From 216fcb2397405a74bac73b86efbeb1849fb3c52e Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 18 Jun 2026 12:32:46 -0400 Subject: [PATCH] Potential fix for pull request finding 'CodeQL / Exposure of private information' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .../Services/DevEmailService.cs | 19 ++++++++++++++++++- 1 file changed, 18 insertions(+), 1 deletion(-) diff --git a/api/src/ProposalSystem.Api/Services/DevEmailService.cs b/api/src/ProposalSystem.Api/Services/DevEmailService.cs index a0447d6..2eadb9a 100644 --- a/api/src/ProposalSystem.Api/Services/DevEmailService.cs +++ b/api/src/ProposalSystem.Api/Services/DevEmailService.cs @@ -18,9 +18,26 @@ public class DevEmailService : IEmailService string pdfUrl, CancellationToken ct = default) { + var maskedRecipient = MaskEmail(toEmail); _logger.LogInformation( "Dev mode - skipping email delivery: proposal {ProposalNumber} to {Recipient}, PDF link: {PdfUrl}", - proposalNumber, toEmail, pdfUrl); + proposalNumber, maskedRecipient, pdfUrl); return Task.CompletedTask; } + + private static string MaskEmail(string email) + { + if (string.IsNullOrWhiteSpace(email)) + { + return "[redacted]"; + } + + var atIndex = email.IndexOf('@'); + if (atIndex <= 1) + { + return "[redacted]"; + } + + return $"{email[0]}***{email.Substring(atIndex)}"; + } }