mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-01 07:23:14 +00:00
Fix: Fix Improper privilege management in server.py (#1789)
Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com> (cherry picked from commit 3ea29d3f231dd66bd7627769b5659564be4525df)
This commit is contained in:
parent
0f0f616cd4
commit
780d980efb
2 changed files with 6 additions and 0 deletions
|
|
@ -63,6 +63,9 @@ def verify_github_signature(body: bytes, signature: str, *, secret: str) -> bool
|
|||
logger.warning("GITHUB_WEBHOOK_SECRET is not configured — rejecting webhook request")
|
||||
return False
|
||||
|
||||
if not signature:
|
||||
return False
|
||||
|
||||
expected = "sha256=" + hmac.new(secret.encode(), body, hashlib.sha256).hexdigest()
|
||||
return hmac.compare_digest(expected, signature)
|
||||
|
||||
|
|
|
|||
|
|
@ -1164,6 +1164,9 @@ def verify_linear_signature(body: bytes, signature: str, secret: str) -> bool:
|
|||
logger.warning("LINEAR_WEBHOOK_SECRET is not configured — rejecting webhook request")
|
||||
return False
|
||||
|
||||
if not signature:
|
||||
return False
|
||||
|
||||
expected = hmac.new(secret.encode("utf-8"), body, hashlib.sha256).hexdigest()
|
||||
if not hmac.compare_digest(expected, signature):
|
||||
return False
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue