Conversation
5013534 to
6b133ce
Compare
6b133ce to
58d78f3
Compare
58d78f3 to
5a88abe
Compare
9fbffb7 to
7fd3fa1
Compare
7fd3fa1 to
aaa91ce
Compare
aaa91ce to
d03cdbf
Compare
d03cdbf to
0f2f787
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved critical access-control, data-integrity, and API contract issues remain.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 5
Open (9)
Generic relationship routes bypass binary ACL checks · New Hashtype updates bypass binary access control · New Reverse relationship exposes inaccessible binaries · New Join table lacks unique constraint for concurrent inserts · New Migration lacks unique constraint for associations · New Relationship schemas overwrite task relationship paths · New Spec advertises unsupported readonly relationship mutations · New Relationship linkage uses plural instead of resource type · New Reverse relationship linkage uses plural resource type · New
What changed in this PR
Adds cracker-binary/hash-type associations, automatic hashcat linking, API management, lifecycle cleanup, OpenAPI updates, and tests.
Changes:
- Adds association schemas, models, factories, and backfill logic.
- Exposes bidirectional API relationships.
- Adds lifecycle handling, documentation, and test coverage.
| File | Summary |
|---|---|
src/migrations/postgres/20260918091600_cracker-binary-hashtypes.sql |
PostgreSQL association schema and backfill |
src/migrations/mysql/20260918091600_cracker-binary-hashtypes.sql |
MySQL association schema and backfill |
src/inc/utils/HashtypeUtils.php |
Hash-type association lifecycle |
src/inc/utils/CrackerUtils.php |
Binary association management and cleanup |
src/inc/startup/setup.php |
Initial hashcat association backfill |
src/inc/apiv2/model/HashTypeAPI.php |
Reverse relationship API |
src/inc/apiv2/model/CrackerBinaryAPI.php |
Editable hashtype relationship API |
src/inc/apiv2/common/AbstractBaseAPI.php |
Factory and permission registration |
src/dba/models/generator.php |
Association model metadata |
src/dba/models/CrackerBinaryHashtypeFactory.php |
Association factory |
src/dba/models/CrackerBinaryHashtype.php |
Association model |
src/dba/Factory.php |
Factory registration |
openapi.json |
Generated API specification |
ci/phpunit/TestBase.php |
Association test cleanup |
ci/phpunit/inc/utils/HashtypeUtilsTest.php |
Hash-type lifecycle tests |
ci/phpunit/inc/utils/CrackerUtilsTest.php |
Binary association tests |
ci/phpunit/inc/apiv2/openapi/SpecBuilderModelApiTest.php |
OpenAPI relationship fixture coverage |
ci/phpunit/fixtures/openapi/hashtype.spec.json |
Hash-type OpenAPI fixture |
ci/apiv2/test_hashtype.py |
Reverse relationship tests |
ci/apiv2/test_cracker.py |
Cracker relationship API tests |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
c5712e8 to
23994f1
Compare
| CREATE TABLE `CrackerBinaryHashtype` ( | ||
| `crackerBinaryHashtypeId` int NOT NULL AUTO_INCREMENT, | ||
| `crackerBinaryId` int NOT NULL, | ||
| `hashTypeId` int NOT NULL, |
There was a problem hiding this comment.
Not 100% sure, but it could perhaps help to put an index on hashtype id, because a frequent search path would be 'select * where hashtypeid = ? innerjoin crackerbinary', since on the task page, we want to load all crackerbinaries that can crack this hashtype, which has to change evrytime a new hashtype is selected. Maybe we also need a helper endpoint to optimise the query if the default tomany relation ship endpoint is not good enough to use the index
23994f1 to
a14443c
Compare
a14443c to
e98feac
Compare


Adds support for defining which hash types each cracker binary can process.
Hashcat binaries are associated with all available hash types automatically, including hash types added later. Other cracker types start without associations, allowing users to explicitly configure only the hash types they support.
Supported hash types can be viewed and managed through the cracker binary API. The reverse relationship is also visible on each hash type, making it possible to determine which cracker binaries support it.
Associations are kept consistent when cracker binaries or hash types are deleted.
NOTE: the edit relations part for crackers which are of binary 'hashcat' is only "temporary", in the next stack PR, this will be superseded by automation. This will then only be used for generic crackers.