From 780d980efb572b7195f50f5f849269da358181fd Mon Sep 17 00:00:00 2001 From: "corridor-security[bot]" <203152403+corridor-security[bot]@users.noreply.github.com> Date: Mon, 20 Jul 2026 02:18:26 +0000 Subject: [PATCH] Fix: Fix Improper privilege management in server.py (#1789) Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com> (cherry picked from commit 3ea29d3f231dd66bd7627769b5659564be4525df) --- agent/utils/github_comments.py | 3 +++ agent/webhooks/common.py | 3 +++ 2 files changed, 6 insertions(+) diff --git a/agent/utils/github_comments.py b/agent/utils/github_comments.py index 5c494e3d..083d2112 100644 --- a/agent/utils/github_comments.py +++ b/agent/utils/github_comments.py @@ -63,6 +63,9 @@ def verify_github_signature(body: bytes, signature: str, *, secret: str) -> bool logger.warning("GITHUB_WEBHOOK_SECRET is not configured — rejecting webhook request") return False + if not signature: + return False + expected = "sha256=" + hmac.new(secret.encode(), body, hashlib.sha256).hexdigest() return hmac.compare_digest(expected, signature) diff --git a/agent/webhooks/common.py b/agent/webhooks/common.py index 97296fed..c47a2bb5 100644 --- a/agent/webhooks/common.py +++ b/agent/webhooks/common.py @@ -1164,6 +1164,9 @@ def verify_linear_signature(body: bytes, signature: str, secret: str) -> bool: logger.warning("LINEAR_WEBHOOK_SECRET is not configured — rejecting webhook request") return False + if not signature: + return False + expected = hmac.new(secret.encode("utf-8"), body, hashlib.sha256).hexdigest() if not hmac.compare_digest(expected, signature): return False