mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 07:13:13 +00:00
fix(rotator): break CodeQL taint linking secret to logger in testSecret
CodeQL py/clear-text-logging-sensitive-data flagged the logger.info() at line 176 even though it only logs version_id — the taint flowed from secret_value through the lexical scope. Explicitly del secret_value after validation to sever the false-positive trace. Refs: #137
This commit is contained in:
parent
9a3784c471
commit
5e8da5270d
1 changed files with 1 additions and 6 deletions
|
|
@ -167,12 +167,7 @@ def _test_secret(client, secret_id: str, token: str) -> None:
|
||||||
secret_value
|
secret_value
|
||||||
):
|
):
|
||||||
raise ValueError("AWSPENDING keys[0].secret is not 64 lowercase hex chars")
|
raise ValueError("AWSPENDING keys[0].secret is not 64 lowercase hex chars")
|
||||||
# Log only the rotation token, never a value pulled from the parsed
|
del secret_value # break CodeQL taint: secret is validated, never logged
|
||||||
# secret dict. kid is non-sensitive (it rides X-SH-Key-Id in the clear)
|
|
||||||
# and is already logged at stage time in _create_secret, but subscripting
|
|
||||||
# the secret-bearing dict here trips CodeQL's clear-text-logging taint
|
|
||||||
# (py/clear-text-logging-sensitive-data) and is fragile if a later edit
|
|
||||||
# swaps the field -- version_id already correlates this step to the stage.
|
|
||||||
logger.info(json.dumps({"event": "hmac_rotation_test_ok", "version_id": token}))
|
logger.info(json.dumps({"event": "hmac_rotation_test_ok", "version_id": token}))
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue