fix(agent-team): clear CodeQL URL-substring alert in confluence client test
The host assertion used `url.startswith("https://seahaven.atlassian.net")`,
which CodeQL flags (incomplete URL substring sanitization — a spoofed host like
`...atlassian.net.evil.com` passes a prefix check). Parse the URL and compare
scheme+netloc exactly instead. (PR #66 review finding.)
This commit is contained in:
parent
0ff0ce2849
commit
9ee2e3c127
1 changed files with 7 additions and 1 deletions
|
|
@ -296,7 +296,13 @@ def test_client_uses_injected_env_mapping() -> None:
|
||||||
client = ConfluenceClient(http=http, env=env)
|
client = ConfluenceClient(http=http, env=env)
|
||||||
fetched = client.get_page("100")
|
fetched = client.get_page("100")
|
||||||
assert fetched["version"]["number"] == 4
|
assert fetched["version"]["number"] == 4
|
||||||
assert http.calls[0]["url"].startswith("https://seahaven.atlassian.net")
|
# Assert the request host EXACTLY (scheme+netloc parsed), not a string prefix:
|
||||||
|
# a `.startswith("https://seahaven.atlassian.net")` check passes for a spoofed
|
||||||
|
# host like `https://seahaven.atlassian.net.evil.com` (CodeQL: incomplete URL
|
||||||
|
# substring sanitization). Compare the parsed components instead.
|
||||||
|
parts = _urlparse.urlsplit(http.calls[0]["url"])
|
||||||
|
assert (parts.scheme, parts.netloc) == ("https", "seahaven.atlassian.net")
|
||||||
|
assert parts.path.startswith("/wiki/api/v2/pages/100")
|
||||||
|
|
||||||
|
|
||||||
# --------------------------------------------------------------------------- #
|
# --------------------------------------------------------------------------- #
|
||||||
|
|
|
||||||
Reference in a new issue