fix(rotator): break CodeQL taint linking secret to logger in testSecret

CodeQL py/clear-text-logging-sensitive-data flagged the logger.info() at
line 176 even though it only logs version_id — the taint flowed from
secret_value through the lexical scope. Explicitly del secret_value
after validation to sever the false-positive trace.

Refs: #137
This commit is contained in:
amoussa1229 2026-07-24 21:05:18 +00:00
parent 9a3784c471
commit 5e8da5270d

View file

@ -167,12 +167,7 @@ def _test_secret(client, secret_id: str, token: str) -> None:
secret_value secret_value
): ):
raise ValueError("AWSPENDING keys[0].secret is not 64 lowercase hex chars") raise ValueError("AWSPENDING keys[0].secret is not 64 lowercase hex chars")
# Log only the rotation token, never a value pulled from the parsed del secret_value # break CodeQL taint: secret is validated, never logged
# secret dict. kid is non-sensitive (it rides X-SH-Key-Id in the clear)
# and is already logged at stage time in _create_secret, but subscripting
# the secret-bearing dict here trips CodeQL's clear-text-logging taint
# (py/clear-text-logging-sensitive-data) and is fragile if a later edit
# swaps the field -- version_id already correlates this step to the stage.
logger.info(json.dumps({"event": "hmac_rotation_test_ok", "version_id": token})) logger.info(json.dumps({"event": "hmac_rotation_test_ok", "version_id": token}))