fix(agent-team): clear CodeQL URL-substring alert in confluence client test
The host assertion used `url.startswith("https://seahaven.atlassian.net")`,
which CodeQL flags (incomplete URL substring sanitization — a spoofed host like
`...atlassian.net.evil.com` passes a prefix check). Parse the URL and compare
scheme+netloc exactly instead. (PR #66 review finding.)
This commit is contained in:
parent
0ff0ce2849
commit
9ee2e3c127
1 changed files with 7 additions and 1 deletions
|
|
@ -296,7 +296,13 @@ def test_client_uses_injected_env_mapping() -> None:
|
|||
client = ConfluenceClient(http=http, env=env)
|
||||
fetched = client.get_page("100")
|
||||
assert fetched["version"]["number"] == 4
|
||||
assert http.calls[0]["url"].startswith("https://seahaven.atlassian.net")
|
||||
# Assert the request host EXACTLY (scheme+netloc parsed), not a string prefix:
|
||||
# a `.startswith("https://seahaven.atlassian.net")` check passes for a spoofed
|
||||
# host like `https://seahaven.atlassian.net.evil.com` (CodeQL: incomplete URL
|
||||
# substring sanitization). Compare the parsed components instead.
|
||||
parts = _urlparse.urlsplit(http.calls[0]["url"])
|
||||
assert (parts.scheme, parts.netloc) == ("https", "seahaven.atlassian.net")
|
||||
assert parts.path.startswith("/wiki/api/v2/pages/100")
|
||||
|
||||
|
||||
# --------------------------------------------------------------------------- #
|
||||
|
|
|
|||
Reference in a new issue