From f996f9600b5c31e64bdb830084ca953e3fd7ff2e Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 27 Jul 2026 13:48:14 -0400 Subject: [PATCH] fix: resolve code-scanning alerts 11-15 (workflow permissions + log taint) (#184) * ci(dependency-review): set explicit read-only GITHUB_TOKEN permissions Resolves code-scanning alert 11 (actions/missing-workflow-permissions). The callable workflow only needs contents: read. * fix(logging): remove taint-flagged values from 3CX and roster-sync logs Resolves code-scanning alerts 12-15 (py/clear-text-logging-sensitive-data). CodeQL taints the 3CX response dicts via the Secrets Manager-sourced domain in the request URL, so entity IDs subscripted from those responses (ivr_id, resource_id, queue_id) and the roster result dict trip the query. None of the flagged values are secrets, but the log lines are rewritten so the pattern cannot trip: entity IDs are dropped in favor of the untainted destination DNs, and the roster summary logs counts instead of the member-derived dict (which also keeps employee names out of the logs). * fix: update ci workflow SHA to latest version * fix(logging): drop employee-derived DNs from forwarding log Resolves new code-scanning alerts 16/17. The closed/holiday DNs added in the previous commit derive from roster employee lookups in the Slack bot, so CodeQL classifies them as private data. Log only the resource type; ring_scheduler already logs the queue number. --- .github/workflows/ci.yaml | 2 +- .github/workflows/dependency-review.yml | 2 ++ src/roster-sync/app.py | 9 ++++++++- src/shared/shared/three_cx_client.py | 8 +++----- 4 files changed, 14 insertions(+), 7 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index cfc13d2..f351bfa 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -8,7 +8,7 @@ permissions: jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@f71002a9ed2938730b683249b28059c92a081af6 with: source-dirs: "src/slack-bot src/weekly-post src/roster-sync src/ring-scheduler src/shared/shared tests" run-tests: true diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 2cd8119..0fa94ff 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,6 +1,8 @@ name: Dependency Review on: pull_request: +permissions: + contents: read jobs: review: uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main diff --git a/src/roster-sync/app.py b/src/roster-sync/app.py index 935884c..116f097 100644 --- a/src/roster-sync/app.py +++ b/src/roster-sync/app.py @@ -119,5 +119,12 @@ def handler(event, context): "updated": updated, "removed": removed, } - logger.info("Roster sync complete: %s", result) + logger.info( + "Roster sync complete: group=%s total_3cx=%d added=%d updated=%d removed=%d", + group_name, + len(threecx_extensions), + len(added), + len(updated), + len(removed), + ) return result diff --git a/src/shared/shared/three_cx_client.py b/src/shared/shared/three_cx_client.py index ae4d7fe..8dde050 100644 --- a/src/shared/shared/three_cx_client.py +++ b/src/shared/shared/three_cx_client.py @@ -102,7 +102,7 @@ class ThreeCXClient: json=payload, ) resp.raise_for_status() - logger.info("Updated %s %s forwarding", resource, resource_id) + logger.info("Updated %s forwarding", resource) return resp.status_code def get_ring_group(self, extension_number: str) -> dict: @@ -142,7 +142,7 @@ class ThreeCXClient: json=payload, ) resp.raise_for_status() - logger.info("Set queue %s agents to %s", queue_id, extensions) + logger.info("Set queue agents to %s", extensions) return resp.status_code # ── IVR (auto-attendant) routing ───────────────────────────────────── @@ -207,9 +207,7 @@ class ThreeCXClient: json=payload, ) resp.raise_for_status() - logger.info( - "Set IVR (Receptionist) %s key-0=%s timeout=%s", ivr_id, key0_dn, timeout_dn - ) + logger.info("Set IVR (Receptionist) key-0=%s timeout=%s", key0_dn, timeout_dn) return resp.status_code @staticmethod