easy to fix.

Change-Id: Ib1eb07b637ebf49ecf954b3d98ced9e9ef0f5a34
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>OpenSSL cleanup</title>
<updated>2026-06-12T16:01:54+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-04-27T21:12:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=048cb1125f42cf748218a3258faeb2e868d1e3cb'/>
<id>urn:sha1:048cb1125f42cf748218a3258faeb2e868d1e3cb</id>
<content type='text'>
Continue moving OpenSSL into reusable RAII classes that can be used in
unit tests and other places.  This is slightly more code, but as we're
adding unit tests, it allows reuse between unit tests rather than
writing C directly.  It also encapsulates the complexity of parsing
openssl output (usually in bytes) into standard types (string) that can
be compared/modified.

Functionally this adds two new classes to the "wrappers" functions,
OpenSSLSSLCtx and OpenSSLSSL, which each wrap SSL_CTX and SSL objects
respectively from openssl.  These are rough approximations of the boost
equivalents.

Change-Id: Id87ac4ccde88890bd70861deffdb256188ec0e39
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>sdbusplus: use shorter type aliases</title>
<updated>2026-06-09T09:31:20+00:00</updated>
<author>
<name>Patrick Williams</name>
<email>patrick@stwcx.xyz</email>
</author>
<published>2026-06-09T09:31:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=dd97aa6b21f70700cd3418f5806937372d717324'/>
<id>urn:sha1:dd97aa6b21f70700cd3418f5806937372d717324</id>
<content type='text'>
The sdbusplus headers provide shortened aliases for many types.
Switch to using them to provide better code clarity and shorter
lines.  Possible replacements are for:
  * bus_t
  * exception_t
  * manager_t
  * match_t
  * message_t
  * object_t
  * slot_t
  * object_path

Change-Id: I05ee2b2cda7c4468ab4117c751ecee797121b7dd
Signed-off-by: Patrick Williams &lt;patrick@stwcx.xyz&gt;
</content>
</entry>
<entry>
<title>account_service: invalidate sessions when account is disabled</title>
<updated>2026-06-08T15:23:04+00:00</updated>
<author>
<name>Chandramohan Harkude</name>
<email>chandramohan.harkude@gmail.com</email>
</author>
<published>2026-05-18T07:30:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=430b30bd5f800b5c7dc0b2bd856f71f72b93c785'/>
<id>urn:sha1:430b30bd5f800b5c7dc0b2bd856f71f72b93c785</id>
<content type='text'>
PATCH /redfish/v1/AccountService/Accounts/ with {"Enabled":false}
flipped UserEnabled on D-Bus but left every active X-Auth-Token session
for that user fully usable. Subsequent token-authenticated requests
continued to succeed (200 OK) until the token's natural expiry, even
though Basic auth for the same account was correctly rejected (401).
DELETE on the same resource does not have this problem because removing
the user object emits InterfacesRemoved, and bmcweb::onUserRemoved (in
include/user_monitor.hpp) handles that signal by calling
removeSessionsByUsername.

Add onUserPropertiesChanged() in include/user_monitor.hpp that drops
the user's sessions via SessionStore::removeSessionsByUsername() when
User.Attributes.UserEnabled transitions to false.
This handles disable of user both from IPMI and Redfish

Tested :

```
Create new user

curl -k -u ${USER}:${PASSWD} -X POST
https://127.0.0.1:2443/redfish/v1/AccountService/Accounts -d '{
UserName:test_admin, Password:Shahapur#13!Shahapur, RoleId:Administrator, Enabled:true}'
{
  "@Message.ExtendedInfo": [
    {
      "@odata.type": "#Message.v1_1_1.Message",
      "Message": "The resource was created successfully.",
      "MessageArgs": [],
      "MessageId": "Base.1.19.Created",
      "MessageSeverity": "OK",
      "Resolution": "None."
    }
  ]
}

Create a-auth-token
curl --insecure -X POST -D headers.txt https://127.0.0.1:2443/redfish/v1/SessionService/Sessions -d '{"UserName":"test_admin", "Password":"Shahapur#13!Shahapur"}'
{
  "@odata.id": "/redfish/v1/SessionService/Sessions/YLMzEtANWr",
  "@odata.type": "#Session.v1_7_0.Session",
  "ClientOriginIPAddress": "10.0.2.2",
  "Description": "Manager User Session",
  "Id": "YLMzEtANWr",
  "Name": "User Session",
  "Roles": [
    "Administrator"
  ],
  "UserName": "test_admin"
}
$ cat headers.txt
HTTP/2 201
allow: GET, HEAD, POST
odata-version: 4.0
x-auth-token: VcufgTshiDjEn8HbGh31
location: /redfish/v1/SessionService/Sessions/YLMzEtANWr
strict-transport-security: max-age=31536000; includeSubdomains
pragma: no-cache
cache-control: no-store, max-age=0
x-content-type-options: nosniff
content-type: application/json
date: Wed, 06 May 2026 12:45:18 GMT
content-length: 305

// Test RF request with token
curl -k -H 'x-auth-token:VcufgTshiDjEn8HbGh31' https://127.0.0.1:2443/redfish/v1/AccountService/Accounts
{
  "@odata.id": "/redfish/v1/AccountService/Accounts",
  "@odata.type": "#ManagerAccountCollection.ManagerAccountCollection",
  "Description": "BMC User Accounts",
  "Members": [
    {
      "@odata.id": "/redfish/v1/AccountService/Accounts/test_admin"
    },
    {
      "@odata.id": "/redfish/v1/AccountService/Accounts/root"
    }
  ],
  "Members@odata.count": 2,
  "Name": "Accounts Collection"
}

// Disable the user
curl -k -u root:0penBmc https://127.0.0.1:2443/redfish/v1/AccountService/Accounts/test_admin -X PATCH  -d '{"Enabled":false}'
204

// Try to use the Tokens
curl -k -H 'x-auth-token:VcufgTshiDjEn8HbGh31' https://127.0.0.1:2443/redfish/v1/AccountService/Accounts
401

```
Change-Id: I3246d3f5ec7db405c9c186a8672a9fed18259249
Signed-off-by: Chandramohan Harkude &lt;chandramohan.harkude@gmail.com&gt;
</content>
</entry>
</feed>
