mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 07:13:13 +00:00
fix(webhook): drop kid from rotator test_ok log (CodeQL clear-text-logging FP)
GHAS CodeQL flagged py/clear-text-logging-sensitive-data (high) at _test_secret's success log because head["kid"] is subscripted from the same parsed-secret dict that holds head["secret"] — the taint tracker can't tell the non-secret key id from the secret. The secret value is never logged. Rather than dismiss the alert (fragile; re-alerts on line moves), remove the flow: kid is already logged at stage time in _create_secret and version_id correlates the steps, so the test_ok log keeps only event + version_id. Also hardens against a future edit that swaps the logged field.
This commit is contained in:
parent
7569bd8250
commit
9a3784c471
1 changed files with 7 additions and 9 deletions
|
|
@ -167,15 +167,13 @@ def _test_secret(client, secret_id: str, token: str) -> None:
|
|||
secret_value
|
||||
):
|
||||
raise ValueError("AWSPENDING keys[0].secret is not 64 lowercase hex chars")
|
||||
logger.info(
|
||||
json.dumps(
|
||||
{
|
||||
"event": "hmac_rotation_test_ok",
|
||||
"version_id": token,
|
||||
"kid": head["kid"],
|
||||
}
|
||||
)
|
||||
)
|
||||
# Log only the rotation token, never a value pulled from the parsed
|
||||
# secret dict. kid is non-sensitive (it rides X-SH-Key-Id in the clear)
|
||||
# and is already logged at stage time in _create_secret, but subscripting
|
||||
# the secret-bearing dict here trips CodeQL's clear-text-logging taint
|
||||
# (py/clear-text-logging-sensitive-data) and is fragile if a later edit
|
||||
# swaps the field -- version_id already correlates this step to the stage.
|
||||
logger.info(json.dumps({"event": "hmac_rotation_test_ok", "version_id": token}))
|
||||
|
||||
|
||||
def _finish_secret(client, secret_id: str, token: str) -> None:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue