<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/OpenBmc/webui-vue.git, branch master</title>
<subtitle>Web-based user interface built on Vue.js for managing OpenBMC systems (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/'/>
<updated>2026-09-28T10:42:29+00:00</updated>
<entry>
<title>Add asset tag edit functionality to overview page</title>
<updated>2026-09-28T10:42:29+00:00</updated>
<author>
<name>Nishant Tiwari</name>
<email>tiwari.nishant@ibm.com</email>
</author>
<published>2026-07-16T08:27:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=85248e05cf5c44fc2a77135f829ae33b0d485e2f'/>
<id>urn:sha1:85248e05cf5c44fc2a77135f829ae33b0d485e2f</id>
<content type='text'>
Implemented the ability to view and edit the system asset tag directly
from the Overview page, including a modal dialog for editing, Vuex store
action for saving, and truncation in the app header.

Changes:
  - Added ModalAssetTag.vue component with:
    - Form input for editing the asset tag value
    - Vuelidate validation requiring a non-empty tag
  - Updated OverviewServer.vue to:
    - Display asset tag in the system information section
    - Add inline edit button using Carbon edit icon
    - Dispatch saveAssetTag store action with toast feedback
    - Refresh global system info after a successful save
  - Added saveAssetTag action to SystemStore.js using PATCH
    against the system path endpoint
  - Updated AppHeader.vue to truncate asset tags longer than
    30 characters with an ellipsis, preserving full value in
    the title attribute for accessibility
  - Added translation keys for asset tag label, modal title,
    and success/error toast messages in en-US, ka-GE, and
    ru-RU locale files

Testing:
  - Verified asset tag displays correctly in system info section
  - Verified modal opens, validates, and submits correctly
  - Verified PATCH request updates asset tag on the server
  - Validated success and error toast notifications display
  - Confirmed long asset tags are truncated in the header

Change-Id: I6ac51dfc24b9d40986b74e9220cff955b029d659
Signed-off-by: Nishant Tiwari &lt;tiwari.nishant@ibm.com&gt;
</content>
</entry>
<entry>
<title>Implemented Reboot BMC with TanStack Vue Query</title>
<updated>2026-09-28T08:33:30+00:00</updated>
<author>
<name>Nikhil Ashoka</name>
<email>a.nikhil@ibm.com</email>
</author>
<published>2026-07-21T11:13:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=4628f24b336ea30b288a4b50d42c0e50d8d62869'/>
<id>urn:sha1:4628f24b336ea30b288a4b50d42c0e50d8d62869</id>
<content type='text'>
This change migrates the Reboot BMC page from Vuex to TanStack Query
and Composition API

Key changes:

1. Redfish types (src/api/types/redfish.ts):
- Adds Manager interface with LastResetTime and Actions fields,
  typed in PascalCase to match the Redfish schema

2. BMC reboot composable
(src/components/Composables/useRebootBmc.ts):
- Replaces Vuex controls/getLastBmcRebootTime and controls/rebootBmc
  with a Composition API composable
- Uses useRedfishRoot() to resolve the Managers collection URI from
  ServiceRoot; fetches the first member (the BMC Manager) in queryFn
- Configures staleTime: Infinity and gcTime: Infinity because
  LastResetTime only changes on a reboot; onSuccess invalidation
  handles the one real change event, avoiding unnecessary refetches
- mutationFn is pure (no i18n strings, no toast calls); view owns
  all user-facing messages via try/catch
- onSuccess calls invalidateQueries only (no optimistic update,
  which would be immediately overwritten by the refetch)
- resetTarget prefers Actions['#Manager.Reset'].target from the
  cached Manager, falls back to the conventional Redfish path

3. View modernization
(src/views/Operations/RebootBmc/RebootBmc.vue):
- Refactors from Options API to &lt;script setup&gt;, using useRebootBmc(),
  useLoadingBar(), and useToast() composables
- Loader semantics: isLoading drives the loading bar on first fetch
  only; cached data renders instantly on re-navigation with a silent
  background refetch (no flicker)
- Reboot button disabled when bmcQuery.isError is true, preventing
  mutation dispatch with an unavailable reset target
- Confirm dialog uses eventBus.$emit('confirm:open', ...) directly,
  matching the $confirm global property contract without Options API

4. Store cleanup
(src/store/modules/Operations/ControlStore.js):
- Removes lastBmcRebootTime state, getter, and setLastBmcRebootTime
  mutation (now owned by bmcQuery in the composable)
- Removes getLastBmcRebootTime and rebootBmc actions (replaced by
  useQuery and useMutation in useRebootBmc.ts)
- Removes unused i18n import
- Remaining ControlStore state (isOperationInProgress,
  lastPowerOperationTime) and server power actions are unchanged;
  they are still used by ServerPowerOperations.vue and Firmware.vue

5. Toast rendering fix (src/components/Composables/useToast.ts,
   src/plugins/toast.js):
- Fixes modelValue: false → true for danger/error toasts in both
  the Composition API useToast composable and the Options API
  ToastPlugin; modelValue: false suppressed toast rendering
  entirely in bootstrap-vue-next, making error toasts invisible
  app-wide

Tested-by: Manual testing on development server
- Last BMC reboot time loads correctly from Manager.LastResetTime
- Reboot button triggers GracefulRestart POST; success and error
  toasts display with localized messages
- Loading bar shows on first page load and during reboot POST;
  subsequent visits render cached data instantly
- Read-only user receives the global Unauthorized toast (403
  interceptor) followed by the page-level error toast

Change-Id: I5d49527f176041958e48889d6261780fcffdd9df
Signed-off-by: Nikhil Ashoka &lt;a.nikhil@ibm.com&gt;
</content>
</entry>
<entry>
<title>Added automated security audit</title>
<updated>2026-09-28T08:33:12+00:00</updated>
<author>
<name>Nikhil Ashoka</name>
<email>a.nikhil@ibm.com</email>
</author>
<published>2026-08-13T08:42:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=03f6b0d3eeb5b40e21a697394e391198cef82a5d'/>
<id>urn:sha1:03f6b0d3eeb5b40e21a697394e391198cef82a5d</id>
<content type='text'>
- Add [`.github/workflows/security.yml`](.github/workflows/security.yml)
  to run npm ci with the lockfile enforced and lifecycle scripts
  disabled.
- Run npm audit --audit-level=high --omit=dev against production
  dependencies.
- Trigger the audit on pushes to master and weekly on Monday at 08:00
  UTC.
- Cancel superseded runs and limit each audit job to 10 minutes.

Change-Id: Icd7227de004fd939629312f8af65fb0858c62d5c
Signed-off-by: Nikhil Ashoka &lt;a.nikhil@ibm.com&gt;
</content>
</entry>
<entry>
<title>Fix reversed expand chevron in the event log table</title>
<updated>2026-09-17T03:10:51+00:00</updated>
<author>
<name>Bill Chan</name>
<email>bill_chan@jabil.com</email>
</author>
<published>2026-09-14T02:32:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=8538dca185982882a0d72986f45c6a76c18b4048'/>
<id>urn:sha1:8538dca185982882a0d72986f45c6a76c18b4048</id>
<content type='text'>
The expand button in Event Logs draws its chevron upside down in both
states: collapsed shows an up chevron, expanded shows a down one.

_tables.scss rotates the icon 180 degrees for any button inside a
.table-row-expand cell that does not carry .collapsed:

    .table-row-expand .btn:not(.collapsed) svg {
        transform: rotate(180deg);
    }

EventLogs opts into that rule through tdClass: 'table-row-expand' but
never applies .collapsed to the button, so the selector matches in both
states and the rotation is permanent.  The template swaps two icons by
hand, chevron--down when collapsed and chevron--up when expanded, and
the constant rotation inverts each of them.

The swap predates the rule and was correct when written.  Before
f4861f9 the stylesheet rotated only .btn.collapsed, which these buttons
never match, so nothing was rotated and the explicit icons showed
through.  Inverting the selector to :not(.collapsed) captured every
button that had opted out of the class.

Adopt the pattern the other nine pages using .table-row-expand already
follow, Certificates and every Inventory table among them: bind
.collapsed to the row state and render chevron--down alone, letting the
stylesheet supply the flip.  chevron--down rotated 180 degrees is
chevron--up exactly, the two path definitions mapping onto each other
point for point under (x,y) -&gt; (32-x, 32-y), so the rendered result is
what the template always intended.  IconChevronUp is then unused and is
removed.

Tested:
eslint and vite build are clean on the modified file.  A scan of every
.vue file using .table-row-expand confirms this was the last one not
binding .collapsed; the other nine already did.

Confirmed in a browser: the expand chevron points down while the row
is collapsed and up while it is expanded.

Change-Id: I2b0e28ca31d6a363c3f18cf308f17dbf09e74c0f
Signed-off-by: Bill Chan &lt;bill_chan@jabil.com&gt;
</content>
</entry>
<entry>
<title>Add Socket Firewall workflow for supply-chain checks</title>
<updated>2026-09-15T06:30:20+00:00</updated>
<author>
<name>Nishant Tiwari</name>
<email>tiwari.nishant@ibm.com</email>
</author>
<published>2026-07-28T12:57:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=2ba5c54362a659518b4f2f1d8520757194961871'/>
<id>urn:sha1:2ba5c54362a659518b4f2f1d8520757194961871</id>
<content type='text'>
Integrate Socket Firewall to enable automated dependency supply-chain
vulnerability scanning.

About Socket Firewall (first-time setup — for first-time readers):
  Socket Security [1] analyses npm dependency trees for
  supply-chain risks, typosquatting, protestware, and CVEs that
  traditional vulnerability scanners miss.

  Socket Firewall is their network-layer proxy approach: instead of
  running a separate CLI scan, it intercepts the ordinary `npm install`
  / `npm ci` call and flags any malicious package present within
  codebase.No separate setup or local install is required for the
  workflow added here — the `socketdev/action` handles everything inside
  the GitHub Actions runner.

Why we need this change:
  Recent npm supply-chain attacks demonstrate the real and growing
  risk to projects that depend on third-party packages:

  - Axios npm compromise (Apr 2026) [2]
  - March 2026 supply-chain surge [3]
  - npm threat landscape / supply-chain attacks [4]
  - Red Hat @redhat-cloud-services compromise [5]
  - Keyv/Cacheable npm worm [6]

  Socket provides early visibility against such risks by
  reviewing the npm dependencies used by webui-vue and providing
  security/vulnerability assessments for our packages.

Changes:
  - Added .github/workflows/socket.yml — GitHub Actions workflow that:
  - Triggers on a rolling 3-day schedule (06:00 UTC) and on
    manual workflow_dispatch
  - Checks out the repository and sets up Node.js 22
  - Installs Socket Firewall via the official socketdev/action
    in firewall-free mode
  - Runs `sfw npm ci` through the firewall proxy; the job fails
    if any malicious or typosquatted package is detected

Testing:
  - Verified socket.yml workflow syntax parses without errors
  - Confirmed socketdev/action runs correctly with mode: firewall-free
  - Verified `sfw npm ci` exits non-zero on a known-bad test package

[1]: https://socket.dev
[2]: https://www.cisa.gov/news-events/alerts/2026/04/20/supply-chain-compromise-impacts-axios-node-package-manager
[3]: https://www.zscaler.com/blogs/security-research/supply-chain-attacks-surge-march-2026
[4]: https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/
[5]: https://access.redhat.com/security/vulnerabilities/RHSB-2026-006
[6]: https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack

Signed-off-by: Nishant Tiwari &lt;tiwari.nishant@ibm.com&gt;
Change-Id: I30384c351afe86cf660dab430e1bd68344c5c8d3
</content>
</entry>
<entry>
<title>Revert policy selection on save error</title>
<updated>2026-09-15T06:29:40+00:00</updated>
<author>
<name>Vedangi Mittal</name>
<email>vedangimittal3004@gmail.com</email>
</author>
<published>2026-08-20T09:57:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=de35b5132d1af03ba119068fe14e5c31294d2b46'/>
<id>urn:sha1:de35b5132d1af03ba119068fe14e5c31294d2b46</id>
<content type='text'>
When a readonly user changes the policy and clicks save,
the failed request left the radio group stuck on the new
selection.
Replace the split computed getter/setter with
a local `selectedPolicy` data property and explicitly
reset it to the store value on error.

Change-Id: I1785384f0a654c8daa447a70e44336bb22ffa4d2
Signed-off-by: Vedangi Mittal &lt;vedangimittal3004@gmail.com&gt;
</content>
</entry>
<entry>
<title>docs: Rework webui-vue offline build/SBOM design</title>
<updated>2026-09-11T01:12:10+00:00</updated>
<author>
<name>Jason Westover</name>
<email>jwestover@nvidia.com</email>
</author>
<published>2026-06-27T17:08:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=a8722a6060aceb5e4d8f5e16edf3c9acb856c642'/>
<id>urn:sha1:a8722a6060aceb5e4d8f5e16edf3c9acb856c642</id>
<content type='text'>
Rewrite the design around one decision: how to make webui-vue build
offline and report per-dependency licenses using Yocto-native
mechanisms.

Recommend teaching autobump to generate per-component Yocto recipes
from package-lock.json (a webui-vue-specific special case that
changes no other recipe's build). Every npm dependency then fetches
like any other recipe, and the image SBOM comes for free via
per-recipe LICENSE and create-spdx. The webui-vue recipe is
rewritten to DEPENDS on those recipes and build Vite offline;
there is no separate pre-fetch step.

Demote pre-built dist and ad-hoc npm pre-fetch to rejected/deferred
alternatives, and abandon the repo-root CycloneDX/git-hook approach
(91792). Incorporate maintainer review feedback: shorter and
decision-focused, with no inlined recipe files.

Change-Id: I7d73812cc91079080af80f22cba49cf19279b839
Signed-off-by: Jason Westover &lt;jwestover@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Security: Pin floating package versions</title>
<updated>2026-08-31T14:19:17+00:00</updated>
<author>
<name>Nikhil Ashoka</name>
<email>a.nikhil@ibm.com</email>
</author>
<published>2026-08-17T15:39:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=1bb0ea03be00cd8df686771491f33d5b1b363298'/>
<id>urn:sha1:1bb0ea03be00cd8df686771491f33d5b1b363298</id>
<content type='text'>
- Remove ^ from the two packages that allowed silent auto-updates
  on every npm install, closing the door on ChainDrop-style npm
  supply-chain attacks where a compromised higher patch/minor
  version is pulled in without review:
    - @typescript-eslint/eslint-plugin: ^8.55.0 → 8.56.1
    - @typescript-eslint/parser:        ^8.55.0 → 8.56.1

Change-Id: Ie8b3878ce2aeaee6a89ee9e4681a6088aa3de770
Signed-off-by: Nikhil Ashoka &lt;a.nikhil@ibm.com&gt;
</content>
</entry>
<entry>
<title>Fix form conditions that test nonexistent properties</title>
<updated>2026-08-28T02:47:57+00:00</updated>
<author>
<name>Bill Chan</name>
<email>bill_chan@jabil.com</email>
</author>
<published>2026-08-25T09:53:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=5c139d53429a8309418a19f226d0c3d4c0c6b8be'/>
<id>urn:sha1:5c139d53429a8309418a19f226d0c3d4c0c6b8be</id>
<content type='text'>
Four conditions read a property that does not exist, so none of them
evaluates the way its author intended.

