Fix: Fix Improper privilege management in server.py (#1789)

Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
(cherry picked from commit 3ea29d3f231dd66bd7627769b5659564be4525df)
This commit is contained in:
corridor-security[bot] 2026-07-20 02:18:26 +00:00 • committed by Adam Moussa
parent 0f0f616cd4
commit 780d980efb
No known key found for this signature in database
2 changed files with 6 additions and 0 deletions

View file

@ -63,6 +63,9 @@ def verify_github_signature(body: bytes, signature: str, *, secret: str) -> bool
logger.warning("GITHUB_WEBHOOK_SECRET is not configured — rejecting webhook request")
return False
if not signature:
return False
expected = "sha256=" + hmac.new(secret.encode(), body, hashlib.sha256).hexdigest()
return hmac.compare_digest(expected, signature)

View file

@ -1164,6 +1164,9 @@ def verify_linear_signature(body: bytes, signature: str, secret: str) -> bool:
logger.warning("LINEAR_WEBHOOK_SECRET is not configured — rejecting webhook request")
return False
if not signature:
return False
expected = hmac.new(secret.encode("utf-8"), body, hashlib.sha256).hexdigest()
if not hmac.compare_digest(expected, signature):
return False