procurement-ingest/lambdas/wo/shoc_hmac_rotator
Adam Moussa 9a3784c471
fix(webhook): drop kid from rotator test_ok log (CodeQL clear-text-logging FP)
GHAS CodeQL flagged py/clear-text-logging-sensitive-data (high) at
_test_secret's success log because head["kid"] is subscripted from the
same parsed-secret dict that holds head["secret"] — the taint tracker
can't tell the non-secret key id from the secret. The secret value is
never logged. Rather than dismiss the alert (fragile; re-alerts on line
moves), remove the flow: kid is already logged at stage time in
_create_secret and version_id correlates the steps, so the test_ok log
keeps only event + version_id. Also hardens against a future edit that
swaps the logged field.
2026-07-24 16:51:55 -04:00
..
__init__.py feat(webhook): SHOC WO webhook emitter — dark-ship streams, HMAC secret + rotation 2026-07-24 14:54:07 -04:00
handler.py fix(webhook): drop kid from rotator test_ok log (CodeQL clear-text-logging FP) 2026-07-24 16:51:55 -04:00