Skip to content

Fixes #31560 - Replace UUID v1 with v4 in JavaScript code - #10934

Closed
jakduch wants to merge 1 commit into
theforeman:developfrom
jakduch:fix/replace-uuid-v1-with-v4
Closed

jakduch wants to merge 1 commit into
theforeman:developfrom
jakduch:fix/replace-uuid-v1-with-v4

Conversation

@jakduch

@jakduch jakduch commented Mar 28, 2026

Copy link
Copy Markdown
Contributor

Fixes https://projects.theforeman.org/issues/31560

Summary

UUID v1 is timestamp-based and includes MAC address information, which is unnecessary and potentially a minor privacy concern for generating React component keys and chart element IDs. UUID v4 is random-based and more appropriate for these use cases.

Changes

  • Replace all uuid/v1 imports with uuid/v4 across 8 files
  • Rename uuidV1 variable references to uuidV4 for consistency
  • Update test mocks to use uuid/v4

No functional change — both produce valid UUIDs suitable for unique key generation.

@ofedoren ofedoren left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, @jakduch, it's a small, but a neat change :)

Although, I'd like to have another ACK from someone more UI/JS talented people.

Maybe @MariaAga have a bit of spare time to take a look? Also, could we bump the package version to a newer one? We currently use 3.3.2, whilst the latest is 13.0.0. I mean, we could probably bump few versions if latest is not compatible. There were some nice changes.

@jakduch

jakduch commented Apr 2, 2026

Copy link
Copy Markdown
Contributor Author

Thanks for the initiative! I've opened #10944 which builds on this - it bumps uuid all the way to v13 and migrates the imports to named exports (import { v4 } from 'uuid'), as @ofedoren suggested. Deep import paths like uuid/v1 were removed in uuid v7, so the version bump requires the import style change anyway.

This PR can be closed in favor of #10944 if CI passes there, or we can keep both open and see which one gets through first. Either way, thanks for kicking this off!

UUID v1 is timestamp-based and leaks MAC address information.
UUID v4 is random-based and more appropriate for generating unique
identifiers for React component keys and chart element IDs.

Replace all uuid/v1 imports with uuid/v4 and rename uuidV1
variables to uuidV4 for consistency.
@jakduch
jakduch force-pushed the fix/replace-uuid-v1-with-v4 branch from 329ac26 to 8fe5d4f Compare September 26, 2026 11:39
@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #10944, which also addresses the requested dependency upgrade and replaces the removed deep imports.

@jakduch jakduch closed this Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants