fix(webhook): drop kid from rotator test_ok log (CodeQL clear-text-logging FP)

GHAS CodeQL flagged py/clear-text-logging-sensitive-data (high) at
_test_secret's success log because head["kid"] is subscripted from the
same parsed-secret dict that holds head["secret"] — the taint tracker
can't tell the non-secret key id from the secret. The secret value is
never logged. Rather than dismiss the alert (fragile; re-alerts on line
moves), remove the flow: kid is already logged at stage time in
_create_secret and version_id correlates the steps, so the test_ok log
keeps only event + version_id. Also hardens against a future edit that
swaps the logged field.
This commit is contained in:
Adam Moussa 2026-07-24 16:51:55 -04:00
parent 7569bd8250
commit 9a3784c471
No known key found for this signature in database

View file

@ -167,15 +167,13 @@ def _test_secret(client, secret_id: str, token: str) -> None:
secret_value secret_value
): ):
raise ValueError("AWSPENDING keys[0].secret is not 64 lowercase hex chars") raise ValueError("AWSPENDING keys[0].secret is not 64 lowercase hex chars")
logger.info( # Log only the rotation token, never a value pulled from the parsed
json.dumps( # secret dict. kid is non-sensitive (it rides X-SH-Key-Id in the clear)
{ # and is already logged at stage time in _create_secret, but subscripting
"event": "hmac_rotation_test_ok", # the secret-bearing dict here trips CodeQL's clear-text-logging taint
"version_id": token, # (py/clear-text-logging-sensitive-data) and is fragile if a later edit
"kid": head["kid"], # swaps the field -- version_id already correlates this step to the stage.
} logger.info(json.dumps({"event": "hmac_rotation_test_ok", "version_id": token}))
)
)
def _finish_secret(client, secret_id: str, token: str) -> None: def _finish_secret(client, secret_id: str, token: str) -> None: