From f06ffb6fad6042f5c91267527f827a7c600e5fd5 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 20 Aug 2026 12:15:57 -0400 Subject: [PATCH] fix(api): log user id instead of email on cognito role sync (SEC-29) Keep AuthResponse.Email unchanged so CodeQL alert 1 closes without altering the callback payload. --- api/src/ProposalSystem.Api/Controllers/AuthController.cs | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/api/src/ProposalSystem.Api/Controllers/AuthController.cs b/api/src/ProposalSystem.Api/Controllers/AuthController.cs index afdd9b8..3cfff2a 100644 --- a/api/src/ProposalSystem.Api/Controllers/AuthController.cs +++ b/api/src/ProposalSystem.Api/Controllers/AuthController.cs @@ -120,8 +120,8 @@ public class AuthController : ControllerBase if (user.Role != role) { // Fix: API-M13 — log previous role on Cognito-synced role changes - _logger.LogInformation("User {Email} role changed from {OldRole} to {NewRole} via Cognito sync", - user.Email, user.Role, role); + _logger.LogInformation("User {UserId} role changed from {OldRole} to {NewRole} via Cognito sync", + user.Id, user.Role, role); user.Role = role; changed = true; }