DateTime guards a block that shifts the third NTP address into the
second slot after a successful save.  The condition reads
this.form.ntp.thirdAddres, while the form model defines thirdAddress,
so it has never been true.  Correcting the name would not make the
block run: submitForm filters the empty entry out of the request and
then calls setNtpValues(), which rebuilds form.ntp from the compacted
list, so by the time the callback runs the second address is already
populated and the third already empty.  updateDateTime does not commit
ntpServers either, so the watcher cannot reopen a hole.  Remove the
block rather than correct the name - a correctly spelled condition
that is always false reads as live code, and invites a later refactor
to revive a shift that would then run twice.  The guard above it,
if (!isNTPEnabled) return, existed only to protect that block and goes
with it.

ModalSettings and ModalAddDestination test validators that are not
declared.  lockoutDuration is validated by minValue but the template
reads minvalue; lockoutThreshold and port are validated by minValue
and maxValue but their templates read minLength and maxLength.  Each
reference yields undefined and the conditions negate it, so the branch
is taken every time the invalid-feedback block renders, leaving the
range message in the DOM even for a valid field, where CSS hides it.
The message that appears is the right one today only because each of
those fields has a single other validator; it would become wrong,
silently, as soon as another one is added.

Test the validator's $invalid flag instead, which is the form these
same files already use for required.$invalid and ipAddress.$invalid.
Negating the validator entry itself would not work either: in
Vuelidate 2 it is an object, so the branch would never be taken.

Tested:
In a browser against a QEMU BMC, machine cypress, with each case run
on this commit and on its parent.

Settings &gt; Date and time, NTP selected, first address set, second
empty, third set: after Save the third value appears in the second
field within 100ms and the third field is empty, identically before
and after this change.  That compaction is setNtpValues() inside
submitForm, not the removed block.  The success toast still appears.

Account policy settings: a lockout threshold of 99999 reports "Value
must be between 0 - 65535" and an empty one reports "Field required";
with unlock method set to manual, a lockout duration of 0 reports
"Must be at least 1" and an empty one "Field required".  SNMP alerts &gt;
Add destination: a port of 99999 and a port of abc both report "Value
must be between 0 - 65535", while 161 and empty are accepted.  Every
one of those messages is identical before and after.  The only
difference observed is that before this change the range message is
present but hidden for a valid field, and after it nothing is
rendered.

Also verified that every corrected name is declared where it is now
read, that a scan of all .vue files reports no Vuelidate reference
whose validator is undeclared in the same file, that eslint passes on
all three files, and that prettier 3.4.2 reports both modal files
clean.

Change-Id: Ib59a22296452e890877e784d3077b166d6d81fc5
Signed-off-by: Bill Chan &lt;bill_chan@jabil.com&gt;
</content>
</entry>
<entry>
<title>Fix auth popup on login page with env builds</title>
<updated>2026-08-20T14:29:19+00:00</updated>
<author>
<name>Jason M. Bills</name>
<email>jason.m.bills@linux.intel.com</email>
</author>
<published>2026-08-18T17:19:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/webui-vue.git/commit/?id=11d1e040453b9494c0447ee70ae13c45bd5b4202'/>
<id>urn:sha1:11d1e040453b9494c0447ee70ae13c45bd5b4202</id>
<content type='text'>
The ~@/ prefix in @font-face url() declarations is webpack-specific
syntax. Vite 6 does not strip the tilde, so the font URLs are left
unresolved in the compiled CSS output and the font files are never
emitted to dist/.

When the browser loads the login page and requests a font at the
broken path, bmcweb cannot find a matching route in webroutes::routes
and — because no session exists — returns 401 with
WWW-Authenticate: Basic, triggering the browser credentials popup.

Remove the leading ~ so Vite resolves the @/ alias correctly, copies
the font files into dist/assets/, and rewrites the CSS references to
proper absolute paths that bmcweb registers and serves without auth.

Fixes both _intel.scss and _ibm.scss which share the same pattern.

Tested:
Confirmed that with .env.intel loaded, there is no longer an auth popup
when loading the login page.

Change-Id: Ie2a40bed55da057ae75bac111736cb947bac5dc4
Signed-off-by: Jason M. Bills &lt;jason.m.bills@linux.intel.com&gt;
</content>
</entry>
</feed>
