fix(logging): remove taint-flagged values from 3CX and roster-sync logs

Resolves code-scanning alerts 12-15 (py/clear-text-logging-sensitive-data).
CodeQL taints the 3CX response dicts via the Secrets Manager-sourced
domain in the request URL, so entity IDs subscripted from those
responses (ivr_id, resource_id, queue_id) and the roster result dict
trip the query. None of the flagged values are secrets, but the log
lines are rewritten so the pattern cannot trip: entity IDs are dropped
in favor of the untainted destination DNs, and the roster summary logs
counts instead of the member-derived dict (which also keeps employee
names out of the logs).
This commit is contained in:
Adam Moussa 2026-07-27 13:31:01 -04:00
parent c46480e3d7
commit ae4e2740a8
No known key found for this signature in database
2 changed files with 13 additions and 6 deletions

View file

@ -119,5 +119,12 @@ def handler(event, context):
"updated": updated,
"removed": removed,
}
logger.info("Roster sync complete: %s", result)
logger.info(
"Roster sync complete: group=%s total_3cx=%d added=%d updated=%d removed=%d",
group_name,
len(threecx_extensions),
len(added),
len(updated),
len(removed),
)
return result

View file

@ -102,7 +102,9 @@ class ThreeCXClient:
json=payload,
)
resp.raise_for_status()
logger.info("Updated %s %s forwarding", resource, resource_id)
logger.info(
"Updated %s forwarding closed=%s holiday=%s", resource, closed, holiday
)
return resp.status_code
def get_ring_group(self, extension_number: str) -> dict:
@ -142,7 +144,7 @@ class ThreeCXClient:
json=payload,
)
resp.raise_for_status()
logger.info("Set queue %s agents to %s", queue_id, extensions)
logger.info("Set queue agents to %s", extensions)
return resp.status_code
# ── IVR (auto-attendant) routing ─────────────────────────────────────
@ -207,9 +209,7 @@ class ThreeCXClient:
json=payload,
)
resp.raise_for_status()
logger.info(
"Set IVR (Receptionist) %s key-0=%s timeout=%s", ivr_id, key0_dn, timeout_dn
)
logger.info("Set IVR (Receptionist) key-0=%s timeout=%s", key0_dn, timeout_dn)
return resp.status_code
@staticmethod