From ae4e2740a82701cce85bc27d14b5d6da5fd1ddcb Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 27 Jul 2026 13:31:01 -0400 Subject: [PATCH] fix(logging): remove taint-flagged values from 3CX and roster-sync logs Resolves code-scanning alerts 12-15 (py/clear-text-logging-sensitive-data). CodeQL taints the 3CX response dicts via the Secrets Manager-sourced domain in the request URL, so entity IDs subscripted from those responses (ivr_id, resource_id, queue_id) and the roster result dict trip the query. None of the flagged values are secrets, but the log lines are rewritten so the pattern cannot trip: entity IDs are dropped in favor of the untainted destination DNs, and the roster summary logs counts instead of the member-derived dict (which also keeps employee names out of the logs). --- src/roster-sync/app.py | 9 ++++++++- src/shared/shared/three_cx_client.py | 10 +++++----- 2 files changed, 13 insertions(+), 6 deletions(-) diff --git a/src/roster-sync/app.py b/src/roster-sync/app.py index 935884c..116f097 100644 --- a/src/roster-sync/app.py +++ b/src/roster-sync/app.py @@ -119,5 +119,12 @@ def handler(event, context): "updated": updated, "removed": removed, } - logger.info("Roster sync complete: %s", result) + logger.info( + "Roster sync complete: group=%s total_3cx=%d added=%d updated=%d removed=%d", + group_name, + len(threecx_extensions), + len(added), + len(updated), + len(removed), + ) return result diff --git a/src/shared/shared/three_cx_client.py b/src/shared/shared/three_cx_client.py index ae4d7fe..b07103c 100644 --- a/src/shared/shared/three_cx_client.py +++ b/src/shared/shared/three_cx_client.py @@ -102,7 +102,9 @@ class ThreeCXClient: json=payload, ) resp.raise_for_status() - logger.info("Updated %s %s forwarding", resource, resource_id) + logger.info( + "Updated %s forwarding closed=%s holiday=%s", resource, closed, holiday + ) return resp.status_code def get_ring_group(self, extension_number: str) -> dict: @@ -142,7 +144,7 @@ class ThreeCXClient: json=payload, ) resp.raise_for_status() - logger.info("Set queue %s agents to %s", queue_id, extensions) + logger.info("Set queue agents to %s", extensions) return resp.status_code # ── IVR (auto-attendant) routing ───────────────────────────────────── @@ -207,9 +209,7 @@ class ThreeCXClient: json=payload, ) resp.raise_for_status() - logger.info( - "Set IVR (Receptionist) %s key-0=%s timeout=%s", ivr_id, key0_dn, timeout_dn - ) + logger.info("Set IVR (Receptionist) key-0=%s timeout=%s", key0_dn, timeout_dn) return resp.status_code @staticmethod