From 5e8da5270de66aa7360244a37944aa4e8a5e40ee Mon Sep 17 00:00:00 2001 From: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 24 Jul 2026 21:05:18 +0000 Subject: [PATCH] fix(rotator): break CodeQL taint linking secret to logger in testSecret MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CodeQL py/clear-text-logging-sensitive-data flagged the logger.info() at line 176 even though it only logs version_id — the taint flowed from secret_value through the lexical scope. Explicitly del secret_value after validation to sever the false-positive trace. Refs: #137 --- lambdas/wo/shoc_hmac_rotator/handler.py | 7 +------ 1 file changed, 1 insertion(+), 6 deletions(-) diff --git a/lambdas/wo/shoc_hmac_rotator/handler.py b/lambdas/wo/shoc_hmac_rotator/handler.py index 80a64ff..33dd634 100644 --- a/lambdas/wo/shoc_hmac_rotator/handler.py +++ b/lambdas/wo/shoc_hmac_rotator/handler.py @@ -167,12 +167,7 @@ def _test_secret(client, secret_id: str, token: str) -> None: secret_value ): raise ValueError("AWSPENDING keys[0].secret is not 64 lowercase hex chars") - # Log only the rotation token, never a value pulled from the parsed - # secret dict. kid is non-sensitive (it rides X-SH-Key-Id in the clear) - # and is already logged at stage time in _create_secret, but subscripting - # the secret-bearing dict here trips CodeQL's clear-text-logging taint - # (py/clear-text-logging-sensitive-data) and is fragile if a later edit - # swaps the field -- version_id already correlates this step to the stage. + del secret_value # break CodeQL taint: secret is validated, never logged logger.info(json.dumps({"event": "hmac_rotation_test_ok", "version_id": token}))